VLDB 2026 Research / reviewers in the wild / expert
Hironori Washizaki
dblp:65/3507
· DBLP profile ↗
151ranked-venue papers
26as first author
49since 2021 · last 2026
0000-0002-1417-9879ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 110 · 23 first-author · 37 since 2021Applied, interdisciplinary, general and emerging computing · 30 · 7 first-author · 12 since 2021Artificial intelligence and machine learning · 22 · 1 first-author · 6 since 2021Human-computer interaction and ubiquitous computing · 18 · 1 first-author · 8 since 2021Security and privacy · 8 · 1 since 2021Computer networks · 3 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Systems, architecture and hardware · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Harassment in Virtual Reality: A Systematic ReviewabstractThis systematic review examines harassment in virtual reality (VR), synthesizing findings from 85 studies published between 2017 and 2025. We propose a nuanced typology of harassment, encompassing spatial intrusion, sexual and verbal abuse, identity-based discrimination, group-targeted harassment, and systemic harms, and demonstrate how VR’s immersive and embodied features amplify risk and impact. Marginalized users, such as women, LGBTQ+ individuals, children, and people with disabilities, face disproportionate harm. We further analyze the psychological and behavioral consequences of harassment, as well as the effectiveness and limitations of current governance, design, and AI-driven interventions. Our review identifies persistent research gaps in theory, measurement, and inclusive protection, and advocates for ethical, participatory, and preventive approaches to platform safety. This work aims to guide researchers and designers in building more equitable and safe VR environments. Jiong Dong, Yuyin Ma, Yuan Ping 0003, Jiang Liu 0005, Hironori Washizaki |
CHI | 7 |
| 2026 | LLM-Based Framework for Semantic Synchronization Across Multiple Models in MDE
Naoki Ando, Aditya Sundar, Hironori Washizaki, Naoyasu Ubayashi, Hiroki Itoh |
COMPSAC | 3 |
| 2026 | Unveiling the Drivers of Developer Satisfaction: Causal Inference Perspective
Kokoro Hidari, Harei Shirao, Hironori Washizaki, Naoyasu Ubayashi, Kenji Matsuoka, Akihiro Mitsui, Takuma Adachi |
COMPSAC | 3 |
| 2026 | GenAI-Driven Transformation of ICT Continuing Education Program: A Case Study of "Smart SE"
Hironori Washizaki, Shoichi Okazaki, Kazunori Sakamoto, Satoshi Okuda |
COMPSAC | 1 |
| 2026 | History and Future of the SWEBOK Guide: Guide to the Software Engineering Body of Knowledge
Hironori Washizaki, María Isabel Sánchez Segura, Juan Garbajosa, Steve Tockey, Joaquim Jorge 0001 |
COMPSAC | 1 |
| 2026 | Why Are Agentic Pull Requests Merged or Rejected? An Empirical Study
Sien Reeve Ordonez Peralta, Fumika Hoshi, Hironori Washizaki, Naoyasu Ubayashi, Inase Kondo, Yoshiki Higo, Hiroki Mukai, Norihiro Yoshida, Kazuki Kusama, Hidetake Tanaka, Youmei Fan |
MSR | 3 |
| 2026 | Generating User Clones from Questionnaires: A Lightweight Approach to Requirements Elicitation
Mai Hirabayashi, Hironori Washizaki, Naoyasu Ubayashi, Juichi Takahashi, Yohei Takagi |
SANER | 2 |
| 2026 | Revealing Reversed Causal Effects in Bug-Fix Delays: A LiNGAM-Based Comparison Between OSS and Enterprise Systems
Ryo Masuda, Takahiro Kinoshita, Hideyuki Kanuka, Sien Reeve Ordonez Peralta, Hironori Washizaki, Masanari Kondo |
SANER | 5 |
| 2026 | BUPLinker: Bridging Users and Developers in Mobile Application Evolution
Ayana Uematsu, Hironori Washizaki, Naoyasu Ubayashi, Masanari Kondo, Juichi Takahashi, Yohei Takagi |
SANER | 2 |
| 2026 | CFDiff: A Diffusion-Based Generative Framework for Efficient Multiphysical Field Prediction in Smart IoTabstractTraditional Internet of Things (IoT) technologies in complex pipeline networking systems of industrial automation face limitations in sensor data acquisition, making it challenging to comprehensively capture the complex distributions of multi-physical fields, such as pressure, temperature, and velocity. This restricts holistic system analysis and optimal decision-making capabilities. However, accurate and efficient prediction of these multi-physical fields is essential for intelligent decision-making and optimization in IoT-enabled industrial systems. Traditional Computational Fluid Dynamics (CFD) methods deliver high fidelity but are computationally expensive and unsuitable for real-time monitoring and control scenarios characteristic of IoT environments. Recent AI-based generative methods, including Transformers and generative adversarial networks (GANs), improve computational efficiency but often suffer from overly smooth predictions and training instability, limiting their effectiveness for precise industrial IoT applications. Motivated by the outstanding performance of diffusion models in generative tasks, we propose CFDiff, a diffusion-based architecture designed explicitly for predicting complex multi-physical fields in IoT-based industrial pipeline applications. By introducing the simulation-free flow-map, a single-channel orientation field that encodes the inlet-to-outlet direction, CFDiff leverages a generative diffusion process combined with a lightweight Cross-Attention Fusion (CAF) module, effectively integrating sparse and multimodal data to generate high-fidelity field distributions. Experimental results demonstrate that CFDiff significantly outperforms existing state-of-the-art methods, reducing prediction errors by approximately 41.6% across various scenarios relevant to industrial IoT. Comprehensive ablation studies further confirm the efficacy of each proposed component, positioning CFDiff as a robust and practical solution to enhance the accuracy, safety, and efficiency of IoT-based monitoring and predictive maintenance systems. Chenhao Wu 0004, Dingjie Peng, Yuntao Zou, Zhichun Liu, Hiroshi Onoda, Hironori Washizaki, Wataru Kameyama, Jiang Liu 0005 |
IEEE Internet Things J. | 7 |
| 2026 | Generative AI for Requirements Engineering: A Systematic Literature ReviewabstractABSTRACT Introduction Requirements engineering (RE) faces challenges due to the handling of increasingly complex software systems. These challenges can be addressed using generative artificial intelligence (GenAI). Given that GenAI‐based RE has not been systematically analyzed in detail, this review examines the related research, focusing on trends, methodologies, challenges, and future work directions. Methods A systematic methodology for paper selection, data extraction, and feature analysis is used to comprehensively review 238 articles published from 2019 to 2025 and available from major academic databases. Results Although generative pretrained transformer models dominate current applications (67.3% of studies), the research focus remains unevenly distributed across RE phases, with analysis (30.0%) and elicitation (22.1%) receiving the most attention and management (6.8%) remaining underexplored. Three core challenges—reproducibility (66.8%), hallucinations (63.4%), and interpretability (57.1%)—form a tightly interlinked triad affecting trust and consistency, and strong correlations ( co‐occurrence) indicate that these challenges must be addressed holistically. Industrial adoption remains nascent, with > 90% of studies corresponding to early‐stage development and only 1.3% reaching production‐level integration. Evaluation practices show maturity gaps, limited tool/dataset availability, and fragmented benchmarking approaches. Conclusions Despite the transformative potential of GenAI‐based RE, several barriers hinder its practical adoption. The strong correlations among core challenges demand specialized architectures targeting interdependencies rather than isolated solutions. The limited real‐world deployment reflects systemic bottlenecks in generalizability, data quality, and scalable evaluation methods. Successful adoption requires coordinated development across technical robustness, methodological maturity, and governance integration. A multiphase research roadmap emphasizing evaluation infrastructure strengthening, governance‐aware development, and industrial‐scale standardization is proposed. Haowei Cheng, Jati H. Husen, Teeradaj Racharak, Nobukazu Yoshioka, Naoyasu Ubayashi, Hironori Washizaki |
Softw. Pract. Exp. | 7 |
| 2025 | An Empirical Study of VR Software Quality Based on Developer Forums and ISO/IEC 25010abstractWith the rapid advancement of virtual reality (VR) technology, understanding developer discussions is essential for improving software quality and maintenance. This study is the first to systematically investigate how developer concerns across major VR platforms, namely SteamVR, Meta, and HTCVive, align with the ISO/IEC 25010 international software quality standard. We collected and analyzed 392,590 posts from 47,280 developers, using topic modeling and manual coding to map discussions to nine ISO/IEC 25010 quality characteristics. We further examined topic distributions, sentiment trends, and interaction patterns across platforms. Our findings show that developers are most challenged by interaction, compatibility, and functionality issues, emphasizing the need to enhance user experience, enable cross device integration, and maintain system stability. Discussion on performance has decreased, signaling a shift in priorities. Platform specific challenges also emerged, highlighting the need for tailored strategies for different VR ecosystems. Based on these insights, we suggest strategies that prioritize optimizing user interaction (e.g., intuitive controls, seamless navigation), strengthening cross platform compatibility (e.g., universal SDKs, shared asset pipelines), and implementing sustainable maintenance practices (e.g., clear codebases, regular updates) to foster a more robust VR software ecosystem. Hironori Washizaki, Naoyasu Ubayashi, Nobukazu Yoshioka, Jiong Dong, Yuyin Ma, Jati H. Husen |
COMPSAC | 2 |
| 2025 | Continuous Data-driven Personas Generation: An LLM-based Knowledge Graph ApproachabstractBusiness-to-business software systems are inherently specialized and operationally intricate, which make them crucial to develop accurate personas that reflect real end-user requirements throughout the development lifecycle. As user needs continuously evolve over time, it becomes imperative to establish a data-driven framework capable of persistently updating these personas and promptly integrating those changes into the development process to maintain long-term value delivery. Conventional persona generation techniques typically depend on clustering approaches applied to qualitative and quantitative data—a process that is time-intensive, expensive, and requires considerable domain expertise. This study introduces an automated method for continuous persona generation, extracting user requirements from an ongoing stream of user data. The approach utilizes large language models to interpret qualitative inputs and dynamically generate knowledge graphs, enabling real-time insights into shifting user needs. A case study involving inquiry call logs from a customer support center was conducted to validate the method. Results demonstrated that the proposed approach outperformed a traditional clustering-based baseline in approximately 86% of the cases in a question–answering task aimed at evaluating the structuring and retrieval of user requirements. Furthermore, clear insights into user pain points and requiring improvements were provided, reinforcing the effectiveness and practical utility of continuous, data-driven persona generation. Ryota Sugiyama, Hironori Washizaki, Naoyasu Ubayashi, Ryoko Tanahashi, Mai Hirabayashi, Satoshi Okuda, Ken Toriumi |
RE | 2 |
| 2025 | Multiple Function Merging for Code Size ReductionabstractResource-constrained environments, such as embedded devices, have limited amounts of memory and storage. Practical programming languages such as C++ and Rust tend to output multiple similar functions by monomorphizing polymorphic functions. An optimization technique called Function Merging, which merges similar functions into a single function, has been studied. However, in the state-of-the-art approach, the number of functions that can be merged at once is limited to two; thus, efficiently merging three or more functions, which are often generated from polymorphic functions, has been impossible. In this study, we propose Multiple Function Merging optimization, which targets merging three or more similar functions into a single function using a multiple sequence alignment algorithm. With multiple aligned information, Multiple Function Merging can increase merge opportunities and reduce extra branching overheads at the code generation stage. We evaluated it using the SPEC CPU benchmark suite and some large-scale C/C++ programs, and the results show that it reduces code size by as much as 7.61% compared with the state-of-the-art approach. Yuta Saito, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
ACM Trans. Archit. Code Optim. | 3 |
| 2024 | Advances and Roadmap of Software Services Engineering EducationabstractWith the advent of the services computing era, challenges in educating capable future software services engineers and researchers have become more pressing than ever. Software services engineers are professionals whose training cuts across computer science, software engineering, services computing, as well as relevant educational elements in management science and engineering, social science, serviceology, and service science and engineering [1]. We foresee an urgent need in this fast-emerging multidisciplinary field "Software Services Engineering" (SSE) [2] [2.1] for a comprehensive collection of education and training artifacts including well-defined body of knowledge (BOK), model curricula, open-source platforms, certification requirements, accreditation criteria, articulation directives, exemplary professional course modules, among other related components. Carl K. Chang, Stephen S. Yau, Hironori Washizaki, Weiping Li 0002, Abdelsalam Helal |
SSE | 3 |
| 2024 | Evaluation of The Generality of Multi-view Modeling Framework for ML SystemsabstractMulti-View Modeling Framework for ML Systems (M3S) provides a framework to synchronize the experimental nature of machine learning and the deterministic side of traditional software engineering. However, understanding the framework's generality and limitations still requires further investigation. This paper compares the existing validation case study to a new case study of the OCT image diagnosis support system. The comparison between the two case studies shows M3S capability to handle variations in the nature of ML system analysis. However, the framework's capability to handle different ML tasks other than multi-class classification still requires further investigation. Jati H. Husen, Jomphon Runpakprakun, Sun Chang, Hironori Washizaki, Hnin Thandar Tun, Nobukazu Yoshioka, Yoshiaki Fukazawa |
CAIN | 4 |
| 2024 | AI Security Continuum: Concept and ChallengesabstractWe propose a conceptual framework, named "AI Security Continuum," consisting of dimensions to deal with challenges of the breadth of the AI security risk sustainably and systematically under the emerging context of the computing continuum as well as continuous engineering. The dimensions identified are the continuum in the AI computing environment, the continuum in technical activities for AI, the continuum in layers in the overall architecture, including AI, the level of AI automation, and the level of AI security measures. We also prospect an engineering foundation that can efficiently and effectively raise each dimension. Hironori Washizaki, Nobukazu Yoshioka |
CAIN | 1 |
| 2024 | Comparison of Methods for Automatically Predicting CVSS Base VectorabstractCommon Vulnerability Scoring System (CVSS) is a standard method for quantifying the severity of software vulnerabilities. Security engineers can identify the underlying causes of vulnerabilities and develop countermeasures based on CVSS base vector and their related scores. The CVSS base vector is a set of metrics used to calculate the severity score of a vulnerability based on its intrinsic characteristics, such as “Attack Vector (AV)” and “Privilege Required (PR)‘. Security experts often take a few weeks to manually determine the CVSS base vector of a new vulnerability report. Consequently, the CVSS base vector is usually unknown for a period after the report is released, and thus delaying vulnerability countermeasures. Therefore, several methods for predicting CVSS base vector have been proposed. This paper compares the performance among methods that use BERT, multinomial logistic regression, or linear regression for automatically predicting CVSS base vector. The comparison results suggested that both BERT and MLR perform better than LR, with distinct advantages. BERT excels in understanding context, making it suitable for predicting general CVSS base vector, while MLR is effective for targeting specific attributes or severity levels. Consequently, these methods hold promise in aiding security engineers to promptly address vulnerabilities. Sho Isogai, Shinpei Ogata, Yutaro Kashiwa, Satoshi Yazawa, Kozo Okano, Takao Okubo, Hironori Washizaki |
COMPSAC | 7 |
| 2024 | Systematic Literature Review of Prompt Engineering Patterns in Software EngineeringabstractAdvancements in large language models (LLMs) are transforming software engineering through innovative prompt engineering strategies. By analyzing prompt-driven enhancements across key software engineering tasks, we present a sys-tematic literature review and a pioneering taxonomy elucidating the practical applications of prompt engineering in software engineering. Our taxonomy offers a foundational framework that clarifies the roles of prompt engineering and measures its impact, thereby guiding evolving AI -driven software engineering research and practices. Yuya Sasaki 0006, Hironori Washizaki, Jialong Li 0001, Dominik Sander, Nobukazu Yoshioka, Yoshiaki Fukazawa |
COMPSAC | 2 |
