VLDB 2026 Research / reviewers in the wild / expert
Shafay Shamail
dblp:37/5730
· DBLP profile ↗
24ranked-venue papers
0as first author
12since 2021 · last 2025
0000-0003-4153-7827ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 8 since 2021Applied, interdisciplinary, general and emerging computing · 6Systems, architecture and hardware · 4 · 2 since 2021Artificial intelligence and machine learning · 2Security and privacy · 2 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Can LLMs Generate Higher Quality Code Than Humans? An Empirical StudyabstractLarge Language Models are being extensively used for AI-assisted programming and code generation. The challenge is to ensure that the generated code is not only functionally correct but also safe, reliable and trustworthy. In this direction, we conduct a comprehensive empirical analysis of AI-generated code to assess whether large language models (LLMs) can produce correct and higher-quality code than humans. We evaluate the code quality of 984 code samples generated by GPT-3.5-Turbo and GPT-4 using various prompt types (simple, instructional, and enhanced) against input queries from the HumanEval dataset. We also enhance the HumanEval benchmark by calculating code quality metrics for the human-written code it contains. Code quality metrics are calculated using established tools like Radon, Bandit, Pylint, and Complexipy, with human-written code serving as a baseline for comparison. To quantify performance, we employ the TOPSIS method to rank the models and human code by their proximity to ideal and anti-ideal code quality metrics. Our results demonstrate that GPT-4, when used with advanced prompts, produces code closest to the ideal solution, outperforming human-written code in several key metrics. Our work provides evidence that LLMs, when properly guided, can surpass human developers in generating high-quality code. Our code and datasets are available online. Mohammad Talal Jamil, Shamsa Abid, Shafay Shamail |
MSR | 3 |
| 2024 | Demo: Orchflow: Orchestration and Management of IoT-Centric Distributed WorkflowsabstractThe evolution of edge and cloud computing infrastructures has opened avenues for developing Internet-centered distributed applications characterized by adaptability, evolvability, and emergence. These applications, such as knowledge-driven distributed workflows are dynamically orchestrated and managed using resources across enterprise networks, cloud data centers, and Internet of Things (IoT) devices. Unlike traditional business processes and scientific workflows, knowledge-driven workflows dynamically evolve and adapt by responding to the environmental context, current execution status, and specific parameters of the case at hand, which are not predictable beforehand. In this demonstration, we present the Orchflow system, designed for dynamic orchestration and management of adaptive IoT-centric workflows. Orchflow enables flexible and location-aware resource selection, iterative and incremental binding, and dynamic deployment of services by considering factors such as spatio-temporal requirements of workflow tasks, resource availability status, underlying service infrastructure constraints, and real-time processing requirements within the workflow. Sehrish Amjad, Ahmed Akhtar, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICDCS | 5 |
| 2024 | Orchestration and Management of Adaptive IoT-Centric Distributed ApplicationsabstractCurrent Internet of Things (IoT) devices provide a diverse range of functionalities, ranging from measurement and dissemination of sensory data observation, to computation services for real-time data stream processing. In extreme situations such as emergencies, a significant benefit of IoT devices is that they can help gain a more complete situational understanding of the environment. However, this requires the ability to utilize IoT resources while taking into account location, battery life, and other constraints of the underlying edge and IoT devices. A dynamic approach is proposed for orchestration and management of distributed workflow applications using services available in cloud data centers, deployed on servers, or IoT devices at the network edge. Our proposed approach is specifically designed for knowledge-driven business process workflows that are adaptive, interactive, evolvable and emergent. A comprehensive empirical evaluation shows that the proposed approach is effective and resilient to situational changes. Sehrish Amjad, Ahmed Akhtar, Ayesha Afzal, Basit Shafiq, Jaideep Vaidya, Shafay Shamail, Omer F. Rana |
IEEE Internet Things J. | 7 |
