VLDB 2026 Research / reviewers in the wild / expert
Rezwana Karim
dblp:43/6129
· DBLP profile ↗
9ranked-venue papers
3as first author
0since 2021 · last 2020
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 7 · 3 first-authorComputer networks · 1Security and privacy · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Software testing · 38% Concurrent programming · 33% Debugging and program repair · 17% | |
| Network and information security
2 papers |
Systems and software security · 67% Privacy and data protection · 20% Web and mobile security · 13% | |
| Human-computer interaction and pervasive computing
2 papers |
User interface design and tools · 51% Design research and methods · 49% |
Topics — the 12 heaviest of 13, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › information flow tracking
dynamic taint analysis |
0.4 | 1 | 2020 | Platform-Independent Dynamic Taint Analysis for JavaScript · IEEE Trans. Software Eng. 2020 |
Software testing
test generation |
0.3 | 1 | 2018 | Test generation for higher-order functions in dynamic languages · Proc. ACM Program. Lang. 2018 |
Software testing
test oracle |
0.3 | 1 | 2018 | Test generation for higher-order functions in dynamic languages · Proc. ACM Program. Lang. 2018 |
Debugging and program repair
automated program repair |
0.3 | 1 | 2017 | Repairing event race errors by controlling nondeterminism · ICSE 2017 |
Concurrent programming
concurrency bugs |
0.3 | 1 | 2017 | Repairing event race errors by controlling nondeterminism · ICSE 2017 |
Concurrent programming › concurrency bugs
event races |
0.3 | 1 | 2017 | Repairing event race errors by controlling nondeterminism · ICSE 2017 |
Design research and methods › design space
design space exploration |
0.2 | 1 | 2015 | Responsive designs in a snap · ESEC/SIGSOFT FSE 2015 |
User interface design and tools › user interface generation
model-based interface design |
0.2 | 1 | 2013 | Compiling mockups to flexible UIs · ESEC/SIGSOFT FSE 2013 |
Privacy and data protection › differential privacy › privacy auditing
privacy leak detection |
0.1 | 1 | 2020 | Platform-Independent Dynamic Taint Analysis for JavaScript · IEEE Trans. Software Eng. 2020 |
Programming languages and type systems
dynamic languages |
0.1 | 1 | 2018 | Test generation for higher-order functions in dynamic languages · Proc. ACM Program. Lang. 2018 |
Programming languages and type systems › dynamic languages
javascript |
0.1 | 1 | 2018 | Test generation for higher-order functions in dynamic languages · Proc. ACM Program. Lang. 2018 |
Web and mobile security
web application security |
0.1 | 1 | 2017 | Repairing event race errors by controlling nondeterminism · ICSE 2017 |
Methods — techniques the papers use, named apart from their topics
source code instrumentation · 0.6event scheduling control · 0.6program instrumentation · 0.4abstract machine · 0.4combinatorial search · 0.4type inference · 0.3iterative improvement · 0.3callback generation · 0.3design space pruning · 0.2CSS rule-based architecture · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2020 | Platform-Independent Dynamic Taint Analysis for JavaScriptabstractPrevious approaches to dynamic taint analysis for JavaScript are implemented directly in a browser or JavaScript engine, limiting their applicability to a single platform and requiring ongoing maintenance as platforms evolve, or they require nontrivial program transformations. We present an approach that relies on instrumentation to encode taint propagation as instructions for an abstract machine. Our approach has two key advantages: it is platform-independent and can be used with any existing JavaScript engine, and it can track taint on primitive values without requiring the introduction of wrapper objects. Furthermore, our technique enables multiple deployment scenarios by varying when and where the generated instructions are executed and it supports indirect taint sources, i.e., situations where taint enters an application via arguments passed to dynamically registered event-listener functions. We implemented the technique for the ECMAScript 5 language in a tool called Ichnaea, and evaluated it on 22 NPM modules containing several types of injection vulnerabilities, including 4 modules containing vulnerabilities that were not previously discovered and reported. On these modules, run-time overheads range from 3.17x to 38.42x, which is significantly better than a previous transformation-based technique. We also report on a case study that shows how Ichnaea can be used to detect privacy leaks in a Tizen web application for the Samsung Gear S2 smart watch. Rezwana Karim, Frank Tip, Alena Sochurková, Koushik Sen |
IEEE Trans. Software Eng. | 1 |