| 2024 | Evaluating Preschoolers' Block Programming Using Complexity and Personality TraitsabstractProgramming learning at an early age effectively fosters logical thinking and self-centeredness, but an appropriate evaluation method for young learners has yet to be established. Herein we propose a new learning evaluation method that incorporates problem constructs and the complexity metrics used in software engineering quality assessments. Specifically, we investigate the relationships between changes in block pro-gramming complexity, personality traits, and learning effects. Evaluation rubrics and log data assess complexity, while person-ality traits are based on Big-5. Then the learning effects of 34 kindergarten children participating in workshops are analyzed in terms of complexity and personality traits. After learning, first-time programmers tend to show a large increase in complexity. The correlation with the rubric score is$\rho=0.43$, and the correlation with log data is$\mathbf{r}s=0.92$. Furthermore, analysis using the Big-5 gives$\rho=0.609$for the rate of increase in extraversion and complexity, indicating a strong relationship between learning effects and personality traits. In the future, this data will be used to build AI tools for automatic evaluations, feedback, and learning curriculum recommendations. Yui Ono, Daisuke Saito, Hironori Washizaki |
CSEE&T | 3 |
| 2024 | Unraveling the Influences on Bug Fixing Time: A Comparative Analysis of Causal Inference ModelabstractIn this study, we employ causal inference models, specifically Bayesian Networks (BN) and Linear Non-Gaussian Acyclic Models (LiNGAM), to investigate the determinants of Bug Fixing Time (BFT) in software development. Moving beyond traditional statistical analyses, our approach aims to identify the true causal factors influencing BFT. Our findings indicate that ’Reporter Reputation’, ’Severity’, and ’Blocker’ status are significant determinants of BFT, with notable differences between bugs reported by users versus developers. This research challenges existing assumptions about the necessity of comprehensive bug reports and underscores the importance of understanding bug resolution’s complexity and organizational context. By applying causal inference models, we offer actionable insights for improving bug prioritization, operational efficiency, and predictive management of development bottlenecks, enhancing the software development lifecycle. Our study bridges the theoretical and practical aspects of software quality optimization and introduces a novel perspective on managing software development processes. Additionally, our analysis reveals counterintuitive results that further contribute to our understanding of the dynamics influencing BFT. Sien Reeve Ordonez Peralta, Hironori Washizaki, Yoshiaki Fukazawa, Yuki Noyori, Shuhei Nojiri, Hideyuki Kanuka |
EASE | 2 |
| 2024 | Improved Program Repair Methods using Refactoring with GPT ModelsabstractTeachers often utilize automatic program repair methods to provide feedback on submitted student code using model answer code. A state-of-the-art tool is Refactory, which achieves a high repair success rate and small patch size (less code repair) by refactoring code to expand the variety of correct code samples that can be referenced. However, Refactory has two major limitations. First, it cannot fix code with syntax errors. Second, it has difficulty fixing code when there are few correct submissions. Herein we propose a new method that combines Refactory and OpenAI's GPT models to address these issues and conduct a performance measurement experiment. The experiment uses a dataset consisting of 5 programming assignment problems and almost 1,800 real-life incorrect Python program submissions from 361 students for an introductory programming course at a large public university. The proposed method improves the repair success rate by 1-21% when the set of correct code samples is sufficient and the patch size is smaller than Refactory alone in 16-45% of the cases. When there was no set of correct code samples at all (only the model answer code was used as a reference for repair), method improves the repair success rate by 1-43% and the patch size is smaller than Refactory alone in 42-68% of the cases. Ryosuke Ishizue, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SIGCSE (1) | 3 |
| 2024 | Enhancing Programming Education through Game-Based Learning: Design and Implementation of a Puyo Puyo-Inspired Teaching ToolabstractAlthough programming is part of primary school curricula in many countries, barriers persist for elementary students learning programming such as an insufficient understanding of the underlying mathematics, complex concepts, and purpose of programming. These challenges often lead to disinterest. Herein we present an innovative game-design-based programming education tool. Students progressively enhance a classic game, Puyo Puyo, using fundamental programming concepts and selecting the appropriate code. This engaging approach improves students' computational thinking abilities as they transform code into a functional game. Here, we describe the tool's background and structure. Then we detail a workshop using the tool, including analyzing the changes in students' programming skills, computational thinking, and interest in programming. Finally, we summarize the findings and future research directions. Ruochen Tian, Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa, Hiroshi Kobayashi, Ayumi Tsuji |
SIGCSE (2) | 3 |
| 2024 | Refining GPT-3 Embeddings with a Siamese Structure for Technical Post Duplicate DetectionabstractOne goal of technical online communities is to help developers find the right answer in one place. A single question can be asked in different ways with different wordings, leading to the existence of duplicate posts on technical forums. The question of how to discover and link duplicate posts has garnered the attention of both developer communities and researchers. For example, Stack Overflow adopts a voting-based mechanism to mark and close duplicate posts. However, addressing these constantly emerging duplicate posts in a timely manner continues to pose challenges. Therefore, various approaches have been proposed to detect duplicate posts on technical forum posts automatically. The existing methods suffer from limitations either due to their reliance on handcrafted similarity metrics which can not sufficiently capture the semantics of posts, or their lack of supervision (i.e., leveraging existing duplicate annotations) to improve the performance. Additionally, the efficiency of these methods is hindered by their dependence on pair-wise feature generation, which can be impractical for large amount of data. In this work, we attempt to employ and refine the GPT-3 embeddings for the duplicate detection task. We assume that the GPT-3 embeddings can accurately represent the semantics of the posts. In addition, by training a Siamese-based network based on the GPT-3 embeddings, we obtain a latent embedding that accurately captures the duplicate relation in technical forum posts. Our experiment on a benchmark dataset confirms the effectiveness of our approach and demonstrates superior performance compared to baseline methods. When applied to the dataset we constructed with a recent Stack Overflow dump, our approach attains a Top-1, Top-5, and Top-30 accuracy of 23.1 %, 43.9 %, and 68.9 %, respectively. With a manual study, we confirm our approach's potential of finding unlabelled duplicates on technical forums. We released our dataset and code in our supplementary package to promote further studies11Supplementary material package: https://github.com/mooselab/suppmaterial-PostDupGPT3. Xingfang Wu, Heng Li 0007, Nobukazu Yoshioka, Hironori Washizaki, Foutse Khomh |
SANER | 4 |
| 2024 | Enterprise architecture-based metamodel for machine learning projects and its managementabstractIn this study, we consider projects for developing service systems using machine learning (ML) techniques. These projects involve collaboration between various stakeholders. Several types of models representing system architectures are introduced so that stakeholders can develop a common understanding of these projects. In addition, metamodels are constructed by combining ML service systems models to provide project practitioners with a holistic view of the projects. In certain cases, these metamodels need to be extended to incorporate other business models for the business–IT alignment used in enterprises. For such situations, an enterprise architecture-based metamodel and method for managing the metamodel are proposed in this study, which provide a holistic view of business–IT alignment for ML projects. We confirm the effectiveness of the proposed metamodel and management method through real examples. Hironori Takeuchi, Jati H. Husen, Hnin Thandar Tun, Hironori Washizaki, Nobukazu Yoshioka |
Future Gener. Comput. Syst. | 4 |
| 2024 | Integrated multi-view modeling for reliable machine learning-intensive software engineeringabstractAbstract Development of machine learning (ML) systems differs from traditional approaches. The probabilistic nature of ML leads to a more experimentative development approach, which often results in a disparity between the quality of ML models with other aspects such as business, safety, and the overall system architecture. Herein the Multi-view Modeling Framework for ML Systems (M3S) is proposed as a solution to this problem. M3S provides an analysis framework that integrates different views. It is supported by an integrated metamodel to ensure the connection and consistency between different models. To facilitate the experimentative nature of ML training, M3S provides an integrated platform between the modeling environment and the ML training pipeline. M3S is validated through a case study and a controlled experiment. M3S shows promise, but future research needs to confirm its generality. Jati H. Husen, Hironori Washizaki, Jomphon Runpakprakun, Nobukazu Yoshioka, Hnin Thandar Tun, Yoshiaki Fukazawa, Hironori Takeuchi |
Softw. Qual. J. | 2 |
| 2023 | A Machine Learning Based Approach to Detect Machine Learning Design PatternsabstractAs machine learning expands to various domains, the demand for reusable solutions to similar problems increases. Machine learning design patterns are reusable solutions to design problems of machine learning applications. They can significantly enhance programmers' productivity in programming that requires machine learning algorithms. Given the critical role of machine learning design patterns, the automated detection of them becomes equally vital. However, identifying design patterns can be time-consuming and error-prone. We propose an approach to detect their occurrences in Python files. Our approach uses an Abstract Syntax Tree (AST) of Python files to build a corpus of data and train a refined Text-CNN model to automatically identify machine learning design patterns. We empirically validate our approach by conducting an exploratory study to detect four common machine learning design patterns: Embedding, Multilabel, Feature Cross, and Hashed Feature. We manually label 450 Python code files containing these design patterns from repositories of projects in GitHub. Our approach achieves accuracy values ranging from 80 % to 92% for each of the four patterns. Weitao Pan, Hironori Washizaki, Nobukazu Yoshioka, Yoshiaki Fukazawa, Foutse Khomh, Yann-Gaël Guéhéneuc |
APSEC | 2 |
| 2023 | Extensible Modeling Framework for Reliable Machine Learning System AnalysisabstractMachine learning system analysis requires different approaches for each different task and domain. Selecting a proper set of analytic models can be challenging for a specific problem. This paper discusses the extensibility of the Multi-View Modeling Framework for ML Systems approach using process mapping and extensible metamodel. We conducted a case study to evaluate the feasibility of such extensibility by extending the approach to facilitate an activity-driven analysis for an optical character recognition system. Based on the result of the case study, we found that Multi-View Modeling Framework for ML Systems is likely to be extensible. Jati H. Husen, Hironori Washizaki, Hnin Thandar Tun, Nobukazu Yoshioka, Yoshiaki Fukazawa, Hironori Takeuchi, Hiroshi Tanaka, Kazuki Munakata |
CAIN | 2 |
| 2023 | Envisioning software engineer training needs in the digital era through the SWEBOK V4 prismabstractOur world’s needs have evolved dramatically since the origins of software engineering in the 1960s. The future software engineer must be able to anticipate our needs and desires in an era where complex challenges continually emerge, and adaptive solutions must be delivered on the fly. This paper addresses the evolution of the IEEE Computer Society’s Guide to the Software Engineering Body of Knowledge (SWEBOK Guide) and its impact on software engineering higher education and professional training that should prepare engineers to fulfill their mission in this dynamic digital future. Hironori Washizaki, María Isabel Sánchez Segura, Juan Garbajosa, Steve Tockey, Kenneth E. Nidiffer |
CSEE&T | 1 |
| 2023 | Analysis of Bug Report Qualities with Fixing Time using a Bayesian NetworkabstractMost client software employs a bug-tracking system, which utilizes user-submitted reports (bug reports) that contain information necessary for software developers to fix bugs. The quality of bug reports drastically differs. Bug reports can include severity, priority, and associated issues determined by researching the addressed bug. Herein we investigate the influence of bug report qualities on successfully fixing a bug and estimating the fixing time. We also examine the claim in previous studies that bias and differences in the treatment of bug reports exist due to broad expertness among the reporters. Our approach examines the relationship between the qualities within the bug-fixing cycle and modeling graphical causal dependencies through a Bayesian Network. Bug reports with attachments, dependencies on another bug, and frequent discussions are more likely to be fixed. In addition, bug reports with a high severity tend to be fixed faster. Moreover, the difficulty of the bug itself may influence the fixing rate such that a straightforward bug will be fixed easier and faster regardless of the bug report quality. Sien Reeve Ordonez Peralta, Hironori Washizaki, Yoshiaki Fukazawa, Yuki Noyori, Shuhei Nojiri, Hideyuki Kanuka |
EASE | 2 |
| 2023 | Identifying Characteristics of the Agile Development Process That Impact User SatisfactionabstractThe purpose of this study is to identify the characteristics of Agile development processes that impact user satisfaction. We used user reviews of OSS smartphone apps and various data from version control systems to examine the relationships, especially time-series correlations, between user satisfaction and development metrics that are expected to be related to user satisfaction. Although no metrics conclusively indicate an improved user satisfaction, motivation of the development team, the ability to set appropriate work units, the appropriateness of work rules, and the improvement of code maintainability should be considered as they are correlated with improved user satisfaction. In contrast, changes in the release frequency and workload are not correlated. Minshun Yang, Seiji Sato, Hironori Washizaki, Yoshiaki Fukazawa, Juichi Takahashi |
EASE | 3 |
| 2023 | Programming Education for Young People using the Falling-Puzzle Game, "Puyo Puyo"abstractThis study utilizes the game rules of a falling-puzzle game, developed as a consumer-oriented digital game, in programming education for young people. When digital games are used in programming education, they are often designed specifically for that purpose. In this study, we focused on the game rules of the consumer falling-object puzzle game, “Puyo Puyo.” Learning impact was investigated on 23 Japanese elementary, junior high, and senior high school students. The results show that the concepts of branching and arraying in programming were taught effectively; thus, consumer digital game rules can be used as a case study for programming education. Daisuke Saito, Ruochen Tian, Hironori Washizaki, Yoshiaki Fukazawa |
EDUCON | 3 |
| 2023 | Metamodel-Based Multi-View Modeling Framework for Machine Learning Systems
Jati H. Husen, Hironori Washizaki, Nobukazu Yoshioka, Hnin Thandar Tun, Yoshiaki Fukazawa, Hironori Takeuchi |
MODELSWARD | 2 |
| 2023 | Log Drift Impact on Online Anomaly Detection Workflows
Scott Lupton, Hironori Washizaki, Nobukazu Yoshioka, Yoshiaki Fukazawa |
PROFES (1) | 2 |
| 2023 | Gender Characteristics and Computational Thinking in ScratchabstractThis study investigates the Computational Thinking skill differences among novice programmers in relation to gender. Block-based visual programming languages such as Scratch particularly benefit K-12 programmers because they learn how to code intuitively. Our study analyzed 124 (62 males, 62 females) Scratch projects on the Scratch website, categorized projects on the basis of each user's gender and project type, and compared their Computational Thinking scores. The results of this study suggest that project types preferred by males require more programming construct reflected in the Computational Thinking score than that of females. Because gender differences appear by project type, project type presumably influences the gender gap in scores. Rose Niousha, Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa |
SIGCSE (2) | 3 |
| 2023 | Machine learning application development: practitioners' insights
Md. Saidur Rahman 0002, Foutse Khomh, Alaleh Hamidi, Jinghui Cheng 0001, Giuliano Antoniol, Hironori Washizaki |
Softw. Qual. J. | 6 |
| 2022 | Traceable business-to-safety analysis framework for safety-critical machine learning systemsabstractMachine learning-based system requires specific attention towards their safety characteristics while considering the higher-level requirements. This study describes our approach for analyzing machine learning safety requirements top-down from higher-level business requirements, functional requirements, and risks to be mitigated. Our approach utilizes six different modeling techniques: AI Project Canvas, Machine Learning Canvas, KAOS Goal Modeling, UML Components Diagram, STAMP/STPA, and Safety Case Analysis. As a case study, we also demonstrated our approach for lane and other vehicle detection functions of self-driving cars. Jati H. Husen, Hironori Washizaki, Hnin Thandar Tun, Nobukazu Yoshioka, Yoshiaki Fukazawa, Hironori Takeuchi |
CAIN | 2 |
