Anna Rita Fasolino

dblp:40/6176 · DBLP profile ↗
← Back
53ranked-venue papers
2as first author
17since 2021 · last 2026
0000-0001-7116-019XORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 49 · 2 first-author · 16 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Databases, data management, data science and information retrieval · 1
YearPublicationVenuePosition
2026 CIAO - Code In Architecture Out - Automated Software Architecture Documentation with Large Language Models
abstract
Software architecture documentation is essential for system comprehension, yet it is often unavailable or incomplete. While recent LLM-based techniques can generate documentation from code, they typically address local artifacts rather than producing coherent, system-level architectural descriptions. This paper presents a structured process for automatically generating system-level architectural documentation directly from GitHub repositories using Large Language Models. The process, called CIAO (Code In Architecture Out), defines an LLM-based work-flow that takes a repository as input and produces system-level architectural documentation following a template derived from ISO/IEC/IEEE 42010, SEI Views & Beyond, and the C4 model. The resulting documentation can be directly added to the target repository. We evaluated the process through a study with 22 developers, each reviewing the documentation generated for a repository they had contributed to. The evaluation shows that developers generally perceive the produced documentation as valuable, comprehensible, and broadly accurate with respect to the source code, while also highlighting limitations in diagram quality, high-level context modeling, and deployment views. We also assessed the operational cost of the process, finding that generating a complete architectural document requires only a few minutes and is inexpensive to run. Overall, the results indicate that a structured, standards-oriented approach can effectively guide LLMs in producing system-level architectural documentation that is both usable and cost-effective.
Tiziano Santilli, Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione
ICSA4
2026 A decontextualized LLM-based safeguard technique for automated jailbreak mitigation
abstract
Context: Large Language Models (LLMs) are increasingly deployed in high-risk settings, where harmful or unethical outputs remain a risk. Adversarial prompting (“jailbreaks”) can circumvent default safeguards. Emerging regulation (e.g., the EU AI Act) demands proactive controls that verify outputs before delivery. Objectives: We present and evaluate D-SHIELD, a plugin-based safeguard that separates generation from validation via a stateless, decontextualized validator. Objectives are to assess alignment with expert judgments, evaluate end-to-end mitigation on publicly sourced jailbreaks, compare with representative plugin-based defenses, and examine a lightweight configuration optimized for cost without reducing protection. Methods: D-SHIELD routes candidate responses from the user-facing LLM to a secondary, decontextualized LLM operating in isolation (no prompt or conversation context) to classify each response based on indications of prohibited content derived from the EU AI Act, The General-Purpose AI Code of Practice, GDPR, and provider policies. This decontextualized design intentionally prevents prompt contamination, adversarial framing, and conversational drift from influencing the validation decision, addressing key weaknesses of context-aware validators. We create an expert-labeled dataset from designed jailbreaks for direct comparison with the decontextualized validator’s classification. We then embed the validator in a working prototype and evaluate on publicly sourced jailbreaks. Finally, we conduct a comparative study against baseline jailbreak-mitigation techniques and analyze a lightweight guard variant. Results: The decontextualized validator closely aligns with expert decisions, especially for explicit harms, while adopting a conservative stance on borderline cases. In prototype evaluation on publicly sourced jailbreaks, the safeguard blocked most harmful responses. Compared with baselines, D-SHIELD yields fewer successful attacks under a common benchmark. The lightweight variant delivers comparable protection at markedly lower cost. Conclusion: Decontextualized, output-level validation provides an effective, regulation-aligned solution for LLM safety. Restricting the validator to the generated text complements input-level defenses and supports practical deployment, particularly in a lightweight configuration.
Tiziano Santilli, Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione
Inf. Softw. Technol.4
2026 Statistical-based metric threshold setting method for software fault prediction in firmware projects: An industrial experience
abstract
Ensuring software quality in embedded firmware is critical, especially in safety-critical domains such as automotive systems, where compliance with functional safety standards like ISO 26262 requires strong guarantees of software reliability. While machine learning-based fault prediction models have demonstrated high accuracy, their lack of transparency and interpretability limits their adoption in industrial settings. Developers need actionable insights that can be directly employed in software quality assurance (SQA) processes and guide defect mitigation strategies. In this paper, we present a structured process for defining context-specific software metric thresholds suitable for integration into fault detection workflows in industrial settings. Our approach supports cross-project fault prediction by deriving thresholds from one set of projects and applying them to independently developed firmware, thereby enabling reuse across similar software systems without retraining or domain-specific tuning. We analyze three real-world C-embedded firmware projects provided by an industrial partner, using Coverity and Understand static analysis tools to extract software metrics. Through statistical analysis and hypothesis testing, we identify discriminative metrics and derived empirical threshold values capable of distinguishing faulty from non-faulty functions. The derived thresholds are then validated through an experimental evaluation, demonstrating their effectiveness in identifying fault-prone functions with high precision. The results confirm that statistically derived thresholds can serve as a practical and interpretable solution for fault prediction, aligning with industry standards and SQA practices. This approach provides a practical alternative to black-box AI models, allowing developers to systematically assess software quality, take preventive actions, and integrate metric-based fault prediction into industrial development workflows to mitigate software faults.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana
J. Syst. Softw.3
2025 Automated Software Architecture Design Recovery from Source Code Using LLMs
Domenico Amalfitano, Tiziano Santilli, Patrizio Pelliccione, Anna Rita Fasolino
ECSA5
2025 Rookie Mistakes: Measuring Software Quality in Student Projects to Guide Educational Enhancement
Sergio Di Martino, Sergio Di Meglio, Anna Rita Fasolino, Luigi L. L. Starace, Porfirio Tramontana
SEAA (3)4
2025 Translating code with Large Language Models and human-in-the-loop feedback
abstract
Context: In recent years, the code translation task has arisen as one of the major software issues in maintaining software quality during migration over complex infrastructure. This task involves human subjects with different background knowledge and could introduce errors due to the semantic gap between the programming languages and the complexity of the task. Generative Artificial Intelligence (AI) showed good capabilities in code generation, albeit this is highly dependent on the human factor . Objective: This paper investigates, from the human perspective, the use of three Generative AI tools (ChatGPT, Google Bard, and GitHub Copilot) in the context of translation tasks from code written in query languages to code written in framework-specific code languages, specifically focused on SQL dialects and PySpark. This translation is especially crucial during the migration from centralized architectures to cloud-based architectures. Methods: We evaluate the usefulness of these tools, the quality of the generated code, and their impact on performance. The models are tested with queries of various type in three different SQL dialects considering three usage scenarios of increasing complexity. It involves 15 participants with diverse programming backgrounds, who aim to solve tasks by interacting multiple times with the tools and manually changing the code. Results: The findings show a positive performance, demonstrating their reliability in generating coherent translations, achieving 100% precision in most tasks with a slight decrease in more complex scenarios, and producing well-documented code, with a response time of under 2 min, with Google Bard responding 50% faster than the others. Conclusion: In conclusion, this paper establishes a methodology and both quantitative and qualitative metrics for evaluating how generative AI tools streamline code translation, shifting the emphasis from production to refinement. It underscores the importance of continuously improving these tools to integrate them into developers’ workflows and to provide guidelines for intelligent use.
