VLDB 2026 Research / reviewers in the wild / expert
Yijun Yu 0001
dblp:74/6710
· DBLP profile ↗
112ranked-venue papers
18as first author
12since 2021 · last 2025
0000-0002-7154-8570ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 85 · 12 first-author · 8 since 2021Databases, data management, data science and information retrieval · 7 · 1 since 2021Applied, interdisciplinary, general and emerging computing · 7 · 1 first-authorArtificial intelligence and machine learning · 6 · 1 first-author · 3 since 2021Security and privacy · 5Graphics, computer vision, multimedia, augmented reality and games · 5 · 2 first-author · 3 since 2021Computer networks · 4Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 1 since 2021Systems, architecture and hardware · 3 · 2 first-authorTheory of computation · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | RustMap: Towards Project-Scale C-to-Rust Migration via Program Analysis and LLM
Xuemeng Cai, Xiping Huang, Yijun Yu 0001, Chunmiao Li, Bo Wang 0050, Imam Nur Bani Yusuf, Lingxiao Jiang |
ICECCS | 4 |
| 2023 | Ownership Guided C to Rust TranslationabstractAbstract Dubbed a safer C, Rust is a modern programming language that combines memory safety and low-level control. This interesting combination has made Rust very popular among developers and there is a growing trend of migrating legacy codebases (very often in C) to Rust. In this paper, we present a C to Rust translation approach centred around static ownership analysis. We design a suite of analyses that infer ownership models of C pointers and automatically translate the pointers into safe Rust equivalents. The resulting tool, Crown, scales to real-world codebases (half a million lines of code in less than 10 s) and achieves a high conversion rate. Hanliang Zhang, Cristina David, Yijun Yu 0001, Meng Wang 0002 |
CAV (3) | 3 |
| 2023 | Accounting for socio-technical resilience in software engineeringabstractResilience engineering (RE) is most commonly applied at the organisational level, and has historically been associated with safety-critical industries such as nuclear, medical or aviation. This paper explores the application of RE frameworks within software engineering, and investigates resilient performance of the socio-technical system that supports the creation of software. We present a preliminary study based on a secondary analysis of data from previous ethnographic studies of commercial software practice. This analysis uses an RE framework devised for small team practice in safety critical settings. We present and discuss three salient episodes of software practice that illustrate the application of RE principles to software engineering, and suggest how this kind of analysis may benefit software engineering. We present challenges and opportunities based on our experience and propose future research directions. Tamara Lopez, Helen Sharp, Michel Wermelinger, Melanie Langer, Mark Levine, Caroline Jay, Yijun Yu 0001, Bashar Nuseibeh |
CHASE | 7 |
| 2023 | Adaptive Observability for Forensic-Ready Microservice SystemsabstractMicroservice-based applications may include multiple instances of microservices running on containerised infrastructures. These infrastructures pose challenges to digital investigations of security incidents because digital evidence can be destroyed when containers are terminated. Observability techniques are used to facilitate the investigation of incidents in microservice systems. However, existing observability approaches do not address security incidents when there is a need to perform digital forensic investigations. Furthermore, approaches to proactively support digital forensic investigations are limited to security incidents that are known a priori. In this paper, we propose an adaptive observability approach based on game theory. The approach addresses the challenge of implementing forensic-ready microservice systems while considering uncertainties in security incidents. Our approach provides evidence collection capabilities for microservice systems and continually adapts to improve the forensic readiness of microservices. Specifically, the approach uses game theory to model and reason about the interactions between users and microservices, determining the optimal time and manner for observing microservices before the occurrence of security incidents. The performance of the approach has been assessed and compared with other observability approaches. Results of the evaluation indicate that adaptive observability outperforms other observability approaches, with improvements ranging from 3.1% up to 42.50%. Davi Monteiro Barbosa, Yijun Yu 0001, Andrea Zisman, Bashar Nuseibeh |
IEEE Trans. Serv. Comput. | 2 |
| 2022 | Towards Robust Models of Code via Energy-Based Learning on Auxiliary DatasetsabstractExisting approaches to improving the robustness of source code models concentrate on recognizing adversarial samples rather than valid samples that fall outside of a given distribution, which we refer to as out-of-distribution (OOD) samples. To this end, we propose to use an auxiliary dataset (out-of-distribution) such that, when trained together with the main dataset, they will enhance the model’s robustness. We adapt energy-bounded learning objective function to assign a higher score to in-distribution samples and a lower score to out-of-distribution samples in order to incorporate such out-of-distribution samples into the training process of source code models. In terms of OOD detection and adversarial samples detection, our evaluation results demonstrate a greater robustness for existing source code models to become more accurate at recognizing OOD data while being more resistant to adversarial attacks at the same time. Nghi D. Q. Bui, Yijun Yu 0001 |
ASE | 2 |
| 2022 | Online adaptation for autonomous unmanned systems driven by requirements satisfaction model
Yixing Luo, Yuan Zhou 0005, Haiyan Zhao 0001, Zhi Jin 0001, Tianwei Zhang 0004, Yang Liu 0003, Danny Barthaud, Yijun Yu 0001 |
Softw. Syst. Model. | 8 |
| 2021 | TreeCaps: Tree-Based Capsule Networks for Source Code ProcessingabstractRecently program learning techniques have been proposed to process source code based on syntactical structures (e.g., abstract syntax trees) and/or semantic information (e.g., dependency graphs). While graphs may be better than trees at capturing code semantics, constructing the graphs from code inputs through the semantic analysis of multiple viewpoints can lead to inaccurate noises for a specific software engineering task. Compared to graphs, syntax trees are more precisely defined on the grammar and easier to parse; unfortunately, previous tree-based learning techniques have not been able to learn semantic information from trees to achieve better accuracy than graph-based techniques. We have proposed a new learning technique, named TreeCaps, by fusing together capsule networks with tree-based convolutional neural networks to achieve a learning accuracy higher than some existing graph-based techniques while it is based only on trees. TreeCaps introduces novel variable-to-static routing algorithms into the capsule networks to compensate for the loss of previous routing algorithms. Aside from accuracy, we also find that TreeCaps is the most robust to withstand those semantic-preserving program transformations that change code syntax without modifying the semantics. Evaluated on a large number of Java and C/C++ programs, TreeCaps models outperform prior deep learning models of program source code, in terms of both accuracy and robustness for program comprehension tasks such as code functionality classification and function name prediction. Our implementation is publicly available at: https://github.com/bdqnghi/treecaps. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
