Chris Porter

dblp:45/9784 · DBLP profile ↗
← Back
14ranked-venue papers
4as first author
8since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 9 · 4 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 4 · 3 since 2021Artificial intelligence and machine learning · 3 · 1 since 2021Systems, architecture and hardware · 3 · 2 first-author · 3 since 2021
YearPublicationVenuePosition
2025 Tackling ML-based Dynamic Mispredictions using Statically Computed Invariants for Attack Surface Reduction
abstract
Recent work has demonstrated the utility of machine learning (ML) in carrying out highly accurate predictions at runtime. One of the major challenges with using ML, however, is that the predictions lack certain guarantees. For such approaches to become practicable in security settings involving debloating and dynamic control flow monitoring, one must distinguish between mispredictions vs. attacks.
Chris Porter, Sharjeel Khan, Kangqi Ni, Santosh Pande
ASPLOS (2)1
2024 How Can Heuristics Be Communicated?
abstract
This position paper proposes a model for choosing how to communicate heuristics in a meaningful, usable and accessible manner. The model is a matrix of nine shapes, where we define ‘shape’ as a combination of the heuristic’s format and its directiveness. Examining heuristics used in UX and software testing practices, we found a variety of formats and levels of directiveness. We discuss these shapes with example heuristics from UX, software testing, and everyday life. We present the outcome from a pilot of the model in one specific context. The shape of a heuristic may contribute to its understandability and usefulness in specific contexts, while different contexts may necessitate different ways of communicating heuristics. This includes considering the effect that the shape of a heuristic has on its accessibility and inclusion, suggesting that shape may be one important aspect of heuristics’ design and evaluation.
Isabel Evans, Chris Porter, Mark Micallef
CHIRA (1)2
2024 Remapping the Document Object Model using Geometric and Hierarchical Data Structures for Efficient Eye Control
abstract
The Web Content Accessibility Guidelines (WCAG) are there to ensure that websites are perceivable, operable, understandable and robust across different user agents and assistive technologies. However, people who rely on eye trackers (ETs) may find that even WCAG-compliant websites are hard to access, and this is further accentuated by designs that offer little to no affordances for ET interaction. Areas with a high density of interactive elements, along with hierarchical navigation menus, such as megamenus or fly-out menus, are just two examples where ET interaction can be problematic. This paper introduces two novel interaction patterns as part of a purpose-built gaze-native web browser (Cactus), namely (a) Quadtree-based Target Selection with Secondary Confirmation and (b) Hierarchical Re-rendering of Navigation Menus. We present results from a between-subject single-blind study with 30 participants and report on metrics such as performance, perceived workload and usability, with demonstrable improvements over the state of the art.
Daniel Vella, Chris Porter
Proc. ACM Hum. Comput. Interact.2
2023 Decker: Attack Surface Reduction via On-Demand Code Mapping
abstract
Modern code reuse attacks take full advantage of bloated software. Attackers piece together short sequences of instructions in otherwise benign code to carry out malicious actions. Mitigating these reusable code snippets, known as gadgets, has become one of the prime focuses of attack surface reduction research. While some debloating techniques remove parts of software that contain such gadgets, other methods focus on making them unusable by breaking up chains of them, thereby substantially diminishing the possibility of code reuse attacks. Third-party libraries are another main focus, because they exhibit a high number of vulnerabilities, but recently, techniques have emerged that deal with whole applications. Attack surface reduction efforts have typically tried to eliminate such attacks by subsetting (debloating) the application, e.g. via user-specified inputs, configurations, or features to achieve high gadget reductions. However, such techniques suffer from the limitations of soundness, i.e. the software might crash during no-attack executions on regular inputs, or they may be conservative and leave a large amount of attack surface untackled.
