Fehmi Jaafar

dblp:47/10516 · DBLP profile ↗
← Back
29ranked-venue papers
6as first author
20since 2021 · last 2026
0000-0002-4101-2281ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 17 · 6 first-author · 8 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 6 since 2021Security and privacy · 4 · 4 since 2021Artificial intelligence and machine learning · 3 · 3 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021
YearPublicationVenuePosition
2026 Enhancing agent's robustness in reinforcement learning via foundation models and domain randomization
abstract
A key challenge in reinforcement learning is enabling agents to generalize their experiences, applying knowledge gained in one environment to new and varied contexts. Generalizability is essential for success in real-world applications, where agents must adapt to distribution shifts and contextual variations. In this work, we propose a novel framework that integrates visual domain randomization with multimodal foundation models to improve the robustness and adaptability of reinforcement learning agents. This integration allows agents to learn policies that are resilient to environmental changes and visual discrepancies. We evaluate our method in the MiniGrid benchmark, including the unseen test environment (DistShift1), where it achieves a mean return of 0.85, outperforming the Proximal Policy Optimization baseline (0.32). These results show the effectiveness of our framework in addressing distribution shift and highlight its potential for real-world RL applications.
Wissam Salhab, Fehmi Jaafar, Hamid Mcheick, Darine Ameyed
Neurocomputing2
2026 Securing LoRaWAN in the AIoT Era: A Systematic Mapping Study and an MITRE-Based Threat Matrix
abstract
The rapid expansion of the Internet of Things (IoT) has established LoRaWAN (Long Range Wide Area Network) as a leading low-power, long-range communication protocol across critical domains such as smart cities, agriculture, and healthcare. However, its minimalist design and reliance on unlicensed spectrum expose vulnerabilities across the entire protocol stack from physical-layer jamming to MAC-layer spoofing and application-layer firmware attacks. Concurrently, the rise of the Artificial Intelligence of Things (AIoT) introduces opportunities to reinforce LoRaWAN security via decentralized, intelligent, and adaptive mechanisms. This paper presents a systematic mapping study of 81 peer-reviewed publications (2020–2025), conducted using a PRISMA-based methodology. Our objectives are to: (1) identify key trends and research directions in LoRaWAN security, (2) propose a MITRE ATT&CK-inspired taxonomy tailored to the LoRaWAN stack, (3) analyze AIoT-based security contributions, and (4) highlight unresolved challenges and future perspectives. Our findings indicate that 62% of documented cyberattacks target the MAC layer, exploiting vulnerabilities such as static keys and weak integrity checks. AI-driven techniques including RF fingerprinting (97% accuracy using CNNs), federated learning for anomaly detection, and blockchain-based key management—show promise but raise concerns about scalability and deployment on constrained devices. We introduce the first MITRE ATT&CK-LoRaWAN matrix, detailing 18 attack techniques (e.g., energy depletion, rogue gateways) and associated countermeasures, including post-quantum Kyber-1024 encryption. Finally, we discuss major technical, methodological, and interoperability challenges, and suggest actionable research directions toward secure, AI-native, and resilient LoRaWAN infrastructures.
Elisée Toé, Fehmi Jaafar, Laurent Charles André Ferrier
IEEE Internet Things J.2
2026 Exploring the Impacts of Antipatterns on Object-Oriented, Service-Oriented, and Mobile-Oriented Systems
abstract
ABSTRACT Objective Antipatterns (APs) represent potential issues in software systems stemming from poor design choices, coding practices, and undisciplined development. This systematic literature review analyzes 97 primary studies (PSs) from 2005 to 2024, exploring the impact of APs on Object‐Oriented (OO), Service‐Oriented (SO), and Mobile‐Oriented (MO) systems across various quality attributes. Methods PSs are classified by techniques, datasets, evaluation measures, and tool support. Result Findings highlight the association of APs with increased maintenance costs (27.8%), fault‐proneness (26.8%), change‐proneness (12.3%), and evolution challenges (25.7%). Most studies employ descriptive statistics, regression analysis, and Pearson correlation, with limited datasets and tool support for SO and MO systems compared to OO systems. Intermediate source code representations and program comprehension strategies are commonly used for analysis. Conclusion These findings emphasize the need for further research on the impact of APs, particularly in MO systems, and their negative effects on software quality attributes.