| 2018 | Test generation for higher-order functions in dynamic languagesabstractTest generation has proven to provide an effective way of identifying programming errors. Unfortunately, current test generation techniques are challenged by higher-order functions in dynamic languages, such as JavaScript functions that receive callbacks. In particular, existing test generators suffer from the unavailability of statically known type signatures, do not provide functions or provide only trivial functions as inputs, and ignore callbacks triggered by the code under test. This paper presents LambdaTester, a novel test generator that addresses the specific problems posed by higher-order functions in dynamic languages. The approach automatically infers at what argument position a method under test expects a callback, generates and iteratively improves callback functions given as input to this method, and uses novel test oracles that check whether and how callback functions are invoked. We apply LambdaTester to test 43 higher-order functions taken from 13 popular JavaScript libraries. The approach detects unexpected behavior in 12 of the 13 libraries, many of which are missed by a state-of-the-art test generator. Marija Selakovic, Michael Pradel, Rezwana Karim, Frank Tip |
Proc. ACM Program. Lang. | 3 |
| 2017 | Repairing event race errors by controlling nondeterminismabstractModern web applications are written in an event-driven style, in which event handlers execute asynchronously in response to user or system events. The nondeterminism arising from this programming style can lead to pernicious errors. Recent work focuses on detecting event races and classifying them as harmful or harmless. However, since modifying the source code to prevent harmful races can be a difficult and error-prone task, it may be preferable to steer away from the bad executions. In this paper, we present a technique for automated repair of event race errors in JavaScript web applications. Our approach relies on an event controller that restricts event handler scheduling in the browser according to a specified repair policy, by intercepting and carefully postponing or discarding selected events. We have implemented the technique in a tool called EventRaceCommander, which relies entirely on source code instrumentation, and evaluated it by repairing more than 100 event race errors that occur in the web applications from the largest 20 of the Fortune 500 companies. Our results show that application-independent repair policies usually suffice to repair event race errors without excessive negative impact on performance or user experience, though application-specific repair policies that target specific event races are sometimes desirable. Christoffer Quist Adamsen, Anders Møller, Rezwana Karim, Manu Sridharan, Frank Tip, Koushik Sen |
ICSE | 3 |
| 2015 | Responsive designs in a snapabstractWith the massive adoption of mobile devices with different form- factors, UI designers face the challenge of designing responsive UIs which are visually appealing across a wide range of devices. De- signing responsive UIs requires a deep knowledge of HTML/CSS as well as responsive patterns - juggling through various design configurations and re-designing for multiple devices is laborious and time-consuming. We present DECOR, a recommendation tool for creating multi-device responsive UIs. Given an initial UI de- sign, user-specified design constraints and a list of devices, DECOR provides ranked, device-specific recommendations to the designer for approval. Design space exploration involves a combinatorial explosion: we formulate it as a design repair problem and devise several design space pruning techniques to enable efficient repair. An evaluation over real-life designs shows that DECOR is able to compute the desired recommendations, involving a variety of responsive design patterns, in less than a minute. Nishant Sinha 0001, Rezwana Karim |
ESEC/SIGSOFT FSE | 2 |
| 2014 | Retargetting Legacy Browser Extensions to Modern Extension Frameworks
Rezwana Karim, Mohan Dhawan, Vinod Ganapathy |
ECOOP | 1 |
| 2013 | Compiling mockups to flexible UIsabstractAs the web becomes ubiquitous, developers are obliged to develop web applications for a variety of desktop and mobile platforms. Re- designing the user interface for every such platform is clearly cumbersome. We propose a new framework based on model-based compilation to assist the designer in solving this problem. Starting from an under-specified visual design mockup drawn by the designer, we show how faithful and flexible web pages can be obtained with virtually no manual effort. Our framework, in sharp contrast to existing web design tools, overcomes the tough challenges involved in mockup compilation by (a) employing combinatorial search to infer hierarchical layouts and (b) mechanizing adhoc principles for CSS design into a modular, extensible rule-based architecture. We believe ours is the first disciplined effort to solve the problem and will inspire rapid, low-effort web design. Nishant Sinha 0001, Rezwana Karim |
ESEC/SIGSOFT FSE | 2 |
| 2012 | An Analysis of the Mozilla Jetpack Extension Framework
Rezwana Karim, Mohan Dhawan, Vinod Ganapathy, Chung-chieh Shan |
ECOOP | 1 |
| 2011 | Fast, memory-efficient regular expression matching with NFA-OBDDs
Rezwana Karim, Vinod Ganapathy, Randy Smith |
Comput. Networks | 2 |
| 2010 | Improving NFA-Based Signature Matching Using Ordered Binary Decision Diagrams
Rezwana Karim, Vinod Ganapathy, Randy Smith |
RAID | 2 |