VLDB 2026 Research / reviewers in the wild / expert
Andrew E. Santosa
dblp:49/6998
· DBLP profile ↗
28ranked-venue papers
0as first author
4since 2021 · last 2022
0000-0003-0396-0894ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 22 · 4 since 2021Artificial intelligence and machine learning · 4Theory of computation · 3Databases, data management, data science and information retrieval · 2Applied, interdisciplinary, general and emerging computing · 2Systems, architecture and hardware · 1Computer networks · 1Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Automated identification of libraries from vulnerability data: can we do better?abstractSoftware engineers depend heavily on software libraries and have to update their dependencies once vulnerabilities are found in them. Software Composition Analysis (SCA) helps developers identify vulnerable libraries used by an application. A key challenge is the identification of libraries related to a given reported vulnerability in the National Vulnerability Database (NVD), which may not explicitly indicate the affected libraries. Recently, researchers have tried to address the problem of identifying the libraries from an NVD report by treating it as an extreme multi-label learning (XML) problem, characterized by its large number of possible labels and severe data sparsity. As input, the NVD report is provided, and as output, a set of relevant libraries is returned. Stefanus A. Haryono, Hong Jin Kang, Abhishek Sharma 0002, Asankhaya Sharma, Andrew E. Santosa, Ming Yi Ang, David Lo 0001 |
ICPC | 5 |
| 2022 | HERMES: Using Commit-Issue Linking to Detect Vulnerability-Fixing CommitsabstractSoftware projects today rely on many third-party libraries, and therefore, are exposed to vulnerabilities in these libraries. When a library vulnerability is fixed, users are notified and advised to upgrade to a new version of the library. However, not all vulnerabilities are publicly disclosed, and users may not be aware of vulnerabilities that may affect their applications. Due to the above challenges, there is a need for techniques which can identify and alert users to silent fixes in libraries; commits that fix bugs with security implications that are not officially disclosed. We propose a machine learning approach to automatically identify vulnerability-fixing commits. Existing techniques consider only data within a commit, such as its commit message, which does not always have sufficiently discriminative information. To address this limitation, our approach incorporates the rich source of information from issue trackers. When a commit does not link to an issue, we use a commit-issue link recovery technique to infer the potential missing link. Our experiments are promising; incorporating information from issue trackers boosts the performance of a vulnerability-fixing commit classifier, improving over the strongest baseline by 11.1% on the entire dataset, which includes commits that do not link to an issue. On a subset of the data in which all commits explicitly link to an issue, our approach improves over the baseline by 12.5%. Giang Nguyen-Truong, Hong Jin Kang, David Lo 0001, Abhishek Sharma 0002, Andrew E. Santosa, Asankhaya Sharma, Ming Yi Ang |
SANER | 5 |
| 2021 | Out of sight, out of mind? How vulnerable dependencies affect open-source projects
Gede Artha Azriadi Prana, Abhishek Sharma 0002, Lwin Khin Shar, Darius Foo, Andrew E. Santosa, Asankhaya Sharma, David Lo 0001 |
Empir. Softw. Eng. | 5 |
| 2021 | Smart Greybox FuzzingabstractCoverage-based greybox fuzzing (CGF) is one of the most successful approaches for automated vulnerability detection. Given a seed file (as a sequence of bits), a CGF randomly flips, deletes or copies some bits to generate new files. CGF iteratively constructs (and fuzzes) a seed corpus by retaining those generated files which enhance coverage. However, random bitflips are unlikely to produce valid files (or valid chunks in files), for applications processing complex file formats. In this work, we introduce smart greybox fuzzing (SGF) which leverages a high-level structural representation of the seed file to generate new files. We define innovative mutation operators that work on the virtual file structure rather than on the bit level which allows SGF to explore completely new input domains while maintaining file validity. We introduce a novel validity-based power schedule that enables SGF to spend more time generating files that are more likely to pass the parsing stage of the program, which can expose vulnerabilities much deeper in the processing logic. Our evaluation demonstrates the effectiveness of SGF. On several libraries that parse complex chunk-based files, our tool AFLsmart achieves substantially more branch coverage (up to 87 percent improvement) and exposes more vulnerabilities than baseline AFL. Our tool AFLsmart discovered 42 zero-day vulnerabilities in widely-used, well-tested tools and libraries; 22 CVEs were assigned. Van-Thuan Pham, Marcel Böhme, Andrew E. Santosa, Alexandru Razvan Caciulescu, Abhik Roychoudhury |