Jean Baptiste Minani, Ghulam Rasool 0002, Fatima Sabir, Fehmi Jaafar, Yann-Gaël Guéhéneuc
Softw. Pract. Exp.5
2025 RBFL: Securing Federated Learning against Data Poisoning Using a Reputation-based Approach
abstract
Federated learning enables distributed clients to train a global model while maintaining privacy and control over their data. Although collaboration can substantially improve the learning process, it also introduces vulnerabilities, as not all participants contribute beneficially. Clients may engage in detrimental activities, such as data poisoning, that compromise the integrity of the global model. Additionally, in a realistic scenario, the quality of the data possessed by these clients is highly heterogeneous, which influences the model training performance. Moreover, malicious clients (aka free riders) intend to obtain the global model without making a real contribution to the training process. Hence, a reliable and fair evaluation of the client contribution is essential to promote diverse client engagement, improve robustness, and address the free-rider problem. This paper proposes a reputation-aware contribution evaluation approach (RBFL) that provides adversarial robustness by tracking reputation over multiple training rounds to ensure that clients consistently contribute positively. We employ CosineGradient as the utility function and Truncated Monte Carlo (TMC) Shapley as the data valuation function. Empirical evaluation demonstrates the effectiveness of our approach in a fair evaluation of clients’ contributions and effective identification of adversarial clients while maintaining a model accuracy of $92 \%$ with adversarial robustness.
Issiaka Ischolla Mazu, Fehmi Jaafar, Darine Ameyed, Hamdi Ben Abdessalem
AICCSA3
2025 Security Evaluation of Industrial Organisations in an Isolated Region
abstract
This paper presents the results of a cybersecurity audit conducted on thirty industrial SMEs located in a remote region of Eastern Canada. These firms face growing cyber threats while having limited access to security expertise and infrastructure. Using a mixed-method approach combining on-site technical assessments, structured interviews, and questionnaires, the study analyzes vulnerabilities through the TOE framework (Technological, Organizational, Environmental). Results show that 90% of companies lacked internal network segmentation, 80% were vulnerable to phishing attacks, and over 70% had no cybersecurity training or formal security policy. Based on these findings, we propose a set of low-cost and practical recommendations tailored to SMEs in isolated regions. These include awareness training, simple network protections, and internal policy development. The study highlights the urgent need for targeted cybersecurity strategies adapted to geographic and resource constraints, and contributes to both academic and operational understanding of how to improve cyber resilience in decentralized industrial ecosystems.
Jules Martial Yin-Belta Mbara, Fehmi Jaafar, Pierre-Martin Tardif
CoDIT2
2025 Content Safety and Response Quality in LLMs: A Data-Centric Refinement Approach
abstract
Recent advancements in large language models (LLMs) have significantly impacted natural language processing. However, ensuring the safety and quality of responses generated by LLMs remains a challenge. Building on previous work with a Corrective-BART Model, which demonstrated significant reductions in toxicity, this paper addresses the trade-of between safety and response quality. A data-centric refinement paradigm is introduced, proactively generating high-quality, safe responses during training. A dynamic dataset is curated using Llama2, where toxic prompt-response pairs are contextually regenerated into safe, relevant alternatives. The enhanced Corrective-BART model employs a multi-threshold correction pipeline, leveraging multiple metrics to detect implicit and explicit harms. For the Type-Token Ratio, the enhanced model paired with GPT-4 achieves an 11% improvement. Similarly, improvements of 8.2% and 8.6% are observed when paired with Gemma-2b-it and Mistral-7B, respectively. In terms of Readability Score, the enhanced BART model paired with GPT-4 shows an 8% improvement while demonstrating a 21% improvement when paired with Mistral-7B and an 8.4% improvement with Gemma-2b-it. For Coherence Score, the enhanced BART model achieves a 6% improvement when paired with GPT-4, a 7% improvement with Mistral-7B, and a 12.7% improvement with Gemma-2b-it. Notably, the Refusal Rate exhibits a 23.4% improvement when the enhanced BART model is paired with GPT-4. Furthermore, impressive increases of 10.5× and 21.3× are observed when paired with Mistral-7B and Gemma-2b-it, respectively. These results demonstrate that the enhanced BART consistently enhances performance across all LLMs, improving lexical diversity, readability, coherence, and safety.