| 2022 | Software Engineering in Digital Transformation and Diversity: Preliminary Literature ReviewabstractWith the social awareness of diversity and inclusion, digital transformation (DX) with software engineering is expected to contribute to diversity in digitalized society. We present research and practice trends and future directions of software engineering activities in diversity and DX by summarizing a result of a preliminary literature review. Hironori Washizaki |
COMPSAC | 1 |
| 2022 | Visualization of automated program repair focusing on suspiciousness valuesabstractAutomated program repair (APR) can realize efficient debugging in software development.Automated program corrections using genetic algorithms (GA) can repair programs, including those with multiple bugs, but the repair process of GA-based APR is difficult to understand using logs because many modification program codes are generated.Consequently, Matsumoto et al. implemented a methodology for visualizing the process.Their proposed methodology provides an intuitive understanding of the conformance values (test case pass rates), generations, states, and operations performed to generate each variant; however, it lacks sufficient information to analyze whether defect localization is appropriate in APR.Herein we propose a new methodology to visualize the impact of fault localization on program evolution in GA-based APR and create a new tool.Additionally, a case study demonstrates the effectiveness of the proposed methodology and future works are considered. Naoki Tane, Yusaku Ito, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 3 |
| 2022 | Detecting Design Patterns in UML Class Diagram Images using Deep LearningabstractDetecting software design pattern is an important part of software reverse engineering because design patterns can provide the most intuitive design idea of software products, which can be useful for maintenance engineers. In past studies, a lot of approaches have been proposed to detect design patterns, and the machine learning-based approach is a new trend in recent years. In this paper, we propose a preliminary idea of a deep learning-based approach to detect design patterns from UML class diagrams of software products, which can be used in some cases that traditional approaches may not work. We propose an overall process, which is divided into preparation phase and application phase. In preparation phase, we train a deep learning-based classifier to do the image classification task. In application phase, users may input the UML class diagram of a micro-architecture into the model and get the pattern it belongs to. We conduct a preliminary experiment to show the effectiveness of our approach, we train a Convolutional Neural Network (CNN) as the classifier and test it on our image dataset, which is constructed with UML images we collected from the Internet. We also use Gradient-weighted Class Activation Mapping (Grad-CAM) to do the visualization and use it to explain why our approach works. Lastly, we analyze the potential advantages and disadvantages of our approach. Hironori Washizaki, Nobukazu Yoshioka, Yoshiaki Fukazawa |
SNPD | 2 |
| 2022 | Abstract security patterns and the design of secure systemsabstractAbstract During the initial stages of software development, the primary goal is to define precise and detailed requirements without concern for software realizations. Security constraints should be introduced then and must be based on the semantic aspects of applications, not on their software architectures, as it is the case in most secure development methodologies. In these stages, we need to identify threats as attacker goals and indicate what conceptual security defenses are needed to thwart these goals, without consideration of implementation details. We can consider the effects of threats on the application assets and try to find ways to stop them. These threats should be controlled with abstract security mechanisms that can be realized by abstract security patterns (ASPs), that include only the core functions of these mechanisms, which must be present in every implementation of them. An abstract security pattern describes a conceptual security mechanism that includes functions able to stop or mitigate a threat or comply with a regulation or institutional policy. We describe here the properties of ASPs and present a detailed example. We relate ASPs to each other and to Security Solution Frames, which describe families of related patterns. We show how to include ASPs to secure an application, as well as how to derive concrete patterns from them. Finally, we discuss their practical value, including their use in “security by design” and IoT systems design. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki, Joseph W. Yoder |
Cybersecur. | 3 |
| 2022 | SWEBOK Matters: Report and Reflection of a SEKE Panel on the Educational and Professional Implications of SWEBOKabstractThis paper provides a summary of the proceedings of a panel on the Guide to the Software Engineering Body of Knowledge (SWEBOK) held under the auspices of the Thirty-Fourth International Conference on Software Engineering and Knowledge Engineering (SEKE 2022), as well as the discussion that ensued thereafter among the panelists. In this regard, a synopsis of the underlying motivation and structure of SWEBOK is given, and the means for integrating SWEBOK in software-intensive organizations and educational institutions offering software engineering-related courses are highlighted and illustrated by pedagogically-oriented examples. Pankaj Kamthan, Hironori Washizaki |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2021 | Literature Review on Log Anomaly Detection Approaches Utilizing Online Parsing MethodologyabstractThe use of anomaly detection for log monitoring requires parsing model input features from raw, unstructured data. Log parsing methods come in many forms, but are generally categorized as being either offline or online. In this study, a systematic literature review of anomaly detection approaches utilizing online parsing methods is performed. An inventory of these approaches is taken, research gaps are explored, and suggestions for future exploration and study are presented. Scott Lupton, Hironori Washizaki, Nobukazu Yoshioka, Yoshiaki Fukazawa |
APSEC | 2 |
| 2021 | Automated Educational Program Mapping on Learning Standards in Computer ScienceabstractThere are many lectures for students or working adults. Educational institutions have created a table that associates educational courses with learning standards in order to understand the content of these courses. Learning standards such as SFIA (Skills Framework for an Information Age) indicate the skills that learners should learn. The mapped table can make contents clear for students or other educational institutions. Koki Miura, Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa |
COMPSAC | 3 |
| 2021 | Preliminary Literature Review of Machine Learning System Development PracticesabstractTo guide practitioners and researchers to design and research Machine Learning (ML) system development processes, we conduct a preliminary literature review on ML system development practices. We identified seven papers and two other papers determined in an ad-hoc review. Our findings include emphasized phases in ML system developments, frequently described ML-specific practices, and tailored traditional practices. Yasuhiro Watanabe, Hironori Washizaki, Kazunori Sakamoto, Daisuke Saito, Kiyoshi Honda, Naohiko Tsuda, Yoshiaki Fukazawa, Nobukazu Yoshioka |
COMPSAC | 2 |
| 2021 | Work-in-Progress: Analysis of the use of Mentoring with Online Mob ProgrammingabstractExtreme programming (XP) approaches such as pair and mob programming (PP and MP, respectively) have been introduced to the educational sector. However, higher education curricula have started implementing online courses as a method for teaching programming, which poses challenges when conducting XP. Because social factors are vital to learning, we examine a project-based learning method using online MP that introduces a high level of communication. It also maintains the advantages of PP through the “driver” and “navigator” approach. However, there are multiple complications, including discomfort, slow code generation, and interpersonal issues, when using conventional MP. Accordingly, we introduce a mentoring approach to the MP setup and examine the differences compared to conventional MP sessions. We create and analyze co-occurrence networks of codes found via open coding. In this paper, we explain our method and show its advantages based on the results of our analysis. Shota Kaieda, Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa |
EDUCON | 3 |
| 2021 | Duplicate Bug Report Detection by Using Sentence Embedding and Fine-tuningabstractIndustrial software maintenance devotes much time and effort to find duplicate bug reports. In this paper, we propose an automated duplicate bug report detection system to improve software maintenance efficiency. Our system detects duplicate reports by vectorizing the contents of each report item by deep-learning-based sentence embedding and calculating the similarity of the whole report from those of the item vectors. The Sentence-BERT fine-tuned with report texts is used for sentence embedding. Finally, we verify that the combination of processing separately by item and Sentence-BERT fine-tuned with reports effectively detects duplicate bug reports in industrial experiments that compare the performance of existing methods. Haruna Isotani, Hironori Washizaki, Yoshiaki Fukazawa, Tsutomu Nomoto, Saori Ouji, Shinobu Saito |
ICSME | 2 |
| 2021 | Comparing Participants' Brainwaves During Solo, Pair, and Mob ProgrammingabstractAbstract Participants’ feelings and impressions utilizing electroencephalography (EEG) and the effectiveness of code are compared for different types of programming sessions. EEG information is obtained as an alternate viewpoint during three programming sessions (solo, pair, and mob programming). MindWave Mobile 2 (brainwave detector) is equipped to collect the attention levels, meditation levels, and EEG brainwaves. These data are utilized to distinguish efficiencies, weaknesses, and points of interest by programming session. The results provide preliminary information to distinguish between the three sessions, but further studies are necessary to make firm conclusions. Additionally, alternative methods or systems are required to analyze the collected data. Makoto Shiraishi, Hironori Washizaki, Daisuke Saito, Yoshiaki Fukazawa |
XP | 2 |
| 2021 | Data-Driven Persona Retrospective Based on Persona Significance Index in B-to-B Software DevelopmentabstractBusiness-to-Business (B-to-B) software development companies develop services to satisfy their customers’ requirements. Developers should prioritize customer satisfaction because customers greatly influence agile software development. However, satisfying current customer’s requirements may not fulfill actual users or future customers’ requirements because customers’ requirements are not always derived from actual users. To reconcile these differences, developers should identify conflicts in their strategic plan. This plan should consider current commitments to end users and their intentions as well as employ a data-driven approach to adapt to rapid market changes. A persona models an end user representation in human-centered design. Although previous works have applied personas to software development and proposed data-driven software engineering frameworks with gap analysis between the effectiveness of commitments and expectations, the significance of developers’ commitment and quantitative decision-making are not considered. Developers often do not achieve their business goal due to conflicts. Hence, the target of commitments should be validated. To address these issues, we propose Data-Driven Persona Retrospective (DDR) to help developers plan future releases. DDR, which includes the Persona Significance Index (PerSI) to reflect developers’ commitments to end users’ personas, helps developers identify a gap between developers’ commitments to personas and expectations. In addition, DDR identifies release situations with conflicts based on PerSI. Specifically, we define four release cases, which include different situations and issues, and provide a method to determine the release case based on PerSI. Then we validate the release cases and their determinations through a case study involving a Japanese cloud application and discuss the effectiveness of DDR. Yasuhiro Watanabe, Hironori Washizaki, Yoshiaki Fukazawa, Kiyoshi Honda, Masahiro Taga, Akira Matsuzaki, Takayoshi Suzuki |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2020 | Binary Similarity Analysis for Vulnerability DetectionabstractBinary similarity has been widely used in function recognition and vulnerability detection. How to define a proper similarity is the key element in implementing a fast detection method. We proposed a scalable method to detect binary vulnerabilities based on similarity. Procedures lifted from binaries are divided into several comparable strands by data dependency, and those strands are transformed into a normalized form by our tool named VulneraBin, so that similarity can be determined between two procedures through a hash value comparison. The low computational complexity allows semantically equivalent code to be identified in binaries compiled from million lines of source code in a fast and accurate way. Zeming Tai, Hironori Washizaki, Yoshiaki Fukazawa, Yurie Fujimatsu, Jun Kanai |
COMPSAC | 2 |
| 2020 | Towards Software Value Co-Creation with AIabstractWe present a vision called "value co-creation of software by artificial intelligence (AI) and developers." In this vision, AI and developers work in collaboration as equal partners to co-create business and societal values through software system development and operations. Towards this vision, we discuss AI automation for development focusing on machine learning by introducing examples, including our own. Finally, we envision the future of value co-creation by AI and developers. Hironori Washizaki |
COMPSAC | 1 |
| 2020 | Value Driven Process Towards Software Engineering for Business and Society (SE4BS)abstractSuccessful digital transformation (DX) requires not only technology, but also an understanding of the importance of business agility. In addition, without careful traceability, software engineering projects can be not based on business and social values. To address these issues, we categorize useful methods, practices, and models in software development and operations that make connections and traceability from business ideas incorporating business agility to software products, services, and user experiences. Then we propose a typical value-driven process stemming from business and social perspectives as new software engineering necessary for the DX era. Hironori Washizaki, Junzo Hagimoto, Kazuo Hamai, Mitsunori Seki, Takeshi Inoue, Shinya Taniguchi, Hiroshi Kobayashi, Kenji Hiranabe, Eiichi Hanyuda |
COMPSAC | 1 |
| 2020 | Smart SE: Smart Systems and Services Innovative Professional Education ProgramabstractThe Smart Systems and Services Innovative Professional Education (Smart SE) program is a certification program developed as part of the education network for the Practical information Technologies (enPiT-Pro) project, which is funded by the Japan Ministry of Education, Culture, Sports, Science and Technology. The Smart SE program provides industry professionals working in fields related to information and communication technology (ICT) with additional training and education in smart systems and services that utilize various technologies such as IoT, Cloud, Big Data, and Artificial Intelligence (AI) for businesses. Here, we illustrate its purpose, curriculum and features to respond to the needs of industrial professional education. Hironori Washizaki, Kenji Tei, Kazunori Ueda, Hayato Yamana, Yoshiaki Fukazawa, Shinichi Honiden, Shoichi Okazaki, Nobukazu Yoshioka, Naoshi Uchihira |
COMPSAC | 1 |
| 2020 | Commit - Defect and Architectural Metrics - based Quality Assessment of C Language
Devansh Tiwari, Hironori Washizaki, Yoshiaki Fukazawa, Tomoyuki Fukuoka, Junji Tamaki, Nobuhiro Hosotani, Munetaka Kohama, Yann-Gaël Guéhéneuc, Foutse Khomh |
ENASE | 2 |
| 2020 | Practitioners' insights on machine-learning software engineering design patterns: a preliminary studyabstractMachine-learning (ML) software engineering design patterns encapsulate reusable solutions to commonly occurring problems within the given contexts of ML systems and software design. These ML patterns should help develop and maintain ML systems and software from the design perspective. However, to the best of our knowledge, there is no study on the practitioners' insights on the use of ML patterns for design of their ML systems and software. Herein we report the preliminary results of a literature review and a questionnaire-based survey on ML system developers' state-of-practices with concrete ML patterns. Hironori Washizaki, Hironori Takeuchi, Foutse Khomh, Naotake Natori, Takuo Doi, Satoshi Okuda |
ICSME | 1 |
| 2020 | A Tool to Manage Traceability on Several Models and Its Use CaseabstractTo examine requirements and design of a system, using graphical models such as UML is one of the effective ways because it helps developers to understand the system and activities using the system. Usually, more than two types of notations are used to represent a system. At the age of digital transformation, relationships among several different systems should be also discussed and they are of course represented in several different notations. To improve the development and the analysis of several systems using such several notations, traceability among elements in the different notations should be managed, but most techniques focus on the traceability among a single project. In this paper, we present a tool to manage traceability on several different models. The tool is developed as a plugin of an existing graphical modeling tool called Astah. Astah enables us to describe UML models as well as mind maps, data flow diagrams, flow charts and so on. To evaluate our tool, we performed a method to elicit requirements of several different systems together by using the tool. We confirmed our tool was helpful to perform the method, but some additional functions would improve the performance more than now. The additional functions are as follows: tracing links transitively, annotating each link to clarify its type and recording an end of a link while the end is removed from a model. Haruhiko Kaiya, Shogo Tatsui, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Nobukazu Yoshioka, Hironori Washizaki |
