Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

Alfusainey Jallow

dblp:385/6372 · DBLP profile ↗
← Back
2ranked-venue papers
2as first author
2since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
2 papers
Software maintenance and evolution · 60% Empirical software engineering · 40%
Network and information security
2 papers
Systems and software security · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Empirical software engineering
mining software repositories
1.122025
Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025
Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024
Software maintenance and evolution › code reuse
code snippet reuse
0.912025
Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025
Systems and software security › software supply chain security
vulnerability propagation
0.812024
Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024
Software maintenance and evolution
code reuse
0.812024
Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024
Systems and software security
vulnerability analysis
0.312025
Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025

Methods — techniques the papers use, named apart from their topics

empirical study · 1.5code clone detection · 1.5
YearPublicationVenuePosition
2025 Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets
Alfusainey Jallow, Sven Bugiel
USENIX Security Symposium1
2024 Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security
abstract
This paper assesses the effects of Stack Overflow code snippet evolution on the security of open-source projects. Users on Stack Overflow actively revise posted code snippets, sometimes addressing bugs and vulnerabilities. Accordingly, developers that reuse code from Stack Overflow should treat it like any other evolving code dependency and be vigilant about updates. It is unclear whether developers are doing so, to what extent outdated code snippets from Stack Overflow are present in GitHub projects, and whether developers miss security-relevant updates to reused snippets.To shed light on those questions, we devised a method to 1) detect outdated code snippets versions from 1.5M Stack Overflow snippets in 11,479 popular GitHub projects and 2) detect security-relevant updates to those Stack Overflow code snippets not reflected in those GitHub projects. Our results show that developers did not update dependent code snippets when those evolved on Stack Overflow. We found that 2,405 code snippet versions reused in 2,109 GitHub projects were outdated, with 43 projects missing fixes to bugs and vulnerabilities on Stack Overflow. Those 43 projects containing outdated, insecure snippets were forked on average 1,085 times (max. 16,121), indicating that our results are likely a lower bound for affected code bases. An important insight from our work is that treating Stack Overflow code as purely static code impedes holistic solutions to the problem of copying insecure code from Stack Overflow. Instead, our results suggest that developers need tools that continuously monitor Stack Overflow for security warnings and code fixes for reused code snippets and not only warn during copy-pasting.
Alfusainey Jallow, Michael Schilling 0001, Michael Backes 0001, Sven Bugiel
SP1