IEEE Trans. Software Eng. | 3 |
| 2020 | A Machine Learning Approach for Vulnerability CurationabstractSoftware composition analysis depends on database of open-source library vulerabilities, curated by security researchers using various sources, such as bug tracking systems, commits, and mailing lists. We report the design and implementation of a machine learning system to help the curation by by automatically predicting the vulnerability-relatedness of each data item. It supports a complete pipeline from data collection, model training and prediction, to the validation of new models before deployment. It is executed iteratively to generate better models as new input data become available. We use self-training to significantly and automatically increase the size of the training dataset, opportunistically maximizing the improvement in the models' quality at each iteration. We devised new deployment stability metric to evaluate the quality of the new models before deployment into production, which helped to discover an error. We experimentally evaluate the improvement in the performance of the models in one iteration, with 27.59% maximum PR AUC improvements. Ours is the first of such study across a variety of data sources. We discover that the addition of the features of the corresponding commits to the features of issues/pull requests improve the precision for the recall values that matter. We demonstrate the effectiveness of self-training alone, with 10.50% PR AUC improvement, and we discover that there is no uniform ordering of word2vec parameters sensitivity across data sources. Andrew E. Santosa, Ming Yi Ang, Abhishek Sharma 0002, Asankhaya Sharma, David Lo 0001 |
MSR | 2 |
| 2019 | ApproxSymate: path sensitive program approximation using symbolic executionabstractApproximate computing, a technique that forgoes quantifiable output accuracy in favor of performance gains, is useful for improving the energy efficiency of error-resilient software, especially in the embedded setting. The identification of program components that can tolerate error plays a crucial role in balancing the energy vs. accuracy trade off in approximate computing. Manual analysis for approximability is not scalable and therefore automated tools which employ static or dynamic analysis have been proposed. However, static techniques are often coarse in their approximations while dynamic efforts incur high overhead. In this work we present ApproxSymate, a framework for automatically identifying program approximations using symbolic execution. ApproxSymate first statically computes symbolic error expressions for program components and then uses a dynamic sensitivity analysis to compute their approximability. A unique feature of this tool is that it explores the previously not considered dimension of program path for approximation which enables safer transformations. Our evaluation shows that ApproxSymate averages about 96% accuracy in identifying the same approximations found in manually annotated benchmarks, outperforming existing automated techniques. Himeshi De Silva, Andrew E. Santosa, Nhut-Minh Ho, Weng-Fai Wong |
LCTES | 2 |
| 2015 | Computing end-to-end delays in stream query processing
Vasvi Kakkad, Andrew E. Santosa, Alan D. Fekete, Bernhard Scholz |
Sci. Comput. Program. | 2 |
| 2014 | Curracurrong: a stream programming environment for wireless sensor networksabstractSUMMARY The technological advances in wireless sensor network (WSN) enable the development of complex applications including health monitoring, environmental sampling, and disaster area monitoring. WSN applications deploy battery‐powered sensors at remote locations for long periods. The development of energy‐efficient and complex WSN applications therefore requires in‐depth embedded systems programming skills that are normally not found in domain experts. So that this challenge can be overcome, programming environments for WSN need to offer a high degree of productivity, flexibility, and efficiency at the same time. In this work, we present Curracurrong, a development environment for WSNs that is based on expressing queries with stream programming. A query is represented as a stream graph consisting of stream operators and communication channels. Curracurrong provides an extensible stream operator library that adapts to a wide range of applications. It uses a novel placement algorithm that optimizes the energy consumption on sensor nodes. Through a case study, we demonstrate the productivity and flexibility of our system. We conduct experiments that evaluate the energy efficiency of our optimized operator placement algorithm. Copyright © 2012 John Wiley & Sons, Ltd. Vasvi Kakkad, Saeed Attar, Andrew E. Santosa, Alan D. Fekete, Bernhard Scholz |