KES | 7 |
| 2020 | Landscape of Architecture and Design Patterns for IoT SystemsabstractDue to the widespread proliferation of today's Internet of Things (IoT), a system designer needs the IoT system and software design patterns to assist in designing scalable and replicable solutions. Patterns are encapsulations of reusable common problems and solutions under specific contexts. Many IoT patterns have been published, such as IoT design patterns and IoT architecture patterns to document the successes (and failures) in IoT systems and software development. However, because these patterns are not well classified, their adoption does not live up to their potential. To understand the reasons, we conducted a systematic literature review. From the 32 identified papers, 143 IoT architecture and design patterns were extracted. We analyzed these patterns according to several characteristics and outlined directions for improvements when publishing and adopting IoT patterns. Of the extracted patterns, 57% are non-IoT patterns, suggesting that IoT systems and software are often designed via conventional architecture and design patterns that are not specific to IoT design. Although most IoT design patterns are applicable to any domain, IoT architecture patterns tend to be domain specific, implying that the unique nature of IoT adoption in specific domains appears at the architecture level. As more domains adopt IoT, the number of domain-specific IoT design patterns should increase. In terms of quality attributes, many IoT patterns address compatibility, security, and maintainability. Hironori Washizaki, Shinpei Ogata, Atsuo Hazeyama, Takao Okubo, Eduardo B. Fernández, Nobukazu Yoshioka |
IEEE Internet Things J. | 1 |
| 2020 | Editorial for the special issue of STVR on the 10th IEEE International Conference on Software Testing, Verification, and Validation (ICST 2017)abstractThe 10th International Conference on Software Testing, Verification, and Validation (ICST 2017) was held on March 13 to 17, 2017, in Tokyo, Japan. The aim of the ICST conference is to bring together researchers and practitioners who study the theory, techniques, technologies, and applications that concern all aspects of software testing, verification, and validation of software systems. In the main research program, the ICST 2017 program chairs, Ina Schieferdecker and Hironori Washizaki selected 36 full papers and 8 short papers for inclusion in the proceedings from among 135 submissions based on the recommendation of the program committee. All papers were refereed by at least three program committee members. Of the 36 full papers accepted, we selected seven papers for consideration for this special issue of STVR. These papers were extended from their conference version by the authors and were reviewed according to the standard STVR reviewing process. We thank all the ICST and STVR reviewers for their hard work. Three papers successfully completed the review process and are contained in this special issue. The rest of this editorial provides a brief overview of these three papers. The first paper - “Choosing The Fitness Function for the Job: Automated Generation of Test Suites that Detect Real Faults” by Alireza Salahirad, Hussein Almulla, and Gregory Gay - studies the effectiveness of different fitness functions in search-based unit test generation for detecting faults. Experiment results on real faults from the Defects4J database reveal that the branch coverage fitness function is the most effective. The study also reveals that the most important factor related to the likelihood of detection is the satisfaction of the chosen criterion's test obligations. The second paper - “Complexity Vulnerability Analysis using Symbolic Execution” - Kasper Luckow, Rody Kersten, and Corina Pasareanu - presents a symbolic execution technique for analyzing the worst-case complexity of programs. The technique uses path policies to guide the symbolic execution towards worst-case paths. The evaluation shows that the technique can detect complexity vulnerabilities in realistic software as well as standard implementations of classic algorithms. The third paper - “Model-based Testing of Apache ZooKeeper: Fundamental API Usage and Watchers” by Cyrille Artho, Kazuaki Banzai, Quentin Gros, Guillaume Rousset, Lei Ma, Takashi Kitamura, Masami Hagiya, Yoshinori Tanabe, and Mitsuharu Yamamoto - presents a model-based testing technique to generate test cases for concurrent client sessions executing against ZooKeeper. The technique defines the semantics of watchers in ZooKeeper and the test oracle to handle the chain of events that eventually leads to the watcher being triggered. The evaluation shows that the technique can detect known defects as well as seeded mutations that implement possible flaws. Ina Schieferdecker, Atif Memon, Hironori Washizaki |
Softw. Test. Verification Reliab. | 3 |
| 2019 | Mob Programming: A Systematic Literature ReviewabstractHere, we present a systematic literature review of mob programming. Mob programming is a new software development approach, a whole team (more than two people) works together on a code at the same time, in the same space, and on the same computer. The objective is to determine the current reported knowledge of mob programming. We searched two digital libraries, but only ten papers were found. These papers were analyzed and the benefits and risks of mob programming as well as the future research directions are discussed. Makoto Shiraishi, Hironori Washizaki, Yoshiaki Fukazawa, Joseph W. Yoder |
COMPSAC (2) | 2 |
| 2019 | Metrics Driven Architectural Analysis using Dependency Graphs for C Language ProjectsabstractThe highest share of cost for a software product is software maintenance. Identifying the quality merit of the software architecture is extremely vital as the quality directly relates to software maintenance. A good design always exhibits good quality characteristics because it is directly related to good architecture. Although C language is a major language in the software industry, few studies investigate the quality of the architecture in C language. This study aims to evaluate the quality of C language projects in a quantifiable form by focusing on dependency graphs, associated metrics, and software architecture. In particular, this study (i) formulates the architecture representation of C projects, (ii) determines the metrics capturing the quality of architecture, (iii) defines code smell and metrics relations and (iv) conducts an empirical analysis on 58 C projects. We show which metrics derived from dependency graphs can detect architectural issues and verify their relation to software architecture quality. Devansh Tiwari, Hironori Washizaki, Yoshiaki Fukazawa, Tomoyuki Fukuoka, Junji Tamaki, Nobuhiro Hosotani, Munetaka Kohama |
COMPSAC (1) | 2 |
| 2019 | Inappropriate Usage Examples in Web API DocumentationsabstractApplication Programming Interfaces (APIs) are common in software development to reuse other products. Although the documentation allows API consumers to learn about API usages, it can be unreliable. Here, we investigate the characteristics of inappropriate usage examples in web API documentation by extracting and comparing OpenAPI Specifications from usage example-response pairs. About 65.5% of the endpoints have some form of inappropriate usage examples. Furthermore, mismatches are classified into four categories: undocumented keys pattern, dynamic keys pattern, unreturned keys pattern, and type mismatched pattern. Our results suggest that the number of keys in the response is correlated with the number of mismatches. These findings should assist both API providers and consumers who deal with unreliable documentation in web APIs. Masaki Hosono, Susumu Tokumoto, Supasit Monpratarnchai, Hironori Washizaki, Kiyoshi Honda, Hiromasa Nagumo, Hisanobu Sonoda, Yoshiaki Fukazawa, Kazuki Munakata, Takao Nakagawa, Yusuke Nemoto |
ICSME | 4 |
| 2019 | Applying Gamification to Motivate Students to Write High-Quality Code in Programming AssignmentsabstractBackground: Traditional programming education focuses on training students' ability to write correct code that meets the specifications in programming assignments. In addition to correctness, software engineering studies argue that code quality is important. Problem: Nurturing students' ability to write high-quality code in programming assignments is difficult due to two main reasons. (1) Considering code quality while grading is undesirable because there are no objective and fair measurement metrics. (2) Grading assignments from multiple viewpoints (correctness and quality) is difficult and time-consuming. Approach: We propose applying gamification with code metrics to measure code quality in programming assignments. Our approach can motivate students to write code with good metric scores independent of grading. We implemented our approach and conducted a control experiment in a programming course at a university. Result: Our approach did not interfere with students' submissions but improved metric scores significantly. Hence, our approach can engage students to write high-quality code. Remin Kasahara, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
ITiCSE | 3 |
| 2019 | Towards A Knowledge Base for Software Developers to Choose Suitable Traceability TechniquesabstractHuge amount of techniques for creating, maintaining and/or recovering traceability among software development artifacts have been proposed. It is thus not easy for a potential user of such techniques to choose a technique suitable for his/her project because too many techniques exist and projects are different from each other. In this paper, we proposed a model for characterizing a traceability technique with respect to its users. The model can become a meta-model of the knowledge base for such users. The model is designed on the basis of the contents of existing technical papers so that we can easily describe model instances on the basis of technical papers. The model is represented in a feature model, and it has four mandatory features: source, destination, consequence and process. The user can at least understand a technique is unsuitable for him/her by referring such features. If a technique estimates the traceability relationships, the instance of its feature model may contain the quality metrics of its estimation such as precision and recall. It has also several optional features: assumptions, preprocess and tool. Although we sometimes cannot obtain such optional features from technical papers, they are so helpful for a user to decide a technique suitable for him/her. On the basis of the feature model, we described model instances of several techniques in technical papers. We also examined and discussed who the suitable user for each technique is. Haruhiko Kaiya, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Nobukazu Yoshioka, Hironori Washizaki |
KES | 6 |
| 2019 | What are Good Discussions Within Bug Report Comments for Shortening Bug Fixing Time?abstractBugs must be resolved efficiently for developers' limited resources. Bug reports are necessary for the bug modification process. Service user reports a bug as a bug report. Developer read bug reports and fix bugs. The developer can make discussion by posting comments on reported bug reports. There are several researches on the initial report of the bug report so that bugs can be fixed efficiently. But there are few researches on bug report comments. We focus on comments on bug reports. Currently, everyone is free to comment, but the modification time may be affected by how to comment. We investigate the topic of comments of the bug report. As a result of the investigation, the fact that the topics are mixed does not affect the modification time, however we found a tendency to shorten the modification time when the topic of the solution started early. Yuki Noyori, Hironori Washizaki, Yoshiaki Fukazawa, Keishi Oshima, Hideyuki Kanuka, Shuhei Nojiri, Ryosuke Tsuchiya |
QRS | 2 |
| 2019 | Rubric to Evaluate Programming Learning of Elementary School StudentsabstractAs more children are exposed to computer science and programming, numerous indicators have been proposed to evaluate programming learning. Because these indicators are not divided by step in a learning goal, learner's growth cannot be evaluated in detail. Our research focuses on resolving this issue in the field of programming. Herein we propose a rubric to measure the progress of programming learning for elementary school students. This rubric, which is comprised of indices, aims to evaluate learning achievement of logical skills such as logical thinking and problem solving using a unified learning goal. Furthermore, this rubric consists of 30 evaluation items in 8 categories. Then we investigate whether this rubric can be adapted to existing workshops of programming learning. The workshops occurred in 2016 and 2017. in addition, A total of 101 students between 6 and 12 years old participated in the workshops. The rubric successfully evaluates programming learning workshops as it provides a unified evaluation that covers common learning objectives in existing indicators. Our rubric is available at https://g7programming.jp/plr/. Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa, Mariko Tamura, Yuki Sakuragi |
SIGCSE | 2 |
| 2019 | Is Fragmentation a Threat to the Success of the Internet of Things?abstractInternet of Things (IoT) aims to bring connectivity to almost every objects, i.e., things, found in the physical space. It extends connectivity to everyday things, however, such increase in the connectivity creates many prominent challenges. Context: Generally, IoT opens the door for new applications for machine-to-machine and human-to-human communications. The current trend of collaborating, distributed teams through the Internet, mobile communications, and autonomous entities, e.g., robots, is the first phase of the IoT to develop and deliver diverse services and applications. However, such collaborations is threatened by the fragmentation that we witness in the industry nowadays as it brings difficulty to integrate the diverse technologies of the various objects found in IoT systems. Diverse technologies induce interoperability issues while designing and developing various services and applications, hence, limiting the possibility of reusing the data, more specifically, the software (including frameworks, firmware, applications programming interfaces, and user interfaces) as well as of facing issues, like security threats and bugs, when developing new services or applications. Different aspects of handling data collection ranging from discovering smart sensors for data collection, integrating and applying reasoning on them must be available to provide interoperability and flexibility to the diverse objects interacting in the system. However, such approaches are bound to be challenged in future IoT scenarios as they bring substantial performance impairments in settings with the very large number of collaborating devices and technologies. Objective: We raise the awareness of the community about the lack of interoperability among technologies developed for IoT and challenges that their integration poses. We also provide guidelines for researchers and practitioners interested in connecting IoT networks and devices to develop services and applications. Method: We apply the methods advocated by the evidence-based software engineering paradigm. This paradigm and its core tool, the systematic literature review (SLR), were introduced to the software-engineering research community early 2004 to help researchers and industry systematically and objectively gather and aggregate evidences about different topics. In this paper, we conduct an SLR of both IoT interoperability issues and the state-of-practice of IoT technologies in the industry, highlighting the integration challenges related to the IoT that have significantly shifted the landscape of Internet-based collaborative services and applications nowadays. Results: Our SLR identifies a number of studies from journals, conferences, and workshops with the highest quality in the field. This SLR reports different trends, including frameworks and technologies, for the IoT for better comprehension of the paradigm and discusses the integration and interoperability challenges across the different layers of this technology while shedding light on the current IoT state-of-practice. It also discusses some future research directions for the community. Mohab Aly, Foutse Khomh, Yann-Gaël Guéhéneuc, Hironori Washizaki, Soumaya Yacout |
IEEE Internet Things J. | 4 |
| 2019 | Advancing software engineering education: New practices and perspectives
Hossein Saiedian, Hironori Washizaki |
J. Syst. Softw. | 2 |
| 2018 | Evaluating the degree of security of a system built using security patternsabstractA variety of methodologies to build secure systems have been proposed. However, most of them do not say much about how to evaluate the degree of security of their products. In fact, we have no generally-accepted ways to measure if the product of some methodology has reached some degree of security. However, if the system has been built with a methodology that uses patterns as artifacts, we believe that a simple evaluation is possible. We propose a metric for the security of systems that have been built using security patterns: We perform threat enumeration, we check if the patterns in the product have stopped the threats, and calculate the coverage of these threats by the patterns. We indicate how to take advantage of the Twin Peaks approach to arrive to a refined measure of security. In early work, we have proposed a secure systems development methodology that uses security patterns and we use it as example. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki |
ARES | 3 |
