VLDB 2026 Research / reviewers in the wild / expert
Nenad Medvidovic
dblp:65/1728
· DBLP profile ↗
114ranked-venue papers
20as first author
13since 2021 · last 2025
0000-0002-1906-4878ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 107 · 20 first-author · 13 since 2021Systems, architecture and hardware · 4Artificial intelligence and machine learning · 2 · 2 first-authorDatabases, data management, data science and information retrieval · 2Security and privacy · 1Human-computer interaction and ubiquitous computing · 1Theory of computation · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Are We Learning the Right Features? A Framework for Evaluating DL-Based Software Vulnerability Detection SolutionsabstractRecent research has revealed that the reported results of an emerging body of deep learning-based techniques for detecting software vulnerabilities are not reproducible, either across different datasets or on unseen samples. This paper aims to provide the foundation for properly evaluating the research in this domain. We do so by analyzing prior work and existing vulnerability datasets for the syntactic and semantic features of code that contribute to vulnerability, as well as features that falsely correlate with vulnerability. We provide a novel, uniform representation to capture both sets of features, and use this representation to detect the presence of both vulnerability and spurious features in code. To this end, we design two types of code perturbations: feature preserving perturbations (FPP) ensure that the vulnerability feature remains in a given code sample, while feature eliminating perturbations (FEP) eliminate the feature from the code sample. These perturbations aim to measure the influence of spurious and vulnerability features on the predictions of a given vulnerability detection solution. To evaluate how the two classes of perturbations influence predictions, we conducted a large-scale empirical study on five state-of-the-art DL-based vulnerability detectors. Our study shows that, for vulnerability features, only$\sim 2 \%$of FPPs yield the undesirable effect of a prediction changing among the five detectors on average. However, on average,$\sim 84 \%$of FEPs yield the undesirable effect of retaining the vulnerability predictions. For spurious features, we observed that FPPs yielded a drop in recall up to 29 % for graph-based detectors. We present the reasons underlying these results and suggest strategies for improving DNN-based vulnerability detectors. We provide our perturbation-based evaluation framework as a public resource to enable independent future evaluation of vulnerability detectors. Satyaki Das, Syeda Tasnim Fabiha, Saad Shafiq, Nenad Medvidovic |
ICSE | 4 |
| 2025 | Trust Dynamics in AI-Assisted Development: Definitions, Factors, and ImplicationsabstractSoftware developers increasingly rely on AI code generation utilities. To ensure that “good” code is accepted into the code base and “bad” code is rejected, developers must know when to trust an AI suggestion. Understanding how developers build this intuition is crucial to enhancing developer-AI collaborative programming. In this paper, we seek to understand how developers (1) define and (2) evaluate the trustworthiness of a code suggestion and (3) how trust evolves when using AI code assistants. To answer these questions, we conducted a mixed method study consisting of an in-depth exploratory survey with (n=29) developers followed by an observation study (n=10). We found that comprehensibility and perceived correctness were the most frequently used factors to evaluate code suggestion trustworthiness. However, the gap in developers' definition and evaluation of trust points to a lack of support for evaluating trustworthy code in real-time. We also found that developers often alter their trust decisions, keeping only 52% of original suggestions. Based on these findings, we extracted four guidelines to enhance developer-AI interactions. We validated the guidelines through a survey with (n=7) domain experts and survey members (n=8). We discuss the validated guidelines, how to apply them, and tools to help adopt them. Sadra Sabouri, Philipp Eibl, Morteza Ziyadi, Nenad Medvidovic, Lars Lindemann, Souti Chattopadhyay |
ICSE | 5 |
| 2025 | Software Engineering Research Trends 1994-2024: Stepping Beyond the LamppostabstractIn this paper, I overview the research trends in software engineering, specifically as reflected in papers published in IEEE TSE over the 30-year period between 1994 and 2024. I used ChatGPT-4o to extract summaries of top-3 topics for each individual year during this period. I make three key observations: (1) Our research community—probably not unlike others—has tended to abandon unsolved difficult problems and move onto new “shiny” topics, even when that has not been warranted by the circumstances. (2) Some of the research problems that are widely-acknowledged as critically important have not been given appropriate attention. (3) There seems to be an emerging expectation that AI, most recently in the form or LLMs, will obviate much of the painstaking work our community has put into solving a range of problems, and that carries with it serious risks. Nenad Medvidovic |
IEEE Trans. Software Eng. | 1 |
| 2025 | Software Architecture Description RevisitedabstractMany languages for modeling various aspects of software systems’ architectures have been proposed over the past three decades. In the late 1990s, we provided the first systematic foundation for understanding, classifying, and comparing the quickly emerging architecture description languages (ADLs). This culminated in a 2000 IEEE TSE publication, which has subsequently been referenced widely. In this paper, we revisit the 2000 framework, consider how it influenced a foundational study of the suitability of the Unified Modeling Language (UML) as an ADL and influenced the development of an extensible ADL (xADL) with a set of highly innovative features. We show how further work with modeling efforts led to a new and deeper understanding of software architecture itself. We conclude by analyzing a series of recent developments that have reshaped the software architecture landscape, posing new questions about the nature of architecture description. Nenad Medvidovic, Richard N. Taylor, Eric M. Dashofy |
IEEE Trans. Software Eng. | 1 |
| 2024 | Message from the ICSA 2024 General Chairs and Program ChairsabstractThe IEEE International Conference on Software Architecture (ICSA) is the premier gathering of practitioners and researchers interested in software architecture, component-based software engineering, and quality aspects of complex software systems. The 21st IEEE International Conference on Software Architecture (ICSA 2024) continued the tradition of a working conference, where attendees met and where software architects were able to explain the challenges they face and try to influence the future of the field. Interactive working sessions were the place where researchers met practitioners to identify opportunities to shape the future of our field. Y. Raghu Reddy, Nenad Medvidovic, Romina Spalazzese, Heiko Koziolek |
ICSA | 2 |
| 2024 | Toward Improved Deep Learning-based Vulnerability DetectionabstractDeep learning (DL) has been a common thread across several recent techniques for vulnerability detection. The rise of large, publicly available datasets of vulnerabilities has fueled the learning process underpinning these techniques. While these datasets help the DL-based vulnerability detectors, they also constrain these detectors' predictive abilities. Vulnerabilities in these datasets have to be represented in a certain way, e.g., code lines, functions, or program slices within which the vulnerabilities exist. We refer to this representation as a base unit. The detectors learn how base units can be vulnerable and then predict whether other base units are vulnerable. We have hypothesized that this focus on individual base units harms the ability of the detectors to properly detect those vulnerabilities that span multiple base units (or MBU vulnerabilities). For vulnerabilities such as these, a correct detection occurs when all comprising base units are detected as vulnerable. Verifying how existing techniques perform in detecting all parts of a vulnerability is important to establish their effectiveness for other downstream tasks. To evaluate our hypothesis, we conducted a study focusing on three prominent DL-based detectors: ReVeal, DeepWukong, and LineVul. Our study shows that all three detectors contain MBU vulnerabilities in their respective datasets. Further, we observed significant accuracy drops when detecting these types of vulnerabilities. We present our study and a framework that can be used to help DL-based detectors toward the proper inclusion of MBU vulnerabilities. Adriana Sejfia, Satyaki Das, Saad Shafiq, Nenad Medvidovic |
ICSE | 4 |
| 2023 | Adhere: Automated Detection and Repair of Intrusive AdsabstractToday, more than 3 million websites rely on online advertising revenue. Despite the monetary incentives, ads often frustrate users by disrupting their experience, interrupting content, and slowing browsing. To improve ad experiences, leading media associations define Better Ads Standards for ads that are below user expectations. However, little is known about how well websites comply with these standards and whether existing approaches are sufficient for developers to quickly resolve such issues. In this paper, we propose Adhere, a technique that can detect intrusive ads that do not comply with Better Ads Standards and suggest repair proposals. Adhere works by first parsing the initial web page to a DOM tree to search for potential static ads, and then using mutation observers to monitor and detect intrusive (dynamic/static) ads on the fly. To handle ads' volatile nature, Adhere includes two detection algorithms for desktop and mobile ads to identify different ad violations during three phases of page load events. It recursively applies the detection algorithms to resolve nested layers of DOM elements inserted by ad delegations. We evaluate Adhere on Alexa Top 1 Million Websites. The results show that Adhere is effective in detecting violating ads and suggesting repair proposals. Comparing to the current available alternative, Adhere detected intrusive ads on 4,656 more mobile websites and 3,911 more desktop websites, and improved recall by 16.6% and accuracy by 4.2%. Yutian Yan, Yunhui Zheng, Xinyue Liu 0005, Nenad Medvidovic, Weihang Wang 0001 |
ICSE | 4 |
| 2022 | Avgust: automating usage-based test generation from videos of app executionsabstractWriting and maintaining UI tests for mobile apps is a time-consuming and tedious task. While decades of research have produced auto- mated approaches for UI test generation, these approaches typically focus on testing for crashes or maximizing code coverage. By contrast, recent research has shown that developers prefer usage-based tests, which center around specific uses of app features, to help support activities such as regression testing. Very few existing techniques support the generation of such tests, as doing so requires automating the difficult task of understanding the semantics of UI screens and user inputs. In this paper, we introduce Avgust, which automates key steps of generating usage-based tests. Avgust uses neural models for image understanding to process video recordings of app uses to synthesize an app-agnostic state-machine encoding of those uses. Then, Avgust uses this encoding to synthesize test cases for a new target app. We evaluate Avgust on 374 videos of common uses of 18 popular apps and show that 69% of the tests Avgust generates successfully execute the desired usage, and that Avgust’s classifiers outperform the state of the art. Yixue Zhao, Saghar Talebipour, Kesina Baral, Hyojae Park, Leon Yee, Safwat Ali Khan, Yuriy Brun, Nenad Medvidovic, Kevin Moran |
ESEC/SIGSOFT FSE | 8 |
| 2021 | Constructing a Shared Infrastructure for Software Architecture Analysis and MaintenanceabstractOver the past three decades software engineering researchers have produced a wide range of techniques and tools for understanding the architectures of large, complex systems. However, these have tended to be one-off research projects, and their idiosyncratic natures have hampered research collaboration, extension and combination of the tools, and technology transfer. The area of software architecture is rich with disjoint research and development infrastructures, and datasets that are either proprietary or captured in proprietary formats. This paper describes a concerted effort to reverse these trends. We have designed and implemented a flexible and extensible infrastructure (SAIN) with the goal of sharing, replicating, and advancing software architecture research. We have demonstrated that SAIN is capable of incorporating the constituent tools extracted from three independently developed, large, long-lived software architecture research environments. We discuss SAIN's ambitious goals, the challenges we have faced in achieving those goals, the key decisions made in SAIN's design and implementation, the lessons learned from our experience to date, and our ongoing and future work. Joshua Garcia, Mehdi Mirakhorli, Lu Xiao 0001, Ibrahim Mujhid, Khoi Pham, Ahmet Okutan, Sam Malek, Rick Kazman, Yuanfang Cai, Nenad Medvidovic |
ICSA | 11 |
| 2021 | Architectural Decay as Predictor of Issue- and Change-PronenessabstractArchitectural decay imposes real costs in terms of developer effort, system correctness, and performance. Over time, those problems are likely to be revealed as explicit implementation issues (defects, feature changes, etc.). Recent empirical studies have demonstrated that there is a significant correlation between architectural "smells"—manifestations of architectural decay—and implementation issues. In this paper, we take a step further in exploring this phenomenon. We analyze the available development data from 10 open-source software systems and show that information regarding current architectural decay in these systems can be used to build models that accurately predict future issue-proneness and change-proneness of the systems’ implementations. As a less intuitive result, we also show that, in cases where historical data for a system is unavailable, such data from other, unrelated systems can provide reasonably accurate issue- and change-proneness prediction capabilities. Duc Minh Le, Suhrid Karthik, Marcelo Schmitt Laser, Nenad Medvidovic |
ICSA | 4 |
| 2021 | Architectural Archipelagos: Technical Debt in Long-Lived Software Research PlatformsabstractThis paper identifies a model of software evolution that is prevalent in large, long-lived academic research tool suites (3L-ARTS). This model results in an "archipelago" of related but haphazardly organized architectural "islands", and inherently induces technical debt. We illustrate the archipelago model with examples from two 3L-ARTS archipelagos identified in literature. Marcelo Schmitt Laser, Duc Minh Le, Joshua Garcia, Nenad Medvidovic |
TechDebt@ICSE | 4 |