Gabriele Dario De Siano, Anna Rita Fasolino, Giancarlo Sperlì, Andrea Vignali
Inf. Softw. Technol.2
2025 A GUI-based Metamorphic Testing Technique for Detecting Authentication Vulnerabilities in Android Mobile Apps
abstract
The increasing use of mobile apps in daily life involves managing and sharing sensitive user information. New vulnerabilities are frequently reported in bug tracking systems, highlighting the need for effective security testing processes for these applications. This study introduces a GUI-based Metamorphic Testing technique designed to detect five common real-world vulnerabilities related to username and password authentication methods in Android applications, as identified by OWASP. We developed five Metamorphic Relationships to test for these vulnerabilities and implemented a Metamorphic Vulnerability Testing Environment to automate the technique. This environment facilitates the generation of Source test case and the automatic creation and execution of Follow-up test case . The technique was applied to 163 real-world Android applications, uncovering 159 vulnerabilities. Out of these, 108 apps exhibited at least one vulnerability. The vulnerabilities were validated through expert analysis conducted by three security professionals, who confirmed the issues by interacting directly with the app’s graphical user interfaces (GUIs). Additionally, to assess the practical relevance of our approach, we engaged with 37 companies whose applications were identified as vulnerable. Nine companies confirmed the vulnerabilities, and 26 updated their apps to address the reported issues. Our findings also indicate a weak inverse correlation between user-perceived quality and vulnerabilities; even highly rated apps can harbor significant security flaws.
Domenico Amalfitano, Misael Costa Júnior, Anna Rita Fasolino, Márcio Eduardo Delamaro
J. Syst. Softw.3
2024 Automatic Assessment of Architectural Anti-patterns and Code Smells in Student Software Projects
abstract
When teaching Programming and Software Engineering in Bachelor’s Degree programs, the emphasis on creating functional software projects often overshadows the focus on software quality, a trend consistent with ACM curricula recommendations. Dedicated Software Engineering courses take typically place in the later stages of the curriculum, and allocate only limited time to software quality, leaving educators with the difficult task of deciding which quality aspects to prioritize. To educate students on the importance of developing high-quality code, it is important to introduce these skills as part of the assessment criteria. To this end, we have implemented a pipeline based on advanced frameworks such as ArchUnit and SonarQube. It was successfully tested on a class of students engaged in the Object Oriented Programming course, demonstrating its usefulness as a resource for educators and providing some concrete evidence of quality problems in student projects.
Sergio Di Meglio, Anna Rita Fasolino, Luigi L. L. Starace, Porfirio Tramontana
EASE3
2024 Automated Architecture Recovery for Embedded Software Systems: An Industrial Case Study
Domenico Amalfitano, Domenico Francesco De Angelis, Anna Rita Fasolino
ECSA4
2024 Characterizing Software Architectural Metrics for Continuous Compliance in the Automotive Domain
abstract
The software of critical systems, such as automotive, is increasingly required to change and evolve after production. In the automotive domain, this is a consequence of self-driving and connected cars, which continuously collect data from the field that is then exploited to produce safer and more advanced and reliable versions of the used algorithms or AI modules. Consequently, there exists a need for techniques and tools to facilitate incremental and Continuous Compliance with safety and security standards. This paper focuses on software architectural metrics that can be used for Continuous Compliance in the automotive domain. Our initial stride involved a literature review to find metrics capable of assessing software architectures. Subsequently, in collaboration with architecture, safety, and security experts in the automotive domain, we proposed a framework defining the characteristics these metrics must possess for continuous evaluation of software architectural compliance. The framework was used to characterize 48 metrics gathered from the literature review and to associate them with a score expressing their suitability to be used in software architecture Continuous Compliance processes.
Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione, Tiziano Santilli
ICSA3
2024 State of the Practice in Software Testing Teaching in Four European Countries
abstract
Software testing is an indispensable component of software development, yet it often receives insufficient attention. The lack of a robust testing culture within computer science and informatics curricula contributes to a shortage of testing expertise in the software industry. Addressing this problem at its root -education- is paramount. In this paper, we conduct a comprehensive mapping review of software testing courses, elucidating their core attributes and shedding light on prevalent subjects and instructional methodologies. We mapped 117 courses offered by Computer Science (and related) degrees in 49 academic institutions from four Western European countries, namely Belgium, Italy, Portugal and Spain. The testing subjects were mapped against the conceptual framework provided by the ISO/IEC/IEEE 29119 standard on software testing. Among the results, the study showed that dedicated software testing courses are offered by only 39% of the analysed universities, whereas the basics of software testing are taught in at least one course at every university. The analysis of the software testing topics highlights the gaps that need to be filled in order to better align the current academic offerings with the real industry needs.
Porfirio Tramontana, Beatriz Marín, Ana C. R. Paiva, Alexandra Mendes, Tanja E. J. Vos, Domenico Amalfitano, Felix Cammaerts, Monique Snoeck, Anna Rita Fasolino
ICST9
2024 Investigating the robustness of locators in template-based Web application testing using a GUI change classification model
abstract
GUI-based test-cases generated by Capture and Replay tools suffer from the well-known fragility problem: they may break even if small layout changes are operated in a Web application, without modifying the app functionality. An approach based on the automatic injection of HTML tag attributes named hooks in the source code of Web templates has been recently proposed to solve this problem. Such hooks allow the unique identification of GUI items to be located during test case execution. This technique showed its effectiveness in a preliminary validation study, where it allowed to significantly reduce the number of test case locator breakages in regression testing of student-made Web applications. This paper presents a further validation study where we compared the robustness of hook-based test cases against state-of-the-art and state-of-the-practice techniques for locating GUI objects. We proposed a three dimensional model for classifying different types of layout changes and used it to define a benchmark of realistic changes. Thanks to the model, we systematically compared the robustness of test cases generated by different techniques with respect to specific types of changes and studied the relationship between fragility issues and types of changes in different test case generation techniques.
Anna Rita Fasolino, Porfirio Tramontana
J. Syst. Softw.2
2024 GUI testing of Android applications: Investigating the impact of the number of testers on different exploratory testing strategies
abstract
Abstract Graphical user interface (GUI) testing plays a pivotal role in ensuring the quality and functionality of mobile apps. In this context, exploratory testing (ET), a distinctive methodology in which individual testers pursue a creative, and experience‐based approach to test design, is often used as an alternative or in addition to traditional scripted testing. Managing the exploratory testing process is a challenging task that can easily result either in wasteful spending or in inadequate software quality, due to the relative unpredictability of exploratory testing activities, which depend on the skills and abilities of individual testers. A number of works have investigated the diversity of testers' performance when using ET strategies, often in a crowdtesting setting. These works, however, investigated ET effectiveness in detecting bugs, and not in scenarios in which the goal is to generate a re‐executable test suite, as well. Moreover, less work has been conducted on evaluating the impact of adopting different exploratory testing strategies. As a first step toward filling this gap in the literature, in this work, we conduct an empirical evaluation involving four open‐source Android apps and 20 masters students that we believe can be representative of practitioners partaking in exploratory testing activities. The students were asked to generate test suites for the apps using a capture and replay tool and different exploratory testing strategies. We then compare the effectiveness, in terms of aggregate code coverage that different‐sized groups of students using different exploratory testing strategies may achieve. Results provide deeper insights into code coverage dynamics to project managers interested in using exploratory approaches to test simple Android apps, on which they can make more informed decisions.
Sergio Di Martino, Anna Rita Fasolino, Luigi L. L. Starace, Porfirio Tramontana
J. Softw. Evol. Process.2
2023 A community detection approach based on network representation learning for repository mining
Anna Rita Fasolino, Antonino Ferraro, Vincenzo Moscato, Giancarlo Sperlì, Porfirio Tramontana
Expert Syst. Appl.2
2022 Towards the Generation of Robust E2E Test Cases in Template-based Web Applications
abstract
Capture and Replay techniques provide a well-known solution for End-To-End (E2E) testing of Web applications. They allow a tester to generate test scripts without requiring advanced programming skills. For this reason, they are very popular in acceptance and regression testing activities. These techniques are affected by the issue of fragility of the produced test cases, which may break even if small changes are operated in the user interface, without modifications of the app functionality. To overcome this issue, several approaches for either generating robust test cases or automatically repairing broken test cases have been proposed. In this paper we propose an alternative solution that aims at improving the testability of Web applications for generating robust test cases. This solution applies to Web applications developed with template-based technologies. It is based on the template source code automatic injection of additional hook attributes and on the proposal of a new type of locators based on such hooks. These locators aid the unique retrieval of the user interface items involved in test cases. We validated our technique in the context of a continuous integration and delivery processes of template-based web applications that was developed from scratch. The study showed that the use of hook-based locators can improve the robustness of test cases generated by a Capture & Replay testing tool, introducing relevant savings in the regression test case repairing activity.