Softw. Pract. Exp. | 3 |
| 2012 | TRACER: A Symbolic Execution Tool for Verification
Joxan Jaffar, Vijayaraghavan Murali, Jorge A. Navas, Andrew E. Santosa |
CAV | 4 |
| 2012 | Migrating operator placement for compositional stream graphsabstractWireless sensor networks (WSN) and mobile clouds are composed of sensor nodes that have limited energy resources. For wireless sensor networks, query processing is the state-of-the-art for data gathering and processing applications to avoid low-level programming. The stream programming model has been widely used to represent queries as an information flow from the sensor nodes to the base station. The model describes queries as stream graphs consisting of operators that process data and channels that connect operators. Operators are deployed in the network to reduce the communication overhead and hence energy. The modification of WSN queries at runtime is of key importance due to changes in the environment and the network energy levels, resulting in the migration of operators between the network nodes. Vasvi Kakkad, Andrew E. Santosa, Bernhard Scholz |
MSWiM | 2 |
| 2012 | Path-Sensitive Backward Slicing
Joxan Jaffar, Vijayaraghavan Murali, Jorge A. Navas, Andrew E. Santosa |
SAS | 4 |
| 2011 | Unbounded Symbolic Execution for Program Verification
Joxan Jaffar, Jorge A. Navas, Andrew E. Santosa |
RV | 3 |
| 2010 | Abstraction Learning
Joxan Jaffar, Jorge A. Navas, Andrew E. Santosa |
ATVA | 3 |
| 2009 | An Interpolation Method for CLP Traversal
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
CP | 2 |
| 2009 | Recursive Abstractions for Parameterized Systems
Joxan Jaffar, Andrew E. Santosa |
FM | 2 |
| 2008 | Efficient Memoization for Dynamic Programming with Ad-Hoc Constraints
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
AAAI | 2 |
| 2008 | A Coinduction Rule for Entailment of Recursively Defined Properties
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
CP | 2 |
| 2007 | A Framework for Separation of Concerns in Concurrent ProgrammingabstractA central issue of all approaches to composing adaptive software is a level of indirection for intercepting and redirecting interactions among program entities. It has been pointed out that separation of concerns is one of the key techniques for reconfigurable software design. In this paper we describe a general framework for the separation of concerns in concurrent applications. Concurrency issues are separated and treated as orthogonal to the system base functionality. The framework combines declarative and imperative programming and provides a powerful mechanism for synchronizing concurrent computations. We describe a particular implementation of the framework (for both uniprocessors and distributed systems) as an extension to the Java programming language, and comment on how model-based verification methods can be automatically applied to programs in the resulting language. Rafael Ramírez 0001, Andrew E. Santosa |
COMPSAC (2) | 2 |
| 2006 | A CLP Method for Compositional and Intermittent Predicate Abstraction
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
VMCAI | 2 |
| 2006 | Relative Safety
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
VMCAI | 2 |
| 2005 | Formal Verification of Concurrent and Distributed Constraint-Based Java ProgramsabstractThe task of programming concurrent systems is substantially more difficult than the task of programming sequential systems with respect to both correctness and efficiency. This paper describes (1) a powerful mechanism for elegantly synchronizing concurrent and distributed computations which supports a declarative model of concurrency that avoids explicitly suspending and resuming computations, (2) its implementation (for both uniprocessors and distributed systems) as an extension to the Java programming language, and (3) how model-based verification methods can be directly applied to programs in the resulting language. Rafael Ramírez 0001, Andrew E. Santosa |
ICECCS | 2 |