| 2018 | An Empirical Study on the Reliability of the Web API DocumentabstractThe importance of APIs in software development, especially web APIs, has increased Developers read documentation, which is available on the internet, and use the corresponding APIs in their products. However, documentation occasionally contains mistakes. Such mistakes can confuse developers or lead to defects that lower the quality of the product. In this paper, we investigate the reliability of web APIs by extracting and comparing OpenAPI specifications from both the documentations and the results of the API calls. Almost half of the documentations are somehow unreliable. Mismatches between documentation and the response can be categorized into four types: 1) Undocumented Keys, 2) Dynamic Keys, 3) Unreturned Keys, and 4) Type Mismatched. This study will help developers design more reliable products. Masaki Hosono, Hironori Washizaki, Yoshiaki Fukazawa, Kiyoshi Honda |
APSEC | 2 |
| 2018 | Security Requirement Modeling Support System Using Software Security Knowledge BaseabstractWith the growing number of services on the Internet, the need for secure software development has increased. It is required for secure software development to consider security in the whole development life cycle. It is indispensable for secure software development to use various types of security knowledge. This study deals with security requirement analysis. Existing security requirements modeling systems do not provide a function to create an artifact while referring to security knowledge in an integrated manner. In this paper, the authors develop a modeling support system for a misuse case diagram that enables the association of knowledge with elements that constitute the diagram. The results of an experiment using the system show the system's usefulness in both the integration of the knowledge base with the artifact creation environment and the association of the knowledge with the elements of the diagram. Atsuo Hazeyama, Shun'ichi Tanaka, Takafumi Tanaka, Hiroaki Hashiura, Seiji Munetoh, Takao Okubo, Haruhiko Kaiya, Hironori Washizaki, Nobukazu Yoshioka |
COMPSAC (2) | 8 |
| 2018 | Cloud Security and Privacy Metamodel - Metamodel for Security and Privacy Knowledge in Cloud Services
Hironori Washizaki, Takehisa Kato, Haruhiko Kaiya, Shinpei Ogata, Eduardo B. Fernández, Hideyuki Kanuka, Masayuki Yoshino, Dan Yamamoto, Takao Okubo, Nobukazu Yoshioka, Atsuo Hazeyama |
MODELSWARD | 2 |
| 2018 | Machine Learning to Evaluate Evolvability Defects: Code Metrics Thresholds for a Given ContextabstractEvolvability defects are non-understandable and non-modifiable states that do not directly produce runtime behavioral failures. Automatic source code evaluation by metrics and thresholds can help reduce the burden of a manual inspection. This study addresses two problems. (1) Evolvability defects are not usually managed in bug tracking systems. (2) Conventional methods cannot fully interpret the relations among the metrics in a given context (e.g., programming language, application domain). The key actions of our method are to (1) gather training-data for machine learning by experts' manual inspection of some of the files in given systems (benchmark) and (2) employ a classification-tree learner algorithm, C5.0, which can deal with non-orthogonal relations between metrics. Furthermore, we experimentally confirm that, even with less training-data, our method provides a more precise evaluation than four conventional methods (the percentile, Alves' method, Bender's method, and the ROC curve-based method). Naohiko Tsuda, Hironori Washizaki, Yoshiaki Fukazawa, Yuichiro Yasuda, Shunsuke Sugimura |
QRS | 2 |
| 2018 | PVC: Visualizing C Programs on Web Browsers for NovicesabstractMany researchers have proposed program visualization tools for memory management because this is a challenging concept for novice programmers. For example, SeeC and PythonTutor (PT) are state-of-the-art tools for C languages. However, three problems hinder the use of these and other tools: capability (P1), installability (P2), and usability (P3). (P1) Tools do not fully support dynamic memory allocation or File Input / Output (I/O) and Standard Input. (P2) Novice programmers often have difficulty installing SeeC due to its dependence on Clang and setting up an offline environment that uses PT. (P3) Revisualization of the modified source code in SeeC requires several steps. To alleviate these issues, we propose a new visualization tool called PlayVisualizerC (PVC). PVC, which is designed for novice C language programmers to provide solutions (S1-3) for P1-3. S1 offers complete support for dynamic memory allocation, standard I/O, and file I/O. S2 involves installation in a user web browser and its server program is initiated by executing a jar file. S3 reduces the steps required for revisualization. To evaluate PVC, we conducted an experiment and questionnaire involving 30 students. Students using PVC solved a set of four programming tasks on average 1.7 times faster and with 19% more correct answers than those using a current state-of-the-art visualization tool. Ryosuke Ishizue, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SIGCSE | 3 |
| 2018 | Improving GQM+Strategies with Balanced Scorecard's Perspectives: A Feasibility StudyabstractAligning business goals and strategies to software requirement is becoming more critical as corporate relies more on software for their business activities. While GQM+Strategies gives the solution to this problem, GQM+Strategies does not explicitly offer attention to relationships between various stakeholders. We propose an integration of Balanced Scorecard's perspectives into GQM+Strategies framework to solve that problem. We evaluated the possibilities by classifying goals and strategies of three existing grids totaling 73 goals and 127 strategies. We also analyzed the relationship between those perspectives in those grids. We found that current application of GQM+Strategies followed balanced scorecard's principles of perspective and concluded that it is possible to use balanced scorecard's perspectives on GQM+Strategies framework. Jati H. Husen, Hironori Washizaki, Yoshiaki Fukazawa |
TENCON | 2 |
| 2018 | Empirical Study on Specification Metrics to Predict Volatility and Software DefectsabstractSuccessful software implementation needs high-quality software requirement specifications (SRSs). However, SRSs are not only difficult to evaluate quantitatively, but there is not an effective indicator to predict which SRSs are prone to modifications. Moreover, few studies have investigated the impact of SRS quality on software quality. Herein we use two specification metrics for SRSs to evaluate their effectiveness to predict future modifications in two actual developments. The results show that our metrics are useful to predict future specification modifications and our specifications are closely related with software quality. Taketo Tsunoda, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Yoshiiku Hanai, Masanobu Kanazawa |
TENCON | 2 |
| 2018 | Body of Knowledge on IoT EducationabstractThe Internet of Things (IoT) has taken an important boom in different areas of knowledge, especially in education. The inclusion of new technologies has impacted the education sector and changed the ways of teaching. Thus, the curricula that are taught in the context of engineering and knowledge areas should be aligned to such change. In this paper, an information mapping was carried out as a scientific methodology to establish the base elements to create a book of knowledge (BOK). This information mapping is aligned with IoT for a standardized education. Pablo Quezada, Liliana Enciso, Hironori Washizaki, Wilmar Hernandez |
WEBIST | 3 |
| 2018 | ProMeTA: a taxonomy for program metamodels in program reverse engineeringabstractTo support program comprehension, maintenance, and evolution, metamodels are frequently used during program reverse engineering activities to describe and analyze constituents of a program and their relations. Reverse engineering tools often define their own metamodels according to the intended purposes and features. Although each metamodel has its own advantages, its limitations may be addressed by other metamodels. Existing works have evaluated and compared metamodels and tools, but none have considered all the possible characteristics and limitations to provide a comprehensive guideline for classifying, comparing, reusing, and extending program metamodels. To aid practitioners and researchers in classifying, comparing, reusing, and extending program metamodels and their corresponding reverse engineering tools according to the intended goals, we establish a conceptual framework with definitions of program metamodels and related concepts. We confirmed that any reverse engineering activity can be clearly described as a pattern based on the framework from the viewpoint of program metamodels. Then the framework is used to provide a comprehensive taxonomy, named Program Metamodel TAxonomy (ProMeTA), which incorporates newly identified characteristics into those stated in previous works, which were identified via a systematic literature review (SLR) on program metamodels, while keeping the orthogonality of the entire taxonomy. Additionally, we validate the taxonomy in terms of its orthogonality and usefulness through the classification of popular metamodels. Hironori Washizaki, Yann-Gaël Guéhéneuc, Foutse Khomh |
Empir. Softw. Eng. | 1 |
| 2018 | Metrics Visualization Techniques Based on Historical Origins and Functional Layers for Developments by Multiple OrganizationsabstractSoftware developments involving multiple organizations such as Open Source Software (OSS)-based projects tend to have numerous defects when one organization develops and another organization edits the program source code files. Developments with complex file creation, modification history (origin), and software architecture (functional layer) are increasing in OSS-based development. As an example, we focus on an Android smart phone and a VirtualBox development project, and propose new visualization techniques for product metrics based on file origin and functional layers. One is the Metrics Area Figure, which can express duplication of edits by multiple organizations intuitively using overlapping figures. The other is Origin City, which was inspired by Code City. It can represent the scale and other measurements, while simultaneously stacking functional layers as 3D buildings. The contributions of our paper are to propose new techniques, implement them as web applications, and share the results of our questionnaire. Our proposed techniques are useful not only to visualize the measured metrics, but also to improve the product quality. Ryosuke Ishizue, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Yoshiiku Hanai, Masanobu Kanazawa, Katsushi Namba |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2017 | Combinations of Personal Characteristic Types and Learning Effectiveness of TeamsabstractIn software and IT systems engineering, personal characteristics are expected to impact performance and attitude. To clarify the optimal composition in a team of students in academic education, we researched the relationship between student personality characteristics and learning effectiveness of teams using the Five Factor and Stress theory (FFS). The results taken from a Project-based Learning (PBL) course at Waseda University showed that educational effectiveness is highest when a team consists of management and anchor types without leadership types. In addition to FFS, we are currently adopting the Five Factor Model (FFM), which is a well-accepted personal characteristic model, to dig deeper the relationship in different courses on IT systems and software development conducted at various universities. Preliminary results show that although individual characteristics are not strongly correlated to learning effectiveness, there are a few strong team correlations. As our future work, we plan to acquire more data and investigate relationship between FFS measurements and FFM ones in terms of learning effectiveness. Hironori Washizaki, Yusuke Sunaga, Masashi Shuto, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo, Bastian Tenbergen |
COMPSAC (1) | 1 |
| 2017 | Traceability Link Mining - Focusing on UsabilityabstractThe recovery of traceability links to requirements from a functional model created through analysis/design is crucial to understand existing systems for reuse, improvement or maintenance. Functional and non-functional requirements generally are implicitly interpreted and non-systematically woven into a functional model by analysts/designers. Traditional traceability link recovery methods focusing on terminology or syntactic structure, however, have a recovery limit because such interpretation and weave are not paid enough attention. This paper presents a novel idea to decompose such a functional model into model components in order to accurately trace a components to requirements especially non-functional requirements. We call such the decomposition traceability link mining. A screen transition model is adopted as the functional model because of the focus on usability. Yukiya Yazawa, Shinpei Ogata, Kozo Okano, Haruhiko Kaiya, Hironori Washizaki |
COMPSAC (2) | 5 |
| 2017 | Student Placement Predictor for Programming Class Using Classes Attitude, Psychological Scale, and Code Metrics
Ryosuke Ishizue, Kuzonori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
ICCE | 3 |
| 2017 | Preliminary Systematic Literature Review of Software and Systems TraceabilityabstractTraceability is important knowledge for improving the artifacts of software and systems and processes related to them. Even in a single system, various kinds of artifacts exist. Various kinds of processes also exist, and each of them relates to different kinds of artifacts. Traceability over them has thus large diversity. In addition, developers in each process have different types of purposes to improve their artifacts and process. Research results in traceability have to be categorized and analyzed so that such a developer can choose one of them to achieve his/her purposes. In this paper, we report on the results of Systematic Literature Review (SLR) related to software and systems traceability. Our SLR is preliminary one because we only analyzed articles in ACM digital library and IEEE computer society digital library. We found several interesting trends in traceability research. For example, researches related to creating or maintaining traceability are larger than those related to using it or thinking its strategy. Various kinds of traceability purposes are addressed or assumed in many researches, but some researches do not specify purposes. Purposes related to changes and updates are dominant. Haruhiko Kaiya, Ryohei Sato, Atsuo Hazeyama, Shinpei Ogata, Takao Okubo, Takafumi Tanaka, Nobukazu Yoshioka, Hironori Washizaki |
KES | 8 |
| 2017 | An interactive Web Application Visualizing Memory Space for Novice C Programmers (Abstract Only)abstractThe concept of memory management in C programming language is particularly challenging for novice programmers. Consequently, many researchers have proposed program visualization tools to alleviate these difficulties: for example, SeeC is one of the state-of-the-art tools for visualizing the behavior and execution status of C programs. However, three problems (P1-3) remain in SeeC, as well as in other existing visualization tools. P1 (Usability): SeeC requires many steps to revisualize modified source code. P2 (Capability): SeeC does not fully support dynamic memory allocation. P3 (Installability): novice programmers often find installation of SeeC challenging due to its dependency on Clang. We propose a new visualization tool named PlayVisualizerC (PVC) for novice C programmers, which provides three solutions (S1-3) for P1-3. S1: PVC reduces the steps required for revisualization. S2: complete support for dynamic memory allocation. S3: designed to be installed in the user's web browser. From a small-scale experiment and a questionnaire given to 20 students, we found that a set of four programming tasks were solved 1.8 times faster and 24% more correctly using PVC. Ryosuke Ishizue, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SIGCSE | 3 |
| 2017 | Relationship between the five factor model personality and learning effectiveness of teams in three information systems education coursesabstractAlthough working in teams is an effective method for students to learn skills necessary for information systems, the optimal combination of team members to maximize the learning effectiveness has yet to be clarified. This study investigates the relationship between the combination of students' personality characteristics and learning effectiveness in three information system lecture courses. Two Five Factor Model (FFM) questionnaires were used to determine each student's personality characteristic. For each course, which has different styles, several different relationships are found. This study should assist educators in maximizing students' learning effectiveness in information systems courses involving teamwork. Masashi Shuto, Hironori Washizaki, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo, Bastian Tenbergen |
SNPD | 2 |
| 2017 | Evaluating the work of experienced and inexperienced developers considering work difficulty in sotware developmentabstractPrevious studies have researched how developer experience affects code quality, but they ignore work difficulty, although experienced developers are more likely to work on the more complex parts of a project. To examine work difficulty, we focus on revised files. Using product metrics, we evaluate file complexity in each type of file origin. Specifically, we analyze three large commercial projects (each project has about 250,000 LOC) executed by the same organization to analyze the relationship between previous project experience and developer's work. Although experienced developers do not always work on more complicated files, they introduce fewer defects, especially if the difference in work difficulty is not significant. Taketo Tsunoda, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Yoshiiku Hanai, Masanobu Kanazawa |
SNPD | 2 |