Anna Rita Fasolino, Porfirio Tramontana
SEAA1
2022 Alternatives for testing of context-aware software systems in non-academic settings: results from a Rapid Review
abstract
Context: Context-awareness challenges the engineering of contemporary software systems and jeopardizes their testing. The variation of context represents a relevant behavior that deepens the limitations of available software testing practices and technologies. However, such software systems are mainstream. Therefore, researchers in non-academic settings also face challenges when developing and testing contemporary soft-ware systems. Objective: To understand how researchers deal with the variation of context when testing context-aware software systems developed in non-academic settings. Method: To undertake a secondary study (Rapid Review) to uncover the necessary evidence from primary sources describing the testing of context-aware software systems outside academia. Results: The current testing initiatives in non-academic settings aim to generate or improve test suites that can deal with the context variation and the sheer volume of test input possibilities. They mostly rely on modeling the systems' dynamic behavior and increasing computing resources to generate test inputs to achieve this. We found no evidence of test results aiming at managing context variation through the testing lifecycle process. Conclusions: So far, the identified testing initiatives and strategies are not ready for mainstream adoption. They are all domain-specific, and while the ideas and approaches can be reproduced in distinct settings, the technologies are to be re-engineered and tailored to the context-awareness of contemporary software systems in different problem domains. Further and joint investigations in academia and experiences in non-academic settings can evolve the body of knowledge regarding the testing of contemporary soft-ware systems in the field.
Santiago Matalonga, Domenico Amalfitano, Andréa Cristina de Souza Doreste, Anna Rita Fasolino, Guilherme Horta Travassos
Inf. Softw. Technol.4
2021 Comparing the effectiveness of capture and replay against automatic input generation for Android graphical user interface testing
abstract
Summary Exploratory testing and fully automated testing tools represent two viable and cheap alternatives to traditional test‐case‐based approaches for graphical user interface (GUI) testing of Android apps. The former can be executed by capture and replay tools that directly translate execution scenarios registered by testers in test cases, without requiring preliminary test‐case design and advanced programming/testing skills. The latter tools are able to test Android GUIs without tester intervention. Even if these two strategies are widely employed, to the best of our knowledge, no empirical investigation has been performed to compare their performance and obtain useful insights for a project manager to establish an effective testing strategy. In this paper, we present two experiments we carried out to compare the effectiveness of exploratory testing approaches using a capture and replay tool (Robotium Recorder) against three freely available automatic testing tools (AndroidRipper, Sapienz, and Google Robo). The first experiment involved 20 computer engineering students who were asked to record testing executions, under strict temporal limits and no access to the source code. Results were slightly better than those of fully automated tools, but not in a conclusive way. In the second experiment, the same students were asked to improve the achieved testing coverage by exploiting the source code and the coverage obtained in the previous tests, without strict temporal constraints. The results of this second experiment showed that students outperformed the automated tools especially for long/complex execution scenarios. The obtained findings provide useful indications for deciding testing strategies that combine manual exploratory testing and automated testing.
Sergio Di Martino, Anna Rita Fasolino, Luigi L. L. Starace, Porfirio Tramontana
Softw. Test. Verification Reliab.2
2020 A Technique for Parallel GUI Testing of Android Applications
Porfirio Tramontana, Nicola Amatucci, Anna Rita Fasolino
ICTSS3
2020 A model-driven engineering approach for supporting questionnaire-based gap analysis processes through application lifecycle management systems
Domenico Amalfitano, Vincenzo De Simone, Stefano Scala, Anna Rita Fasolino
Softw. Qual. J.4
2019 Combining Automated GUI Exploration of Android apps with Capture and Replay through Machine Learning
Domenico Amalfitano, Vincenzo Riccio, Nicola Amatucci, Vincenzo De Simone, Anna Rita Fasolino
Inf. Softw. Technol.5
2019 Using tool integration for improving traceability management testing processes: An automotive industrial experience
abstract
Abstract Despite the high relevance of traceability in software processes, the activities of traceability creation and management are not always adequately supported in practice. The lack of integration between the tools adopted in the development processes is one of the main causes of such an ineffective management, where traceability relationships are still manually generated and maintained. In this paper we present an industrial experience we performed for improving the traceability management in a testing process performed in the Fiat Chrysler Automobiles company. In this context, we carried out a process for analyzing and identifying the main issues due to the ineffective traceability management and proposed a solution for addressing them. We designed and implemented a software architecture for integrating the existing application lifecycle management platform with the tools used in the process with the aim of automating the process execution and the traceability links management. The new architecture was validated by a case study that showed how the integration solution produced beneficial effects on quality attributes of the testing process.
Domenico Amalfitano, Vincenzo De Simone, Raffaele Rodolfo Maietta, Stefano Scala, Anna Rita Fasolino
J. Softw. Evol. Process.5
2019 Automated functional testing of mobile applications: a systematic mapping study
Porfirio Tramontana, Domenico Amalfitano, Nicola Amatucci, Anna Rita Fasolino
Softw. Qual. J.4
2019 Developing and Evaluating Objective Termination Criteria for Random Testing
abstract
Random testing is a software testing technique through which programs are tested by generating and executing random inputs. Because of its unstructured nature, it is difficult to determine when to stop a random testing process. Faults may be missed if the process is stopped prematurely, and resources may be wasted if the process is run too long. In this article, we propose two promising termination criteria, “All Equivalent” (AEQ) and “All Included in One” (AIO), applicable to random testing. These criteria stop random testing once the process has reached a code-coverage-based saturation point after which additional testing effort is unlikely to provide additional effectiveness. We model and implement them in the context of a general random testing process composed of independent random testing sessions. Thirty-six experiments involving GUI testing and unit testing of Java applications have demonstrated that the AEQ criteria is generally able to stop the process when a code coverage equal or very near to the saturation level is reached, while AIO is able to stop the process earlier in cases it reaches the saturation level of coverage. In addition, the performance of the two criteria has been compared against other termination criteria adopted in the literature.