| 2021 | UI Test Migration Across Mobile PlatformsabstractWriting UI tests manually requires significant effort. Several approaches have tried to address this problem in mobile apps: by exploiting the similarities of different apps within the same domain on a single platform, they have shown that it is possible to transfer tests that exercise similar functionality between the apps. A related recent technique enables transfer of UI tests uni-directionally, from an open-source iOS app to the same app implemented for Android. This paper presents MAPIT, a technique that expands existing work in three important ways: (1) it enables bi-directional UI test transfer between pairs of "sibling" Android and iOS apps; (2) it does not assume that the apps’ source code is available; (3) it is capable of transferring tests containing oracles in addition to UI events. MAPIT runs existing tests on a "source" app and builds a partial model of the app corresponding to each test. The model comprises the app’s screenshots, obtainable properties of each screenshot’s constituent elements, and labeled transitions between the screenshots. MAPIT uses this model to determine the corresponding information on the "target" app and generates an equivalent test, via a novel approach that leverages computer vision and NLP. Our evaluation on a diverse set of widely used, closed-source sibling Android and iOS apps shows that MAPIT is feasible, accurate, and useful in transferring UI tests across platforms. Saghar Talebipour, Yixue Zhao, Luka Dojcilovic, Chenggang Li, Nenad Medvidovic |
ASE | 5 |
| 2021 | Identifying casualty changes in software patchesabstractNoise in software patches impacts their understanding, analysis, and use for tasks such as change prediction. Although several approaches have been developed to identify noise in patches, this issue has persisted. An analysis of a dataset of security patches for the Tomcat web server, which we further expanded with security patches from five additional systems, uncovered several kinds of previously unreported noise which we call nonessential casualty changes. These are changes that themselves do not alter the logic of the program but are necessitated by other changes made in the patch. In this paper, we provide a comprehensive taxonomy of casualty changes. We then develop CasCADe, an automated technique for automatically identifying casualty changes. We evaluate CasCADe with several publicly available datasets of patches and tools that focus on them. Our results show that CasCADe is highly accurate, that the kinds of noise it identifies occur relatively commonly in patches, and that removing this noise improves upon the evaluation results of a previously published change-based approach. Adriana Sejfia, Yixue Zhao, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 3 |
| 2020 | Strategies for Pattern-Based Detection of Architecturally-Relevant Software VulnerabilitiesabstractSoftware vulnerabilities expose a system to security breaches. In this paper, we focus on vulnerabilities rooted in a system's architecture. Specifically, we describe our attempt at developing ways of depicting and detecting architectural vulnerabilities. Our guiding observation was that vulnerabilities that belong to the same category result in commonalities in the source code. This observation led us to hypothesize that it is possible to define patterns that can be used to detect similar vulnerabilities. To test this hypothesis, we collected a dataset of vulnerabilities reported for the Tomcat web server that spanned 20 different categories and 90 unique vulnerabilities. We represented each individual vulnerability with a Program Dependence Graph (PDG) and employed two approaches we believed to be especially promising based on the results they yielded when applied to similar problems. The first approach relied on graph-theory research to identify shared subgraphs in vulnerability PDGs. The second approach performed a multi-level hierarchical clustering on the PDGs to account for cases in which vulnerabilities of the same category exhibit more than one pattern. In the end, neither approach yielded successful results: the former was too computationally expensive to be practically applicable and had limited applicability, while the latter generated patterns that performed poorly when applied on real examples of vulnerabilities. Even though the two approaches were ultimately unsuccessful, we report on several important lessons that emerged from this endeavor. Adriana Sejfia, Nenad Medvidovic |
ICSA | 2 |
| 2020 | AirMochi - A Tool for Remotely Controlling iOS DevicesabstractThis paper presents AirMochi, a tool that provides remote access and control of apps by leveraging a mobile platform's publicly exported accessibility features. While AirMochi is designed to be platform-independent, we discuss its iOS implementation. We show that AirMochi places no restrictions on apps, is able to handle a variety of scenarios, and imposes a negligible performance overhead. https://youtu.be/rhPz2Hs4Ius https://github.com/nkllkc/air_mochi Nikola Lukic, Saghar Talebipour, Nenad Medvidovic |
ASE | 3 |
| 2020 | ARCADE: an extensible workbench for architecture recovery, change, and decay evaluationabstractThis paper presents the design, implementation, and usage details of ARCADE, an extensible workbench for supporting the recovery of software systems' architectures, and for evaluating architectural change and decay. ARCADE has been developed and maintained over the past decade, and has been deployed in a number of research labs as well as within three large companies. ARCADE's implementation is available at https://bitbucket.org/joshuaga/arcade and the video depicting its use at https://tinyurl.com/arcade-tool-demo. Marcelo Schmitt Laser, Nenad Medvidovic, Duc Minh Le, Joshua Garcia |
ESEC/SIGSOFT FSE | 2 |
| 2020 | Online sports betting through the prism of software engineeringabstractOnline sports betting is a $50B industry that is heavily driven by software. The domain imposes significant demands on developers: the resulting solutions are large, complex, distributed, concurrent software systems with strict availability, real-time performance, scalability, reliability, and security requirements. This paper describes our experience with EmpireBet, a family of online sports betting platforms built and deployed over the past 15 years. The initial solution, implemented by four developers in a start-up, catered to users who connected to the system intermittently, for limited periods, via dial-up connections. Today’s system, engineered and maintained in 27 programming and markup languages by a team of 20 developers, is deployed in over 30 countries, integrated with over 50 third-party systems, and processes tens of millions daily transactions by over 680,000 players who are continuously using the system. This was accomplished via an an explicit focus on EmpireBet’s critical non-functional requirements; a modular, extensible architecture; a set of novel abstractions we introduced into the system; and several reusable libraries developed in the process. Gvozden Marinkovic, Nikola Lukic, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 3 |
| 2020 | eQual: informing early design decisionsabstractWhen designing a software system, architects make a series of design decisions that directly impact the system's quality. The number of available design alternatives grows rapidly with system size, creating an enormous space of intertwined design concerns that renders manual exploration impractical. We present eQual, a model-driven technique for simulation-based assessment of architectural designs. While it is not possible to guarantee optimal decisions so early in the design process, eQual improves decision quality. eQual is effective in practice because it (1) limits the amount of information the architects have to provide and (2) adapts optimization algorithms to effectively explore massive spaces of design alternatives. We empirically demonstrate that eQual yields designs whose quality is comparable to a set of systems' known optimal designs. A user study shows that, compared to the state-of-the-art, engineers using eQual produce statistically significantly higher-quality designs with a large effect size, are statistically significantly more confident in their designs, and find eQual easier to use. Arman Shahbazian, Suhrid Karthik, Yuriy Brun, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 4 |
| 2020 | FrUITeR: a framework for evaluating UI test reuseabstractUI testing is tedious and time-consuming due to the manual effort required. Recent research has explored opportunities for reusing existing UI tests from an app to automatically generate new tests for other apps. However, the evaluation of such techniques currently remains manual, unscalable, and unreproducible, which can waste effort and impede progress in this emerging area. We introduce FrUITeR, a framework that automatically evaluates UI test reuse in a reproducible way. We apply FrUITeR to existing test-reuse techniques on a uniform benchmark we established, resulting in 11,917 test reuse cases from 20 apps. We report several key findings aimed at improving UI test reuse that are missed by existing work. Yixue Zhao, Adriana Sejfia, Marcelo Schmitt Laser, Jie Zhang 0050, Federica Sarro, Mark Harman, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 8 |
| 2019 | Editorial: State of the Journal
Nenad Medvidovic |
IEEE Trans. Software Eng. | 1 |
| 2018 | An Empirical Study of Architectural Decay in Open-Source SoftwareabstractArchitecture is the set of principal design decisions about a software system. In practice, new architectural decisions are added and existing ones reversed or modified throughout a system's lifetime. Frequently, these decisions deviate from the architect's well-considered intent, and software systems regularly exhibit increased architectural decay as they evolve. The manifestations of such ill-considered design decisions are seen as “architectural smells”. To date, there has been no in-depth study of the characteristics or trends involving this phenomenon. Instead, when referring to architectural smells and their negative effects, both researchers and practitioners had to rely on folklore and their personal, inherently limited experience. In this paper, we report on the systematic step we have taken in investigating the nature and impact of architectural smells. We have selected a set of representative architectural smells from literature and analyzed their instances in 421 versions from 8 open-source software systems. We have (1) developed algorithms to automatically detect instances of multiple architectural smell types, and (2) analyzed relationships between the detected smells and the lists of issues reported in the systems' respective issue trackers. Our study shows that architectural smells have tangible negative consequences in the form of implementation issues as well as code commits requiring increased maintenance effort throughout a system's lifetime. Duc Minh Le, Daniel Link 0003, Arman Shahbazian, Nenad Medvidovic |
ICSA | 4 |
| 2018 | Recovering Architectural Design DecisionsabstractDesigning and maintaining a software system's architecture typically involve making numerous design decisions, each potentially affecting the system's functional and nonfunctional properties. Understanding these design decisions can help inform future decisions and implementation choices and can avoid introducing regressions and architectural inefficiencies later. Unfortunately, design decisions are rarely well documented and are typically a lost artifact of the architecture creation and maintenance process. The loss of this information can thus hurt development. To address this shortcoming, we develop RecovAr, a technique for automatically recovering design decisions from the project's readily available history artifacts, such as an issue tracker and version control repository. RecovAr uses state-of-the-art architectural recovery techniques on a series of version control commits and maps those commits to issues to identify decisions that affect system architecture. While some decisions can still be lost through this process, our evaluation on Hadoop and Struts, two large open-source systems with over 8 years of development each and, on average, more than 1 million lines of code, shows that RecovAr has the recall of 75% and a precision of 77%. Our work formally defines architectural design decisions and develops an approach for tracing such decisions in project histories. Additionally, the work introduces methods to classify whether decisions are architectural and to map decisions to code elements. Finally, our work contributes a methodology engineers can follow to preserve design-decision knowledge in their projects. Arman Shahbazian, Youn Kyu Lee, Duc Minh Le, Yuriy Brun, Nenad Medvidovic |
ICSA | 5 |
| 2018 | Leveraging program analysis to reduce user-perceived latency in mobile applicationsabstractReducing network latency in mobile applications is an effective way of improving the mobile user experience and has tangible economic benefits. This paper presents PALOMA, a novel client-centric technique for reducing the network latency by prefetching HTTP requests in Android apps. Our work leverages string analysis and callback control-flow analysis to automatically instrument apps using PALOMA's rigorous formulation of scenarios that address "what" and "when" to prefetch. PALOMA has been shown to incur significant runtime savings (several hundred milliseconds per prefetchable HTTP request), both when applied on a reusable evaluation benchmark we have developed and on real applications. Yixue Zhao, Marcelo Schmitt Laser, Yingjun Lyu, Nenad Medvidovic |
ICSE | 4 |
| 2018 | Empirically assessing opportunities for prefetching and caching in mobile appsabstractNetwork latency in mobile software has a large impact on user experience, with potentially severe economic consequences. Prefetching and caching have been shown effective in reducing the latencies in browser-based systems. However, those techniques cannot be directly applied to the emerging domain of mobile apps because of the differences in network interactions. Moreover, there is a lack of research on prefetching and caching techniques that may be suitable for the mobile app domain, and it is not clear whether such techniques can be effective or whether they are even feasible. This paper takes the first step toward answering these questions by conducting a comprehensive study to understand the characteristics of HTTP requests in over 1,000 popular Android apps. Our work focuses on the prefetchability of requests using static program analysis techniques and cacheability of resulting responses. We find that there is a substantial opportunity to leverage prefetching and caching in mobile apps, but that suitable techniques must take into account the nature of apps’ network interactions and idiosyncrasies such as untrustworthy HTTP header information. Our observations provide guidelines for developers to utilize prefetching and caching schemes in app development, and motivate future research in this area. Yixue Zhao, Paul Wat, Marcelo Schmitt Laser, Nenad Medvidovic |
ASE | 4 |