AAAI | 2 |
| 2021 | Quantum Cognitively Motivated Decision Fusion for Video Sentiment AnalysisabstractVideo sentiment analysis as a decision-making process is inherently complex, involving the fusion of decisions from multiple modalities and the so-caused cognitive biases. Inspired by recent advances in quantum cognition, we show that the sentiment judgment from one modality could be incompatible with the judgment from another, i.e., the order matters and they cannot be jointly measured to produce a final decision. Thus the cognitive process exhibits ``quantum-like'' biases that cannot be captured by classical probability theories. Accordingly, we propose a fundamentally new, quantum cognitively motivated fusion strategy for predicting sentiment judgments. In particular, we formulate utterances as quantum superposition states of positive and negative sentiment judgments, and uni-modal classifiers as mutually incompatible observables, on a complex-valued Hilbert space with positive-operator valued measures. Experiments on two benchmarking datasets illustrate that our model significantly outperforms various existing decision level and a range of state-of-the-art content-level fusion approaches. The results also show that the concept of incompatibility allows effective handling of all combination patterns, including those extreme cases that are wrongly predicted by all uni-modal classifiers. Dimitris Gkoumas, Qiuchi Li, Shahram Dehdashti, Massimo Melucci, Yijun Yu 0001, Dawei Song 0001 |
AAAI | 5 |
| 2021 | InferCode: Self-Supervised Learning of Code Representations by Predicting SubtreesabstractLearning code representations has found many uses in software engineering, such as code classification, code search, comment generation, and bug prediction, etc. Although representations of code in tokens, syntax trees, dependency graphs, paths in trees, or the combinations of their variants have been proposed, existing learning techniques have a major limitation that these models are often trained on datasets labeled for specific downstream tasks, and as such the code representations may not be suitable for other tasks. Even though some techniques generate representations from unlabeled code, they are far from being satisfactory when applied to the downstream tasks. To overcome the limitation, this paper proposes InferCode, which adapts the self-supervised learning idea from natural language processing to the abstract syntax trees (ASTs) of code. The novelty lies in the training of code representations by predicting subtrees automatically identified from the contexts of ASTs. With InferCode, subtrees in ASTs are treated as the labels for training the code representations without any human labelling effort or the overhead of expensive graph construction, and the trained representations are no longer tied to any specific downstream tasks or code units. We have trained an instance of InferCode model using Tree-Based Convolutional Neural Network (TBCNN) as the encoder of a large set of Java code. This pre-trained model can then be applied to downstream unsupervised tasks such as code clustering, code clone detection, cross-language code search, or be reused under a transfer learning scheme to continue training the model weights for supervised tasks such as code classification and method name prediction. Compared to prior techniques applied to the same downstream tasks, such as code2vec, code2seq, ASTNN, using our pre-trained InferCode model higher performance is achieved with a significant margin for most of the tasks, including those involving different programming languages. The implementation of InferCode and the trained embeddings are available at the link: https://github.com/bdqnghi/infercode. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
ICSE | 2 |
| 2021 | An Entanglement-driven Fusion Neural Network for Video Sentiment AnalysisabstractVideo data is multimodal in its nature, where an utterance can involve linguistic, visual and acoustic information. Therefore, a key challenge for video sentiment analysis is how to combine different modalities for sentiment recognition effectively. The latest neural network approaches achieve state-of-the-art performance, but they neglect to a large degree of how humans understand and reason about sentiment states. By contrast, recent advances in quantum probabilistic neural models have achieved comparable performance to the state-of-the-art, yet with better transparency and increased level of interpretability. However, the existing quantum-inspired models treat quantum states as either a classical mixture or as a separable tensor product across modalities, without triggering their interactions in a way that they are correlated or non-separable (i.e., entangled). This means that the current models have not fully exploited the expressive power of quantum probabilities. To fill this gap, we propose a transparent quantum probabilistic neural model. The model induces different modalities to interact in such a way that they may not be separable, encoding crossmodal information in the form of non-classical correlations. Comprehensive evaluation on two benchmarking datasets for video sentiment analysis shows that the model achieves significant performance improvement. We also show that the degree of non-separability between modalities optimizes the post-hoc interpretability. Dimitris Gkoumas, Qiuchi Li, Yijun Yu 0001, Dawei Song 0001 |
IJCAI | 3 |
| 2021 | Self-Supervised Contrastive Learning for Code Retrieval and Summarization via Semantic-Preserving TransformationsabstractWe propose Corder, a self-supervised contrastive learning framework for source code model. Corder is designed to alleviate the need of labeled data for code retrieval and code summarization tasks. The pre-trained model of Corder can be used in two ways: (1) it can produce vector representation of code which can be applied to code retrieval tasks that do not have labeled data; (2) it can be used in a fine-tuning process for tasks that might still require label data such as code summarization. The key innovation is that we train the source code model by asking it to recognize similar and dissimilar code snippets through acontrastive learning objective. To do so, we use a set of semantic-preserving transformation operators to generate code snippets that are syntactically diverse but semantically equivalent. Through extensive experiments, we have shown that the code models pretrained by Corder substantially outperform the other baselines for code-to-code retrieval, text-to-code retrieval, and code-to-text summarization tasks. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