Porfirio Tramontana, Domenico Amalfitano, Nicola Amatucci, Atif M. Memon, Anna Rita Fasolino
ACM Trans. Softw. Eng. Methodol.5
2018 Exploiting ALM and MDE for Supporting Questionnaire-Based Gap Analysis Processes
abstract
Gap Analysis is a common approach in industry to evaluate the gaps between the implemented software processes and the requirements suggested by both Process Quality Frameworks and Standards. Gap Analysis processes are usually executed by approaches based on questionnaires that need to be crafted ad-hoc according to specific appraisal goals and submitted to the industrial personnel. The approaches used for developing, compiling and evaluating the answers given to these questionnaires do not follow well-defined methodologies or processes, and lack of adequate tool support. In this paper we aim at understanding the main issues affecting Questionnaire-based Gap Analysis processes in industrial practices. Moreover, we evaluate the feasibility of adopting state-of-the-art software engineering technologies for executing such processes. We propose a novel approach based on Application Lifecycle Management for configuring and enacting Questionnaire-based Gap Analysis processes. The approach exploits Model Driven Engineering for configuring and implementing the Application Lifecycle Management system. This configuration activity is aided by a tool, named GADGET, we developed for modeling the process and automatically transforming it towards the Application Lifecycle Management technology.
Vincenzo De Simone, Domenico Amalfitano, Anna Rita Fasolino
SEAA3
2018 Why does the orientation change mess up my Android application? From GUI failures to code faults
abstract
Summary This paper investigates the failures exposed in mobile apps by the mobile‐specific event of changing the screen orientation. We focus on GUI failures resulting in unexpected GUI states that should be avoided to improve the apps quality and to ensure better user experience. We propose a classification framework that distinguishes 3 main classes of GUI failures due to orientation changes and exploit it in 2 studies that investigate the impact of such failures in Android apps. The studies involved both open‐source and apps from Google Play that were specifically tested exposing them to orientation change events. The results showed that more than 88% of these apps were affected by GUI failures, some classes of GUI failures were more common than others, and some GUI objects were more frequently involved. The app source code analysis allowed us to identify 6 classes of common faults causing specific GUI failures.
Domenico Amalfitano, Vincenzo Riccio, Ana C. R. Paiva, Anna Rita Fasolino
Softw. Test. Verification Reliab.4
2017 Improving traceability management through tool integration: an experience in the automotive domain
abstract
Despite the relevance of traceability in software processes is well-known, the activities of traceability creation and management are not always adequately supported in real software projects. The lack of integration between the tools adopted in the development processes is one of the main causes of such an ineffective management, where traceability relationships are still manually generated and maintained. In this paper we present an industrial experience we performed for improving the traceability management in a software development process performed in Fiat Chrysler Automobiles FCA company. We designed a software architecture for integrating the existing Application Lifecycle Management (ALM) platform with the tools used in the testing process. The architecture aimed at fully automating the execution of the testing process and at automatically generating the appropriate traceability links when they are established. It was implemented using a Continuous Integration Engine that allowed us to develop a modular, evolvable and reconfigurable integration architecture. The new architecture was validated by an experiment that showed its capability in correctly and completely generating and handling traceability links between artifacts involved in the testing process. The experiment demonstrated that the integration solution produced also beneficial effects on other quality attributes of the process.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Stefano Scala
ICSSP3
2017 A general framework for comparing automatic testing techniques of Android mobile apps
Domenico Amalfitano, Nicola Amatucci, Atif M. Memon, Porfirio Tramontana, Anna Rita Fasolino
J. Syst. Softw.5
2016 Introducing Software Product Lines in Model-Based Design Processes: An Industrial Experience
abstract
Software has gained a critical role in the automotive domain that is becoming more and more complex. The ever-growing complexity in automotive software development is due to its high variability. In this scenario, automotive companies need to adopt cost-effective development processes in order to manage the variability of the produced software. A well-known solution for dealing with this problem is the adoption of Software Product Lines (SPL). In this paper we report an experience we performed in collaboration with the Fiat Chrysler Automobiles (FCA) company for the application of the SPL in one of its Model-Based Design (MBD) processes. SPL were supported by AutoMative, a software infrastructure we implemented for the semi-automatic generation of Product Architectures from specification documents.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Mario Lubrano, Stefano Scala
WICSA3
2016 EXACT: A tool for comprehending VBA-based Excel spreadsheet applications
abstract
Spreadsheet applications are widely adopted by millions of end users from several application domains and provide strategic support to many business, scientific, industrial, and organizational processes. These applications are usually developed by rapid application development processes, exploiting host scripting languages allowing the basic spreadsheets to provide complex functionality, business rules, and user interfaces. Several factors complicate the comprehension of these applications because they are usually developed and maintained by end users without specific software engineering skills, grow over time, are not adequately documented, and do not present explicit separation between data, business logic, and user interface layers. This paper presents a reverse engineering tool intended to support the comprehension of Excel spreadsheet applications developed using the Visual Basic for Application programming language. The tool has been implemented as an add-in that extends the Excel working environment by providing analysis and visualization features. It is able to extract information about the elements composing the analyzed Excel spreadsheet application, the functionality it exposes through its user interface, and the dependencies among its cells. This information is provided by means of interactive views. The validity of the tool has been assessed by a qualitative case study performed with professional end users from an automotive industrial domain. Copyright © 2016 John Wiley & Sons, Ltd.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Porfirio Tramontana
J. Softw. Evol. Process.3
2014 Information Extraction from Legacy Spreadsheet-based Information System - An Experience in the Automotive Context
abstract