| 2018 | Toward predicting architectural significance of implementation issuesabstractIn a software system's development lifecycle, engineers make numerous design decisions that subsequently cause architectural change in the system. Previous studies have shown that, more often than not, these architectural changes are unintentional by-products of continual software maintenance tasks. The result of inadvertent architectural changes is accumulation of technical debt and deterioration of software quality. Despite their important implications, there is a relative shortage of techniques, tools, and empirical studies pertaining to architectural design decisions. In this paper, we take a step toward addressing that scarcity by using the information in the issue and code repositories of open-source software systems to investigate the cause and frequency of such architectural design decisions. Furthermore, building on these results, we develop a predictive model that is able to identify the architectural significance of newly submitted issues, thereby helping engineers to prevent the adverse effects of architectural decay. The results of this study are based on the analysis of 21,062 issues affecting 301 versions of 5 large open-source systems for which the code changes and issues were publicly accessible. Arman Shahbazian, Daye Nam, Nenad Medvidovic |
MSR | 3 |
| 2018 | Measuring the Impact of Code Dependencies on Software Architecture Recovery TechniquesabstractMany techniques have been proposed to automatically recover software architectures from software implementations. A thorough comparison among the recovery techniques is needed to understand their effectiveness and applicability. This study improves on previous studies in two ways. First, we study the impact of leveraging accurate symbol dependencies on the accuracy of architecture recovery techniques. In addition, we evaluate other factors of the input dependencies such as the level of granularity and the dynamic-bindings graph construction. Second, we recovered the architecture of a large system, Chromium, that was not available previously. Obtaining the ground-truth architecture of Chromium involved two years of collaboration with its developers. As part of this work, we developed a new submodule-based technique to recover preliminary versions of ground-truth architectures. The results of our evaluation of nine architecture recovery techniques and their variants suggest that (1) using accurate symbol dependencies has a major influence on recovery quality, and (2) more accurate recovery techniques are needed. Our results show that some of the studied architecture recovery techniques scale to very large systems, whereas others do not. Thibaud Lutellier, Devin Chollak, Joshua Garcia, Lin Tan 0001, Derek Rayside, Nenad Medvidovic, Robert Kroeger |
IEEE Trans. Software Eng. | 6 |
| 2018 | Editorial from the New Editor in ChiefabstractPresents the introductory editorial for this issue of the publication. Nenad Medvidovic |
IEEE Trans. Software Eng. | 1 |
| 2017 | Continuous Analysis of Collaborative DesignabstractIn collaborative design, architects' individual design decisions may conflict and, when joined, may violate system consistency rules or non-functional requirements. These design conflicts can hinder collaboration and result in wasted effort. Proactive detection of code-level conflicts has been shown to improve collaborative productivity, however, the computational resource requirements for proactively computing design conflicts have hindered its applicability in practice. Our survey and interviews of 50 architects from six large software companies find that 60% of their projects involve collaborative design, that architects consider integration costly, and that design conflicts are frequent and lead to lost work. To aid collaborative design, we re-engineer FLAME, our prior design conflict detection technique, to use cloud resources and a novel prioritization algorithm that, together, achieve efficient and nonintrusive conflict detection, and guarantee a bound on the time before a conflict is discovered. Two controlled experiments with 90 students trained in software architecture in a professional graduate program, demonstrate that architects using FLAME design more efficiently, produce higher-quality designs, repair conflicts faster, and prefer using FLAME. An empirical performance evaluation demonstrates FLAME's scalability and verifies its time-bound guarantees. Jae Young Bang, Yuriy Brun, Nenad Medvidovic |
ICSA | 3 |
| 2017 | A SEALANT for inter-app security holes in androidabstractAndroid's communication model has a major security weakness: malicious apps can manipulate other apps into performing unintended operations and can steal end-user data, while appearing ordinary and harmless. This paper presents SEALANT, a technique that combines static analysis of app code, which infers vulnerable communication channels, with runtime monitoring of inter-app communication through those channels, which helps to prevent attacks. SEALANT's extensive evaluation demonstrates that (1) it detects and blocks inter-app attacks with high accuracy in a corpus of over 1,100 real-world apps, (2) it suffers from fewer false alarms than existing techniques in several representative scenarios, (3) its performance overhead is negligible, and (4) end-users do not find it challenging to adopt. Youn Kyu Lee, Jae Young Bang, Gholamreza Safi, Arman Shahbazian, Yixue Zhao, Nenad Medvidovic |
ICSE | 6 |
| 2017 | SEALANT: a detection and visualization tool for inter-app security vulnerabilities in AndroidabstractAndroid's flexible communication model allows interactions among third-party apps, but it also leads to inter-app security vulnerabilities. Specifically, malicious apps can eavesdrop on interactions between other apps or exploit the functionality of those apps, which can expose a user's sensitive information to attackers. While the state-of-the-art tools have focused on detecting inter-app vulnerabilities in Android, they neither accurately analyze realistically large numbers of apps nor effectively deliver the identified issues to users. This paper presents SEALANT, a novel tool that combines static analysis and visualization techniques that, together, enable accurate identification of inter-app vulnerabilities as well as their systematic visualization. SEALANT statically analyzes architectural information of a given set of apps, infers vulnerable communication channels where inter-app attacks can be launched, and visualizes the identified information in a compositional representation. SEALANT has been demonstrated to accurately identify inter-app vulnerabilities from hundreds of real-world Android apps and to effectively deliver the identified information to users. (Demo Video: https://youtu.be/E4lLQonOdUw) Youn Kyu Lee, Peera Yoodee, Arman Shahbazian, Daye Nam, Nenad Medvidovic |
ASE | 5 |
| 2017 | A large-scale study of architectural evolution in open-source software systems
Pooyan Behnamghader, Duc Minh Le, Joshua Garcia, Daniel Link 0003, Arman Shahbazian, Nenad Medvidovic |
Empir. Softw. Eng. | 6 |
| 2016 | Disseminating architectural knowledge on open-source projects: a case study of the book "architecture of open-source applications"abstractThis paper reports on an interview-based study of 18 authors of different chapters of the two-volume book "Architecture of Open-Source Applications". The main contributions are a synthesis of the process of authoring essay-style documents (ESDs) on software architecture, a series of observations on important factors that influence the content and presentation of architectural knowledge in this documentation form, and a set of recommendations for readers and writers of ESDs on software architecture. We analyzed the influence of three factors in particular: the evolution of a system, the community involvement in the project, and the personal characteristics of the author. This study provides the first systematic investigation of the creation of ESDs on software architecture. The observations we collected have implications for both readers and writers of ESDs, and for architecture documentation in general. Martin P. Robillard, Nenad Medvidovic |
ICSE | 2 |
| 2016 | An end-to-end domain specific modeling and analysis platformabstractSoftware architecture models are specifications of the principal design decisions about a software system that primarily govern its structure, behavior, and quality. They serve as a basis for experimentation and rationalization of design decisions. While many techniques utilize and support software architecture modeling and analysis, a recurring obstacle is that often advances in one area (e.g., architecture-based modeling) tend to be disconnected from those in another area (e.g., simulation). In this work we aim to provide an end-to-end model-driven engineering approach, called DoMAINPro, that bridges this gap and supports engineers throughout the software modeling, analysis, and implementation process by automatically synthesizing a range of model interpreters (MI). DomainPro is also available to download at https://goo.gl/4sRT9B. You can also watch the demo video describing DomainPro's prominent features at https://youtu.be/6rg7pC6bhO0. Arman Shahbazian, George Edwards, Nenad Medvidovic |
MiSE@ICSE | 3 |
| 2016 | Automated Extraction of Rich Software Models from Limited System InformationabstractReverse engineering a software system is challenged by the typically very limited information available about existing systems. Useful reverse engineering tasks include recovering a system's architectural, behavioral, and usage models, which can then be leveraged to answer important questions about a system. For example, using such models to analyze and predict a system's non-functional properties would help to efficiently assess the system's current state, planned adaptations, scalability issues, etc. Existing approaches typically only extract a system's static architecture, omitting the dynamic information that is needed for such analyses. The contribution of this paper is an automated technique that extracts a system's static architecture, behavior, and usage models from very limited, but readily available information: source code and test cases. These models can then be fed into known performance, reliability, and cost prediction techniques. We evaluated our approach for accuracy against systems with already established usage models, and observed that our approach finds the correct, but more detailed usage models. We also analyzed 14 open source software systems spanning over 2 million lines of code to evaluate the scalability of our approach. Michael Langhammer, Arman Shahbazian, Nenad Medvidovic, Ralf Reussner |
WICSA | 3 |
| 2016 | Relating Architectural Decay and Sustainability of Software SystemsabstractEnsuring the longevity of a software system is an important concern for developers and maintainers. However, when a system's architecture decays during evolution and its quality degrades as a result, the system's long-term sustainability is highly affected. In this light, providing mediums to estimate and track the sustainability of a software system is necessary to help engineers stay aware of system health. Most existing techniques and tools estimate the level of sustainability in code, paying significantly less attention to the analysis and understanding of architectural decay. This position paper provides a taxonomy of architectural smells, metrics, and their impacted quality properties. We relate these smells to maintenance and evolution areas as a first step toward our ultimate goal of estimating the sustainability of systems. We finally report some initial results drawn from a set of subject systems as promising future work using our taxonomy. Duc Minh Le, Carlos Carrillo 0001, Rafael Capilla, Nenad Medvidovic |
WICSA | 4 |
| 2016 | Software architectural principles in contemporary mobile software: from conception to practice
Hamid Bagheri, Joshua Garcia, Sam Malek, Nenad Medvidovic |
J. Syst. Softw. | 5 |
| 2015 | Comparing Software Architecture Recovery Techniques Using Accurate DependenciesabstractMany techniques have been proposed to automatically recover software architectures from software implementations. A thorough comparison among the recovery techniques is needed to understand their effectiveness and applicability. This study improves on previous studies in two ways. First, we study the impact of leveraging more accurate symbol dependencies on the accuracy of architecture recovery techniques. Previous studies have not seriously considered how the quality of the input might affect the quality of the output for architecture recovery techniques. Second, we study a system (Chromium) that is substantially larger (9.7 million lines of code) than those included in previous studies. Obtaining the ground-truth architecture of Chromium involved two years of collaboration with its developers. As part of this work we developed a new sub module-based technique to recover preliminary versions of ground-truth architectures. The other systems that we study have been examined previously. In some cases, we have updated the ground-truth architectures to newer versions, and in other cases we have corrected newly discovered inconsistencies. Our evaluation of nine variants of six state-of-the-art architecture recovery techniques shows that symbol dependencies generally produce architectures with higher accuracies than include dependencies. Despite this improvement, the overall accuracy is low for all recovery techniques. The results suggest that (1) in addition to architecture recovery techniques, the accuracy of dependencies used as their inputs is another factor to consider for high recovery accuracy, and (2) more accurate recovery techniques are needed. Our results show that some of the studied architecture recovery techniques scale to the 10M lines-of-code range (the size of Chromium), whereas others do not. Thibaud Lutellier, Devin Chollak, Joshua Garcia, Lin Tan 0001, Derek Rayside, Nenad Medvidovic, Robert Kroeger |
ICSE (2) | 6 |
| 2015 | An Empirical Study of Architectural Change in Open-Source Software SystemsabstractFrom its very inception, the study of software architecture has recognized architectural decay as a regularly occurring phenomenon in long-lived systems. Architectural decay is caused by repeated changes to a system during its lifespan. Despite decay's prevalence, there is a relative dearth of empirical data regarding the nature of architectural changes that may lead to decay, and of developers' understanding of those changes. In this paper, we take a step toward addressing that scarcity by conducting an empirical study of changes found in software architectures spanning several hundred versions of 14 open-source systems. Our study reveals several new findings regarding the frequency of architectural changes in software systems, the common points of departure in a system's architecture during maintenance and evolution, the difference between system-level and component-level architectural change, and the suitability of a system's implementation-level structure as a proxy for its architecture. Duc Minh Le, Pooyan Behnamghader, Joshua Garcia, Daniel Link 0003, Arman Shahbazian, Nenad Medvidovic |
MSR | 6 |