| 2017 | Generalized Software Reliability Model Considering Uncertainty and Dynamics: Model and ApplicationsabstractToday’s development environment has changed drastically; the development periods are shorter than ever and the number of team members has increased. Consequently, controlling the activities and predicting when a development will end are difficult tasks. To adapt to changes, we propose a generalized software reliability model (GSRM) based on a stochastic process to simulate developments, which include uncertainties and dynamics such as unpredictable changes in the requirements and the number of team members. We assess two actual datasets using our formulated equations, which are related to three types of development uncertainties by employing simple approximations in GSRM. The results show that developments can be evaluated quantitatively. Additionally, a comparison of GSRM with existing software reliability models confirms that the approximation by GSRM is more precise than those by existing models. Kiyoshi Honda, Hironori Washizaki, Yoshiaki Fukazawa |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2016 | Learning Effectiveness of Team Discussions in Various Software Engineering Education CoursesabstractStudents working in teams to complete software tasks is an effective method to learn necessary skills. Previously we examined the educational effectiveness as a function of personal characteristics, but the findings were inconclusive. Because we hypothesize that team discussions impact learning and are related to educational effectiveness, this study investigates the influence of team discussions on learning effectiveness in various types of software engineering education courses. Students' responses to questionnaires about how much students contribute to discussions indicate that learning effectiveness and the number of remarks during a discussion are related. Additionally, upon comparing two learning courses (a system development course and a IT management course), two antithetical results are elucidated. We expect that this research will help improve the effectiveness of educators leading student team discussions. Masashi Shuto, Hironori Washizaki, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo |
CSEE&T | 2 |
| 2016 | Which Combinations of Personal Characteristic Types are more Effective in Different Project-Based Learning Courses?abstractTo improve practical IT education, many universities are implementing project-based learning (PBL). Although researchers have examined the relationship between projects and personality, they have not investigated the type of projects and team construction based on personality. We consider not to construct optimal team for the view of educational effectiveness if we do not understand the difference of each course characteristic. Herein the Five Factor & Stress theory is used to measure personal characteristics and classify students enrolled in two different PBL courses at a university into four types -- leadership, management, tugboat, and anchor. Then knowledge and skills questionnaires are used to measure educational effectiveness. The results show that educational effectiveness is highest when a team consists of management and anchor types but not leadership types in the PBL course which teaches system development, and a team without management types is consisted in the PBL course which teaches IT management strategy. Yusuke Sunaga, Masashi Shuto, Hironori Washizaki, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo |
CSEE&T | 3 |
| 2016 | A Taxonomy for Program Metamodels in Program Reverse EngineeringabstractTo support program comprehension, maintenance, and evolution, metamodels are frequently used during program reverse engineering activities to describe and analyze constituents of a program and their relations. Reverse engineering tools often define their own metamodels according to the intended purposes and features. Although each metamodel has its own advantages, its limitations may be addressed by other metamodels. Existing works have evaluated and compared metamodels and tools, but none have considered all the possible characteristics and limitations to provide a comprehensive guideline for classifying, comparing, reusing, and extending program metamodels. To aid practitioners and researchers in classifying, comparing, reusing, and extending program metamodels and their corresponding reverse engineering tools according to the intended goals, we establish a conceptual framework with definitions of program metamodels and related concepts. Then this framework is used to provide a comprehensive taxonomy, named Program Metamodel TAxonomy (ProMeTA), which incorporates newly identified characteristics into those stated in previous works, which were identified via a systematic literature survey on program metamodels, while keeping the orthogonality of the entire taxonomy. Additionally, we validate the taxonomy in terms of its orthogonality and usefulness through the classification of popular metamodels. Hironori Washizaki, Yann-Gaël Guéhéneuc, Foutse Khomh |
ICSME | 1 |
| 2016 | Influence of the Programming Environment on Programming EducationabstractAlthough both visual and text environments have been used to teach programming, the most appropriate method for beginners is unknown. Herein we research the most suitable programming environment to introduce programming to beginners using Minecraft to provide different programming learning environments (Visual or Text) via ComputerCraftEdu as an extended function. The learning effects between these two environments are compared using a lecture course. The results show that a visual environment is more suitable to introduce programming to beginners. Daisuke Saito, Hironori Washizaki, Yoshiaki Fukazawa |
ITiCSE | 2 |
| 2016 | A Metamodel for Security and Privacy Knowledge in Cloud ServicesabstractWe propose a metamodel for handling security and privacy in cloud service development and operation. The metamodel is expected to be utilized for building a knowledge base to accumulate, classify and reuse existing cloud security and privacy patterns and practices in a consistent and uniform way. Moreover the metamodel and knowledge base are expected to be utilized for designing and maintaining architectures for cloud service systems incorporating security and privacy. Hironori Washizaki, Sota Fukumoto, Misato Yamamoto, Masatoshi Yoshizawa, Yoshiaki Fukazawa, Takehisa Kato, Shinpei Ogata, Haruhiko Kaiya, Eduardo B. Fernández, Hideyuki Kanuka, Yuki Kondo, Nobukazu Yoshioka, Takao Okubo, Atsuo Hazeyama |
SERVICES | 1 |
| 2016 | Requirements Analysis for Privacy Protection and Third Party Awareness Using Logging ModelsabstractAn information system can store personal information of its primary users such as shopping histories, and some third party wants or happens to know such information. Because the system usually provides its privacy policy and its users have to give their consent to it, they sometimes have to partially give up the protection of their privacy. On the other hand, a chance of a third party to know such information is too limited if the policy is too defensive. We proposed a method to explore trade-offs between protection of such information and access permissions for a third party, and exemplified it. In this method, operation logs of a system are focused. The structure of each log is then modelled for analysing what kinds of information can be accessed by a third party. Access limitations of each third party are explored so as to balance the protection of privacy information against access right of third parties. Haruhiko Kaiya, Nobukazu Yoshioka, Takao Okubo, Hironori Washizaki, Atsuo Hazeyama |
SoMeT | 4 |
| 2016 | Metrics Visualization Technique Based on the Origins and Function Layers for OSS-Based DevelopmentabstractSoftware developments involving multiple organizations such as OSS (Open Source Software)-based projects tend to have numerous defects when one organization develops and another organization edits the program source code files. Developments with complex file creation, modification history (origin), and software architecture (functional layer) are increasing in OSS-based development. As an example, here we focus on an Android smart phone development project and propose new visualization techniques for product metrics based on the file origin and functional layers. One is the Metrics Area Figure, which can express duplication of edits by multiple organizations intuitively using overlapping figures. The other is Origin City, which was inspired by Code City. It can represent the scale and other measurements, while simultaneously stacking functional layers as 3D buildings. Ryosuke Ishizue, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Yoshiiku Hanai, Masanobu Kanazawa, Katsushi Namba |
VISSOFT | 2 |
| 2015 | A Third-Party Extension Support Framework Using PatternsabstractSoftware extension is a fundamental challenge in software engineering which involves extending the functionalities of a software module without modifying it. Many modern software developers choose to adapt third-party extension platform to further improve customizability. As the project evolves, the requirements may change to include third-party extension support. However to design and to implement such platform is no trivial task, and should happen at the beginning of the project. In this paper, we have shown the four types of extensions that are often made to object-oriented software, namely Member Access Extension, Subclass Extension, Event-based Extension and Data Extension. And proposed a language-independent platform design that can be applied to an existing software project to support such third-party extensions. The platform exercises design patterns to implement its features. We also developed an Eclipse plugin that helps developers introduce the platform to existing Java software via semi-automatic code manipulation. We further conducted a comparative experiment to test our tool with volunteers from Waseda University and noticed a significant decrease of required effort. Yiyang Hao, Hironori Washizaki, Yoshiaki Fukazawa |
APSEC | 2 |
| 2015 | Interactive Recovery of Requirements Traceability Links Using User Feedback and Configuration Management Logs
Ryosuke Tsuchiya, Hironori Washizaki, Yoshiaki Fukazawa, Keishi Oshima, Ryota Mibe |
CAiSE | 2 |
| 2015 | Recovering transitive traceability links among software artifactsabstractAlthough many methods have been suggested to automatically recover traceability links in software development, they do not cover all link combinations (e.g., links between the source code and test cases) because specific documents or artifact features (e.g., log documents and structures of source code) are used. In this paper, we propose a method called the Connecting Links Method (CLM) to recover transitive traceability links between two artifacts using a third artifact. Because CLM uses a different artifact as a document, it can be applied to kinds of various data. Basically, CLM recovers traceability links using the Vector Space Model (VSM) in Information Retrieval (IR) methods. For example, by connecting links between A and B and between B and C, CLM retrieves the link between A and C transitively. In this way, CLM can recover transitive traceability links when a suggested method cannot. Here we demonstrate that CLM can effectively recover links that VSM is hard using Open Source Software. Kazuki Nishikawa, Hironori Washizaki, Yoshiaki Fukazawa, Keishi Oshima, Ryota Mibe |
ICSME | 2 |
| 2015 | TESEM: A Tool for Verifying Security Design Pattern Applications by Model TestingabstractBecause software developers are not necessarily security experts, identifying potential threats and vulnerabilities in the early stage of the development process (e.g., the requirement- or design-phase) is insufficient. Even if these issues are addressed at an early stage, it does not guarantee that the final software product actually satisfies security requirements. To realize secure designs, we propose extended security patterns, which include requirement-and design-level patterns as well as a new model testing process. Our approach is implemented in a tool called TESEM (Test Driven Secure Modeling Tool), which supports pattern applications by creating a script to execute model testing automatically. During an early development stage, the developer specifies threats and vulnerabilities in the target system, and then TESEM verifies whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved. Takanori Kobashi, Masatoshi Yoshizawa, Hironori Washizaki, Yoshiaki Fukazawa, Nobukazu Yoshioka, Takao Okubo, Haruhiko Kaiya |
ICST | 3 |
| 2015 | History-Based Test Case Prioritization for Black Box Testing Using Ant Colony OptimizationabstractTest case prioritization is a technique to improve software testing. Although a lot of work has investigated test case prioritization, they focus on white box testing or regression testing. However, software testing is often outsourced to a software testing company, in which testers are rarely able to access to source code due to a contract. Herein a framework is proposed to prioritize test cases for black box testing on a new product using the test execution history collected from a similar prior product and the Ant Colony Optimization. A simulation using two actual products shows the effectiveness and practicality of our proposed framework. Tadahiro Noguchi, Hironori Washizaki, Yoshiaki Fukazawa, Atsutoshi Sato, Kenichiro Ota |
ICST | 2 |
| 2015 | A Case-based Management System for Secure Software Development Using Software Security KnowledgeabstractIn recent years, importance on software security technologies has been recognized and various types of technologies have been developed. On the other hand, in spite of recognition of necessity of providing cases that deal with full life cycle for secure software development, only few are reported. This paper describes a case-based management system (CBMS) that consists of an artifact management system and a knowledge-based management system (KBMS) to manage cases for secure software development. The former manages the artifacts created in secure software life cycle. The latter manages software security knowledge. The case-based management system also manages association between artifacts and software security knowledge and supports both visualization among software security knowledge and between artifacts and software security knowledge. We conducted an experiment to evaluate the system. We describe the effectiveness and future work of the system. Masahito Saito, Atsuo Hazeyama, Nobukazu Yoshioka, Takanori Kobashi, Hironori Washizaki, Haruhiko Kaiya, Takao Okubo |
KES | 5 |
| 2015 | How Does Defect Removal Activity of Developer Vary with Development Experience?abstractBecause developers significantly impact software development projects, many researchers have studied developers as a means to improve the quality of software.However, most works have examined developers in a single project, and research involving multiple projects has yet to be published.Herein we propose an analysis method which investigates whether an evaluation of developers based on individual experience is feasible when targeting more than one project by the same organization transversely.Our method deals with the logs of the version control system and the bug tracking system.To support this method, we also propose two models to evaluate developer, the defect removal overhead rate (DROR) and developer's experience point (EXP).The results reveal the following.1) DROR cannot be used to compare different projects in the same organization.2) There is certainly a difference in DROR's between experienced and inexperienced developers.3) EXP should be a useful model to evaluate developers as the number of projects increases.The data obtained from our method should propose the personnel distribution measures within the development framework for future developments, which might lead to improve the quality of software.I. Reou Ando, Seiji Sato, Chihiro Uchida, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Hiroyuki Ono, Yoshiiku Hanai, Masanobu Kanazawa, Kazutaka Sone, Katsushi Namba, Mikihiko Yamamoto |
SEKE | 4 |
| 2015 | Finding and Emulating Keyboard, Mouse, and Touch Interactions and Gestures while Crawling RIA'sabstractCrawling JavaScript heavy Rich Internet Applications has been a hot topic in recent years, giving us automated tools for indexing content, test generation, and security-and accessibility evaluation to mention a few examples.However, existing crawling techniques tend to ignore user interactions beyond mouse clicking, and therefore often fail to consider potential mouse, keyboard and touch interactions.We propose a new technique for finding and exercising mouse, keyboard, and touch interactions when crawling highly interactive JavaScript-based websites by analyzing and exercising event handlers registered in the DOM.A basic form of gesture emulation is employed to find states accessible via swiping and tapping.Testing the tool against 6 well-known gesture libraries and 5 actual RIA's, we find that the technique discovers many states and transitions resulting from such interactions.Our findings indicate the technique could be useful for automatic test generation, error discovery, and accessibility evaluation, especially for mobile web applications with advanced interaction options. Frederik Nakstad, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 2 |