Nevertheless spreadsheets were originally designed for computing purposes and for commercial applications, they are often used in industry to implement Information Systems, thanks to the functionalities offered by integrated scripting languages and ad-hoc frameworks (e.g., Visual Basic for Applications). This technological solution allows the adoption of Rapid Application Development processes for the quickly development of Spreadsheets-based Information Systems, but the resulting systems are quite difficult to be maintained and very difficult to be migrated to other architectures such as Database-oriented Informative Systems or Web applications. In this paper we present an approach for reverse engineering the data model from an Excel spreadsheet-based system in the context of a process of migration to a Web based application based on a MVC architecture. The proposed approach was successfully applied in a real context of a company operating in the automotive industry. The main contribution of this paper is represented by the Data Model Reverse Engineering activity that is the basis of the Migration process.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Vincenzo De Simone, Giancarlo Di Mare, Stefano Scala
DATA2
2012 A toolset for GUI testing of Android applications
abstract
This paper presents a toolset for GUI testing of Android applications. The toolset is centered on a GUI ripper that systematically explores the GUI structure of an application under test with the aim of firing sequences of user events and exposing failures of the application. The toolset supports the execution of a testing procedure that automatically performs crash testing of subject applications and provides test results made of several artifacts. The paper illustrates some examples of using the toolset for testing real Android applications.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Salvatore De Carmine, Gennaro Imparato
ICSM2
2012 Using GUI ripping for automated testing of Android applications
abstract
We present AndroidRipper, an automated technique that tests Android apps via their Graphical User Interface (GUI). AndroidRipper is based on a user-interface driven ripper that automatically explores the app’s GUI with the aim of exercising the application in a structured manner. We evaluate AndroidRipper on an open-source Android app. Our results show that our GUI-based test cases are able to detect severe, previously unknown, faults in the underlying code, and the structured exploration outperforms a random approach.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Salvatore De Carmine, Atif M. Memon
ASE2
2011 Ensuring Semantic Interoperability for e-Health Applications
abstract
The exchange of information between heterogeneous and distributed health information systems preserving the semantics is an important open issue for the health care sector. In this paper, we propose an approach that, exploiting the Semantic Web technologies, has the objective of allowing semantic interoperability among software agents for e-Health applications that preserves, not only the semantic of transmitted messages, but also the subjectivity of agent's world vision in the communication The proposed approach exploits the Semantic Triangle Model to differentiate the roles of referents (real world objects) and concepts (mental image or impression about a real object) in the communication process and ensures an effective semantic interoperability without the need of a unique shared conceptualization.
Flora Amato, Anna Rita Fasolino, Antonino Mazzeo, Vincenzo Moscato, Antonio Picariello, Sara Romano, Porfirio Tramontana
CISIS2
2011 A Novel Approach for Semantic Interoperability in the Web Based on the Semantic Triangle Communication Model
abstract
In this paper we propose a novel communication approach and a possible implementation of it that, exploiting the Semantic Web technologies, allows semantic interoperability among software agents in the Web, preserving not only the semantics but also the subjectivity of the agent's world vision in the communication. Such an approach takes advantage of a particular communication model called Semantic Triangle in which communication agents share the referents (real world objects) and not the concepts (mental image or impression of a real object from the sender agents point of view), thus ensuring an effective semantic interoperability in the information exchange process. The proposed approach has been submitted to an experiment that involved an instantiation of the communication process based on semantic machines and showed the approach feasibility for the semantic information exchange and its effectiveness.
Angelo Chianese, Anna Rita Fasolino, Vincenzo Moscato, Porfirio Tramontana, Mario Caropreso
Int. J. Softw. Eng. Knowl. Eng.2
2010 DynaRIA: A Tool for Ajax Web Application Comprehension
abstract
Thanks to Rich Internet Applications (RIAs) with their enhanced interactivity, responsiveness and dynamicity, the user experience in the Web 2.0 is becoming more and more appealing and user-friendly. At the same time, the dynamic nature of RIAs, and the heterogeneous technologies, frameworks, communication models used for implementing them negatively affect their analyzability and understandability, so that specific software techniques and tools are needed for supporting their comprehension. This paper presents DynaRIA, a tool for the comprehension of RIAs implemented in Ajax that is based on dynamic analysis and provides functionalities for recording and analyzing user sessions from several perspectives, and producing various types of abstractions and visualizations about the run-time behaviour of the application.
Domenico Amalfitano, Anna Rita Fasolino, Armando Polcaro, Porfirio Tramontana
ICPC2
2009 Experimenting a reverse engineering technique for modelling the behaviour of rich internet applications
abstract
While the rapid and growing diffusion of rich Internet applications (RIAs) with their enhanced interactive, responsive and dynamic behaviour is sharpening the distance between Web applications and desktop applications, at the same time, the maintenance community is experiencing the need for effective analysis approaches for understanding and modelling this behaviour adequately. This paper presents a reverse engineering technique based on dynamic analysis and supported by a tool that reconstructs a model of the RIA behaviour based on finite state machines. The technique is based on the analysis of the RIA user interface evolution shown in user sessions, and exploits user interface equivalence criteria for abstracting relevant states and state transitions to be included in the model. For assessing the effectiveness and the cost of this technique, an experiment involving four distinct RIAs implemented with AJAX technique was carried out.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana
ICSM2
2009 Using Ontologies to Achieve Semantic Interoperability in the Web: An Approach Based on the Semantic Triangle Model
abstract
In this paper, we propose an architecture that, exploiting the Semantic Web technologies, has the objective of allowing semantic interoperability among software agents in the Web. Such an architecture takes advantage by the Semantic Triangle model in which communication agents share the referents (real world objects) and not the references (mental image of a real object of the sender agent), thus ensuring an effective semantic interoperability in the information exchange process. We have carried a case study in order to assess the appropriateness and the feasibility of the process for the semantic information exchange by realizing and testing an instantiation of the related architecture.