| 2015 | Detecting event anomalies in event-based systemsabstractEvent-based interaction is an attractive paradigm because its use can lead to highly flexible and adaptable systems. One problem in this paradigm is that events are sent, received, and processed nondeterministically, due to the systems’ reliance on implicit invocation and implicit concurrency. This nondeterminism can lead to event anomalies, which occur when an event-based system receives multiple events that lead to the write of a shared field or memory location. Event anomalies can lead to unreliable, error-prone, and hard to debug behavior in an event-based system. To detect these anomalies, this paper presents a new static analysis technique, DEvA, for automatically detecting event anomalies. DEvA has been evaluated on a set of open-source event-based systems against a state-of-the-art technique for detecting data races in multithreaded systems, and a recent technique for solving a similar problem with event processing in Android applications. DEvA exhibited high precision with respect to manually constructed ground truths, and was able to locate event anomalies that had not been detected by the existing solutions. Gholamreza Safi, Arman Shahbazian, William G. J. Halfond, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 4 |
| 2015 | Proactive Detection of Higher-Order Software Design ConflictsabstractSoftware architects who collaboratively evolve a software model rely on version control systems (VCSs) to synchronize their individual changes to the model. However, with the current generation of software model VCSs, architects remain unaware of newly arising conflicts until the next synchronization, raising the risk that delayed conflict resolution will be much harder. There are existing tools that proactively detect analogous conflicts at the level of source code. However, it is challenging to directly use them for software models because those tools are constructed to manage code-level rather than model-level changes. Furthermore, no empirical data is currently available regarding the impact of proactive conflict detection on collaborative design. In this paper, we report on our design-level proactive conflict detection research, which specifically targets a class of higher-order conflicts that do not prevent merging but do violate a system's consistency rule. We present FLAME, an extensible, operation-based collaborative software design framework that proactively detects conflicts. We also present a user study result involving FLAME conducted with 42 participants. The study indicated that the participants who used FLAME were able to create higher quality models in the same amount of time, and to detect and resolve higher-order conflicts earlier and more quickly. Jae Young Bang, Nenad Medvidovic |
WICSA | 2 |
| 2015 | Revisiting the Anatomy and Physiology of the GridabstractA domain-specific software architecture (DSSA) represents an effective, generalized, reusable solution to constructing software systems within a given application domain. In this paper, we revisit the widely cited DSSA for the domain of grid computing. We have studied systems in this domain over the last ten years. During this time, we have repeatedly observed that, while individual grid systems are widely used and deemed successful, the grid DSSA is actually underspecified to the point where providing a precise answer regarding what makes a software system a grid system is nearly impossible. Moreover, every one of the existing purported grid technologies actually violates the published grid DSSA. In response to this, based on an analysis of the source code, documentation, and usage of eighteen of the most pervasive grid technologies, we have significantly refined the original grid DSSA. We demonstrate that this DSSA much more closely matches the grid technologies studied. Our refinements allow us to more definitively identify a software system as a grid technology, and distinguish it from software libraries, middleware, and frameworks. Chris Mattmann, Joshua Garcia, Ivo Krka, Daniel Popescu 0001, Nenad Medvidovic |
J. Grid Comput. | 5 |
| 2015 | Self-Adapting Reliability in Distributed Software SystemsabstractDeveloping modern distributed software systems is difficult in part because they have little control over the environments in which they execute. For example, hardware and software resources on which these systems rely may fail or become compromised and malicious. Redundancy can help manage such failures and compromises, but when faced with dynamic, unpredictable resources and attackers, the system reliability can still fluctuate greatly. Empowering the system with self-adaptive and self-managing reliability facilities can significantly improve the quality of the software system and reduce reliance on the developer predicting all possible failure conditions. We present iterative redundancy, a novel approach to improving software system reliability by automatically injecting redundancy into the system's deployment. Iterative redundancy self-adapts in three ways: (1) by automatically detecting when the resource reliability drops, (2) by identifying unlucky parts of the computation that happen to deploy on disproportionately many compromised resources, and (3) by not relying on a priori estimates of resource reliability. Further, iterative redundancy is theoretically optimal in its resource use: Given a set of resources, iterative redundancy guarantees to use those resources to produce the most reliable version of that software system possible; likewise, given a desired increase in the system's reliability, iterative redundancy guarantees achieving that reliability using the least resources possible. Iterative redundancy handles even the Byzantine threat model, in which compromised resources collude to attack the system. We evaluate iterative redundancy in three ways. First, we formally prove its self-adaptation, efficiency, and optimality properties. Second, we simulate it at scale using discrete event simulation. Finally, we modify the existing, open-source, volunteer-computing BOINC software system and deploy it on the globally-distributed PlanetLab testbed network to empirically evaluate that iterative redundancy is self-adaptive and more efficient than existing techniques. Yuriy Brun, Jae Young Bang, George Edwards, Nenad Medvidovic |
IEEE Trans. Software Eng. | 4 |
| 2014 | Revisiting Compatibility of Input-Output Modal Transition Systems
Ivo Krka, Nicolás D'Ippolito, Nenad Medvidovic, Sebastián Uchitel |
FM | 3 |
| 2014 | Automatic mining of specifications from invocation traces and method invariantsabstractSoftware library documentation often describes individual methods' APIs, but not the intended protocols and method interactions. This can lead to library misuse, and restrict runtime detection of protocol violations and automated verification of software that uses the library. Specification mining, if accurate, can help mitigate these issues, which has led to significant research into new model-inference techniques that produce FSM-based models from program invariants and execution traces. However, there is currently a lack of empirical studies that, in a principled way, measure the impact of the inference strategies on model quality. To this end, we identify four such strategies and systematically study the quality of the models they produce for nine off-the-shelf libraries. We find that (1) using invariants to infer an initial model significantly improves model quality, increasing precision by 4% and recall by 41%, on average; (2) effective invariant filtering is crucial for quality and scalability of strategies that use invariants; and (3) using traces in combination with invariants greatly improves robustness to input noise. We present our empirical evaluation, implement new and extend existing model-inference techniques, and make public our implementations, ground-truth models, and experimental data. Our work can lead to higher-quality model inference, and directly improve the techniques and tools that rely on model inference. Ivo Krka, Yuriy Brun, Nenad Medvidovic |
SIGSOFT FSE | 3 |
| 2014 | Component-Aware Triggered ScenariosabstractUse-case scenarios, with notations such as UML sequence diagrams, are widely used to specify software system behavior. Although intuitive, these notations allow engineers to specify behaviors with unintended semantic side-effects. To address these inconsistencies, one class of languages targets triggered scenario specifications for expressing a system's reactive behaviors. However, these languages lack adequate facilities for modeling the intended behavior of the individual system components. This runs the risks of sacrificing the expressive power required to model component behaviors, misinterpreting the stakeholder intent, and misspecifying the component behaviors. The risks are particularly prominent when the requirements specification and software architecture specification are refined iteratively and in parallel. To remedy these problems, we propose component-aware Triggered Scenarios (caTS), an enhancement to triggered scenario languages that allows an engineer to define components' obligations within a scenario. We have formalized the syntax and semantics of ccaTSats, and have applied cats on a real-world case study, which suggests improved accuracy and conciseness of caTS in comparison to existing alternatives. Ivo Krka, Nenad Medvidovic |
WICSA | 2 |
| 2014 | Guest editorial to the Special Issue on Component-Based Software Engineering and Software Architecture
Barbora Buhnova, Antonio Vallecillo, Nenad Medvidovic, Magnus Larsson, Javier López 0001, Jorge Cuéllar |
Sci. Comput. Program. | 3 |
| 2014 | iDARE - a reference architecture for integrated software environmentsabstractSUMMARY Traditionally, software development environments have tended to treat a system's development‐time activities separately from its run‐time. After a system is in operation, it frequently needs to be maintained and evolved. In traditional environments, this results in frequent relocations of a system between the disjoint development and run‐time environments, which is undesirable for several reasons. A more effective solution is to couple the development and run‐time environments to directly monitor and adapt running systems. Given the growing need for interaction between development‐time and run‐time aspects of modern software systems, it is important to understand development and run‐time environments, and their relationship. To this end, we study and classify a wide range of software development environments on the basis of their level of interaction with the corresponding run‐time environments. Particularly, we identify, study, and characterize Self‐Adaptive Life‐cycle Environments (SALEs), an emerging class of modern development environments that are tightly integrated with run‐time environments. We reify our study of the development environments into a novel reference architecture, iDARE, that captures and differentiates the architectures of software environments – from those, such as traditional development environments, that have no interaction with the run‐time environments, to the ones, such as SALEs, that are tightly integrated with the run‐time environments. We use iDARE to highlight several shortcomings of existing SALEs. Adherence to iDARE has the potential to improve certain quality properties of the integrated development and run‐time environments, such as adaptability, fault‐tolerance, robustness, availability, and resource consumption. We identify a number of opportunities for future research. Copyright © 2013 John Wiley & Sons, Ltd. Hossein Tajalli, Nenad Medvidovic |
Softw. Pract. Exp. | 2 |
| 2013 | Obtaining ground-truth software architecturesabstractUndocumented evolution of a software system and its underlying architecture drives the need for the architecture's recovery from the system's implementation-level artifacts. While a number of recovery techniques have been proposed, they suffer from known inaccuracies. Furthermore, these techniques are difficult to evaluate due to a lack of “ground-truth” architectures that are known to be accurate. To address this problem, we argue for establishing a suite of ground-truth architectures, using a recovery framework proposed in our recent work. This framework considers domain-, application-, and context-specific information about a system, and addresses an inherent obstacle in establishing a ground-truth architecture - the limited availability of engineers who are closely familiar with the system in question. In this paper, we present our experience in recovering the ground-truth architectures of four open-source systems. We discuss the primary insights gained in the process, analyze the characteristics of the obtained ground-truth architectures, and reflect on the involvement of the systems' engineers in a limited but critical fashion. Our findings suggest the practical feasibility of obtaining ground-truth architectures for large systems and encourage future efforts directed at establishing a large scale repository of such architectures. Joshua Garcia, Ivo Krka, Chris Mattmann, Nenad Medvidovic |
ICSE | 4 |
| 2013 | A comparative analysis of software architecture recovery techniquesabstractMany automated techniques of varying accuracy have been developed to help recover the architecture of a software system from its implementation. However, rigorously assessing these techniques has been hampered by the lack of architectural “ground truths”. Over the past several years, we have collected a set of eight architectures that have been recovered from open-source systems and independently, carefully verified. In this paper, we use these architectures as ground truths in performing a comparative analysis of six state-of-the-art software architecture recovery techniques. We use a number of metrics to assess each technique for its ability to identify a system's architectural components and overall architectural structure. Our results suggest that two of the techniques routinely outperform the rest, but even the best of the lot has surprisingly low accuracy. Based on the empirical data, we identify several avenues of future research in software architecture recovery. Joshua Garcia, Igor Ivkovic, Nenad Medvidovic |
ASE | 3 |
| 2013 | Distributing refinements of a system-level partial behavior modelabstractEarly in a system's life cycle, a system's behavior is typically partially specified using scenarios, invariants, and temporal properties. These specifications prohibit or require certain behaviors, while leaving other behaviors uncategorized into either of those. Engineers refine the specification by eliciting more requirements to finally arrive at a complete behavioral description. Partial-behavior models have been utilized as a formal foundation for capturing partial system specifications. Mapping the requirements to partial behavior models enables automated analyses (e.g., requirements consistency checking) and helps to elicit new requirements. Under the current practices, software systems are reasoned about and their behavior specified exclusively at the system level, disregarding of the fact that a system typically consists of interacting components. However, exclusively refining a behavior specification at the system-level runs the risk of arriving at an inconsistent specification, i.e. one that is not realizable as a composition of the system's components. To address this problem, we propose a framework that provides the lacking support: a newly specified requirement implicitly refines the system's underlying partial behavior model; our framework maps the new requirement to components by automatically distributing the system model refinements to the components' underlying models. By doing so, our framework prevents requirements inconsistencies and helps to identify further necessary requirements. We discuss the framework's soundness and correctness, and demonstrate its features on a case study previously used in related literature. Ivo Krka, Nenad Medvidovic |