Chris Porter, Sharjeel Khan, Santosh Pande
ASPLOS (2)1
2023 Towards Gesture Based Assistive Technology for Persons Experiencing Involuntary Muscle Contractions
Christine Pocock, Chris Porter, May Agius
CHIRA (1)2
2023 Beacons: An End-to-End Compiler Framework for Predicting and Utilizing Dynamic Loop Characteristics
abstract
Efficient management of shared resources is a critical problem in high-performance computing (HPC) environments. Existing workload management systems often promote non-sharing of resources among different co-executing applications to achieve performance isolation. Such schemes lead to poor resource utilization and suboptimal process throughput, adversely affecting user productivity. Tackling this problem in a scalable fashion is extremely challenging, since it requires the workload scheduler to possess an in-depth knowledge about various application resource requirements and runtime phases at fine granularities within individual applications. In this work, we show that applications’ resource requirements and execution phase behaviour can be captured in a scalable and lightweight manner at runtime by estimating important program artifacts termed as “ dynamic loop characteristics ”. Specifically, we propose a solution to the problem of efficient workload scheduling by designing a compiler and runtime cooperative framework that leverages novel loop-based compiler analysis for resource allocation . We present Beacons Framework , an end-to-end compiler and scheduling framework, that estimates dynamic loop characteristics, encapsulates them in compiler-instrumented beacons in an application, and broadcasts them during application runtime, for proactive workload scheduling. We focus on estimating four important loop characteristics : loop trip-count , loop timing , loop memory footprint , and loop data-reuse behaviour , through a combination of compiler analysis and machine learning. The novelty of the Beacons Framework also lies in its ability to tackle irregular loops that exhibit complex control flow with indeterminate loop bounds involving structure fields, aliased variables and function calls , which are highly prevalent in modern workloads. At the backend, Beacons Framework entails a proactive workload scheduler that leverages the runtime information to orchestrate aggressive process co-locations, for maximizing resource concurrency, without causing cache thrashing . Our results show that Beacons Framework can predict different loop characteristics with an accuracy of 85% to 95% on average, and the proactive scheduler obtains an average throughput improvement of 1.9x (up to 3.2x ) over the state-of-the-art schedulers on an Amazon Graviton2 machine on consolidated workloads involving 1000-10000 co-executing processes, across 51 benchmarks.
Girish Mururu, Sharjeel Khan, Bodhisatwa Chatterjee, Chao Chen 0024, Chris Porter, Ada Gavrilovska, Santosh Pande
Proc. ACM Program. Lang.5
2022 CASE: a compiler-assisted SchEduling framework for multi-GPU systems
abstract
Modern computing platforms tend to deploy multiple GPUs on a single node to boost performance. GPUs have large computing capacities and are an expensive resource. Increasing their utilization without causing performance degradation of individual workloads is an important and challenging problem. Although services such as NVIDIA's MPS allow multiple cooperative kernels to simultaneously run on a single device, they do not solve the co-execution problem for uncooperative, independent kernels on such a multi-GPU system. To tackle this problem, we propose CASE --- a fully automated compiler-assisted scheduling framework. During the compilation of an application, CASE constructs GPU tasks from CUDA programs and instruments the code with a probe before each one. At runtime, each probe conveys information about its task's resource requirements such as memory and the number of streaming multiprocessor (SMs) needed to a user-level scheduler. The scheduler then places each task onto a suitable device by employing a policy appropriate to the system. In our prototype, a throughput-oriented scheduling policy is implemented to evaluate our resource-aware scheduling framework. The Rodinia benchmark suite and the Darknet neural network framework were used in our evaluation. The results show that, as compared to existing state-of-the-art methods, CASE improves throughput by up to 2.5X for Rodinia, and up to 2.7X for Darknet on modern NVIDIA GPU platforms, mainly due to the fact that it improves the average system utilization by up to 3.36X and the job turnaround time by up to 4.9X. Meanwhile, it limits individual kernel performance degradation within 2.5%. CASE achieved peak system utilization of 78% for Rodinia and 80% for Darknet on a 4XV100 system.
Chao Chen 0024, Chris Porter, Santosh Pande
PPoPP2
2022 Investigating Cognitive Workload during Comprehension and Application Tasks in Software Testing
abstract
Software testers are an integral part of software development teams, and consequently need to understand from different perspectives the project entrusted to them.While developers might be required to understand a particular module or area of specialisation within a project, testers' comprehension requirements are more far-reaching [1].Gaining insights into how testers fare in different comprehension tasks is useful because it sheds light on how we could potentially support the efforts of the testing community.This paper reports the results of a laboratory experiment involving 15 professional software testers.Using NASA Task Load Index as our instrument of choice, we asked participants to carry out eight comprehension and application tasks across four categories (test case design, test automation, bug finding and adequacy analysis).We then analysed the data collected to seek to understand the effect of different task types, education level and participant experience on effectiveness and cognitive workload.The results suggest that, while experience is a key element in successful task completion, this is also influenced by task type.In fact, the more experienced persons actually tended to fare worse than their less experienced counterparts in certain tasks (namely, test case design and adequacy analysis).Level of education had no significant bearing on successful task completion but differences in cognitive workload could be observed for both experience and education-level variables.