Angelo Chianese, Anna Rita Fasolino, Vincenzo Moscato, Porfirio Tramontana
ISDA2
2008 A wrapping approach for migrating legacy system interactive functionalities to Service Oriented Architectures
Gerardo Canfora, Anna Rita Fasolino, Gianni Frattolillo, Porfirio Tramontana
J. Syst. Softw.2
2007 Web Pages Classification using Concept Analysis
abstract
Analysis and classification of Web application user interfaces is a relevant problem in Web maintenance processes. This paper presents an approach for the reliable classification of HTML pages of a dynamic Web application. The approach is based on the assumption that groups of semantically equivalent built pages are characterized by the same key features which can be used for discriminating the pages. These features are obtained by an iterative process that exploits formal concept analysis for finding features that are specific for each class of pages. The process is supported by a toolkit that allows an effective definition of the discriminating features. The approach has been preliminarily validated with an experiment that produced encouraging results.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Porfirio Tramontana
ICSM2
2007 A policy-based evaluation framework for Quality and Security in Service Oriented Architectures
abstract
In dynamic cooperative architectures that are based on services (SOA), customers are not only interested in service functionalities, but also in their quality, such as performance, cost, reliability, security and so on. In this scenario, models, techniques and tools supporting the selection of the best service are needed. In this paper, we propose an evaluation framework that includes a flexible quality meta-model for formalising customer and provider views of quality, and a decisional model defining a systematic approach for comparing offered and requested quality of services. We also illustrate the applicability of the framework in a Web service (WS) scenario.
Valentina Casola, Anna Rita Fasolino, Nicola Mazzocca, Porfirio Tramontana
ICWS2
2006 Testing Web-based applications: The state of the art and future trends
Giuseppe A. Di Lucca, Anna Rita Fasolino
Inf. Softw. Technol.2
2004 Supporting Concept Assignment in the Comprehension of Web Applications
abstract
An approach providing automatic support in the assignment of concepts to documents recovered by reverse engineering Web applications is presented. Web pages composing Web applications usually include relevant textual information from the domain of the application, while different editing formats are used for emphasising to the end users the various concepts provided by the pages. The proposed concept assignment approach exploits both the textual information contained in the Web pages, and the editing formal used to display it in order to identify automatically a set of candidate concepts describing a Web page or a set of pages. These concepts can be used by maintainers involved in the task of assigning a meaning to software artefacts recovered by reverse engineering the Web applications. Validation experiments carried out with Web applications selected from the real world showed the validity of the proposed approach. The experimental results are presented in the paper.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Porfirio Tramontana, Ugo de Carlini
COMPSAC2
2004 Reverse engineering Web applications: the WARE approach
abstract
Abstract The rapid, progressive diffusion of Web applications in several productive contexts of our modern society is laying the foundations of a renewed scenario of software development, where one of the emerging problems is that of defining and validating cost‐effective approaches for maintaining and evolving these software systems. Due to several factors, the solution to this problem is not straightforward. The heterogeneous and dynamic nature of components making up a Web application, the lack of effective programming mechanisms for implementing basic software engineering principles in it, and undisciplined development processes induced by the high pressure of a very short time‐to‐market, make Web application maintenance a challenging problem. A relevant issue consists of reusing the methodological and technological experience in the sector of traditional software maintenance, and exploring the opportunity of using reverse engineering to support effective Web application maintenance. This paper presents an approach for defining reverse engineering processes involving Web applications. The approach has been used to implement a process, including reverse engineering methods and a supporting software tool, that helps to understand existing undocumented Web applications to be maintained or evolved, through the reconstruction of UML diagrams. The proposed reverse engineering process has been submitted to a validation experiment, the results of which showed the usability of the process for reverse engineering Web applications with different characteristics, and highlighted possible areas for improvement of its effectiveness. The experiment and the lessons learned from it are presented in the paper. Copyright © 2004 John Wiley & Sons, Ltd.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Porfirio Tramontana
J. Softw. Maintenance Res. Pract.2
2003 Recovering a Business Object Model from Web Applications
abstract
The growing market request for Web applications is forcing software industries to produce applications under the pressure of a short time-to-market and a strong competition, with the consequence that low quality and poor documented software is often produced. Maintaining, evolving or comprehending these applications are not straightforward tasks, and reverse engineering processes should be defined and validated to support them. In this paper a reverse engineering approach for reconstructing an object-oriented conceptual model of the application domain of a Web application is presented. The proposed approach defines a process that reconstructs the model in three steps. In each step, heuristic criteria exploiting source code analysis are used for the identification of objects and their relationships. Tools for implementing this method have been produced, and experiments for validating it have been carried out with the support of case studies. Experimental results showed the feasibility and the effectiveness of the proposed approach.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Porfirio Tramontana, Ugo de Carlini
COMPSAC2
2002 An Approach to Identify Duplicated Web Pages
abstract
A relevant consequence of the expansion of the web and e-commerce is the growth of the demand of new web sites and web applications. As a result, web sites and applications are usually developed without a formalized process, and web pages are directly coded in an incremental way, where new pages are obtained by duplicating existing ones. Duplicated web pages, having the same structure and just differing for the data they include, can be considered as clones. The identification of clones may reduce the effort devoted to test, maintain and evolve web sites and applications. Moreover, clone detection among different web sites aims to detect cases of possible plagiarism. In this paper we propose an approach. based on similarity metrics, to detect duplicated pages in web sites and applications, implemented with HTML language and ASP technology. The proposed approach has been assessed by analyzing several web sites and Web applications. The obtained results are reported in the paper with respect to some case studies.