RE | 2 |
| 2013 | Identifying message flow in distributed event-based systemsabstractDistributed event-based (DEB) systems contain highly-decoupled components that interact by exchanging messages. This enables flexible system composition and adaptation, but also makes DEB systems difficult to maintain. Most existing program analysis techniques to support maintenance are not well suited to DEB systems, while those that are tend to suffer from inaccuracy or make assumptions that limit their applicability. This paper presents Eos, a static analysis technique that identifies message information useful for maintaining a DEB system, namely, message types and message flow within a system. Eos has been evaluated on six off-the-shelf DEB systems spanning five different middleware platforms, and has exhibited excellent accuracy and efficiency. Furthermore, a case study involving a range of maintenance activities undertaken on three existing DEB systems shows that, on average, Eos enables an engineer to identify the scope and impact of required changes more accurately than existing alternatives. Joshua Garcia, Daniel Popescu 0001, Gholamreza Safi, William G. J. Halfond, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 5 |
| 2013 | The future of software engineering IN and FOR the cloud
Rami Bahsoon, Ivan Mistrík, Nour Ali, T. S. Mohan, Nenad Medvidovic |
J. Syst. Softw. | 5 |
| 2013 | Entrusting Private Computation and Data to Untrusted NetworksabstractWe present sTile, a technique for distributing trust-needing computation onto insecure networks, while providing probabilistic guarantees that malicious agents that compromise parts of the network cannot learn private data. With sTile, we explore the fundamental cost of achieving privacy through data distribution and bound how much less efficient a privacy-preserving system is than a nonprivate one. This paper focuses specifically on NP-complete problems and demonstrates how sTile-based systems can solve important real-world problems, such as protein folding, image recognition, and resource allocation. We present the algorithms involved in sTile and formally prove that sTile-based systems preserve privacy. We develop a reference sTile-based implementation and empirically evaluate it on several physical networks of varying sizes, including the globally distributed PlanetLab testbed. Our analysis demonstrates sTile's scalability and ability to handle varying network delay, as well as verifies that problems requiring privacy-preservation can be solved using sTile orders of magnitude faster than using today's state-of-the-art alternatives. Yuriy Brun, Nenad Medvidovic |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2012 | Keeping Data Private while Computing in the CloudabstractThe cloud offers unprecedented access to computation. However, ensuring the privacy of that computation remains a significant challenge. In this paper, we address the problem of distributing computation onto the cloud in a way that preserves the privacy of the computation's data even from the cloud nodes themselves. The approach, called sTile, separates the computation into small subcomputations and distributes them in a way that makes it prohibitively hard to reconstruct the data. We evaluate sTile theoretically and empirically: First, we formally prove that sTile systems preserve privacy. Second, we deploy a prototype implementation on three different networks, including the globally-distributed PlanetLab testbed, to show that sTile is robust to network delay and efficient enough to significantly outperform existing privacy-preserving approaches. Yuriy Brun, Nenad Medvidovic |
IEEE CLOUD | 2 |
| 2012 | Architecture-level reliability prediction of concurrent systemsabstractStringent requirements on modern software systems dictate evaluation of dependability qualities, such as reliability, as early as possible in a system's life cycle. A primary shortcoming of the existing design-time reliability prediction approaches is their lack of support for modeling and analyzing concurrency in a scalable way. To address the scalability challenge, we propose SHARP, an architecture-level reliability prediction framework that analyzes a hierarchical scenario-based specification of system behavior. It achieves scalability by utilizing the scenario relations embodied in this hierarchy. SHARP first constructs and solves models of basic scenarios, and combines the obtained results based on the defined scenario dependencies; the dependencies we handle are sequential and parallel execution of multiple scenarios. This process iteratively continues through the scenario hierarchy until finally obtaining the system reliability estimate. Our evaluations performed on real-world specifications indicate that SHARP is (a) almost as accurate as a traditional non-hierarchical method, and (b) more scalable than other existing techniques. Leslie Cheung, Ivo Krka, Leana Golubchik, Nenad Medvidovic |
ICPE | 4 |
| 2012 | An Extensible Framework for Improving a Distributed Software System's Deployment ArchitectureabstractA distributed system's allocation of software components to hardware nodes (i.e., deployment architecture) can have a significant impact on its quality of service (QoS). For a given system, there may be many deployment architectures that provide the same functionality, but with different levels of QoS. The parameters that influence the quality of a system's deployment architecture are often not known before the system's initial deployment and may change at runtime. This means that redeployment of the software system may be necessary to improve the system's QoS properties. This paper presents and evaluates a framework aimed at finding the most appropriate deployment architecture for a distributed software system with respect to multiple, possibly conflicting QoS dimensions. The framework supports formal modeling of the problem and provides a set of tailorable algorithms for improving a system's deployment. We have realized the framework on top of a visual deployment architecture modeling and analysis environment. The framework has been evaluated for precision and execution-time complexity on a large number of simulated distributed system scenarios, as well as in the context of two third-party families of distributed applications. Sam Malek, Nenad Medvidovic, Marija Mikic-Rakic |
IEEE Trans. Software Eng. | 2 |
| 2011 | Smart Redundancy for Distributed ComputationabstractMany distributed software systems allow participation by large numbers of untrusted, potentially faulty components on an open network. As faults are inevitable in this setting, these systems utilize redundancy and replication to achieve fault tolerance. In this paper, we present a novel "smart" redundancy technique called iterative redundancy, which ensures efficient replication of computation and data given finite processing and storage resources, even when facing Byzantine faults. Iterative redundancy is more efficient and more adaptive than comparable state-of-the-art techniques that operate in environments with unknown system resource reliability. We show how systems that solve computational problems using a network of independent nodes can benefit from iterative redundancy. We present a formal analytical analysis and an empirical analysis, demonstrate iterative redundancy on a real-world volunteer-computing system, and compare it to existing methods. Yuriy Brun, George Edwards, Jae Young Bang, Nenad Medvidovic |
ICDCS | 4 |
| 2011 | Workshop on software engineering for cloud computing: (SECLOUD 2011)abstractCloud computing is emerging as more than simply a technology platform but a software engineering paradigm for the future. Hordes of cloud computing technologies, techniques, and integration approaches are widely being adopted, taught at the university level, and expected as key skills in the job market. The principles and practices of the software engineering and software architecture community can serve to help guide this emerging domain. The fundamental goal of the ICSE 2011 Software Engineering for Cloud Workshop is to bring together the diverse communities of cloud computing and of software engineering and architecture research with the hopes of sharing and disseminating key tribal knowledge between these rich areas. We expect as the workshop output a set of identified key software engineering challenges and important issues in the domain of cloud computing, specifically focused on how software engineering practice and research can play a role in shaping the next five years of research and practice for clouds. Furthermore, we expect to share "war stories", best practices and lessons learned between leaders in the software engineering and cloud computing communities. Chris Mattmann, Nenad Medvidovic, T. S. Mohan, T. Owen O'Malley |
ICSE | 2 |
| 2011 | Isomorphism in model tools and editorsabstractDomain-specific languages (DSLs) are modeling languages that are customized for a specific context or project. DSLs allow for fast and precise modeling because the language features and constructs can be precisely tailored based on the needs of the modeling effort. There exist highly customizable model-editing tools that can be easily configured to support DSLs defined by end-users (e.g., system architects, engineers, and analysts). However, to leverage models created using these tools for automated analysis, simulation, and code generation, end-users must build custom analysis tools and code generators. In contrast to model editors, the implementation and maintenance of these analysis and code generation tools can be tedious and hampers the utility of DSLs. In this paper, we posit that analysis and code generation tools for DSLs are, in fact, isomorphic to model editing tools. The implication of this insight is that model editors, analysis tools, and code generators can be treated as analogs conceptually and architecturally, and highly customizable analysis and code generation tools for DSLs can be built using the same approach that has already proven successful for the construction of DSL model editors. George Edwards, Yuriy Brun, Nenad Medvidovic |
ASE | 3 |
| 2011 | Enhancing architectural recovery using concernsabstractArchitectures of implemented software systems tend to drift and erode as they are maintained and evolved. To properly understand such systems, their architectures must be recovered from implementation-level artifacts. Many techniques for architectural recovery have been proposed, but their degrees of automation and accuracy remain unsatisfactory. To alleviate these shortcomings, we present a machine learning-based technique for recovering an architectural view containing a system's components and connectors. Our approach differs from other architectural recovery work in that we rely on recovered software concerns to help identify components and connectors. A concern is a software system's role, responsibility, concept, or purpose. We posit that, by recovering concerns, we can improve the correctness of recovered components, increase the automation of connector recovery, and provide more comprehensible representations of architectures. Joshua Garcia, Daniel Popescu 0001, Chris Mattmann, Nenad Medvidovic, Yuanfang Cai |
ASE | 4 |
| 2010 | CoDesign: a highly extensible collaborative software modeling frameworkabstractLarge, multinational software development organizations face a number of issues in supporting software design and modeling by geographically distributed architects. To address these issues, we present CoDesign, an extensible, collaborative, event-based software modeling framework developed in a distributed, collaborative setting by our two organizations. CoDesign's core capabilities include real-time model synchronization between geographically distributed architects, as well as detection and resolution of a range of modeling conflicts via several off-the-shelf conflict detection engines. Jae Young Bang, Daniel Popescu 0001, George Edwards, Nenad Medvidovic, Naveen N. Kulkarni, Girish Maskeri Rama, Srinivas Padmanabhuni |
ICSE (2) | 4 |
| 2010 | Using dynamic execution traces and program invariants to enhance behavioral model inferenceabstractSoftware behavioral models have proven useful for design, validation, verification, and maintenance. However, existing approaches for deriving such models sometimes overgeneralize what behavior is legal. We outline a novel approach that utilizes inferred likely program invariants and method invocation sequences to obtain an object-level model that describes legal execution sequences. The key insight is using program invariants to identify similar states in the sequences. We exemplify how our approach improves upon certain aspects of the state-of-the-art FSA-inference techniques. Ivo Krka, Yuriy Brun, Daniel Popescu 0001, Joshua Garcia, Nenad Medvidovic |
ICSE (2) | 5 |
| 2010 | Software architecture: foundations, theory, and practiceabstractSoftware architecture has become a centerpiece subject for software engineers, both researchers and practitioners alike. At the heart of every software system is its software architecture, i.e., "the set of principal design decisions about the system". Architecture permeates all major facets of a software system, for principal design decisions may potentially be made at any time during a system's lifetime, and potentially by any stakeholder. Such decisions encompass structural concerns, such as the system's high-level building blocks---components, connectors, and configurations; the system's deployment; the system's non-functional properties; and the system's evolution patterns, including runtime adaptation. Software architectures found particularly useful for families of systems---product lines---are often codified into architectural patterns, architectural styles, and reusable, parameterized reference architectures. This tutorial affords the participant an extensive treatment of the field of software architecture, its foundation, principles, and elements, including those mentioned above. Additionally, the tutorial introduces the participants to the state-of-the-art as well as the state-of-the-practice in software architecture, and looks at emerging and likely future trends in this field. The discussion is illustrated with numerous real-world examples. One example given prominent treatment is the architecture of the World Wide Web and its underlying architectural style, REpresentational State Transfer (REST). Nenad Medvidovic, Richard N. Taylor |
ICSE (2) | 1 |