Chaima Njeh, Haïfa Nakouri, Fehmi Jaafar
KES3
2025 Cost-Performance Analysis: A Comparative Study of CPU-Based Serverless and GPU-Based Training Architectures
Amine Barrak, Fábio Petrillo, Fehmi Jaafar
PDCAT3
2025 FaaSGuard: Secure CI/CD for Serverless Applications - An OpenFaaS Case Study
abstract
Serverless computing significantly alters software development by abstracting infrastructure management and enabling rapid, modular, event-driven deployments. Despite its benefits, the distinct characteristics of serverless functions, such as ephemeral execution and fine-grained scalability, pose unique security challenges, particularly in open-source platforms like OpenFaaS. Existing approaches typically address isolated phases of the DevSecOps lifecycle, lacking an integrated and comprehensive security strategy. To bridge this gap, we propose FaaSGuard, a unified DevSecOps pipeline explicitly designed for open-source serverless environments. FaaSGuard systematically embeds lightweight, fail-closed security checks into every stage of the development lifecycle—planning, coding, building, deployment, and monitoring—effectively addressing threats such as injection attacks, hard-coded secrets, and resource exhaustion. We validate our approach empirically through a case study involving 20 real-world serverless functions from public GitHub repositories. Results indicate that FaaSGuard effectively detects and prevents critical vulnerabilities, demonstrating high precision (95%) and recall (91%) without significant disruption to established CI/CD practices.
Amine Barrak, Emna Ksontini, Ridouane Atike, Fehmi Jaafar
SCAM4
2025 A Hybrid Approach to Improve the Intrusion Detection Systems Using Generative Artificial Intelligence and Deep Reinforcement Learning
Ines Ben Makhlouf, Ghassen Kilani, Fehmi Jaafar, Haïfa Nakouri
SECRYPT3
2024 Detecting and Mitigating Adversarial Perturbations to Improve E-Commerce Security
abstract
E-commerce platforms face the critical challenge of adversary events, including fraudulent transactions and fake reviews, which can lead to significant financial and reputational damage. Addressing this, our research introduces a hybrid Deep Learning model, tailored for the detection of such adversarial activities. This innovative approach leverages spatial and sequential data processing capabilities, enhancing the identification of subtle adversarial manipulations across diverse e-commerce contexts. Our findings indicate a high detection rate of 93 percent for adversarial attacks, with precision, recall, and Matthews Correlation Coefficient metrics underscoring the model’s efficacy. This work significantly contributes to e-commerce security by advancing the robustness of detection systems against a spectrum of adversarial threats, including account takeovers and deceptive reviews. While demonstrating a notable improvement over existing methods, our research also acknowledges the potential for evasion by sophisticated attacks, highlighting areas for future work in enhancing model resilience. This balance of innovation and critical insight provides a solid foundation for further advancements in the field of e-commerce security
Usman Tariq, Fehmi Jaafar, Yasir Malik
BDCAT2
2024 On Securing Sensitive Data Using Deep Convolutional Autoencoders
abstract
There are various traditional methods used for securing sensitive data, such as cryptography algorithms like AES-HMAC-SHA256, Twofish, and Chacha20. However, several studies showed that these cryptography algorithms suffer from security vulnerabilities. In this paper, we explore the use of a cryptography model based on a Deep Convolutional Autoencoder and we compare its performances to the cryptography algorithms. We report the results of a comparative study based on several metrics. We incorporate more nuanced metrics such as cosine similarity, entropy, Kendall and Spearman rate, and Mean Squared Error (MSE) for a comprehensive assessment of model performance and security, in addition to encryption and decryption time metrics.The results obtained are very promising. Our model performs the best on two essential metrics, entropy and MSE. We obtain a decrypted file entropy of 8.01, compared to 7.99 for the three other standard models, with a very low MSE of 0.003, compared to 105.43 for AES, which remains the most efficient compared to the other algorithms.
Abib Sy, Fehmi Jaafar, Kevin Bouchard
CoDIT2
2024 Securing AWS Lambda: Advanced Strategies and Best Practices
abstract
The emergence of the serverless paradigm, embodied by AWS Lambda functions, has revolutionized the landscape of cloud computing. This model empowers users to offload server management tasks, allowing them to focus their efforts on core business logic while achieving substantial cost savings. However, this transition to serverless exposes significant vulnerabilities, especially in terms of security. This article delves into the specific security challenges associated with AWS Lambda functions, with a focus on major threats such as malicious code injection, sensitive data leaks, DDoS attacks, excessive privileges, vulnerable dependencies, and certificate issues. Our investigation, centered around the AWS Lambda platform, thoroughly analyzes these challenges by identifying underlying mechanisms and inherent risks. We review the state of the art solutions from the literature while examining the strategies adopted by AWS and the industry to enhance security. By implementing these solutions on an AWS server, we concretely illustrate possible protective measures. In this paper, we aims to provide a comprehensive understanding of security issues in the context of Lambda functions, paving the way for recommendations and research directions to bolster the resilience of this essential serverless cloud technology.