SIGIR | 2 |
| 2021 | On the generalizability of Neural Program Models with respect to semantic-preserving program transformations
Md. Rafiqul Islam Rabin, Nghi D. Q. Bui, Ke Wang 0022, Yijun Yu 0001, Lingxiao Jiang, Mohammad Amin Alipour |
Inf. Softw. Technol. | 4 |
| 2020 | Dynamic Gas Estimation of Loops Using Machine Learning
Chunmiao Li, Shijie Nie, Yang Cao 0011, Yijun Yu 0001, Zhenjiang Hu 0002 |
BlockSys | 4 |
| 2020 | Privacy-Aware UAV Flights through Self-Configuring Motion PlanningabstractDuring flights, an unmanned aerial vehicle (UAV) may not be allowed to move across certain areas due to soft constraints such as privacy restrictions. Current methods on self-adaption focus mostly on motion planning such that the trajectory does not trespass predetermined restricted areas. When the environment is cluttered with uncertain obstacles, however, these motion planning algorithms are not flexible enough to find a trajectory that satisfies additional privacy-preserving requirements within a tight time budget during the flights. In this paper, we propose a privacy risk aware motion planning method through the reconfiguration of privacy-sensitive sensors. It minimises environmental impact by re-configuring the sensor during flight, while still guaranteeing the safety and energy hard constraints such as collision avoidance and timeliness. First, we formulate a model for assessing privacy risks of dynamically detected restricted areas. In case the UAV cannot find a feasible solution to satisfy both hard and soft constraints from the current configuration, our decision making method can then produce an optimal reconfiguration of the privacy-sensitive sensor with a more efficient trajectory. We evaluate the proposal through various simulations with different settings in a virtual environment and also validate the approach through real test flights on DJI Matrice 100 UAV. Yixing Luo, Yijun Yu 0001, Zhi Jin 0001, Yao Li 0011, Zuohua Ding, Yuan Zhou 0005, Yang Liu 0003 |
ICRA | 2 |
| 2020 | A Feature Table approach to decomposing monolithic applications into microservicesabstractMicroservice architecture refers to the use of numerous small-scale and independently deployed services, instead of encapsulating all functions into one monolith. It has been a challenge in software engineering to decompose a monolithic system into smaller parts. In this paper, we propose the Feature Table approach, a structured approach to service decomposition based on the correlation between functional features and microservices: (1) we defined the concept of Feature Cards and 12 instances of such cards; (2) we formulated Decomposition Rules to decompose monolithic applications; (3) we designed the Feature Table Analysis Tool to provide semi-automatic analysis for identification of microservices; and (4) we formulated Mapping Rules to help developers implement microservice candidates. We performed a case study on Cargo Tracking System to validate our microservice-oriented decomposition approach. Cargo Tracking System is a typical case that has been decomposed by other related methods (dataflow-driven approach, Service Cutter, and API Analysis). Through comparison with the related methods in terms of specific coupling and cohesion metrics, the results show that the proposed Feature Table approach can deliver more reasonable microservice candidates, which are feasible in implementation with semi-automatic support. Yuyang Wei, Yijun Yu 0001, Minxue Pan, Tian Zhang 0001 |
Internetware | 2 |
| 2020 | EUD-MARS: End-user development of model-driven adaptive robotics software systems
Pierre A. Akiki, Paul A. Akiki, Arosha K. Bandara, Yijun Yu 0001 |
Sci. Comput. Program. | 4 |
| 2020 | Recommending software features to designers: From the perspective of usersabstractSummary With lots of public software descriptions emerging in the application market, it is significant to extract common software features from these descriptions and recommend them to new designers. However, existing approaches often recommend features according to their frequencies which reflect designers' preferences. In order to identify those users' favorite features and help design more popular software, this paper proposes to make use of the public data of users' ratings and products' downloads which reflect users' preferences to recommend extracted features. The proposed approach distinguishes users' perspective from designers' perspective and argues that users' perspective is better for recommending features because most products are designed for users and expect to be popular among users. Based on the lasso regression to estimate the relationship between the extracted features and the users' ratings, it first distinguishes the extracted features to identify those recommendable and undesirable features. By treating each download as a support from users to the product featurefeatures, it further mines the feature association rules from users' perspective for recommending features. By taking the public data on the market of SoftPedia.com for evaluation, our empirical studies indicate that: (i) selecting recommendable features by lasso regression is better than that by feature frequencies in terms ofF1measure; and (ii) recommending features based on the feature association rules mined from users' perspective is not only feasible but also has competitive performance compared with that based on the rules mined from designs' perspective in terms ofF1measure. Chun Liu 0008, Wei Yang 0038, Zheng Li 0029, Yijun Yu 0001 |
Softw. Pract. Exp. | 4 |
| 2019 | AutoFocus: Interpreting Attention-Based Neural Networks by Code PerturbationabstractDespite being adopted in software engineering tasks, deep neural networks are treated mostly as a black box due to the difficulty in interpreting how the networks infer the outputs from the inputs. To address this problem, we propose AutoFocus, an automated approach for rating and visualizing the importance of input elements based on their effects on the outputs of the networks. The approach is built on our hypotheses that (1) attention mechanisms incorporated into neural networks can generate discriminative scores for various input elements and (2) the discriminative scores reflect the effects of input elements on the outputs of the networks. This paper verifies the hypotheses by applying AutoFocus on the task of algorithm classification (i.e., given a program source code as input, determine the algorithm implemented by the program). AutoFocus identifies and perturbs code elements in a program systematically, and quantifies the effects of the perturbed elements on the network's classification results. Based on evaluation on more than 1000 programs for 10 different sorting algorithms, we observe that the attention scores are highly correlated to the effects of the perturbed code elements. Such a correlation provides a strong basis for the uses of attention scores to interpret the relations between code elements and the algorithm classification results of a neural network, and we believe that visualizing code elements in an input program ranked according to their attention scores can facilitate faster program comprehension with reduced code. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
