VLDB 2026 Research / reviewers in the wild / expert
Mahzabin Tamanna
dblp:345/3770
· DBLP profile ↗
7ranked-venue papers
2as first author
7since 2021 · last 2025
0009-0005-3162-7580ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 3 · 1 first-author · 3 since 2021Security and privacy · 2 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Your Build Scripts Stink: The State of Code Smells in Build ScriptsabstractBuild scripts automate the process of compiling source code, managing dependencies, running tests, and packaging software into deployable artifacts. These scripts are ubiquitous in modern software development pipelines for streamlining testing and delivery. While developing build scripts, practitioners may inadvertently introduce code smells, which are recurring patterns of poor coding practices that may lead to build failures or increase risk and technical debt. The goal of this study is to aid practitioners in avoiding code smells in build scripts through an empirical study of build scripts and issues on GitHub. We employed a mixed-methods approach, combining qualitative and quantitative analysis. First, we conducted a qualitative analysis of 2000 build-script-related GitHub issues to understand recurring smells. Next, we developed a static analysis tool, Sniffer, to automatically detect code smells in 5882 build scripts of Maven, Gradle, CMake, and Make files, collected from 4877 open-source GitHub repositories. To assess Sniffer’s performance, we conducted a user study, where Sniffer achieved higher precision, recall, and F-score. We identified 13 code smell categories, with a total of 10,895 smell occurrences, where 3184 were in Maven, 1214 in Gradle, 337 in CMake, and 6160 in Makefiles.Our analysis revealed that Insecure URLs were the most prevalent code smell in Maven build scripts, while Hardcoded Paths/URLs were commonly observed in both Gradle and CMake scripts. Wildcard Usage emerged as the most frequent smell in Makefiles. The co-occurrence analysis revealed strong associations between specific smell pairs of Hardcoded Paths/URLs with Duplicates, and Inconsistent Dependency Management with Empty or Incomplete Tags, which indicate potential underlying issues in the build script structure and maintenance practices. Based on our findings, we also recommended strategies to remove code smells in build scripts to improve the efficiency, reliability, and maintainability of software projects. Mahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski, Laurie A. Williams, Dominik Wermke |
ASE | 1 |
| 2025 | How Do Undergraduates Interested in Computer Science Use Online, On-Demand CS Coursework?abstractStudents often enroll in university programs to learn the skills necessary to enter the workforce or attend a graduate program. However, students feel an increasing need to supplement their degree programs with online, on-demand (OOD) coursework. Undergraduate computer science (CS) students' motivations for taking OOD CS coursework, how they perceive their usage of OOD CS coursework, and why they stop are not well understood. To address this research gap, we surveyed 51 undergraduate students enrolled in or interested in computer science about their attitudes and usage of OOD CS coursework. We additionally interviewed four of the survey takers to understand the factors that drove them to enroll and stop OOD CS coursework. Our results showed that students perceived OOD CS coursework positively. There is a positive correlation between student self-perceptions of learning during OOD CS coursework and intentions to persist in OOD CS coursework. Students reported primarily using OOD coursework to prepare for interviews and build skills for their resumes. The main reason for attrition was the loss of trial access and replacement by LLMs such as ChatGPT. The contributions of this work include design insights for OOD CS platforms to increase retention and lower attrition, and the understanding that undergraduate CS students perceive free OOD CS coursework as a useful tool to supplement their undergraduate studies. Sam Gilson, Tiffany Barnes, Mahzabin Tamanna, Saminur Islam |
L@S | 3 |
| 2025 | Security implications of user non-compliance behavior to software updates: A risk assessment studyabstractSoftware updates are essential to enhance security, fix bugs, and add better features to the existing software. While some users accept software updates, non-compliance remains a widespread issue. End users’ systems remain vulnerable to security threats when security updates are not installed or are installed with a delay. Despite research efforts, users’ noncompliance behavior with software updates is still prevalent. In this study, we explored how psychological factors influence users’ perception and behavior toward software updates. In addition, we investigated how information about potential vulnerabilities and risk scores influence their behavior. Next, we proposed a model that utilizes attributes from the National Vulnerability Database (NVD) to effectively assess the overall risk score associated with delaying software updates. Next, we conducted a user study with Windows OS users, showing that providing a risk score for not updating their systems and information about vulnerabilities significantly increased users’ willingness to update their systems. Additionally, we examined the influence of demographic factor, gender, on users’ decision-making regarding software updates. Our results show no statistically significant difference in male and female users’ responses in terms of concerns about securing their system. The implications of this study are relevant for software developers and manufacturers as they can use this information to design more effective software update notification messages. The communication of the potential risks and their corresponding risk scores may motivate users to take action and update their systems in a timely manner, which can ultimately improve the overall security of the system. Mahzabin Tamanna, Mohd Anwar, Joseph D. W. Stephens |
J. Inf. Secur. Appl. | 1 |