Amine Barrak, Gildas Fofe, Léo Mackowiak, Emmanuel Kouam, Fehmi Jaafar
CSCloud5
2024 Wiki-IoT: Registering and Evaluating the Security and Resilience of Internet of Things and Connected Devices Using a Collaborative Platform
abstract
The number of connected devices and the Internet of Things (IoT) continues growing significantly, with global spending expected to exceed $1 trillion by 2026. Despite this growth, IoT and connected devices face security challenges, as millions of devices are reportedly involved in botnets. IoT and connected devices are more vulnerable to medium- and high-severity attacks since more than 91.5% of the IoT’s traffic is unencrypted. Governments have planned or initiated national registries of certified devices and labeling programs to address these challenges. As those registries and labels remain national, multiple governments have started signing mutual recognition between their programs, adding complexity. This motivated us to create a unified and collaborative labeling registry and a rating system that uses 12 criteria to classify IoT devices. Through multiple experiments, 52 users submitted 252 device classifications. Our proposed tool is helping us identify the criteria that define IoT and connected devices’ security.
Jean Decian, Fehmi Jaafar
DASC2
2024 Benchmarking Deep Learning Algorithms for Intrusion Detection IoT Networks
abstract
With the increasing popularity of Internet of Things (IoT) and its connected devices, security has become a major concern. In this paper, we conducted a benchmark to evaluate performance of different deep learning algorithm device based on its network traffic. We developed our own dataset for our pilot study that included three different types of cyberattacks: reverse shell, keylogger, and synflood.The diversity and scope of our research has been enhanced by the incorporation of the CIC IoT dataset, which has been added to our initial work. We conducted a systematic evaluation of the performance of various deep learning models, which included CNNs and LSTM networks. Our benchmarking efforts on the CIC IoT dataset resulted in a significant improvement, with all models achieving an accuracy of over 99% and more than 93% on our custom dataset.
Hoummady Enzo, Fehmi Jaafar
DASC2
2023 A Privacy-Preserving Federated Learning for IoT Intrusion Detection System
abstract
The Internet of Things (IoT) is an impending area with applications in numerous fields. The number of IoT devices has seen exponential growth, increasing apprehensions around security. Cyberattacks are of rising concern because of the expanded attack surface of threats that have plagued networks. Adding to that are insecure practices among users who may not know to protect their IoT devices. Therefore, IoT security has become fundamental, especially as IoT devices carry sensitive data. This paper provides a proof of concept of an Intelligent Intrusion Detection System for IoT. We centered our work on a privacy-preserving approach offering a Federated Learning (FL) based solution for intrusions recognition combining network and energy data. Our model has achieved high accuracy while preserving a short running time in multiple FL rounds.
Riadh Ben Chaabene, Darine Ameyed, Fehmi Jaafar, Alexis Roger, Esma Aïmeur, Mohamed Cheriet
CoDIT3
2023 Exploring the Impact of Serverless Computing on Peer To Peer Training Machine Learning
abstract
The increasing demand for computational power in big data and machine learning has driven the development of distributed training methodologies. Among these, peer-to-peer (P2P) networks provide advantages such as enhanced scalability and fault tolerance. However, they also encounter challenges related to resource consumption, costs, and communication overhead as the number of participating peers grows. In this paper, we introduce a novel architecture that combines serverless computing with P2P networks for distributed training and present a method for efficient parallel gradient computation under resource constraints.Our findings show a significant enhancement in gradient computation time, with up to a 97.34% improvement compared to conventional P2P distributed training methods. As for costs, our examination confirmed that the serverless architecture could incur higher expenses, reaching up to 5.4 times more than instance-based architectures. It is essential to consider that these higher costs are associated with marked improvements in computation time, particularly under resource-constrained scenarios.Despite the cost-time trade-off, the serverless approach still holds promise due to its pay-as-you-go model. Utilizing dynamic resource allocation, it enables faster training times and optimized resource utilization, making it a promising candidate for a wide range of machine learning applications.