ASE | 2 |
| 2019 | Cautious Adaptation of Defiant ComponentsabstractSystems-of-systems are formed by the composition of independently created software components. These components are designed to satisfy their individual requirements, rather than the global requirements of the systems-of-systems. We refer to components that cannot be adapted to meet both individual and global requirements as "defiant" components. In this paper, we propose a "cautious" adaptation approach which supports changing the behaviour of such defiant components under exceptional conditions to satisfy global requirements, while continuing to guarantee the satisfaction of the components' individual requirements. The approach represents both normal and exceptional conditions as scenarios; models the behaviour of exceptional conditions as wrappers implemented using an aspect-oriented technique; and deals with both single and multiple instances of defiant components with different precedence order at runtime. We evaluated an implementation of the approach using drones and boats for an organ delivery application conceived by our industrial partners, in which we assess how the proposed approach help achieve the system-of-systems' global requirements while accommodating increased complexity of hybrid aspects such as multiplicity, precedence ordering, openness and heterogeneity. Paulo Henrique M. Maia, Matheus Lima Chagas, Yijun Yu 0001, Andrea Zisman, Bashar Nuseibeh |
ASE | 4 |
| 2019 | RE4CPS: Requirements Engineering for Cyber-Physical SystemsabstractCyber-Physical Systems (CPSs) connect the cyber world with the physical world through a network of interrelated elements, such as sensors and actuators, robots, and other computing devices. There are increasing number of beneficial applications in dependable sectors such as aviation, transportation, aerospace, healthcare, etc.. The inherent characteristics of CPSs pose a number of challenges to requirements engineering. Unlike normal information systems, CPSs need to continuously detect and adapt to the environment changes. The interactive environment becomes the first-class citizen because the features and the changing patterns in environment are must-to-be considered. Moreover, in such systems, many non-functional requirements are environment related, like timing, safety, security, and privacy requirements. This tutorial will introduce an environment modelling based approach to engineering the requirements of CPSs. Extending the Problem Frames representations, this approach structures the model of the environmental elements and provides analysis methods for deriving and specifying requirements. We deliver this tutorial with a few supporting tools that assist the modelling and verification of the system specification, demonstrated with working examples in sufficient details. After the tutorial, participants will be able to work on the environment modelling requirements engineering for their own projects, with some hands-on experience and a good knowledge of some tool support. Zhi Jin 0001, Xiaohong Chen 0001, Zhi Li 0017, Yijun Yu 0001 |
RE | 4 |
| 2019 | Environment-Centric Safety Requirements for Autonomous Unmanned SystemsabstractAutonomous unmanned systems (AUS) emerge to take place of human operators in harsh or dangerous environments. However, such environments are typically dynamic and uncertain, causing unanticipated accidents when autonomous behaviours are no longer safe. Even though safe autonomy has been considered in the literature, little has been done to address the environmental safety requirements of AUS systematically. In this paper, we conduct a systematical literature review and set up a taxonomy of environment-centric safety requirements for AUS. We then analyse the neglected issues to suggest several new research directions towards the vision of environmental-centric safe autonomy. Yixing Luo, Yijun Yu 0001, Zhi Jin 0001, Haiyan Zhao 0001 |
RE | 2 |
| 2019 | SAR: learning cross-language API mappings with little knowledgeabstractTo save effort, developers often translate programs from one programming language to another, instead of implementing it from scratch. Translating application program interfaces (APIs) used in one language to functionally equivalent ones available in another language is an important aspect of program translation. Existing approaches facilitate the translation by automatically identifying the API mappings across programming languages. However, these approaches still require large amount of parallel corpora, ranging from pairs of APIs or code fragments that are functionally equivalent, to similar code comments. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
ESEC/SIGSOFT FSE | 2 |
| 2019 | Bilateral Dependency Neural Networks for Cross-Language Algorithm ClassificationabstractAlgorithm classification is to automatically identify the classes of a program based on the algorithm(s) and/or data structure(s) implemented in the program. It can be useful for various tasks, such as code reuse, code theft detection, and malware detection. Code similarity metrics, on the basis of features extracted from syntax and semantics, have been used to classify programs. Such features, however, often need manual selection effort and are specific to individual programming languages, limiting the classifiers to programs in the same language.To recognize the similarities and differences among algorithms implemented in different languages, this paper describes a framework of Bilateral Neural Networks (Bi-NN) that builds a neural network on top of two underlying sub-networks, each of which encodes syntax and semantics of code in one language. A whole Bi-NN can be trained with bilateral programs that implement the same algorithms and/or data structures in different languages and then be applied to recognize algorithm classes across languages.We have instantiated the framework with several kinds of token-, tree- and graph-based neural networks that encode and learn various kinds of information in code. We have applied the instances of the framework to a code corpus collected from GitHub containing thousands of Java and C++ programs implementing 50 different algorithms and data structures. Our evaluation results show that the use of Bi-NN indeed produces promising algorithm classification results both within one language and across languages, and the encoding of dependencies from code into the underlying neural networks helps improve algorithm classification accuracy further. In particular, our custom-built dependency trees with tree-based convolutional neural networks achieve the highest classification accuracy among the different instances of the framework that we have evaluated. Our study points to a possible future research direction to tailor bilateral and multilateral neural networks that encode more relevant semantics for code learning, mining and analysis tasks. Nghi D. Q. Bui, Yijun Yu 0001, Lingxiao Jiang |