Daryl Camilleri, Mark Micallef, Chris Porter
SEKE3
2020 Towards Accurate Browser-based SSVEP Stimuli Generation
Alison Camilleri, Chris Porter, Tracey A. Camilleri
CHIRA2
2020 BlankIt library debloating: getting what you want instead of cutting what you don't
abstract
Modern software systems make extensive use of libraries derived from C and C++. Because of the lack of memory safety in these languages, however, the libraries may suffer from vulnerabilities, which can expose the applications to potential attacks. For example, a very large number of return-oriented programming gadgets exist in glibc that allow stitching together semantically valid but malicious Turing-complete and -incomplete programs. While CVEs get discovered and often patched and remedied, such gadgets serve as building blocks of future undiscovered attacks, opening an ever-growing set of possibilities for generating malicious programs. Thus, significant reduction in the quantity and expressiveness (utility) of such gadgets for libraries is an important problem.
Chris Porter, Girish Mururu, Prithayan Barua, Santosh Pande
PLDI1
2019 Towards human-centric software testing
abstract
Software testing is widely perceived to be the main activity in the software development process that provides confidence in the quality of a product prior to release.However, the term software testing itself provokes a multitude of different definitions and opinions as to the nature of the profession, the role of software testers and the utility of different processes and tools that come with the territory [1][2].We argue that in order for researchers to effectively study the field and contribute to its progress, a consensus first needs to be reached about the entity being studied.In this paper we present an empirical study based on the modified Delphi card sort method involving four cohorts of testers in Malta and London.The result of this study is a consolidated consensus-based mental model outlining how software testers perceive their profession.This mental model can be used to align any future research efforts and tool development with testers' own perception of their context.
Samantha Catania, Chris Porter, Mark Micallef
SEKE2
2019 Towards Detecting and Managing Information Anxiety in the ICT Industry
abstract
Information Anxiety is defined as "stress caused by the inability to access, understand, or make use of information necessary for employees to do their job".Even though it is in itself an intangible phenomenon, it is widely acknowledged and has been linked to impaired decision-making ability, information withdrawal, information avoidance, burnout and other health issues.The ICT industry is acknowledged to be a fully fledged knowledge industry.That is to say that its workers are mainly tasked with creating, understanding, applying and distributing knowledge as part of their day-to-day job.The industry is also characterised by disruptive innovations, continuously changing technologies and customers who constantly change their mind about what they want systems to do.In this paper, we present the results of a study which tracked 18 participants for a period of one month in order to investigate the presence of information anxiety in the Maltese ICT industry.Our results indicate that information anxiety is present in nontrivial levels amongst our cohort of participants, with information overload being the predominant cause.Also, participants working in a quality assurance (QA) function are more exposed to the phenomenon as well as being exposed to a wider variety of sources of anxiety than developers.Experience is also shown to be a factor with participants being less prone to symptoms of information overload as they gain more experience in the field.
Mark Micallef, Chris Porter
SEKE2
2015 Poster: Is Carmen Better than George? Testing the Exploratory Tester Using HCI Techniques
abstract
Exploratory software testing is an activity which can be carried out by both untrained and formally trained testers. In this paper, we propose using Human Computer Interaction (HCI) techniques to carry out a study of exploratory testing strategies used by the two groups of testers. This data will be used to make recommendations to companies with regards to the mix of skills and training required for testing teams.
Andrea Borg, Chris Porter, Mark Micallef
ICSE (2)2
2014 Building a National E-Service using Sentire experience report on the use of Sentire: A volere-based requirements framework driven by calibrated personas and simulated user feedback
abstract
User experience (UX) is difficult to quantify and thus more challenging to require and guarantee. It is also difficult to gauge the potential impact on users' lived experience, especially at the earlier stages of the development life cycle, particularly before hi fidelity prototypes are developed. We believe that the enrolment process is a major hurdle for e-government service adoption and badly designed processes might result in negative repercussions for both the policy maker and the different user groups involved; non-adoption and resentment are two risks that may result in low return on investment (ROI), lost political goodwill and ultimately a negative lived experience for citizens. Identity assurance requirements need to balance out the real value of the assets being secured (risk) with the user groups' acceptance thresholds (based on a continuous cost-benefit exercise factoring in cognitive and physical workload). Sentire is a persona-centric requirements framework built on and extending the Volere requirements process with UX-analytics, reusable user behavioural models and simulated user feedback through calibrated personas. In this paper we present a story on how Sentire was adopted in the development of a national public-facing e-service. Daily journaling was used throughout the project and a custom built cloud-based CASE tool was used to manage the whole process. This paper outlines our experiences and lessons learnt.
Chris Porter, Emmanuel Letier, M. Angela Sasse
RE1