Amine Barrak, Ranim Trabelsi, Fehmi Jaafar, Fábio Petrillo
IC2E3
2023 SPIRT: A Fault-Tolerant and Reliable Peer-to-Peer Serverless ML Training Architecture
abstract
The advent of serverless computing has ushered in notable advancements in distributed machine learning, particularly within parameter server-based architectures. Yet, the integration of serverless features within peer-to-peer (P2P) distributed networks remains largely uncharted. In this paper, we introduce SPIRT, a fault-tolerant, reliable, scalable and secure serverless P2P ML training architecture. designed to bridge this existing gap. Capitalizing on the inherent robustness and reliability innate to P2P systems, we emphasized Intra-peer scalability for concurrent gradient to mitigate communication overhead from increased peer interactions. SPIRT, employs RedisAI for in-database operations, achieves an 82% reduction in model update times. This architecture showcases resilience against peer failures and adeptly manages the integration of new peers. Furthermore, SPIRT ensures secure communication between peers, enhancing the reliability of distributed machine learning tasks. Even in the face of Byzantine attacks, the system’s robust aggregation algorithms maintain high levels of accuracy. These findings illuminate the promising potential of serverless architectures in P2P distributed machine learning, offering a significant stride towards the development of more efficient, scalable, and resilient applications.
Amine Barrak, Mayssa Jaziri, Ranim Trabelsi, Fehmi Jaafar, Fábio Petrillo
QRS4
2021 Identification of Compromised IoT Devices: Combined Approach Based on Energy Consumption and Network Traffic Analysis
abstract
In the burgeoning age of digitalization, the Internet of Things presents a core part of the digital ecosystem. Unfortunately, as the deployment of connected devices is increasing tremendously, so are cyber-attacks. The consequences of cyber-attacks could be devastating as they gain access to sensitive data and even damages critical infrastructures. This urges the development and integration of proactive and intelligent security breach detection mechanisms in different levels of the IoT platforms including the devices themselves. Several empirical observations indicated a change in the energy consumption and network behaviour of compromised devices. Thus, we propose in this paper a machine learning based approach to identify compromised IoT devices using their energy consumption footprint and network traffic. We base our study on real data collected from real experiments using different commercially available IoT devices infected with authentic IoT botnets. Our results show that machine learning algorithms can classify correctly attacks reaching 98.40% precision for Mirai, over 99.91% for Ufonet and respectively 97.63% and 99.93% performance. Overall, our exploratory study is one of the very first of its kind to explore the energy consumption combined with network behavior analysis to detect IoT compromised devices and its outcomes will be a starting point for further research on this topic.
Fehmi Jaafar, Darine Ameyed, Amine Barrak, Mohamed Cheriet
QRS1
2021 Investigating design anti-pattern and design pattern mutations and their change- and fault-proneness
Zeinab Azadeh Kermansaravi, Md. Saidur Rahman 0002, Foutse Khomh, Fehmi Jaafar, Yann-Gaël Guéhéneuc
Empir. Softw. Eng.4
2021 On the Impact of Interlanguage Dependencies in Multilanguage Systems Empirical Case Study on Java Native Interface Applications (JNI)
abstract
Nowadays, developers are often using multiple programming languages to exploit the advantages of each language and to reuse code. However, dependency analysis across multilanguage is more challenging compared to mono-language systems. In this article, we introduce two approaches for multilanguage dependency analysis: static multilanguage dependency analyzer) and historical multilanguage dependency analyzer, which we apply on ten open-source multilanguage systems to empirically analyze the prevalence of the dependencies across languages, i.e., interlanguage dependencies and their impact on software quality and security. Our main results show that: the more interlanguage dependencies, the higher the risk of bugs and vulnerabilities being introduced, while this risk remains constant for intralanguage dependencies; the percentage of bugs within interlanguage dependencies is three times higher than the percentage of bugs identified in intralanguage dependencies; the percentage of vulnerabilities within interlanguage dependencies is twice the percentage of vulnerabilities introduced in intralanguage dependencies.