SANER | 2 |
| 2019 | Text Filtering and Ranking for Security Bug Report PredictionabstractSecurity bug reports can describe security critical vulnerabilities in software products. Bug tracking systems may contain thousands of bug reports, where relatively few of them are security related. Therefore finding unlabelled security bugs among them can be challenging. To help security engineers identify these reports quickly and accurately, text-based prediction models have been proposed. These can often mislabel security bug reports due to a number of reasons such as class imbalance, where the ratio of non-security to security bug reports is very high. More critically, we have observed that the presence of security related keywords in both security and non-security bug reports can lead to the mislabelling of security bug reports. This paper proposes FARSEC, a framework for filtering and ranking bug reports for reducing the presence of security related keywords. Before building prediction models, our framework identifies and removes non-security bug reports with security related keywords. We demonstrate that FARSEC improves the performance of text-based prediction models for security bug reports in 90 percent of cases. Specifically, we evaluate it with 45,940 bug reports from Chromium and four Apache projects. With our framework, we mitigate the class imbalance issue and reduce the number of mislabelled security bug reports by 38 percent. Fayola Peters, Thein Than Tun, Yijun Yu 0001, Bashar Nuseibeh |
IEEE Trans. Software Eng. | 3 |
| 2018 | Are Smell-Based Metrics Actually Useful in Effort-Aware Structural Change-Proneness Prediction? An Empirical StudyabstractBad code smells (also named as code smells) are symptoms of poor design choices in implementation. Existing increases the likelihood of subsequent changes (i.e., change-proness). However, to the best of our knowledge, no prior studies have leveraged smell-based metrics to predict particular change type (i.e., structural changes). Moreover, when evaluating the effectiveness of smell-based metrics in structural change-proneness prediction, none of existing studies take into account of the effort inspecting those change-prone source code. In this paper, we consider five smell-based metrics for effort-aware structural change-proneness prediction and compare these metrics with a baseline of well-known CK metrics in predicting particular categories of change types. Specifically, we first employ univariate logistic regression to analyze the correlation between each smell-based metric and structural change-proneness. Then, we build multivariate prediction models to examine the effectiveness of smell-based metrics in effort-aware structural change-proneness prediction when used alone and used together with the baseline metrics, respectively. Our experiments are conducted on six Java open-source projects with up to 60 versions and results indicate that: (1) all smell-based metrics are significantly related to structural change-proneness, except metric ANOS in hive and SCM in camel after removing confounding effect of file size; (2) in most cases, smell-based metrics outperform the baseline metrics in predicting structural change-proneness; and (3) when used together with the baseline metrics, the smell-based metrics are more effective to predict change-prone files with being aware of inspection effort. Yijun Yu 0001, Bixin Li, Yibiao Yang, Ru Jia |
APSEC | 2 |
| 2018 | Locating bugs without looking backabstractBug localisation is a core program comprehension task in software maintenance: given the observation of a bug, e.g. via a bug report, where is it located in the source code? Information retrieval (IR) approaches see the bug report as the query, and the source code files as the documents to be retrieved, ranked by relevance. Such approaches have the advantage of not requiring expensive static or dynamic analysis of the code. However, current state-of-the-art IR approaches rely on project history, in particular previously fixed bugs or previous versions of the source code. We present a novel approach that directly scores each current file against the given report, thus not requiring past code and reports. The scoring method is based on heuristics identified through manual inspection of a small sample of bug reports. We compare our approach to eight others, using their own five metrics on their own six open source projects. Out of 30 performance indicators, we improve 27 and equal 2. Over the projects analysed, on average we find one or more affected files in the top 10 ranked files for 76% of the bug reports. These results show the applicability of our approach to software projects without history. Tezcan Dilshener, Michel Wermelinger, Yijun Yu 0001 |
Autom. Softw. Eng. | 3 |
| 2018 | Feature-Driven Mediator Synthesis: Supporting Collaborative Security in the Internet of ThingsabstractAs the number, complexity, and heterogeneity of connected devices in the Internet of Things (IoT) increase, so does our need to secure these devices, the environment in which they operate, and the assets they manage or control. Collaborative security exploits the capabilities of these connected devices and opportunistically composes them to protect assets from potential harm. By dynamically composing these capabilities, collaborative security implements the security controls that satisfy both security and non-security requirements. However, this dynamic composition is often hampered by the heterogeneity of the devices available in the environment and the diversity of their behaviours. In this article, we present a systematic, tool-supported approach for collaborative security where the analysis of requirements drives the opportunistic composition of capabilities to realise the appropriate security control in the operating environment. This opportunistic composition is supported through a combination of feature modelling and mediator synthesis. We use features and transition systems to represent and reason about capabilities and requirements. We formulate the selection of the optimal set of features to implement adequate security control as a multi-objective constrained optimisation problem and use constraint programming to solve it efficiently. The selected features are then used to scope the behaviours of the capabilities and thereby restrict the state space for synthesising the appropriate mediator. The synthesised mediator coordinates the behaviours of the capabilities to satisfy the behaviour specified by the security control. Our approach ensures that the implemented security controls are the optimal ones, given the capabilities available in the operating environment. We demonstrate the validity of our approach by implementing a feature-driven mediation for collaborative security tool and applying it to a collaborative robots case study. Amel Bennaceur, Thein Than Tun, Arosha K. Bandara, Yijun Yu 0001, Bashar Nuseibeh |
ACM Trans. Cyber Phys. Syst. | 4 |