| 2024 | Blockchain Based Auditable Access Control for Business Processes With Event Driven PoliciesabstractThe use of blockchain technology has been proposed to provide auditable access control for individual resources. Unlike the case where all resources are owned by a single organization, this work focuses on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may have event-driven constraints and can be overlapping in terms of the component conditions/rules as well as events. Existing work cannot handle event-driven constraints and does not sufficiently account for overlaps leading to significant overhead in terms of cost and computation time for evaluating authorizations over the blockchain. In this work, we propose an automata-theoretic approach for generating a cost-efficient composite access control policy. We reduce this composite policy generation problem to the standard weighted set cover problem. We show that the composite policy correctly captures all the local access control policies and reduces the policy evaluation cost over the blockchain. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and empirically validated the effectiveness and efficiency of our approach. Ablation studies were conducted to determine the impact of changes in individual service policies on the overall cost. Ahmed Akhtar, Masoud Barati, Basit Shafiq, Omer F. Rana, Ayesha Afzal, Jaideep Vaidya, Shafay Shamail |
IEEE Trans. Dependable Secur. Comput. | 7 |
| 2023 | Collaborative Business Process Fault Resolution in the Services CloudabstractThe emergence of cloud and edge computing has enabled rapid development and deployment of Internet-centric distributed applications. There are many platforms and tools that can facilitate users to develop distributed business process (BP) applications by composing relevant service components in a plug and play manner. However, there is no guarantee that a BP application developed in this way is fault-free. In this paper, we formalize the problem of collaborative BP fault resolution which aims to utilize information from existing fault-free BPs that use similar services to resolve faults in a user developed BP. We present an approach based on association analysis of pairwise transformations between a faulty BP and existing BPs to identify the smallest possible set of transformations to resolve the fault(s) in the user developed BP. An extensive experimental evaluation over both synthetically generated faulty BPs and real BPs developed by users shows the effectiveness of our approach. Muhammad Adeel Zahid, Basit Shafiq, Jaideep Vaidya, Ayesha Afzal, Shafay Shamail |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | BP-DEBUG: A Fault Debugging and Resolution Tool for Business ProcessesabstractCloud computing and Internet-ware software paradigm have enabled rapid development of distributed business process (BP) applications. Several tools are available to facilitate automated/ semi-automated development and deployment of such distributed BPs by orchestrating relevant service components in a plug-and-play fashion. However, the BPs developed using such tools are not guaranteed to be fault-free. In this demonstration, we present a tool called BP-DEBUG for debugging and automated repair of faulty BPs. BP-DEBUG implements our Collaborative Fault Resolution (CFR) approach that utilizes the knowledge of existing BPs with a similar set of web services fault detection and resolution in a given user BP. Essentially, CFR attempts to determine any semantic and structural differences between a faulty BP and related BPs and computes a minimum set of transformations which can be used to repair the faulty BP. Demo url: https://youtu.be/mf49oSekLOA. Muhammad Adeel Zahid, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICDCS | 3 |
| 2022 | An Integrated Framework for Fault Resolution in Business ProcessesabstractCloud and edge-computing based platforms have enabled rapid development of distributed business process (BP) applications in a plug and play manner. However, these platforms do not provide the needed capabilities for identifying or repairing faults in BPs. Faults in BP may occur due to errors made by BP designers because of their lack of understanding of the underlying component services, misconfiguration of these services, or incorrect/incomplete BP workflow specifications. Such faults may not be discovered at design or development stage and may occur at runtime. In this paper, we present a unified framework for automated fault resolution in BPs. The proposed framework employs a novel and efficient fault resolution approach that extends the generate-and-validate program repair approach. In addition, we propose a hybrid approach that performs fault resolution by analyzing a faulty BP in isolation as well as by comparing with other BPs using similar services. This hybrid approach results in improved accuracy and broader coverage of fault types. We also perform an extensive experimental evaluation to compare the effectiveness of the proposed approach using a dataset of 208 faulty BPs. Muhammad Adeel Zahid, Ahmed Akhtar, Basit Shafiq, Shafay Shamail, Ayesha Afzal, Jaideep Vaidya |