Manel Grichi, Mouna Abidi, Fehmi Jaafar, Ellis E. Eghan, Bram Adams
IEEE Trans. Reliab.3
2020 On the Impact of Inter-language Dependencies in Multi-language Systems
abstract
Nowadays, developers are often using multiple programming languages to exploit the advantages of each language and to reuse code. However, dependency analysis across multi-language is more challenging compared to mono-language systems. In this paper, we introduce two approaches for multi- language dependency analysis: S-MLDA (Static Multi-language Dependency Analyzer) and H-MLDA (Historical Multi-language Dependency Analyzer), which we apply on ten open-source multi-language systems to empirically analyze the prevalence of the dependencies across languages i.e., inter-language dependencies and their impact on software quality and security. Our main results show that: the more inter-language dependencies, the higher the risk of bugs and vulnerabilities being introduced, while this risk remains constant for intra-language dependencies; the percentage of bugs within inter-language dependencies is three times higher than the percentage of bugs identified in intra-language dependencies; the percentage of vulnerabilities within inter-language dependencies is twice the percentage of vulnerabilities introduced in intra-language dependencies.
Manel Grichi, Mouna Abidi, Fehmi Jaafar, Ellis E. Eghan, Bram Adams
QRS3
2018 Analysis of Overhead Caused by Security Mechanisms in IaaS Cloud
abstract
The process of determining the amount of resources needed to deploy applications or services in the cloud and provisioning for these resources is known as cloud capacity planning. Capacity planning is essential for meeting current and future levels of the minimal wastage requirements. Capacity planning can be applied to a company's computer network, storage and security appliances. Security appliances typically accompany most cloud-based deployments. They can be deployed in cloud either by the cloud service provider or the organization itself. This paper intends to evaluate the network overhead caused by client-deployed security mechanisms in cloud services in a fluctuating workload environment. We present in this paper several simulations performed to evaluate firewall architectures with OPNET simulator on a growing number of clients. Finally, we provide recommendations for organizations to assure proper capacity planning for deployment of security mechanisms.
Gurjot Balraj Singh, Fehmi Jaafar, Sergey Butakov
CoDIT2
2018 Is Predicting Software Security Bugs Using Deep Learning Better Than the Traditional Machine Learning Algorithms?
abstract
Software insecurity is being identified as one of the leading causes of security breaches. In this paper, we revisited one of the strategies in solving software insecurity, which is the use of software quality metrics. We utilized a multilayer deep feedforward network in examining whether there is a combination of metrics that can predict the appearance of security-related bugs. We also applied the traditional machine learning algorithms such as decision tree, random forest, naïve bayes, and support vector machines and compared the results with that of the Deep Learning technique. The results have successfully demonstrated that it was possible to develop an effective predictive model to forecast software insecurity based on the software metrics and using Deep Learning. All the models generated have shown an accuracy of more than sixty percent with Deep Learning leading the list. This finding proved that utilizing Deep Learning methods and a combination of software metrics can be tapped to create a better forecasting model thereby aiding software developers in predicting security bugs.
Caesar Jude Clemente, Fehmi Jaafar, Yasir Malik
QRS2
2018 Protecting Internet users from becoming victimized attackers of click-fraud
abstract
Abstract Internet users are often victimized by malicious attackers. Some attackers infect and use innocent users' machines to launch large‐scale attacks without the users' knowledge. One of such attacks is the click‐fraud attack. Click‐fraud happens in pay‐per‐click ad networks where the ad network charges advertisers for every click on their ads. Click‐fraud has been proved to be a serious problem for the online advertisement industry. In a click‐fraud attack, a user or an automated software clicks on an ad with a malicious intent and advertisers need to pay for those valueless clicks. Among many forms of click‐fraud, botnets with the automated clickers are the most severe ones. In this study, we present a method for detecting automated clickers from the user side. The proposed method to fight click‐fraud, FCFraud, can be integrated into the desktop and smart device operating systems. Since most modern operating systems already provide some kind of antimalware service, our proposed method can be implemented as a part of the service. We believe that an effective protection at the operating system level can save billions of dollars of the advertisers. Experiments show that FCFraud is 99.6% (98.2% in mobile ad library–generated traffic) accurate in classifying ad requests from all user processes and it is 100% successful in detecting clickbots in both desktop and mobile devices. We implement a cloud backend for the FCFraud service to save battery power in mobile devices. The overhead of executing FCFraud is also analyzed and we show that it is reasonable for both the platforms.