| 2018 | An Empirical Study of Cohesion and Coupling: Balancing Optimization and DisruptionabstractSearch-based software engineering has been extensively applied to the problem of finding improved modular structures that maximize cohesion and minimize coupling. However, there has, hitherto, been no longitudinal study of developers' implementations, over a series of sequential releases. Moreover, results validating whether developers respect the fitness functions are scarce, and the potentially disruptive effect of search-based remodularization is usually overlooked. We present an empirical study of 233 sequential releases of ten different systems; the largest empirical study reported in the literature so far, and the first longitudinal study. Our results provide evidence that developers do, indeed, respect the fitness functions used to optimize cohesion/coupling (they are statistically significantly better than arbitrary choices with p ≪ 0.01), yet they also leave considerable room for further improvement (cohesion/coupling can be improved by 25% on average). However, we also report that optimizing the structure is highly disruptive (on average more than 57% of the structure must change), while our results reveal that developers tend to avoid such disruption. Therefore, we introduce and evaluate a multiobjective (MO) evolutionary approach that minimizes disruption while maximizing cohesion/coupling improvement. This allows developers to balance reticence to disrupt existing modular structure, against their competing need to improve cohesion and coupling. The MO approach is able to find modular structures that improve the cohesion of developers' implementations by 22.52%, while causing an acceptably low level of disruption (within that already tolerated by developers). Matheus Paixão, Mark Harman, Yuanyuan Zhang 0003, Yijun Yu 0001 |
IEEE Trans. Evol. Comput. | 4 |
| 2018 | Simplifying the Formal Verification of Safety Requirements in Zone Controllers Through Problem Frames and Constraint-Based ProjectionabstractFormal methods have been applied widely to verifying the safety requirements of communication-based train control (CBTC) systems, while the problem situations could be much simplified. In industrial practices of CBTC systems, however, huge complexity arises, which renders those methods nearly impossible to apply. In this paper, we aim to reduce the state space of formal verification problems in zone controller, a sub-system of a typical CBTC. We achieve the simplification goal by reducing the total number of device variables. To do this, two projection methods are proposed based on problem frames and constraints, respectively. The problem frame-based method decomposes the system according to sub-properties through functional decomposition, while the constraint-based projection method removes redundant variables. Our industrial case study demonstrates the feasibility through an evaluation, confirming that these two methods are effective in reducing the state spaces of complex verification problems in this application domain. Zhengheng Yuan, Xiaohong Chen 0007, Jing Liu 0012, Yijun Yu 0001, Haiying Sun, Tingliang Zhou, Zhi Jin 0001 |
IEEE Trans. Intell. Transp. Syst. | 4 |
| 2018 | CrowdService: Optimizing Mobile Crowdsourcing and Service CompositionabstractSome user needs can only be met by leveraging the capabilities of others to undertake particular tasks that require intelligence and labor. Crowdsourcing such capabilities is one way to achieve this. But providing a service that leverages crowd intelligence and labor is a challenge, since various factors need to be considered to enable reliable service provisioning. For example, the selection of an optimal set of workers from those who bid to perform a task needs to be made based on their reliability, expected reward, and distance to the target locations. Moreover, for an application involving multiple services, the overall cost and time constraints must be optimally allocated to each involved service. In this article, we develop a framework, named C rowd S ervice , that supplies crowd intelligence and labor as publicly accessible crowd services via mobile crowdsourcing. The article extends our earlier work by providing an approach for constraints synthesis and worker selection. It employs a genetic algorithm to dynamically synthesize and update near-optimal cost and time constraints for each crowd service involved in a composite service and selects a near-optimal set of workers for each crowd service to be executed. We implement the proposed framework on Android platforms and evaluate its effectiveness, scalability, and usability in both experimental and user studies. Xin Peng 0001, Jingxiao Gu, Tian Huat Tan, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao |
ACM Trans. Internet Techn. | 5 |
| 2017 | Enabling End-Users to Protect their PrivacyabstractIn this paper we present our ongoing work to build an approach to empower users of IoT-based cyber physical systems to protect their privacy by themselves. Our approach allows users to identify the privacy risks involved in sharing private data with a data consumer, assess the value of their private data based on identified risks and take a pragmatic data sharing decision balancing the risks with the benefits generated by the sharing. Our approach features a knowledgebase, called the Privacy Oracle, that exploits the power of the Semantic Web to determine how raw metadata can be combined by data consumers to infer privacy-sensitive information as well as the privacy risks associated with the disclosure of inferred information. Mahmoud Barhamgi, Mu Yang, Chia-Mu Yu, Yijun Yu 0001, Arosha K. Bandara, Djamal Benslimane, Bashar Nuseibeh |
AsiaCCS | 4 |
| 2017 | Transforming Timing Requirements into CCSL Constraints to Verify Cyber-Physical Systems
Xiaohong Chen 0001, Ling Yin 0002, Yijun Yu 0001, Zhi Jin 0001 |
ICFEM | 3 |
| 2017 | O2O service composition with social collaborationabstractIn Online-to-Offline (O2O) commerce, customer services may need to be composed from online and offline services. Such composition is challenging, as it requires effective selection of appropriate services that, in turn, support optimal combination of both online and offline services. In this paper, we address this challenge by proposing an approach to O2O service composition which combines offline route planning and social collaboration to optimize service selection. We frame general O2O service composition problems using timed automata and propose an optimization procedure that incorporates: (1) a Markov Chain Monte Carlo (MCMC) algorithm to stochastically select a concrete composite service, and (2) a model checking approach to searching for an optimal collaboration plan with the lowest cost given certain time constraint. Our procedure has been evaluated using the simulation of a rich scenario on effectiveness and scalability. Wenyi Qian, Xin Peng 0001, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao |
ASE | 4 |