ICWS | 4 |
| 2022 | Context-aware code recommendation in Intellij IDEAabstractDevelopers spend a lot of time online, searching for code to help them implement their desired features. While code recommenders help improve developers’ productivity, there is currently no support for context-aware code recommendation for opportunistic code reuse on-the-go. Typical code recommendation systems provide recommendations against a search query, whereas a code recommender that supports opportunistic reuse can recommend related code snippets that represent features that the developer may want to implement next. In this paper, we present a novel Context-aware Feature-driven API usage-based Code Recommender (CA-FACER) tool, which is an Intellij IDEA plugin that leverages a developer’s development context to recommend related code snippets. We consider the methods having API usages in a developer’s active project as part of the development context. Our approach uses contextual data from a developer’s active project to find similar projects and recommends code from popular features of those projects. The popular features are identified as frequently occurring API usage based Method Clone Classes. From our experimental evaluation on 120 Android Java projects from GitHub, we observe a 46% improvement of precision using our proposed context-aware approach over a baseline system. Our technique recommends related code examples with an average precision ([email protected]) of 94% and 83% and a success rate of 90% and 95% for initial and evolved development stages respectively. A video demonstration of our tool is available at https://youtu.be/UjuM8WRc318. Shamsa Abid, Hamid Abdul Basit, Shafay Shamail |
ESEC/SIGSOFT FSE | 3 |
| 2022 | A Framework for Dynamic Composition and Management of Emergency Response ProcessesabstractAn emergency response process outlines the workflow of different activities that need to be performed in response to an emergency. Effective emergency response requires communication and coordination with the operational systems belonging to different collaborating organizations. Therefore, it is necessary to establish information sharing and system-level interoperability among the diverse operational systems. Unlike typical e-government processes that are well structured and have a well-defined outcome, emergency response processes are knowledge-centric and their workflow structure and execution may evolve as the incident unfolds. It is impractical to define static plans and response process workflows for every possible situation. Instead, a dynamic response should be adaptable to the changing situation. We present an integrated approach that facilitates the dynamic composition of an executable response process. The proposed approach employs ontology-based reasoning to determine the default actions and resource requirements for the given incident and to identify relevant response organizations based on their jurisdictional and mutual aid agreement rules. The Web service APIs of the identified response organizations are then used to generate an executable response process that evolves dynamically. The proposed approach is implemented and experimentally validated using an example scenario derived from the FEMA Hazardous Materials Tabletop Exercises Manual. Abeer Elahraf, Ayesha Afzal, Ahmed Akhtar, Basit Shafiq, Jaideep Vaidya, Shafay Shamail, Nabil R. Adam |
IEEE Trans. Serv. Comput. | 6 |
| 2021 | FACER-AS: An API Usage-based Code Recommendation Tool for Android StudioabstractAndroid developers often need to search for example code to complete their development tasks. While existing code search systems for Android can deliver code against a search query, they do not recommend code for features that a developer might later need to implement. In this paper, we present FACER-AS (FACER for Android Studio); an Android Studio plugin, which uses FACER (Feature-driven API usage-based Code Examples Recommender) as its back-end code search and recommendation engine. FACER provides relevant code against natural language queries (Stage 1) and also recommends code of multiple related features (Stage 2) to facilitate opportunistic code reuse. To evaluate FACER-AS, we perform a user study involving one professional Android developer who uses our tool for the development of their ongoing live Android projects. We analyze the developer's usage of our tool over a span of seven days and find that FACER-AS achieves a 79% success rate for retrieving code against user queries (Stage 1) and a 41% success rate for recommending code for related features (Stage 2). We also observe a 43% reuse rate of Stage 1 recommendations and a 45% reuse rate of Stage 2 recommendations. Our tool's performance analysis and the developer's positive feedback show that FACER-AS can help Android developers with their coding activities. A video demonstration of our tool is available at https://youtu.be/3yN-39wP_FU and the source code of our tool is available at https://doi.org/10.5281/zenodo.5176816. Maha Kamal, Ayman Abaid, Shamsa Abid, Shafay Shamail |