Shahrear Iqbal, Mohammad Zulkernine, Fehmi Jaafar, Yuan Gu
J. Softw. Evol. Process.3
2017 On the Analysis of Co-Occurrence of Anti-Patterns and Clones
abstract
In software engineering, a smell is a part of a software system's source code with a poor quality and that may indicate a deeper problem. Although many kinds of smells have been studied to analyze their causes, their behavior, and their impact on software quality, those smells typically are studied independently from each other. However, if two smells coincide inside a class, this could increases their negative effect (e.g., spaghetti code that is being cloned across the system). In this paper we report results from an empirical study conducted to examine the relationship between two specific kinds of smells: code clones and antipatterns. We conducted our study on three open-source software systems: Azureus, Eclipse, and JHotDraw. Results show that between 32% and 63% of classes in the analysed systems present co-occurrence of smells, and that such classes are more risky in term of fault-proneness.
Fehmi Jaafar, Angela Lozano, Yann-Gaël Guéhéneuc, Kim Mens
QRS1
2017 Analyzing software evolution and quality by extracting Asynchrony change patterns
Fehmi Jaafar, Angela Lozano, Yann-Gaël Guéhéneuc, Kim Mens
J. Syst. Softw.1
2016 Evaluating the impact of design pattern and anti-pattern dependencies on changes and faults
Fehmi Jaafar, Yann-Gaël Guéhéneuc, Sylvie Hamel, Foutse Khomh, Mohammad Zulkernine
Empir. Softw. Eng.1
2014 Detecting asynchrony and dephase change patterns by mining software repositories
abstract
SUMMARY Software maintenance accounts for the largest part of the costs of any program. During maintenance activities, developers implement changes (sometimes simultaneously) on artifacts in order to fix bugs and to implement new requirements. To reduce this part of the costs, previous work proposed approaches to identify the artifacts of programs that change together. These approaches analyze historical data, mined from version control systems, and report change patterns, which lead at the causes, consequences, and actors of the changes to source code files. They also introduce so‐called change patterns that describe some typical change dependencies among files. In this paper, we introduce two novel change patterns: the asynchrony change pattern, corresponding to macro co‐changes (MC), that is, of files that co‐change within a large time interval (change periods) and the dephase change pattern, corresponding to dephase macro co‐changes (DC), that is, MC that always happens with the same shifts in time. We present our approach, that we named Macocha, to identify these two change patterns in large programs. We use the k‐nearest neighbor algorithm to group changes into change periods. We also use the Hamming distance to detect approximate occurrences of MC and DC. We apply Macocha and compare its performance in terms of precision and recall with UMLDiff (file stability) and association rules (co‐changing files) on seven systems: ArgoUML, FreeBSD, JFreeChart, Openser, SIP, XalanC, and XercesC developed with three different languages (C, C++, and Java). These systems have a size ranging from 532 to 1693 files, and during the study period, they have undergone 1555 to 23,944 change commits. We use external information and static analysis to validate (approximate) MC and DC found by Macocha. Through our case study, we show the existence and usefulness of these novel change patterns to ease software maintenance and, potentially, reduce related costs. Copyright © 2013 John Wiley & Sons, Ltd.
Fehmi Jaafar, Yann-Gaël Guéhéneuc, Sylvie Hamel, Giuliano Antoniol
J. Softw. Evol. Process.1
2012 On the analysis of evolution of software artefacts and programs
abstract
The literature describes several approaches to identify the artefacts of programs that evolve together to reveal the (hidden) dependencies among these artefacts and to infer and describe their evolution trends. We propose the use of biological methods to group artefacts, to detect co-evolution among them, and to construct their phylogenic trees to express their evolution trends. First, we introduced the novel concepts of macro co-changes (MCCs), i.e., of artefacts that co-change within a large time interval and of dephase macro co-changes (DMCCs), i.e., macro co-changes that always happen with the same shifts in time. We developed an approach, Macocha, to identify these new patterns of artefacts co-evolution in large programs. Now, we are analysing the evolution of classes playing roles in design patterns and - or antipatterns. In parallel to previous work, we are detecting what classes are in macro co-change or in dephase macro co-change with the design motifs. Results try to show that classes playing roles in design motifs have specifics evolution trends. Finally, we are implementing an approach, Profilo, to achieve the analysis of the evolution of artefacts and versions of large object-oriented programs. Profilo creates a phylogenic tree of different versions of program that describes versions evolution and the relation among versions and programs. We will, also, evaluate the usefulness of our tools using lab and field studies.
Fehmi Jaafar
ICSE1