Giuseppe A. Di Lucca, Massimiliano Di Penta, Anna Rita Fasolino
COMPSAC3
2002 Testing Web Applications
abstract
The rapid diffusion of Internet and open standard technologies is producing a significant growth of the demand of Web sites and Web applications with more and more strict requirements of usability, reliability, interoperability and security. While several methodological and technological proposals for developing Web applications are coining both from industry and academia, there is a general lack of methods and tools to carry out the key processes that significantly impact the quality of a Web application (WA), such as the validation & verification (V&V), and quality assurance. Some open issues in the field of Web application testing are addressed in this paper. The paper exploits an object-oriented model of a WA as a test model, and proposes a definition of the unit level for testing the WA. Based on this model, a method to test the single units of a WA and for the integration testing is proposed. Moreover, in order to experiment with the proposed technique and strategy, an integrated platform of tools comprising a Web application analyzer, a repository, a test case generator and a test case executor, has been developed and is presented in the paper. A case study, carried out with the aim of assessing the effectiveness of the proposed method and tools, produced interesting and encouraging results.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Francesco Faralli, Ugo de Carlini
ICSM2
2001 A Decisional Framework for Legacy System Management
abstract
Making a decision about how to evolve a legacy system cannot be made spontaneously; rather, it requires a decisional framework that takes into account several factors including software value, risk analysis, and cost estimation. We present a decisional framework to manage legacy systems that exploits an assessment model and a taxonomy of maintenance interventions a legacy system can undergo during its life-cycle. The decisional framework has been defined within a pilot project involving a major international software enterprise. The project aims at assessing and improving the current practices of the organization and at experimenting software maintenance processes conducted by teams distributed at different sites in a cooperative networking environment.
Andrea De Lucia, Anna Rita Fasolino, Eugenio Pompella
ICSM2
2000 Recovering Class Diagrams from Data-Intensive Legacy Systems
abstract
Several reverse engineering methods for recovering objects from legacy systems have been proposed in the literature, but most of them neglect to identify the relationships among the objects, or recover only a part of them. The paper describes a method for recovering an OO (object oriented) model together with the objects and relationships among them. The proposed approach integrates the results of reverse engineering of both the procedural code and the persistent data stores of the system, and exploits a number of heuristic criteria to obtain a class diagram. A preliminary experiment carried out to validate the method on a COBOL medium-sized system yielded encouraging results.
Giuseppe A. Di Lucca, Anna Rita Fasolino, Ugo de Carlini
ICSM2
2000 Metrics in the development and maintenance of software: an application in a large scale environment
abstract
The importance of metrics in software projects is well known. Assessing and controlling quality and productivity in large scale environments requires the establishment of software measurement systems for both products and processes. Product and process measurements should be considered simultaneously to assess software projects effectively. Unfortunately, measurement programs are rarely carried out extensively in practice or they just provide a limited set of sample data. This paper reports experience with software measurement systems gained in a large scale environment and describes an approach whereby product and process measurements can be jointly used to assess and control project evolution. In the paper, data collection and data analysis techniques are presented to describe a solution for a real organization. Insights into how to make decisions about software projects and set the goals for improvement are made. Copyright © 2000 John Wiley & Sons, Ltd.
Anna Rita Fasolino, Domenico Natale, Alessio Poli, Alessandro Alberigi Quaranta
J. Softw. Maintenance Res. Pract.1
1999 Identifying objects in legacy systems using design metrics
Aniello Cimitile, Andrea De Lucia, Giuseppe A. Di Lucca, Anna Rita Fasolino
J. Syst. Softw.4
1997 Migrating Legacy Systems towards Object-Oriented Platforms
abstract
Presents an approach to migrate legacy systems to object-oriented platforms. The process consists of six sequential phases and encompasses reverse engineering and re-engineering activities. The aim of the reverse engineering phases is to decompose programs into components implementing user interface management and components implementing application domain objects. The identification of objects is centred around a persistent data store and exploits object-oriented design metrics. Wrapping techniques are the core of the re-engineering activities. They make new systems able to exploit existing resources, thus allowing an incremental and selective translation of the identified objects
Giuseppe A. Di Lucca, Anna Rita Fasolino, Patrizia Guerra, Silvia Petruzzelli
ICSM2
1995 Towards reengineering in reuse reengineering processes
abstract
Reuse of existing software has been regarded in recent years as a feasible solution to software quality and productivity improvement problems. Various reference paradigms for setting up a reuse reengineering process have been proposed. With reference to the RE/sup 2/ (Reverse Engineering and Reuse Reengineering) paradigm, this paper addresses the problems of the election phase. In particular, by describing an approach to the reuse reengineering of COBOL programs, it tackles the transformation of a set of candidate components into a set of actually reusable modules. This involves the identification of a module template that allows the COBOL code components to be easily reused, and the definition of reverse engineering and reengineering techniques to package the components into the template.
Gerardo Canfora, Anna Rita Fasolino, Maria Tortorella
ICSM2
1993 Reuse Reengineering and Validation via Concept Assignment
abstract
The first step in a software reuse reengineering process is to analyze the structural characteristics of the existing software so as to produce software component sets, each of which is a candidate for clustering and reengineering into a reusable module. This step is founded on one or more candidature criteria and the cost of the following steps depends on their quality. The notions of completeness and adequacy as applied to candidature criteria are introduced, the need for an adequacy validation process before they are applied on a software system is outlined. An adequate validation process founded on the assignment of a concept to the candidate modules is proposed, and the results of an application of this process are described and discussed.>
Aniello Cimitile, Anna Rita Fasolino, Paolo Maresca
ICSM2