ICSME | 4 |
| 2021 | FACER: An API usage-based code-example recommender for opportunistic reuse
Shamsa Abid, Shafay Shamail, Hamid Abdul Basit, Sarah Nadi |
Empir. Softw. Eng. | 2 |
| 2021 | ASSEMBLE: Attribute, Structure and Semantics Based Service Mapping Approach for Collaborative Business Process DevelopmentabstractDevelopment of a Business Process (BP) is a challenging task for small and medium enterprises (SMEs) which often do not have adequate resources for design, coding, and management of their BPs. Knowledge of existing BPs of related organizations can be exploited for collaborative BP development. However, syntactic and semantic heterogeneity among the Web service operations of BPs across organizations is a major obstacle to such collaborative BP development. In this paper, we propose an approach for collaborative BP development that exploits the attribute and structural similarity of related BPs as well as the semantic information including preconditions and postconditions of operations, to compute a mapping between the available service operations of the user organization and the BP operations of other organizations. We experimentally evaluate the approach with real world data from e-commerce sales BPs and demonstrate its effectiveness. Ayesha Afzal, Basit Shafiq, Shafay Shamail, Abeer Elahraf, Jaideep Vaidya, Nabil R. Adam |
IEEE Trans. Serv. Comput. | 3 |
| 2020 | BP-Com: A Service Mapping Tool for Rapid Development of Business ProcessesabstractBusiness Process (BP) composition is a challenging task for small and medium organizations that do not have sufficient resources for design, coding, and management of their BPs. Cloud infrastructure and service-oriented middleware can be leveraged for rapid development and deployment of BPs of such organizations. BP development in the cloud-based environment can be done by exploiting the knowledge of existing BPs of related organizations. In this demonstration, we present the BP- Com tool which is a Web-based interactive system that enables efficient development of BPs in the cloud. BP-Com implements our service mapping approach called ASSEMBLE that utilizes the attribute, structural and semantics information of service operations of existing BPs in a given domain to help a user organization to compose its BP. Given a collection of related BPs and available service operations of a user organization, BP-Com computes a mapping between the available service operations of the user organization and the BP operations of other organizations. The results of operation mapping are presented to the user for refinement and customization of the generated BP workflow. Executable BP code is then generated in standard BPEL language, which can be deployed on any process execution engine on the user organization's site or on the cloud. Ayesha Afzal, Muhammad Adeel Zahid, Ahmad Akhtar, Basit Shafiq, Shafay Shamail, Abeer Elahraf, Jaideep Vaidya, Nabil R. Adam |
ICDCS | 5 |
| 2020 | Blockchain Based Auditable Access Control for Distributed Business ProcessesabstractThe use of blockchain technology has been proposed to provide auditable access control for individual resources. However, when all resources are owned by a single organization, such expensive solutions may not be needed. In this work we focus on distributed applications such as business processes and distributed workflows. These applications are often composed of multiple resources/services that are subject to the security and access control policies of different organizational domains. Here, blockchains can provide an attractive decentralized solution to provide auditability. However, the underlying access control policies may be overlapping in terms of the component conditions/rules, and simply using existing solutions would result in repeated evaluation of user's authorization separately for each resource, leading to significant overhead in terms of cost and computation time over the blockchain. To address this challenge, we propose an approach that formulates a constraint optimization problem to generate an optimal composite access control policy. This policy is in compliance with all the local access control policies and minimizes the policy evaluation cost over the blockchain. The developed smart contract(s) can then be deployed to the blockchain, and used for access control enforcement. We also discuss how the access control enforcement can be audited using a game-theoretic approach to minimize cost. We have implemented the initial prototype of our approach using Ethereum as the underlying blockchain and experimentally validated the effectiveness and efficiency of our approach. Ahmad Akhtar, Basit Shafiq, Jaideep Vaidya, Ayesha Afzal, Shafay Shamail, Omer F. Rana |