| 2010 | PLASMA: a plan-based layered architecture for software model-driven adaptationabstractModern software-intensive systems are expected to adapt, often while the system is executing, to changing requirements, failures, and new operational contexts. This paper describes an approach to dynamic system adaptation that utilizes plan-based and architecture-based mechanisms. Our approach utilizes an architecture description language (ADL) and a planning-as-model-checking technology to enable dynamic replanning. The ability to automatically generate adaptation plans based solely on ADL models and an application problem description simplifies the specification and use of adaptation mechanisms for system architects. The approach uses a three-layer architecture that, while similar to previous work, provides several significant improvements. We apply our approach within the context of a mobile robotics case study. Hossein Tajalli, Joshua Garcia, George Edwards, Nenad Medvidovic |
ASE | 4 |
| 2010 | Kadre: domain-specific architectural recovery for scientific software systemsabstractScientists today conduct new research via software-based experimentation and validation in a host of disciplines. Scientific software represents a significant investment due to its complexity and longevity yet there is little reuse of scientific software beyond small libraries which increases development and maintenance costs. To alleviate this disconnect, we have developed KADRE, a domain-specific architecture recovery approach and toolset to aid automatic and accurate identification of workflow components in existing scientific software. KADRE improves upon state of the art general cluster techniques, helping to promote component-based reuse within the domain. David Woollard, Chris Mattmann, Daniel Popescu 0001, Nenad Medvidovic |
ASE | 4 |
| 2010 | An architecture-driven software mobility framework
Sam Malek, George Edwards, Yuriy Brun, Hossein Tajalli, Joshua Garcia, Ivo Krka, Nenad Medvidovic, Marija Mikic-Rakic, Gaurav S. Sukhatme |
J. Syst. Softw. | 7 |
| 2010 | Software architecture and mobility: A roadmap
Nenad Medvidovic, George Edwards |
J. Syst. Softw. | 1 |
| 2009 | Enabling more precise dependency analysis in event-based systemsabstractMaintenance engineers need to understand component dependencies in a system to successfully modify component implementations. Interaction dependencies are especially hard to understand in event-based systems, since transfer of control between components typically happens implicitly and asynchronously. We present a framework for event-based systems that guarantees that unspecified event-based dependencies do not occur. Consequently, the framework enables automated computation of architectural dependencies that are more precise than those possible in other event-based frameworks. Daniel Popescu 0001, Joshua Garcia, Nenad Medvidovic |
ICPC | 3 |
| 2009 | Synthesizing partial component-level behavior models from system specificationsabstractInitial system specifications, such as use-case scenarios and properties, only partially specify the future system. We posit that synthesizing partial component-level behavior models from these early specifications can improve software development practices. In this paper, we provide a novel algorithm for deriving a Modal Transition System (MTS) for individual system components from system-level scenario and property specifications. The generated MTSs capture the possible component implementations that (1) necessarily provide the behavior required by the scenarios, (2) restrict behavior forbidden by the properties, and (3) leave the behavior that is neither explicitly required nor forbidden as undefined. We also show how our algorithm helps to discover potential design flaws. Ivo Krka, Yuriy Brun, George Edwards, Nenad Medvidovic |
ESEC/SIGSOFT FSE | 4 |
| 2008 | Early prediction of software component reliabilityabstractThe ability to predict the reliability of a software system early in its development, e.g., during architectural design, can help to improve the system's quality in a cost-effective manner. Existing architecture-level reliability prediction approaches focus on system-level reliability and assume that the reliabilities of individual components are known. In general, this assumption is unreasonable, making component reliability prediction an important missing ingredient in the current literature. Early prediction of component reliability is a challenging problem because of many uncertainties associated with components under development. In this paper we address these challenges in developing a software component reliability prediction framework. We do this by exploiting architectural models and associated analysis techniques, stochastic modeling approaches, and information sources available early in the development lifecycle. We extensively evaluate our framework to illustrate its utility as an early reliability prediction approach. Leslie Cheung, Roshanak Roshandel, Nenad Medvidovic, Leana Golubchik |
ICSE | 3 |
| 2008 | A Methodology and Framework for Creating Domain-Specific Development InfrastructuresabstractDomain-specific architectures, middleware platforms, and analysis techniques leverage domain knowledge to help engineers build systems more effectively. An integrated set of these elements is called a domain-specific development infrastructure (DSDI). DSDIs are commonly created in a costly, ad-hoc fashion because current model-driven engineering (MDE) technologies lack sufficient mechanisms for capturing the semantics of domain concepts. In this paper, we propose a methodology for incorporating semantics within MDE frameworks to simplify and automate DSDI integration. We also present and evaluate a framework, called XTEAM, that implements our approach, resulting in structured processes and enforceable guidelines for DSDI integration. We have applied our approach to several DSDIs, and report on the benefits accrued. George Edwards, Nenad Medvidovic |
ASE | 2 |
| 2008 | Estimating the Energy Consumption in Pervasive Java-Based SystemsabstractWe define and evaluate a framework for estimating the energy consumption of pervasive Java-based software systems. The framework's primary objective is to enable an engineer to make informed decisions when adapting a system's architecture, such that the energy consumption on hardware devices with a finite battery life is reduced, and the lifetime of the system's key software services increases. Our framework explicitly takes a component-based perspective, which renders it well suited for a large class of today's distributed, embedded, and pervasive applications. The framework provides a novel approach that facilitates the accurate estimation of a system's energy consumption both during system construction-time and during runtime. In a large number of distributed application scenarios, the framework showed very good precision on the whole, giving results that were within 5% of the actually measured power losses incurred by executing the software. Chiyoung Seo, Sam Malek, Nenad Medvidovic |
PerCom | 3 |
| 2008 | A Framework for Estimating the Impact of a Distributed Software System's Architectural Style on its Energy ConsumptionabstractThe selection of an architectural style for a given software system is an important factor in satisfying its quality requirements. In battery-powered environments, such as mobile and pervasive systems, efficiency with respect to energy consumption has increasingly been recognized as an important quality attribute. In this paper, we present a framework that (1) facilitates early estimation of the energy consumption induced by an architectural style in a distributed software system, and (2) consequently enables an engineer to use energy consumption estimates along with other quality attributes in determining the most appropriate style for a given distributed application. We have applied the framework on five distributed systems styles to date, and have evaluated it for precision and accuracy using a particular middleware platform that supports the implementation of those styles. In a large number of application scenarios, our framework exhibited excellent precision, in that it was consistently able to correctly rank the five styles and estimate the relative differences in their energy consumptions. Moreover, the framework has also proven to be accurate: its estimates were within 7% of the different style implementations ' actually measured energy consumptions. Chiyoung Seo, George Edwards, Sam Malek, Nenad Medvidovic |
WICSA | 4 |
| 2007 | Scenario-Driven Dynamic Analysis of Distributed Architectures
George Edwards, Sam Malek, Nenad Medvidovic |
FASE | 3 |
| 2007 | Reconceptualizing a Family of Heterogeneous Embedded Systems via Explicit Architectural SupportabstractIt has been widely advocated that software architecture provides an effective set of abstractions for engineering (families of) complex software systems. However, architectural concepts are seldom supported directly at the level of system implementation. In embedded environments in particular, developers are often forced to rely on low-level programming languages. While this is conducive to fine-grain control over the system, it does not lend itself to addressing larger issues such as ensuring architectural integrity or managing an application family. In this paper we describe our experience with fundamentally altering the manner in which a family of embedded applications is designed, analyzed, implemented, deployed, and evolved using explicit architectural constructs. We discuss our strategy, the challenges we faced in the course of our project, the lessons learned in the process, and several open issues that remain unresolved. Sam Malek, Chiyoung Seo, Sharmila Ravula, Brad Petrus, Nenad Medvidovic |
ICSE | 5 |
| 2007 | Identifying and Addressing Uncertainty in Architecture-Level Software Reliability ModelingabstractAssessing reliability at early stages of software development, such as at the level of software architecture, is desirable and can provide a cost-effective way of improving a software system's quality. However, predicting a component's reliability at the architectural level is challenging because of uncertainties associated with the system and its individual components due to the lack of information. This paper discusses representative uncertainties which we have identified at the level of a system's components, and illustrates how to represent them in our reliability modeling framework. Our preliminary evaluation indicates promising results in our framework's ability to handle such uncertainties. Leslie Cheung, Leana Golubchik, Nenad Medvidovic, Gaurav S. Sukhatme |
IPDPS | 3 |
| 2007 | An energy consumption framework for distributed java-based systemsabstractIn this paper we define and evaluate a framework for estimating the energy consumption of Java-based software systems. Our primary objective in devising the framework is to enable an engineer to make informed decisions when adapting a system's architecture, such that the energy consumption on hardware devices with a finite battery life is reduced, and the lifetime of the system's key software services increases. Our framework explicitly takes a component-based perspective, which renders it well suited for a large class of today's distributed, embedded, and pervasive applications. The framework allows the engineer to estimate the software system's energy consumption at system construction-time and refine it at runtime. In a large number of distributed application scenarios, the framework showed very good precision on the whole, giving results that were within 5% (and often less) of the actually measured power losses incurred by executing the software. Our work to date has also highlighted a number of possible enhancements Chiyoung Seo, Sam Malek, Nenad Medvidovic |
ASE | 3 |
| 2007 | A Framework for the Assessment and Selection of Software Components and Connectors in COTS-Based ArchitecturesabstractSoftware systems today are composed from prefabricated commercial components and connectors that provide complex functionality and engage in complex interactions. Unfortunately, because of the distinct assumptions made by developers of these products, successfully integrating them into a software system can be complicated, often causing budget and schedule overruns. A number of integration risks can often be resolved by selecting the 'right' set of COTS components and connectors that can be integrated with minimal effort. In this paper we describe a framework for selecting COTS software components and connectors ensuring their interoperability in software-intensive systems. Our framework is built upon standard definitions of both COTS components and connectors and is intended for use by architects and developers during the design phase of a software system. We highlight the utility of our framework using a challenging example from the data-intensive systems domain. Our preliminary experience in using the framework indicates an increase in interoperability assessment productivity by 50% and accuracy by 20%. Jesal Bhuta, Chris Mattmann, Nenad Medvidovic, Barry W. Boehm |
WICSA | 3 |
| 2007 | Moving architectural description from under the technology lamppost
Nenad Medvidovic, Eric M. Dashofy, Richard N. Taylor |
Inf. Softw. Technol. | 1 |
| 2006 | A software architecture-based framework for highly distributed and data intensive scientific applicationsabstractModern scientific research is increasingly conducted by virtual communities of scientists distributed around the world. The data volumes created by these communities are extremely large, and growing rapidly. The management of the resulting highly distributed, virtual data systems is a complex task, characterized by a number of formidable technical challenges, many of which are of a software engineering nature. In this paper we describe our experience over the past seven years in constructing and deploying OODT, a software framework that supports large, distributed, virtual scientific communities. We outline the key software engineering challenges that we faced, and addressed, along the way. We argue that a major contributor to the success of OODT was its explicit focus on software architecture. We describe several large-scale, real-world deployments of OODT, and the manner in which OODT helped us to address the domain-specific challenges induced by each deployment. Chris Mattmann, Daniel J. Crichton, Nenad Medvidovic, Steve Hughes |
ICSE | 3 |
| 2006 | Estimating software component reliability by leveraging architectural modelsabstractSoftware reliability techniques are aimed at reducing or eliminat-ing failures in software systems. Reliability in software systems istypically measured during or after system implementation. How-ever, software engineering methodology lays stress on doing the"correct things" early on in the software development lifecycle inorder to curb development and maintenance costs. In this paper, wepropose a framework for reliability estimation of software compo-nents at the level of software architecture. Roshanak Roshandel, Somo Banerjee, Leslie Cheung, Nenad Medvidovic, Leana Golubchik |
ICSE | 4 |