| 2025 | Research Directions in Software Supply Chain SecurityabstractReusable software libraries, frameworks, and components, such as those provided by open source ecosystems and third-party suppliers, accelerate digital innovation. However, recent years have shown almost exponential growth in attackers leveraging these software artifacts to launch software supply chain attacks. Past well-known software supply chain attacks include the SolarWinds, log4j, and xz utils incidents. Supply chain attacks are considered to have three major attack vectors: through vulnerabilities and malware accidentally or intentionally injected into open source and third-party dependencies/components/containers ; by infiltrating the build infrastructure during the build and deployment processes; and through targeted techniques aimed at the humans involved in software development, such as through social engineering. Plummeting trust in the software supply chain could decelerate digital innovation if the software industry reduces its use of open source and third-party artifacts to reduce risks. This article contains perspectives and knowledge obtained from intentional outreach with practitioners to understand their practical challenges and from extensive research efforts. We then provide an overview of current research efforts to secure the software supply chain. Finally, we propose a future research agenda to close software supply chain attack vectors and support the software industry. Laurie A. Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, William Enck |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2025 | Trusting Code in the Wild: Exploring Contributor Reputation Measures to Review Dependencies in the Rust EcosystemabstractDevelopers rely on open-source packages and must review dependencies to safeguard against vulnerable or malicious upstream code. A careful review of all dependencies changes often does not occur in practice. Therefore, developers need signals to inform of dependency changes that require additional examination, particularly measures for contributor reputation. The goal of this study is to help developers prioritize dependency review efforts by analyzing contributor reputation measures as a signal in the Rust ecosystem. We use network centrality measures to proxy contributor reputation using collaboration activity. We employ a mixed method methodology from the top 1,644 packages in the Rust ecosystem to build a network of 6,949 developers, survey 285 developers, and model 5 centrality measures. Through our survey, we find that only 24% of respondents often review dependencies before adding or updating a package, mentioning difficulties in the review process and signals are therefore employed. Particularly, 51% of respondents often consider contributor reputation when reviewing dependencies. We further explore contributor reputation through network centrality measures employing multivariate mixed-effect linear regression models. We find that the closeness centrality measure is a significant factor in explaining how developers choose to review dependencies. Yet, centrality measures alone do not account for how developers choose to review dependencies. We recommend the Rust ecosystem implement a contributor reputation badge based on our modeled coefficients to complement developers’ dependency review efforts. Sivana Hamer, Nasif Imtiaz, Mahzabin Tamanna, Preya Shabrina, Laurie A. Williams |
IEEE Trans. Software Eng. | 3 |
| 2024 | Towards a Taxonomy of Challenges in Security Control ImplementationabstractCybersecurity researchers and practitioners identify and design security controls (e.g., the use of strong passwords), which refer to the countermeasures and safeguards to protect information systems’ confidentiality, integrity, and availability. The effectiveness of controls depends on their implementation. However, controls may have technical and operational issues that challenge effective implementation. Systematizing such challenges would benefit practitioners in enhancing their defense. The goal of this study is to aid security practitioners in defending against cyberattacks by constructing a taxonomy of challenges in security control implementation. We first obtain information regarding the challenges of implementing security control, cataloged in MITRE ATT&CK, using three Large Language Models: ChatGPT, Gemini, and Copilot. Then, using inductive coding and reflexive thematic analysis, we construct a taxonomy comprising 73 challenges across 8 high-level categories and map the taxonomy with the security controls. We perform a case study on attack techniques in MITRE ATT&CK to identify the challenges associated with security controls for mitigating prevalent attack techniques. We identify that 9 out of 24 prevalent attack techniques do not have any security controls. The rest of the prevalent techniques can be defended. However, the effectiveness of the controls associated with the rest of the prevalent techniques can be limited due to the following: human resources requirements, false positive issues, static detection rules, disruption, and user inconvenience. Our work highlights that security control implementation is subjective, where a diverse set of organizational, technical, human, and external factors can impact its implementation. We recommend organizations not treating security controls as a ticking-off checklist, rather resolve the impeding issues in their implementation. Rayhanur Rahman, Brandon Wroblewski, Mahzabin Tamanna, Imranur Rahman, Andrew Anufryienak, Laurie A. Williams |
ACSAC | 3 |
| 2023 | Comparing Foraging Behavior Across Code Hosting and Q&A Platforms Through a Gender LensabstractThis study compares the information foraging behavior of developers on two prominent platforms, StackOverflow and GitHub, which are widely used for code hosting and question and answer purposes. Understanding how developers seek and retrieve information is crucial for designing effective interfaces. In a gender and expertise-balanced study involving 12 developers, we utilized Information Foraging Theory to analyze their foraging behavior. Our findings revealed contrasting patterns, with women spending 30% more time and utilizing 21.24% more cues on GitHub, while men utilized 55% more time and 19.7% more cues on StackOverflow. These insights have significant implications for optimizing website design and information presentation to enhance the efficiency and effectiveness of developers' information seeking processes. Shahnewaz Leon, Mahzabin Tamanna, Sandeep Kaur Kuttal |
VL/HCC | 2 |