ICDCS | 5 |
| 2015 | Preserving Privacy in Collaborative Business Process CompositionabstractCollaborative business process composition exploits the knowledge of existing business processes of related organizations to compose an executable business process for a given organization based on its requirements and design specifications. Typically, this requires organizations to share and upload their existing business process execution sequences to a central repository. However, even after masking of confidential data, the execution sequences may still include sensitive business information which organizations may not want to share with their competitors. To address this issue, we develop a privacy-preserving Business Process Recommendation and Composition System (BPRCS), that generates a differentially private dataset of execution sequences which can be published and shared with other organizations for composition and implementation of their business processes. We also employ process mining and classification techniques on this differentially private dataset to regenerate the executable business process workflow. We experimentally validate the effectiveness of our approach. Hassaan Irshad, Basit Shafiq, Jaideep Vaidya, Muhammad Ahmed Bashir, Shafay Shamail, Nabil R. Adam |
SECRYPT | 5 |
| 2015 | Improving Recall of software defect prediction models using association mining
Zeeshan Ali Rana, Mian M. Awais, Shafay Shamail |
Knowl. Based Syst. | 3 |
| 2015 | Lean quality improvement model for quality practices in software industry in PakistanabstractAbstract Implementation of quality and achieving quality culture in small and medium software houses (SMSH) have been a subject of discussion among the industry. The existing software process improvement frameworks are too heavy for SMSH. There is a need of lean quality models that will help SMSH in establishing quality culture with minimal effort and resources. The objective of this research study is to map the environment and culture of SMSH in Pakistan towards quality improvement and process improvement by implementing total quality management philosophy. A lean quality improvement model (LQIM) consisting of four quality constructs and 10 quality practices has been proposed. The LQIM is validated using good fit indices in structural equation modeling. At the end, implementation of the proposed LQIM is explained using the Deming's philosophy of plan, do, check, act cycle for continuous process improvement. Copyright © 2015 John Wiley & Sons, Ltd. Faisal Tehseen Shah, Shafay Shamail, Niaz Ahmad Akhtar |
J. Softw. Evol. Process. | 2 |
| 2014 | Impact of Using Information Gain in Software Defect Prediction Models
Zeeshan Ali Rana, Mian M. Awais, Shafay Shamail |
ICIC (1) | 3 |
| 2013 | Identifying Association between Longer Itemsets and Software Defects
Zeeshan Ali Rana, Sehrish Abdul Malik, Shafay Shamail, Mian M. Awais |
ICONIP (3) | 3 |
| 2013 | A Randomized Partitioning Approach for CBR-Based Autonomic Systems to Improve Retrieval PerformanceabstractAutonomic systems exhibit self-managing behavior using various algorithms. Case-based reasoning is one the techniques that enable the autonomic manager to learn from past experience. Case-base is partitioned into some clusters in order to improve the retrieval efficiency. Deciding an appropriate number of clusters for a case-base is not a trivial problem. This paper proposes a randomized algorithm for determining the number of clusters to be formed of the case-base. Subsequently, a binary search-based case retrieval strategy has been applied to ensure enhanced retrieval time performance. The paper presents two versions of the randomized algorithm. The first version guarantees success but its computational cost is a function of random variable; the other guarantees a deterministic computational cost but success is not guaranteed. The performance of the proposed algorithms has been reported on a simulated case study of the Autonomic Forest Fire Application. Malik Jahan Khan, Mian M. Awais, Shafay Shamail |
Comput. J. | 3 |
| 2009 | An FIS for Early Detection of Defect Prone Modules
Zeeshan Ali Rana, Mian M. Awais, Shafay Shamail |
ICIC (2) | 3 |
| 2007 | Arabic Phoneme Identification Using Conventional and Concurrent Neural Networks in Non Native Speakers
Mian M. Awais, Shahid Masud, Junaid Akhtar, Shafay Shamail |
ICIC (1) | 4 |
| 2007 | Achieving Self-configuration Capability in Autonomic Systems Using Case-Based Reasoning with a New Similarity Measure
Malik Jahan Khan, Mian M. Awais, Shafay Shamail |
ICIC (3) | 3 |
| 2004 | A Hybrid Multi-layered Speaker Independent Arabic Phoneme Identification System
Mian M. Awais, Shahid Masud, Shafay Shamail, Junaid Akhtar |
IDEAL | 3 |