| 2015 | Finding and Emulating Keyboard, Mouse, and Touch Interactions and Gestures while Crawling RIAsabstractExisting techniques for crawling Javascript-heavy Rich Internet Applications tend to ignore user interactions beyond mouse clicking, and therefore often fail to consider potential mouse, keyboard and touch interactions. We propose a new technique for automatically finding and exercising such interactions by analyzing and exercising event handlers registered in the DOM. A basic form of gesture emulation is employed to find states accessible via swiping and tapping. Testing the tool against 6 well-known gesture libraries and 5 actual RIAs, we find that the technique discovers many states and transitions resulting from such interactions, and could be useful for cases such as automatic test generation and error discovery, especially for mobile web applications. Frederik Nakstad, Hironori Washizaki, Yoshiaki Fukazawa |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2014 | Verifying Implementation of Security Design Patterns Using a Test TemplateabstractAlthough security patterns contain security expert knowledge to support software developers, these patterns may be inappropriately applied because most developers are not security specialists, leading to threats and vulnerabilities. Here we propose a validation method for security design patterns in the implementation phase of software development. Our method creates a test template from a security design pattern, which consists of the "aspect test template" to observe the internal processing and the "test case template". Providing design information creates a test from the test template. Because a test template is recyclable, it can create easily a test, which can validate the security design patterns. As a case study, we applied our method to a web system. The result shows that our method can test repetition in the early stage of implementation, verify pattern applications, and assess whether vulnerabilities are resolved. Masatoshi Yoshizawa, Takanori Kobashi, Hironori Washizaki, Yoshiaki Fukazawa, Takao Okubo, Haruhiko Kaiya, Nobukazu Yoshioka |
ARES | 3 |
| 2014 | Predicting Time Range of Development Based on Generalized Software Reliability ModelabstractDevelopment environments have changed drastically, development periods are shorter than ever and the number of team members has increased. These changes have led to difficulties in controlling the development activities and predicting when the development will end. Especially, quality managers try to control software reliability and project managers try to estimate the end of development for planning developing term and distribute the manpower to other developments. In order to assess recent software developments, we propose a generalized software reliability model (GSRM) based on a stochastic process, and simulate developments that include uncertainties and dynamics. We also compare our simulation results to those of other software reliability models. Using the values of uncertainties and dynamics obtained from GSRM, we can evaluate the developments in a quantitative manner. Additionally, we use equations to define the uncertainty regarding the time required to complete a development, and predict whether or not a development will be completed on time. We compare GSRM with an existing model using two old actual datasets and one new actual dataset which we collected, and show that the approximation curve generated by GSRM is about 12% more precise than that generated by the existing model. Furthermore, GSRM can narrow down the predicted time range in which a development will end to less than 40% of that obtained by the existing model. Kiyoshi Honda, Hidenori Nakai, Hironori Washizaki, Yoshiaki Fukazawa, Ken Asoh, Kazuyoshi Takahashi, Kentarou Ogawa, Maki Mori, Takashi Hino, Yosuke Hayakawa, Yasuyuki Tanaka, Shinichi Yamada, Daisuke Miyazaki |
APSEC (1) | 3 |
| 2014 | Initial Industrial Experience of GQM-Based Product-Focused Project Monitoring with Trend PatternsabstractIt is important for project stakeholders to identify the states of projects and quality of products. Although metrics are useful for identifying them, it is difficult for project stake-holders to select appropriate metrics and determine the purpose of measuring metrics. We propose an approach that defines the measured metrics by GQM method to identify tendency in projects and products based on Trend Pattern. Additionally, we implement a tool as a Jenkins Plug in to visualize an evaluation results based on GQM method. We perform an industrial case study, which objects are two software development projects. In our industrial case study, we can identify the problem that product contains. As our future work, we will adopt our approach and GQM Plug in to software development project continuously to assess their effectiveness in the long term. Hidenori Nakai, Kiyoshi Honda, Hironori Washizaki, Yoshiaki Fukazawa, Ken Asoh, Kazuyoshi Takahashi, Kentarou Ogawa, Maki Mori, Takashi Hino, Yosuke Hayakawa, Yasuyuki Tanaka, Shinichi Yamada, Daisuke Miyazaki |
APSEC (2) | 3 |
| 2014 | Continuous Product-Focused Project Monitoring with Trend Patterns and GQMabstractIt is important for project stakeholders to identify the states of projects and quality of products. Although metrics are useful for identifying them, it is difficult for project stakeholders to select appropriate metrics and determine the purpose of measuring metrics. We propose an approach that defines the measured metrics by GQM method, and supports identifying tendency in projects and products based on Trend Pattern. Additionally, we implement a tool as a Jenkins Plug in which to visualizes an evaluation results based on GQM method. We perform an experiment with OSS and industrial case study with two software development projects. In our experiment, we can identify the problem and project tendency. In our industrial case study, we can also identify the problem that project contains. As our future work, we will adopt our approach and GQM Plug in to software development project continuously to assess their effectiveness in the long term. Hidenori Nakai, Kiyoshi Honda, Hironori Washizaki, Yoshiaki Fukazawa, Ken Asoh, Kazuyoshi Takahashi, Kentarou Ogawa, Maki Mori, Takashi Hino, Yosuke Hayakawa, Yasuyuki Tanaka, Shinichi Yamada, Daisuke Miyazaki |
APSEC (2) | 3 |
| 2014 | A Tool to Suggest Similar Program Element ModificationsabstractMany program tasks require continuous modification of similar program elements, which is burdensome on programmers because continuous modifications are time consuming and some modifications are easily overlooked. To resolve this issue, we developed a tool, named Similar Highlight, which extracted all possible matching elements via similarity patterns from recently modified elements using a sub syntax tree comparison. Similar Highlight suggests similar program elements that may be modified during the next modification. Potential elements are highlighted and their text can be immediately selected by shortcut keys. Evaluations indicate that Similar Highlight can improve programming productivity. Currently, Similar Highlight supports C, C#, JAVA, Java Script, and PHP, but in the future we will expand it to other languages. Yujiang Yang, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
APSEC (1) | 3 |
| 2014 | Predicting Release Time Based on Generalized Software Reliability Model (GSRM)abstractDevelopment environments have changed drastically, development periods are shorter than ever and the number of team members has increased. Especially in open source software (OSS), a large number of developers contribute to OSS. OSS has difficulties in predicting or deciding when it will be released. In order to assess recent software developments, we proposed a generalized software reliability model (GSRM) based on a stochastic process, and compared GSRM with other models. In this paper, we focus on the release dates of OSS and the growth of faults (issues). Kiyoshi Honda, Hironori Washizaki, Yoshiaki Fukazawa |
COMPSAC | 2 |
| 2014 | The impacts of personal characteristic on educational effectiveness in controlled-project based learning on software intensive systems developmentabstractIn practical courses on software-intensive business systems, students work in teams to acquire practical skills in systems acquisition and provisioning. However, we do not yet have an established method to determine the optimal team composition to achieve maximum educational effectiveness. In this study, we quantitatively and qualitatively investigate how personal characteristics and the learning process of team members affect educational effectiveness by examining a university course in which students work in teams on a realistic project in a classroom setting. We use the Five Factors and Stress (FFS) theory and the modified grounded theory approach (M-GTA) to measure the personal characteristics and to identify the learning process of each team member. Additionally, we compare the learning process of a team with a high educational effectiveness to one with a low educational effectiveness based on number of topics about the learning process and the kind of topics. As a result, we find that it is better for a team to have members with different personal characteristic as defined by FFS theory in order for the students to acquire more knowledge and skills through the course. Additionally, teams that focus on fewer learning process topics acquire more knowledge and skills. We expect that our findings will help increase the educational effectiveness in similar practical courses. Yusuke Yamada, Shota Inaga, Hironori Washizaki, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo, Teruhiko Kume, Manabu Tamaki |
CSEE&T | 3 |
| 2014 | Semi-automatic Incompatibility Localization for Re-engineered Industrial SoftwareabstractAfter a legacy system is re-engineered, it is important to perform compatibility testing so as to identify the differences and reduce the introduced bugs. We can first apply symbolic execution to obtain an exhaustive set of test cases, then use them to check the compatibility of the old system and the new one. However there may be a lot of failed test cases which are a mix of erroneous and allowable incompatibilities. To locate the causes of failures detected during the testing, we apply multiple statistical bug localization techniques. We are able to localize 90% of the incompatibilities in 10% of the code for an industrial application with around 20k lines by Tarantula. And we identify the characteristics of failure causes which are difficult to be detected by statistical bug localization. Susumu Tokumoto, Kazunori Sakamoto, Kiyofumi Shimojo, Tadahiro Uehara, Hironori Washizaki |
ICST | 5 |
| 2014 | Validating ajax applications using a delay-based mutation techniqueabstractThe challenge of validating Asynchronous JavaScript and XML (Ajax) applications lies in actual errors exposed in a user environment. Several studies have proposed effective and efficient testing techniques to identify executable faults. However, the applications might have faults that are not executed during testing, but might cause actual errors in a user environment. Although we have investigated static methods for finding ``potential faults'' that seem to cause actual errors if executed, developers need to confirm whether or not the potential faults are actually executable. Herein, we propose a mutation-based testing method implemented in a tool called JSPreventer. Even if the potential faults are not easily executable in a given environment, our method mutates the applications until they are executable using two delay-based mutation operators to manipulate the timing of the applications handling interactions. Thus, JSPreventer provides executable evidences of the not-easily-executable faults for developers, if it reveals actual errors by testing the mutated applications. We applied our method to real-world applications and found actual errors that developers could debug to improve their reliability. Therefore, JSPreventer can help developers validate reliable real-world Ajax applications. Yuta Maezawa, Kazuki Nishiura, Hironori Washizaki, Shinichi Honiden |
ASE | 3 |
| 2014 | Identifying Rationales of Strategies by Stakeholder Relationship Analysis to Refine and Maintain GQM+Strategies Models
Takanobu Kobori, Hironori Washizaki, Yoshiaki Fukazawa, Daisuke Hirabayashi, Katsutoshi Shintani, Yasuko Okazaki, Yasuhiro Kikushima |
PROFES | 2 |
| 2014 | Security and Privacy Behavior Definition for Behavior Driven Development
Takao Okubo, Yoshio Kakizaki, Takanori Kobashi, Hironori Washizaki, Shinpei Ogata, Haruhiko Kaiya, Nobukazu Yoshioka |
PROFES | 4 |
| 2014 | Do Open Source Software Projects Conduct Tests Enough?
Ryohei Takasawa, Kazunori Sakamoto, Akinori Ihara, Hironori Washizaki, Yoshiaki Fukazawa |
PROFES | 4 |
| 2014 | RefactoringScript: A Script and Its Processor for Composite Refactoring
Linchao Yang, Tomoyuki Kamiya, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 4 |
| 2013 | Validating Security Design Patterns Application Using Model TestingabstractSoftware developers are not necessarily security specialists, security patterns provide developers with the knowledge of security specialists. Although security patterns are reusable and include security knowledge, it is possible to inappropriately apply a security pattern or that a properly applied pattern does not mitigate threats and vulnerabilities. Herein we propose a method to validate security pattern applications. Our method provides extended security patterns, which include requirement- and design-level patterns as well as a new model testing process using these patterns. Developers specify the threats and vulnerabilities in the target system during an early stage of development, and then our method validates whether the security patterns are properly applied and assesses whether these vulnerabilities are resolved. Takanori Kobashi, Nobukazu Yoshioka, Takao Okubo, Haruhiko Kaiya, Hironori Washizaki, Yoshiaki Fukazawa |
ARES | 5 |
| 2013 | Effects of Organizational Changes on Product Metrics and DefectsabstractThe development organization often changes during software development. Derivative developments, forks, and change of developers due to acquisition or open-sourcing are some conceivable situations. However, the impact of this change on software quality has yet to be elucidated. Herein we introduce the concept of origins to study the effects of organizational changes on software quality. A file's origin is defined as its creation and modification history. Using the concept of origins, we analyze two open source projects, Open Office and Virtual Box, which were each developed by a total of three organizations. We conduct statistical analysis to investigate the relationship between the origins, product metrics, the number of modifications, and defects. Results show that files that are created or modified by multiple organizations or by later organizations tend to be faultier due to the increase in complexity and modification frequency. Seiji Sato, Hironori Washizaki, Yoshiaki Fukazawa, Sakae Inoue, Hiroyuki Ono, Yoshiiku Hanai, Mikihiko Yamamoto |
APSEC (1) | 2 |
| 2013 | Team characteristics for maximizing the educational effectiveness of practical lectures on software intensive systems developmentabstractIn practical lectures on software intensive business systems, we do not yet have an established method for determining what kind of personal characteristics and team compositions are most beneficial to obtaining the maximal educational effectiveness. Here, we propose a framework for analyzing the effects of personal characteristics of team members on educational effectiveness. We also apply the framework to an actual practical lecture. As a result, we find that it is better for a team to have members with a similar degree of tendency of conservative for acquiring more knowledge and skills and the team members have similar characteristics of progressive or conservative. It is expected that in similar practical lectures, we can also obtain the desired educational effectiveness if we can compose a team with the suitable characteristics as based on our findings. Shota Inaga, Hironori Washizaki, Yusuke Yoshida, Yoshiaki Fukazawa, Shoso Yamato, Masashi Okubo, Teruhiko Kume, Manabu Tamaki, Toshikazu Kanou |
CSEE&T | 2 |
| 2013 | POGen: A Test Code Generator Based on Template Variable Coverage in Gray-Box Integration Testing for Web Applications
Kazunori Sakamoto, Kaizu Tomohiro, Daigo Hamura, Hironori Washizaki, Yoshiaki Fukazawa |
FASE | 4 |
| 2013 | Learning System for Computational Thinking using Appealing User Interface with Icon-Based Programming Language on SmartphonesabstractComputational thinking is one of the most important skills for using computers. Most existing learning systems for computational thinking work only on desktop or laptop computers, although the popularity of smartphones has rapidly been growing. Moreover, most existing programming languages to teach are based on English and most learning systems employ poor user interfaces. Thus, such programming languages and learning systems are not suitable for users who are not familiar with English or who are enchanted to such user interfaces. We propose a gamified learning system using an appealing user interface with a novel icon-based non-verbal programming language. Our system works on smartphones with which many Japanese teenager students are more familiar than PCs. Our system employs an appealing interface that a female student designs for other female students and icons to motivate university students to learn programming through playing. We conducted an experiment with 16 female students from Waseda University to evaluate our system. We confirmed our system motivated the students to learn programming and helped learn computational thinking concepts. Kazunori Sakamoto, Koichi Takano, Hironori Washizaki, Yoshiaki Fukazawa |
ICCE | 3 |
| 2013 | OCCF: A Framework for Developing Test Coverage Measurement Tools Supporting Multiple Programming LanguagesabstractAlthough many programming languages and test coverage criteria currently exist, most coverage measurement tools only support select programming languages and coverage criteria. Consequently, multiple measurement tools must be combined to measure coverage for software which uses multiple programming languages such as web applications. However, such combination leads to inconsistent and inaccurate measurement results. In this paper, we describe a consistent and flexible framework for measuring coverage supporting multiple programming languages, called Open Code Coverage Framework (OCCF). OCCF allows users to add new extensions for supporting programming languages and coverage criteria with low development costs. To evaluate the effectiveness of OCCF, sample implementation to support statement coverage and decision coverage for eight programming languages (C, C++, C#, Java, JavaScript, Python, Ruby and Lua) are demonstrated. Additionally, applications of OCCF for localizing faults and minimizing tests are shown. Kazunori Sakamoto, Kiyofumi Shimojo, Ryohei Takasawa, Hironori Washizaki, Yoshiaki Fukazawa |