| 2017 | Visual Simple Transformations: Empowering End-Users to Wire Internet of Things ObjectsabstractEmpowering end-users to wire Internet of Things (IoT) objects (things and services) together would allow them to more easily conceive and realize interesting IoT solutions. A challenge lies in devising a simple end-user development approach to support the specification of transformations, which can bridge the mismatch in the data being exchanged among IoT objects. To tackle this challenge, we present Visual Simple Transformations (ViSiT) as an approach that allows end-users to use a jigsaw puzzle metaphor for specifying transformations that are automatically converted into underlying executable workflows. ViSiT is explained by presenting meta-models and an architecture for implementing a system of connected IoT objects. A tool is provided for supporting end-users in visually developing and testing transformations. Another tool is also provided for allowing software developers to modify, if they wish, a transformation's underlying implementation. This work was evaluated from a technical perspective by developing transformations and measuring ViSiT's efficiency and scalability and by constructing an example application to show ViSiT's practicality. A study was conducted to evaluate this work from an end-user perspective, and its results showed positive indications of perceived usability, learnability, and the ability to conceive real-life scenarios for ViSiT. Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001 |
ACM Trans. Comput. Hum. Interact. | 3 |
| 2016 | CrowdService: serving the individuals through mobile crowdsourcing and service compositionabstractSome user needs in real life can only be accomplished by leveraging the intelligence and labor of other people via crowdsourcing tasks. For example, one may want to confirm the validity of the description of a secondhand laptop by asking someone else to inspect the laptop on site. To integrate these crowdsourcing tasks into user applications, it is required that crowd intelligence and labor be provided as easily accessible services (e.g., Web services), which can be called crowd services. In this paper, we develop a framework named CROWDSERVICE which supplies crowd intelligence and labor as publicly accessible crowd services via mobile crowdsourcing. We implement the proposed framework on the Android platform and evaluate the usability of the framework with a user study. Xin Peng 0001, Jingxiao Gu, Tian Huat Tan, Jun Sun 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao |
ASE | 5 |
| 2016 | Locating bugs without looking backabstractBug localisation is a core program comprehension task in software maintenance: given the observation of a bug, where is it located in the source code files? Information retrieval (IR) approaches see a bug report as the query, and the source code files as the documents to be retrieved, ranked by relevance. Such approaches have the advantage of not requiring expensive static or dynamic analysis of the code. However, most of state-of-the-art IR approaches rely on project history, in particular previously fixed bugs and previous versions of the source code. We present a novel approach that directly scores each current file against the given report, thus not requiring past code and reports. The scoring is based on heuristics identified through manual inspection of a small set of bug reports. We compare our approach to five others, using their own five metrics on their own six open source projects. Out of 30 performance indicators, we improve 28. For example, on average we find one or more affected files in the top 10 ranked files for 77% of the bug reports. These results show the applicability of our approach to software projects without history. Tezcan Dilshener, Michel Wermelinger, Yijun Yu 0001 |
MSR | 3 |
| 2016 | Engineering Adaptive Model-Driven User InterfacesabstractSoftware applications that are very large-scale, can encompass hundreds of complex user interfaces (UIs). Such applications are commonly sold as feature-bloated off-the-shelf products to be used by people with variable needs in the required features and layout preferences. Although many UI adaptation approaches were proposed, several gaps and limitations including: extensibility and integration in legacy systems, still need to be addressed in the state-of-the-art adaptive UI development systems. This paper presents Role-Based UI Simplification (RBUIS) as a mechanism for increasing usability through adaptive behavior by providing end-users with a minimal feature-set and an optimal layout, based on the context-of-use. RBUIS uses an interpreted runtime model-driven approach based on the Cedar Architecture, and is supported by the integrated development environment (IDE), Cedar Studio. RBUIS was evaluated by integrating it into OFBiz, an open-source ERP system. The integration method was assessed and measured by establishing and applying technical metrics. Afterwards, a usability study was carried out to evaluate whether UIs simplified with RBUIS show an improvement over their initial counterparts. This study leveraged questionnaires, checking task completion times and output quality, and eye-tracking. The results showed that UIs simplified with RBUIS significantly improve end-user efficiency, effectiveness, and perceived usability. Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001 |
IEEE Trans. Software Eng. | 3 |
| 2015 | Investigating naming convention adherence in Java referencesabstractNaming conventions can help the readability and comprehension of code, and thus the onboarding of new developers. Conventions also provide cues that help developers and tools extract information from identifier names to support software maintenance. Tools exist to automatically check naming conventions but they are often limited to simple checks, e.g. regarding typography. The adherence to more elaborate conventions, such as the use of noun and verbal phrases in names, is not checked. We present Nominal, a naming convention checking library for Java that allows the declarative specification of conventions regarding typography and the use of abbreviations and phrases. To test Nominal, and to investigate the extent to which developers follow conventions, we extract 3.5 million reference - field, formal argument and local variable - name declarations from 60 FLOSS projects and determine their adherence to two well-known Java naming convention guidelines that give developers scope to choose a variety of forms of name, and sometimes offer conflicting advice. We found developers largely follow naming conventions, but adherence to specific conventions varies widely. Simon Butler 0001, Michel Wermelinger, Yijun Yu 0001 |
ICSME | 3 |