| 2006 | An architectural style for high-performance asymmetrical parallel computationsabstractResearchers with deep knowledge of scientific domains are becoming more interested in developing highly-adaptive and irregular (asymmetrical) parallel computations, leading to development challenges for both delivery of data for computation and mapping of processes to physical resources. Using software engineering principles, we have developed a new communications protocol and architectural style for asymmetrical parallel computations called ADaPT.Utilizing the support of architecturally-aware middleware, we show that ADaPT provides a more efficient solution in terms of message passing and load balancing than asymmetrical parallel computations using collective calls in the Message-Passing Interface (MPI) or more advanced frameworks implementing explicit load-balancing policies. Additionally, developers using ADaPT gain significant windfall from good practices in software engineering, including implementation-level support of architectural artifacts and separation of computational loci from communication protocols. David Woollard, Nenad Medvidovic |
ICSE | 2 |
| 2006 | Engineering reliability into hybrid systems via rich design models: recent results and current directionsabstractSoftware reliability techniques are aimed at reducing or eliminating failures in software systems. Reliability in software systems has traditionally been measured during or after system implementation. However, software engineering methodology lays stress on doing the "correct things" early on in the software development lifecycle in order to curb development and maintenance costs. In this paper, we argue that reliability of a software system should be assessed throughout the system's life span, starting with the software architecture level. Our research goal is to estimate the reliability of software systems in early design stages, which we believe involves the ability to reason about numerous uncertainties that exist in this stage, including uncertainty due to lack of execution artifacts. Our proposed approach is to develop techniques that will couple software architectural models with a suite of stochastic reliability estimation models and allow us to reason about these uncertainties. In this paper, we present our recent results using our technique for reliability estimation of software components at the level of software architecture. Another important part of this paper is the discussion of our ongoing research efforts and open research problems in this area. Somo Banerjee, Leslie Cheung, Leana Golubchik, Nenad Medvidovic, Roshanak Roshandel, Gaurav S. Sukhatme |
IPDPS | 4 |
| 2006 | Using software evolution to focus architectural recovery
Nenad Medvidovic, Vladimir Jakobac |
Autom. Softw. Eng. | 1 |
| 2006 | Understanding the past, improving the present, and mapping out the future of software architecture
Nenad Medvidovic, René L. Krikhaar, Robert L. Nord, Judith A. Stafford |
J. Syst. Softw. | 1 |
| 2005 | Improving System Understanding via Interactive, Tailorable, Source Code Analysis
Vladimir Jakobac, Alexander Egyed, Nenad Medvidovic |
FASE | 3 |
| 2005 | A Style-Aware Architectural Middleware for Resource-Constrained, Distributed SystemsabstractA recent emergence of small, resource-constrained, and highly mobile computing platforms presents numerous new challenges for software developers. We refer to development in this new setting as programming-in-the-small-and-many (Prism). This paper provides a description and evaluation of Prism-MW, a middleware platform intended to support software architecture-based development in the Prism setting. Prism-MW provides efficient and scalable implementation-level support for the key aspects of Prism application architectures, including their architectural styles. Additionally, Prism-MW is extensible to support different application requirements suitable for the Prism setting. Prism-MW has been applied in a number of applications and used as an educational tool in graduate-level software architecture and embedded systems courses. Recently, Prism-MW has been successfully evaluated by a major industrial organization for use in one of their key distributed embedded systems. Our experience with the middleware indicates that the principles of architecture-based software development can be successfully, and flexibly, applied in the Prism setting. Sam Malek, Marija Mikic-Rakic, Nenad Medvidovic |
IEEE Trans. Software Eng. | 3 |
| 2004 | Modeling Behavior in Compositions of Software Architectural Primitives
Nikunj R. Mehta, Nenad Medvidovic, Marjan Sirjani, Farhad Arbab |
ASE | 2 |
| 2004 | Understanding Tradeoffs among Different Architectural Modeling ApproachesabstractOver the past decade, a number of architecture description languages (ADLs) have been proposed to facilitate modeling and analysis of software architecture. While each claims to have various benefits, to date, there have been few studies to assess the relative merits of these approaches. In this paper, we describe our experience using two ADLs to model a system initially described in UML, and compare their effectiveness in identifying system design flaws. We also describe the techniques we used for extracting architectural models from a UML system description. Roshanak Roshandel, Bradley R. Schmerl, Nenad Medvidovic, David Garlan, Dehua Zhang |
WICSA | 3 |
| 2004 | Reconciling software requirements and architectures with intermediate models
Paul Grünbacher, Alexander Egyed, Nenad Medvidovic |
Softw. Syst. Model. | 3 |
| 2004 | Mae - a system model and environment for managing architectural evolutionabstractAs with any other artifact produced as part of the software life cycle, software architectures evolve and this evolution must be managed. One approach to doing so would be to apply any of a host of existing configuration management systems, which have long been used successfully at the level of source code. Unfortunately, such an approach leads to many problems that prevent effective management of architectural evolution. To overcome these problems, we have developed an alternative approach centered on the use of an integrated architectural and configuration management system model. Because the system model combines architectural and configuration management concepts in a single representation, it has the distinct benefit that all architectural changes can be precisely captured and clearly related to each other---both at the fine-grained level of individual architectural elements and at the coarse-grained level of architectural configurations. To support the use of the system model, we have developed Mae, an architectural evolution environment through which users can specify architectures in a traditional manner, manage the evolution of the architectures using a check-out/check-in mechanism that tracks all changes, select a specific architectural configuration, and analyze the consistency of a selected configuration. We demonstrate the benefits of our approach by showing how the system model and its accompanying environment were used in the context of several representative projects. Roshanak Roshandel, André van der Hoek, Marija Mikic-Rakic, Nenad Medvidovic |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2003 | Adaptable Architectural Middleware for Programming-in-the-Small-and-Many
Marija Mikic-Rakic, Nenad Medvidovic |
Middleware | 2 |
| 2003 | Composing architectural styles from architectural primitivesabstractArchitectural styles are named collections of constraints on configurations of architectural elements, and are believed to bring economies of scale in applying software architecture techniques to software development. Existing research on architectural styles provides little guidance for the systematic design and construction of architectural style elements. This paper proposes a framework, Alfa, for systematically and constructively composing "architectural primitives" to obtain elements of architectural styles. This is based on our observation that architectural styles share many underlying concepts that lead to architectural primitives. We have identified eight forms and nine functions as architectural primitives that reflect the syntactic and semantic characteristics of architectural styles and are expressive enough to compose their elements. Our approach is also illustrated using a familiar style -- pipe-and-filter. Nikunj R. Mehta, Nenad Medvidovic |
ESEC / SIGSOFT FSE | 2 |
| 2003 | The Role of Middleware in Architecture-Based Software DevelopmentabstractSoftware architectures promote development focused on modular functional building blocks (components), their interconnections (configurations), and their interactions (connectors). Since architecture-level components often contain complex functionality, it is reasonable to expect that their interactions will be complex as well. Middleware technologies such as CORBA, COM, and RMI provide a set of predefined services for enabling component composition and interaction. However, the potential role of such services in the implementations of software architectures is not well understood. In practice, middleware can resolve various types of component heterogeneity — across platform and language boundaries, for instance — but also can induce unwanted architectural constraints on application development. We present an approach in which components communicate through architecture-level software connectors that are implemented using middleware. This approach preserves the properties of the architecture-level connectors while leveraging the beneficial capabilities of the underlying middleware. We have implemented this approach in the context of a component- and message-based architectural style called C2 and demonstrated its utility in the context of several diverse applications. We argue that our approach provides a systematic and reasonable way to bridge the gap between architecture-level connectors and implementation-level middleware packages. Nenad Medvidovic, Eric M. Dashofy, Richard N. Taylor |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2003 | Bridging models across the software lifecycle
Nenad Medvidovic, Paul Grünbacher, Alexander Egyed, Barry W. Boehm |
J. Syst. Softw. | 1 |
| 2002 | On the role of middleware in architecture-based software developmentabstractSoftware architectures promote development focused on modular functional building blocks (components), their interconnections (configurations), and their interactions (connectors). Since architecture-level components often contain complex functionality, it is reasonable to expect that their interactions will be complex as well. Middleware technologies such as CORBA, COM, and RMI, provide a set of predefined services for enabling component composition and interaction. However, the potential role of such services in the implementations of software architectures is not well understood. Furthermore, components adhering to one middleware standard cannot readily interact with those adhering to another. In order to understand the role and tradeoffs among middleware technologies in implementing architectures and enable component interoperability across middleware platforms, we have investigated a set of techniques and conducted preliminary case studies involving a particular architectural style, C2, and its implementation infrastructure. In particular, by encapsulating middleware functionality within C2's explicit software connectors, we have been able to couple C2's existing benefits such as component interchangeability, substrate independence, and structural guidance with new capabilities of multi-lingual, multi-process, and distributed application development in a manner that is transparent to architects. Furthermore, we have demonstrated the utility of our connector-based approach in enabling components implemented on top of different middleware platforms to interoperate. Though several details of our approach derive from the characteristics of the C2 style, we believe that a number of lessons learned are more generally applicable. We argue that these lessons can help form a broader research agenda for coupling the modeling power of software architectures with the implementation support provided by middleware. Nenad Medvidovic |
SEKE | 1 |
| 2002 | A Family of Software Architecture Implementation Frameworks
Nenad Medvidovic, Nikunj R. Mehta, Marija Mikic-Rakic |
WICSA | 1 |
| 2002 | Modeling software architectures in the Unified Modeling LanguageabstractThe Unified Modeling Language (UML) is a family of design notations that is rapidly becoming a de facto standard software design language. UML provides a variety of useful capabilities to the software designer, including multiple, interrelated design views, a semiformal semantics expressed as a UML meta model, and an associated language for expressing formal logic constraints on design elements. The primary goal of this work is an assessment of UML's expressive power for modeling software architectures in the manner in which a number of existing software architecture description languages (ADLs) model architectures. This paper presents two strategies for supporting architectural concerns within UML. One strategy involves using UML "as is," while the other incorporates useful features of existing ADLs as UML extensions. We discuss the applicability, strengths, and weaknesses of the two strategies. The strategies are applied on three ADLs that, as a whole, represent a broad cross-section of present-day ADL capabilities. One conclusion of our work is that UML currently lacks support for capturing and exploiting certain architectural concerns whose importance has been demonstrated through the research and practice of software architectures. In particular, UML lacks direct support for modeling and exploiting architectural styles, explicit software connectors, and local and global architectural constraints. Nenad Medvidovic, David S. Rosenblum, David F. Redmiles, Jason E. Robbins |
ACM Trans. Softw. Eng. Methodol. | 1 |
| 2001 | Reconciling Software Requirements and Architectures: The CBSP ApproachabstractLittle guidance and few methods are available to refine a set of software requirements into an architecture satisfying those requirements. Part of the challenge stems from the fact that requirements and architectures leverage different terms and concepts to capture the artifacts relevant to each. We present CBSP (Component-Bus-System- Property), a lightweight approach intended to provide a systematic way of reconciling requirements and architectures. CBSP leverages a simple set of architectural concepts (components, connectors, overall systems, and their properties) to recast the requirements in a way that facilitates their straightforward mapping to architectures. Furthermore, the approach allows us to capture and maintain arbitrarily complex relationships between requirements and architectural artifacts, as well as across different CBSP artifacts. We have extensively applied CBSP within the context of particular requirements and architecture definition techniques, EasyWinWin and C2. We leverage that experience to demonstrate the CBSP method and tool support using a large-scale example that highlights the transition from an EasyWinWin requirements negotiation into a C2-style architectural model. Paul Grünbacher, Alexander Egyed, Nenad Medvidovic |
RE | 3 |
| 2001 | Software Model Connectors: Bridging Models across the Software Lifecycle
Nenad Medvidovic, Paul Grünbacher, Alexander Egyed, Barry W. Boehm |
SEKE | 1 |