ICST | 4 |
| 2013 | Automated verification of pattern-based interaction invariants in Ajax applicationsabstractWhen developing asynchronous JavaScript and XML (Ajax) applications, developers implement Ajax design patterns for increasing the usability of the applications. However, unpredictable contexts of running applications might conceal faults that will break the design patterns, which decreases usability. We propose a support tool called JSVerifier that auto-matically verifies interaction invariants; the applications handle their interactions in invariant occurrence and order. We also present a selective set of interaction invariants derived from Ajax design patterns, as input. If the application behavior breaks the design patterns, JSVerifier automatically outputs faulty execution paths for debugging. The results of our case studies show that JSVerifier can verify the interaction invariants in a feasible amount of time, and we conclude that it can help developers increase the usability of Ajax applications. Yuta Maezawa, Hironori Washizaki, Yoshinori Tanabe, Shinichi Honiden |
ASE | 2 |
| 2013 | A Generalized Software Reliability Model Considering Uncertainty and Dynamics in Development
Kiyoshi Honda, Hironori Washizaki, Yoshiaki Fukazawa |
PROFES | 2 |
| 2013 | Comparative Evaluation of Programming Paradigms: Separation of Concerns with Object-, Aspect-, and Context-Oriented Programming (S)
Fumiya Kato, Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 3 |
| 2013 | Mutation Analysis for JavaScriptWeb Application Testing
Kazuki Nishiura, Yuta Maezawa, Hironori Washizaki, Shinichi Honiden |
SEKE | 3 |
| 2013 | Extended Design Patterns in New Object-Oriented Programming Languages (S)
Kazunori Sakamoto, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 2 |
| 2013 | Joint Workshop of the 5th International Workshop on Model-Driven Approaches in Software Product Line Engineering and the 4th Workshop on Scalable Modeling Techniques for Software Product Lines (MAPLE/SCALE 2013)abstractOne of the greatest barriers on the way to the efficient creation, handling, and evolution of product lines is the complexity and scale of the underlying artifacts. In this context, the MAPLE/SCALE workshop focuses on the investigation of scalability issues and the application of model-driven concepts and techniques in software product line engineering (SPLE). The workshop explores how to handle product lines of realistic complexity and how to facilitate systematic and efficient product derivation. Goetz Botterweck, Deepak Dhungana, Natsuko Noda, Rick Rabiser, Hironori Washizaki |
SPLC | 5 |
| 2013 | Recovering traceability links between requirements and source code in the same series of software productsabstractIf traceability links between requirements and source code are not clarified when conducting maintenance and enhancements for the same series of software products, engineers cannot immediately find the correction location in the source code for requirement changes. However, manually recovering links in a large group of products requires significant costs and some links may be overlooked. Here, we propose a semi-automatic method to recover traceability links between requirements and source code in the same series of large software products. In order to support differences in representation between requirements and source code, we recover links by using the configuration management log as an intermediary. We refine the links by classifying requirements and code elements in terms of whether they are common or specific to the products. As a result of applying our method to real products that have 60KLOC, we have recovered valid traceability links within a reasonable amount of time. Automatic parts have taken 13 minutes 36 seconds, and non-automatic parts have taken about 3 hours, with a recall of 76.2% and a precision of 94.1%. Moreover, we recovered some links that were unknown to engineers. By recovering traceability links, software reusability will be improved, and software product line introduction will be facilitated. Ryosuke Tsuchiya, Tadahisa Kato, Hironori Washizaki, Masumi Kawakami, Yoshiaki Fukazawa, Kentaro Yoshimura |
SPLC | 3 |
| 2012 | Reusability Metrics for Program Source Code Written in C Language and Their Evaluation
Hironori Washizaki, Toshikazu Koike, Rieko Namiki, Hiroyuki Tanabe |
PROFES | 1 |
| 2012 | Towards a Unified Source Code Measurement Framework Supporting Multiple Programming Languages
Reisha Humaira, Kazunori Sakamoto, Akira Ohashi, Hironori Washizaki, Yoshiaki Fukazawa |
SEKE | 4 |
| 2012 | Supporting commonality and variability analysis of requirements and structural modelsabstractThe commonality and variability analysis of legacy software assets requires high costs in terms of personnel and time in extractive core asset development. We propose a technique for supporting the commonality and variability analysis, targeting the requirements and structural models of legacy software assets for the development of a feature diagram and a product line architecture (PLA). We analyze the commonality and variability of the sentences as requirements and classes as structural models by calculating similarities based on a vector space model. By using our technique, the costs in terms of personnel and time required for the analysis of legacy software assets can be reduced. Kentaro Kumaki, Ryosuke Tsuchiya, Hironori Washizaki, Yoshiaki Fukazawa |
SPLC (2) | 3 |
| 2011 | An Approach to Model-based Development of Secure and Reliable SystemsabstractA good way to obtain secure systems is to build applications in a systematic way where security is an integral part of the lifecycle. The same applies to reliability. If we want a system which is secure and reliable, both security and reliability must be built together. If we build not only applications but also middleware and operating systems in the same way, we can build systems that not only are inherently secure but also can withstand attacks from malicious applications and resist errors. In addition, all security and reliability constraints should be defined in the application level, where their semantics is understood and propagated to the lower levels. The lower levels provide the assurance that the constraints are being followed. In this approach all security constraints are defined at the conceptual or application level. The lower levels just enforce that there are no ways to bypass these constraints. By mapping to a highly secure platform, e.g., one using capabilities, we can produce a very secure system. Our approach is based on security patterns that are mapped through the architectural levels of the system. We make a case for this approach and we present here three aspects to further develop it. These aspects include a metamodel for security requirements, a mapping of models across architectural levels, and considerations about the degree of security of the system. Eduardo B. Fernández, Hironori Washizaki, Nobukazu Yoshioka, Michael VanHilst |
ARES | 2 |
| 2011 | Evaluation of Understandability of UML Class Diagrams by Using Word SimilarityabstractUML class diagrams representing the static structure of the relations between different concepts existing in a problem are widely used in model-based software development. However, no effective measures of a class diagram's understandability yet exist. We have devised quantitative measures of a class diagram's understandability and evaluated their validity. We obtained strong correlations between the domain experts' subjective evaluations of the understandability of a class diagram and the measurements of our methods. These results indicate that our measures can effectively quantify the understandability of class diagrams. Yuto Nakamura, Kazunori Sakamoto, Kiyohisa Inoue, Hironori Washizaki, Yoshiaki Fukazawa |
IWSM/Mensura | 4 |
| 2010 | Measuring the Level of Security Introduced by Security PatternsabstractIt is possible to reasonably measure the security quality of individual security patterns. However, more interesting is to ask: Can we show that a system built using security patterns is secure in some sense? We discuss here some issues about evaluating the security of a system built using security patterns. We consider the use of threats and misuse patterns to perform this evaluation. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki, Michael VanHilst |
ARES | 3 |
| 2010 | Model-Driven Security Patterns Application Based on Dependences among PatternsabstractThe spread of open-software services through the Internet increases the importance of security. A security pattern is one of the techniques in which developers utilize security experts' knowledge. Security patterns contain typical solutions about security problems. However there is a possibility that developers may apply security patterns in inappropriate ways due to a lack of consideration on dependencies among patterns. Application techniques of security patterns that consider such dependencies have not been proposed yet. In this paper, we propose an automated application technique of security patterns in model driven software development by defining applications procedures of security patterns to models as model transformation rules with consideration for pattern dependencies. Our technique prevents inappropriate applications such as the application of security patterns to wrong model elements and that in wrong orders. Therefore our technique supports developers apply security patterns to their own models automatically in appropriate ways. Yuki Shiroma, Hironori Washizaki, Yoshiaki Fukazawa, Atsuto Kubo, Nobukazu Yoshioka |
ARES | 2 |
| 2009 | Modeling Misuse PatternsabstractSecurity patterns are now starting to be accepted by industry. Security patterns are useful to guide the security design of systems by providing generic solutions that can stop a variety of attacks but it is not clear to an inexperienced designer what pattern should be applied to stop a specific attack. They are not useful either for forensics because they do not emphasize the modus operandi of the attack. To complement security patterns, we have proposed a new type of pattern, the misuse pattern. This pattern describes, from the point of view of the attacker, how a type of attack is performed (what units it uses and how), defines precisely the context of the attack, analyzes the ways of stopping the attack by enumerating possible security patterns that can be applied for this purpose, and describes how to trace the attack once it has happened by appropriate collection and observation of forensics data. We present here a model that characterizes the precise structure of this type of pattern. Eduardo B. Fernández, Nobukazu Yoshioka, Hironori Washizaki |
ARES | 3 |
| 2008 | Classifying Security Patterns
Eduardo B. Fernández, Hironori Washizaki, Nobukazu Yoshioka, Atsuto Kubo, Yoshiaki Fukazawa |
APWeb | 2 |
| 2008 | A Metrics Suite for Measuring Quality Characteristics of JavaBeans Components
Hironori Washizaki, Hiroki Hiraguchi, Yoshiaki Fukazawa |
PROFES | 1 |
| 2007 | Automatic Extraction and Verification of Page Transitions in aWeb ApplicationabstractDemand for reliability in Web applications has increased greatly in recent years as they have begun to be used more for enterprise applications. Model checking is an effective way to increase software reliability, but because most Web applications have short delivery times, preparation and application costs make it difficult to introduce model-checking techniques into the development process. In this paper, we propose a technique for automatically extracting page transitions from a Web application that has been developed using a Web application framework, such as Struts configuration files and Java Server Page templates, and transforming it into a format that can be used by existing model-checking tools. Using the proposed technique, Web application developers will be able to reduce the preparation and application costs of introducing model-checking techniques. Atsuto Kubo, Hironori Washizaki, Yoshiaki Fukazawa |
APSEC | 2 |
| 2007 | 1st International Workshop on Software Patterns and Quality (SPAQu'07)abstractAlthough numbers of software pattern catalogues and languages have been published, little is known about quality of patterns, quality by patterns and quality aspects of pattern activities. This workshop seeks to gain an improved understanding on the theoretical, social, technological and practical issues related to quality aspects of patterns including security and safety. Hironori Washizaki, Nobukazu Yoshioka |
APSEC | 1 |
| 2007 | Top SE: Educating Superarchitects Who Can Apply Software Engineering Tools to Practical Development in JapanabstractThis paper discusses the Top SE program established to bridge the industry-academia gap. The program features extensive use of software engineering tools, not only to introduce students to the tools, but also as a conduit for learning the techniques and guidelines needed to apply the tools to practical software development situations. The curriculum is organized around practical problems mainly from the area of digital home appliances and focuses on upper stream software development processes. The Top SE program is developed and operated by a close collaboration between industry and academia. We illustrate our discussion with examples from one of the courses, verification of design models, which takes up model checking technologies, including three specific tools: SPIN, SMV, and LTSA. Shinichi Honiden, Yasuyuki Tahara, Nobukazu Yoshioka, Kenji Taguchi 0001, Hironori Washizaki |
ICSE | 5 |
| 2007 | A Framework for Measuring and Evaluating Program Source Code Quality
Hironori Washizaki, Rieko Namiki, Tomoyuki Fukuoka, Yoko Harada, Hiroyuki Watanabe |
PROFES | 1 |
| 2006 | A precise estimation technique for test coverage of components in object-oriented frameworksabstractIn general, a component-based system uses only a part of the functions of its software components. Therefore, precise structural testing for components requires to specify what functions of the components are used in the system. In addition, in the case with an object-oriented component, some existing studies point out that testing of all possible bindings between a call site and the methods that the site may invoke is extremely ineffective. In this paper, we propose a method for precisely estimating test coverage of components on an object-oriented framework by using its deployment descriptor and evaluate its effectiveness. Yuji Sakata, Kazutoshi Yokoyama, Hironori Washizaki, Yoshiaki Fukazawa |
APSEC | 3 |
| 2006 | A Coupling-based Complexity Metric for Remote Component-based Software Systems Toward Maintainability EstimationabstractRemote-component-based software systems (CBS) must provide high maintainability to support operation over long periods of time and correspond to changes in enterprise requirements/environments. Measurements of the degree of complexity of a system are one technique for evaluating maintainability. However, conventional complexity metrics are unable to reflect the overall complexity of the system, because they do not incorporate a procedure to account for characteristics of CBS. To help maintenance work proceed smoothly, we propose a new metric that measures the coupling-based complexity of CBS by abstracting the target system's structure through a step-wise process and taking into consideration the characteristics of remote components. Our metric can be applied to CBS based on the Enterprise JavaBeans component architecture. As a result of experimental evaluations, it is found that our metric better reflects the maintainability than conventional metrics. It is also found that our metric is nonredundant with existing metrics such as coupling factor. Hironori Washizaki, Tomoki Nakagawa, Yuhki Saito, Yoshiaki Fukazawa |
APSEC | 1 |
| 2006 | Experiments on quality evaluation of embedded software in Japan robot software design contestabstractAs a practical opportunity for educating Japanese young developers in the field of embedded software development, a software design contest involving the design of software to automatically control a line-trace robot, and conduct running performance tests was held. In this paper,we give the results of the contest from the viewpoint of software quality evaluation. We create a framework for evaluating the software quality which integrated design model quality and the final system performance, and conduct analysis using the framework. As a result of analysis,it is found that the quantitative measurement of the structural complexity of the design models bears a strong relationship to qualitative evaluation of the design conducted by judges. It is also found that there is no strong correlation between design model quality evaluated by the judges and the final system performance. For embedded software development, it is particularly important to estimate and verify reliability and performance in the early stages,using the model. Based on the analysis result,we consider possible remedies with respect to the models submitted,the evaluation methods used and the contest specifications. In order to adequately measure several non-functional quality characteristics including performance on the model,it is necessary to improve the way of developing robot software (such as applying model driven development)and reexamine the evaluation methods. Hironori Washizaki, Yasuhide Kobayashi, Hiroyuki Watanabe, Eiji Nakajima, Yuji Hagiwara, Kenji Hiranabe, Kazuya Fukuda |
ICSE | 1 |
| 2006 | Building Software Process Line Architectures from Bottom Up
Hironori Washizaki |
PROFES | 1 |
| 2005 | Relation Analysis Among Patterns on Software Development Process
Hironori Washizaki, Atsuto Kubo, Atsuhiro Takasu, Yoshiaki Fukazawa |
PROFES | 1 |
| 2005 | A technique for automatic component extraction from object-oriented programs by refactoring
Hironori Washizaki, Yoshiaki Fukazawa |
Sci. Comput. Program. | 1 |
| 2004 | Component-Extraction-Based Search System for Object-Oriented Programs
Hironori Washizaki, Yoshiaki Fukazawa |
ICSR | 1 |
| 2004 | Conditional Test for JavaBeans Components
Hironori Washizaki, Yuhki Sakai, Yoshiaki Fukazawa |
XP | 1 |
| 2003 | Automated Extract Component Refactoring
Hironori Washizaki, Yoshiaki Fukazawa |
XP | 1 |