| 2005 | Modeling Systems in CLP
Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
ICLP | 2 |
| 2004 | Scalable Distributed Depth-First Search with Greedy Work StealingabstractWe present a framework for the parallelization of depth-first combinatorial search algorithms on a network of computers. Our architecture is intended for a distributed setting and uses a work stealing strategy coupled with a small number of primitives for the processors (which we call workers) to obtain new work and to communicate to other workers. These primitives are a minimal imposition and integrate easily with constraint programming systems. The main contribution is an adaptive architecture, which allows workers to incrementally join and leave and has good scaling properties as the number of workers increases. Our empirical results illustrate that near-linear speedup for backtrack search is achieved for up to 61 workers. It suggests that near-linear speedup is possible with even more workers. The experiments also demonstrate where departures from linearity can occur for small problems, and also for problems where the parallelism can itself affect the search as in branch and bound. Joxan Jaffar, Andrew E. Santosa, Roland H. C. Yap, Kenny Q. Zhu |
ICTAI | 2 |
| 2004 | A CLP Proof Method for Timed AutomataabstractConstraint logic programming (CLP) has been used to model programs and transition systems for the purpose of verification problems. In particular, it has been used to model timed safety automata (TSA). In this paper, we start with a systematic translation of TSA into CLP. The main contribution is an expressive assertion language and a CLP inference method for proving assertions. A distinction of the assertion language is that it can specify important properties beyond traditional safety properties. We highlight one important property: that a system of processes is symmetric. The inference mechanism is based upon the well-known method of tabling in logic programming. It is distinguished by its ability to use assertions that are not yet proven, using a principle of coinduction. Apart from given assertions, the proof mechanism can also prove implicit assertions such as discovering a lower or upper bound of a variable. Finally, we demonstrate significant improvements over state-of-the-art systems using standard TSA benchmark examples. Joxan Jaffar, Andrew E. Santosa, Razvan Voicu |
RTSS | 2 |
| 2002 | A Meeting Scheduling System Based on Open Constraint Programming
Kenny Q. Zhu, Andrew E. Santosa |
CAiSE | 2 |
| 2001 | Reactive Web Agents with Open Constraint ProgrammingabstractThis paper describes a new programming system for writing Web applications with reactive agents, i.e. the agents can have complex responses which depend on how the environment changes. Our prototype system is based on the open constraint programming framework using the constraint logic programming language CLP(R). The benefit of reactive Web agents is that activities of agents can be coordinated and synchronized using a common store and the agents can themselves be written as a system of interacting rules. Our thesis is that such a system makes it easy to write powerful reactive applications. We use a stock trading system to illustrate our reactive agents. Some details of the implementation are also given. Kenny Q. Zhu, Wee-Yeh Tan, Andrew E. Santosa, Roland H. C. Yap |
ISADS | 3 |
| 2000 | Implementing Declarative Concurrency in Java
Rafael Ramírez 0001, Andrew E. Santosa, Lee Wei Hong |
Euro-Par | 2 |
| 2000 | Concurrent Programming Made EasyabstractThe task of programming concurrent systems is substantially more difficult than the task of programming sequential systems with respect to both correctness and efficiency. In this paper we describe a constraint-based methodology for writing concurrent applications. A system is modeled as: (a) a set of processes containing a sequence of "markers" denoting the processes points of interest; and (b) a constraint store. Process synchronization is specified by incrementally adding constraints on the markers execution order into the constraint store. The constraint store contains a declarative specification based on a temporal constraint logic program. The store, thus, acts as a coordination entity which on the one hand encapsulates the system synchronization requirements, and on the other hand, provides a declarative specification of the system concurrency issues. This provide great advantages in writing concurrent programs and manipulating them while preserving correctness. Rafael Ramírez 0001, Andrew E. Santosa, Roland H. C. Yap |
ICECCS | 2 |