| 2001 | Taming architectural evolutionabstractIn the world of software development everything evolves. So, then, do software architectures. Unlike source code, for which the use of a configuration management (CM) system is the predominant approach to capturing and managing evolution, approaches to capturing and managing architectural evolution span a wide range of disconnected alternatives. This paper contributes a novel architecture evolution environment, called Mae, which brings together a number of these alternatives. The environment facilitates an incremental design process in which all changes to all architectural elements are integrally captured and related. Key to the environment is a rich system model that combines architectural concepts with those from the field of CM. Not only does this system model form the basis for Mae, but in precisely capturing architectural evolution it also facilitates automated support for several innovative capabilities that rely on the integrated nature of the system model. This paper introduces three of those: the provision of design guidance at the architectural level, the use of specialized software connectors to ensure run-time reliability during component upgrades, and the creation of component-level patches to be applied to deployed system configurations. André van der Hoek, Marija Mikic-Rakic, Roshanak Roshandel, Nenad Medvidovic |
ESEC / SIGSOFT FSE | 4 |
| 2001 | Focus: A Light-Weight, Incremental Approach to Software Architecture Recovery and EvolutionabstractDuring the past decade (1991-2001), object-orientation (OO) has become the dominant software development methodology, accompanied by a number of modeling notations, programming languages, and development environments. OO applications of today are increasingly complex and user driven. They are also developed more rapidly and evolved more frequently than was the case with software systems of the past. All of these factors contribute to a plethora of potential problems when maintaining and evolving an OO application. These problems are caused by architectural erosion, where the initial architecture of an application is (arbitrarily) modified to the point where its key properties no longer hold. We propose an approach, called Focus, whose goal is to enable effective evolution of such an application with minimal effort, by recovering its architecture and using it as the basis of evolution. Focus allows engineers to direct their primary attention to the part of the system that is directly impacted by the desired change; subsequent changes will incrementally uncover additional parts of the system's architecture. We have applied Focus to four off-the-shelf applications to date. We discuss its key strengths and point out several open issues that will frame our future work. Nenad Medvidovic |
WICSA | 2 |
| 2000 | A Formal Approach to Heterogeneous Software Modeling
Alexander Egyed, Nenad Medvidovic |
FASE | 2 |
| 2000 | Towards a taxonomy of software connectorsabstractSoftware systems of today are frequently composed from prefabricated, heterogeneous components that provide complex functionality and engage in complex interactions. Existing research on component-based development has mostly focused on component structure, interfaces, and functionality. Recently, software architecture has emerged as an area that also places significant importance on component interactions, embodied in the notion of software connectors. However, the current level of understanding and support for connectors has been insufficient. This has resulted in their inconsistent treatment and a notable lack of understanding of what the fundamental building blocks of software interaction are and how they can be composed into more complex interactions. This paper attempts to address this problem. It presents a comprehensive classification framework and taxonomy of software connectors. The taxonomy is obtained through an extensive analysis of existing component interactions. The taxonomy is used both to understand existing software connectors and to suggest new, unprecedented connectors. We demonstrate the use of the taxonomy on the architecture of a large, existing system. Nikunj R. Mehta, Nenad Medvidovic, Sandeep Phadke |
ICSE | 2 |
| 2000 | A Classification and Comparison Framework for Software Architecture Description LanguagesabstractSoftware architectures shift the focus of developers from lines-of-code to coarser-grained architectural elements and their overall interconnection structure. Architecture description languages (ADLs) have been proposed as modeling notations to support architecture-based development. There is, however, little consensus in the research community on what is an ADL, what aspects of an architecture should be modeled in an ADL, and which of several possible ADLs is best suited for a particular problem. Furthermore, the distinction is rarely made between ADLs on one hand and formal specification, module interconnection, simulation and programming languages on the other. This paper attempts to provide an answer to these questions. It motivates and presents a definition and a classification framework for ADLs. The utility of the definition is demonstrated by using it to differentiate ADLs from other modeling notations. The framework is used to classify and compare several existing ADLs, enabling us, in the process, to identify key properties of ADLs. The comparison highlights areas where existing ADLs provide extensive support and those in which they are deficient, suggesting a research agenda for the future. Nenad Medvidovic, Richard N. Taylor |
IEEE Trans. Software Eng. | 1 |
| 1999 | Using Off-the-Shelf Middleware to Implement Connectors in Distributed Software ArchitecturesabstractSoftware architectures promote development focused on modular building blocks and their interconnections. Since architecture-level components often contain complex functionality, it is reasonable to expect that their interactions will also be complex. Modeling and implementing software connectors thus becomes a key aspect of architecture-based development. Software interconnection and middleware technologies such as RMI, CORBA, ILU, and ActiveX provide a valuable service in building applications from components. The relation of such services to software connectors in the context of software architectures, however, is not well understood. To understand the tradeoffs among these technologies with respect to architectures, we have evaluated several off-the-shelf middleware technologies and identified key techniques for utilizing them in implementing software connectors. Our platform for investigation was C2, a component- and message-based architectural style. By encapsulating middleware functionality within software connectors, we have coupled C2's existing benefits such as component interchangeability, substrate independence and structural guidance with new capabilities of multi-lingual, multi-process and distributed application development in a manner that is transparent to architects. Eric M. Dashofy, Nenad Medvidovic, Richard N. Taylor |
ICSE | 2 |
| 1999 | A Language and Environment for Architecture-Based Software Development and EvolutionabstractSoftware architectures have the potential to substantially improve the development and evolution of large, complex, multi-lingual, multi-platform, long-running systems.However, in order to achieve this potential, specific techniques for architecture-based modeling, analysis, and evolution must be provided.Furthermore, one cannot fully benefit from such techniques unless support for mapping an architecture to an implementation also exists.This paper motivates and presents one such approach, which is an outgrowth of our experience with systems developed and evolved according to the C2 architectural style.We describe an architecture description language (ADL) specifically designed to support architecturebased evolution and discuss the kinds of evolution the language supports.We then describe a component-based environment that enables modeling, analysis, and evolution of architectures expressed in the ADL, as well as mapping of architectural models to an implementation infrastructure.The architecture of the environment itself can be evolved easily to support multiple ADLs, kinds of analyses, architectural styles, and implementation platforms.Our approach is fully reflexive: the environment can be used to describe, analyze, evolve, and (partially) implement itself, using the very ADL it supports.An existing architecture is used throughout the paper to provide illustrations and examples. Nenad Medvidovic, David S. Rosenblum, Richard N. Taylor |
ICSE | 1 |
| 1999 | Assessing the Suitability of a Standard Design Method for Modeling Software Architectures
Nenad Medvidovic, David S. Rosenblum |
WICSA | 1 |
| 1998 | Architecture-Based Runtime Software EvolutionabstractContinuous availability is a critical requirement for an important class of software systems. For these systems, runtime system evolution can mitigate the costs and risks associated with shutting down and restarting the system for an update. We present an architecture-based approach to runtime software evolution and highlight the role of software connectors in supporting runtime change. An initial implementation of a tool suite for supporting the runtime modification of software architectures, called ArchStudio, is presented. Peyman Oreizy, Nenad Medvidovic, Richard N. Taylor |
ICSE | 2 |
| 1998 | Integrating Architecture Description Languages with a Standard Design MethodabstractSoftware architecture descriptions are high-level models of software systems. Some researchers have proposed special-purpose architectural notations that have a great deal of expressive power but are not well integrated with common development methods. Others have used mainstream development methods that are accessible to developers, but lack semantics needed for extensive analysis. We describe an approach to combining the advantages of these two ways of modeling architectures. We present two examples of extending UML, an emerging standard design notation, for use with two architecture description languages, C2 and Wright. Our approach suggests a practical strategy for bringing architectural modeling into wider use, namely by incorporating substantial elements of architectural models into a standard design method. Jason E. Robbins, Nenad Medvidovic, David F. Redmiles |
ICSE | 2 |
| 1997 | Reuse of Off-the-Shelf Components in C2-Style ArchitecturesabstractReuse of large-grain software components offers the potential for significant savings in application development cost and time.Successful comuonent reuse and substitutability depends both on qualities of the &mponents reused as well as the sofiware context in which the reuse is attempted.Disciplined approaches to the structure and design of software applications offers the potential of providing a hospitable setting for such reuse+ We present the results of a series of exercises designed to determine how well "offthe-shelf" components could be reused in applications designed in accordance with the C2 software architectural style.The exercises involved the reuse of two user-interface constraint solvers, two graphics toolkits, a World Wide Web browser, and a persistent object manager.A subset of these components was used to construct numemus variations of a single application (thus an application family).The exercises also included construction of a simple development environment for locating and downloading a component off the Web and incorporating it into an application.The paper summarizes the style rules that facilitate reuse and presents the results from the exercises.The exercises were successful in a variety of dimensions; one conclusion is that the C2 style offers significant reuse potential to application developers.At the same time, wider trials and additional tool support are needed' Index Terms -software reuse, architectural styles, messagebased architectures, component-based development, graphical user interfaces (GUI). Nenad Medvidovic, Peyman Oreizy, Richard N. Taylor |
ICSE | 1 |
| 1996 | Using Object-Oriented Typing to Support Architectural Design in the C2 StyleabstractSoftware architectures enable large-scale software development. Component reuse and substitutability, two key aspects of large-scale development, must be planned for during software design. Object-oriented (OO) type theory supports reuse by structuring inter-component relationships and verifying those relationships through type checking in an architecture definition language (ADL). In this paper, we identify the issues and discuss the ramifications of applying OO type theory to the C2 architectural style. This work stems from a series of experiments that were conducted to investigate component reuse and substitutability in C2. We also discuss the limits of applicability of OO typing to C2 and how we addressed them in the C2 ADL. Nenad Medvidovic, Peyman Oreizy, Jason E. Robbins, Richard N. Taylor |
SIGSOFT FSE | 1 |
| 1996 | A Component- and Message-Based Architectural Style for GUI SoftwareabstractWhile a large fraction of application code is devoted to graphical user interface (GUI) functions, support for reuse in this domain has largely been confined to the creation of GUI toolkits ("widgets"). We present a novel architectural style directed at supporting larger grain reuse and flexible system composition. Moreover, the style supports design of distributed, concurrent applications. Asynchronous notification messages and asynchronous request messages are the sole basis for intercomponent communication. A key aspect of the style is that components are not built with any dependencies on what typically would be considered lower-level components, such as user interface toolkits. Indeed, all components are oblivious to the existence of any components to which notification messages are sent. While our focus has been on applications involving graphical user interfaces, the style has the potential for broader applicability. Several trial applications using the style are described. Richard N. Taylor, Nenad Medvidovic, Kenneth M. Anderson, E. James Whitehead Jr., Jason E. Robbins, Kari A. Nies, Peyman Oreizy, Deborah L. Dubrow |
IEEE Trans. Software Eng. | 2 |
| 1995 | A Component- and Message-Based Architectural Style for GUI SoftwareabstractWhile a large j7action of application system code is devoted to user interface (U[)fi.mctions,support for reuse in this domain has largely been conjined to creation of UI toolkits ("widgets").We present a novel architectural style directed at supporting larger grain reuse andjexible system composition.Moreoveq the style supports design of distributed, concurrent, applications.A key aspect of the style is that components are not built with any dependencies on what typically would be considered lower-level components, such as user interface toolkits.Indeed, all components are oblivious to the existence of any components to which notijcation messages are sent.Asynchronous notification messages and asynchronous request messages are the sole basis for inter-component communication.While our focus has been on applications involving graphical user interfaces, the style has the potential for broader applicability.Several trial applications using the style are described~. Richard N. Taylor, Nenad Medvidovic, Kenneth M. Anderson, E. James Whitehead Jr., Jason E. Robbins |
ICSE | 2 |