| 2015 | A survey of the forms of Java reference namesabstractThe readability of identifiers is a major factor of program comprehension and an aim of naming convention guidelines. Due to their semantic content, identifiers are also used in feature and bug location, among other software maintenance tasks. Looking at how names are used in practice may lead to insights on potential problems for comprehension and for programming support tools that process identifiers. Class and method names are already well represented in the literature. This paper presents an investigation of Java field, formal argument and local variable names, which we collectively call reference names. These names cannot be ignored because they constitute over half the unique names and almost 70% of the name declarations in the corpus investigated. We analysed the forms of 3.5 million reference name declarations in 60 well known Java projects, examining the phrasal structure of names composed of known words and acronyms. The structures found in practice were evaluated against those given in the literature. The use of unknown abbreviations and words, which may pose a problem for program comprehension, was also identified. Based on our observations of the rich diversity of reference names, we suggest issues to be taken into account for future academic research and for improving tools that rely on names as sources of information. Simon Butler 0001, Michel Wermelinger, Yijun Yu 0001 |
ICPC | 3 |
| 2015 | An Architectural Evolution DatasetabstractA good evolution process and a good architecture can greatly support the maintainability of long-lived, large software systems. We present AREVOL, a dataset for the empirical study of architectural evolution. The dataset comprises two popular systems from the same domain and using the same component model, to make comparative studies possible. Besides the original component metadata, AREVOL includes scripts to obtain simplified models that nevertheless support rich studies of architectural evolution, as the authors' previous work has shown. Michel Wermelinger, Yijun Yu 0001 |
MSR | 2 |
| 2015 | An Open Framework for Semantic Code Queries on Heterogeneous RepositoriesabstractTo help developers understand and reuse programs, semantic queries on the source code itself is attractive. Although programs in heterogeneous languages are being controlled for collaborative software development, most queries supported by various source code repositories are based either on the metadata of the repositories, or on indexed identifiers and method signatures. Few provide full support to search for semantic structures that are common across different programming languages. To facilitate the understanding and reuses, in this paper, we propose a novel source code query framework that (1) supports the semantic code queries across different programming languages with a new query language, (2) transforms source code to a unified abstract syntax format and handles heterogeneity at the abstract level, (3) stores source code on a cloud-based NoSQL storage in MangoDB. The efficiency of the framework has been evaluated and confirmed by experiments. Tian Zhang 0001, Minxue Pan, Jizhou Zhao, Yijun Yu 0001, Xuandong Li |
TASE | 4 |
| 2015 | Automated analysis of security requirements through risk-based argumentation
Yijun Yu 0001, Virginia N. L. Franqueira, Thein Than Tun, Roel J. Wieringa, Bashar Nuseibeh |
J. Syst. Softw. | 1 |
| 2015 | The Aftermath of the Missing Flight MH370: What Can Engineers Do? [Point of View]abstractExamines how engineers can work to solve major aircraft disasters, focusing on missing flight MH370. It is not yet known what has really happened to the missing flight MH370; the plane could not be located from radar signals. Its last hourly ping signals to the Inmarsat satellite suggested that the flight headed toward the southern Indian Ocean, which was speculated from the Doppler effect of drifting frequency caused by the signal source moving at high speed. Yijun Yu 0001 |
Proc. IEEE | 1 |
| 2015 | Guest editorial: Special section: Software quality and maintainability
Yiannis Kanellopoulos, Yijun Yu 0001 |
Softw. Qual. J. | 2 |
| 2015 | Requirements-Driven Self-Optimization of Composite Services Using Feedback ControlabstractIn an uncertain and changing environment, a composite service needs to continuously optimize its business process and service selection through runtime adaptation. To achieve the overall satisfaction of stakeholder requirements, quality tradeoffs are needed to adapt the composite service in response to the changing environments. Existing approaches on service selection and composition, however, are mostly based on quality preferences and business processes decisions made statically at the design time. In this paper, we propose a requirements-driven self-optimization approach for composite services. It measures the quality of services (QoS), estimates the earned business value, and tunes the preference ranks through a feedback loop. The detection of unexpected earned business value triggers the proposed self-optimization process systematically. At the process level, a preference-based reasoner configures a requirements goal model according to the tuned preference ranks of QoS requirements, reconfiguring the business process according to its mappings from the goal configurations. At the service level, selection decisions are optimized by utilizing the tuned weights of QoS criteria. We used an experimental study to evaluate the proposed approach. Results indicate that the new approach outperforms both fixed-weighted and floating-weighted service selection approaches with respect to earned business value and adaptation flexibility. Bihuan Chen 0001, Xin Peng 0001, Yijun Yu 0001, Wenyun Zhao |
IEEE Trans. Serv. Comput. | 3 |
| 2014 | Traceability for Adaptive Information Security in the CloudabstractOne of the key challenges in cloud computing is the security of the consumer data stored and processed by cloud machines. When the usage context of a cloud application changes, or when the context is unknown, there is a risk that security policies are violated. To minimize this risk, cloud applications need to be engineered to adapt their security policies to maintain satisfaction of security requirements despite changes in their usage context. We call such adaptation capability Adaptive Information Security. The paper argues that one of the prerequisites to adaptive information security is the use of traceability as a means to understanding the relationship between security requirements and security policies. Using an example, we motivate the need for improving traceability in the development of cloud applications. Armstrong Nhlabatsi, Thein Than Tun, Niamul Khan, Yijun Yu 0001, Arosha K. Bandara, Khaled M. Khan, Bashar Nuseibeh |
IEEE CLOUD | 4 |
| 2014 | Evolving Commitments for Self-Adaptive Socio-technical SystemsabstractSocio-technical systems (STSs) consist of human, hardware and software agents that work in tandem to fulfill stakeholder requirements. A specification for an STS consists of a set of (social) commitments among participating agents that serve as a contract among them. However, by their very nature, STSs are open, dynamic and continuously evolving along with their environments. To ensure that such systems continue to satisfy their requirements, the agents that comprise an STS must continuously adapt their behaviors to take into account risks and opportunities that arise at runtime. This paper presents a decision-theoretic self-adaptation framework that proposes candidate adaptation strategies for participating agents. These strategies are implementable by reconfiguration of plans or even changes in contractual commitments among agents. The adaptation procedure involves negotiating commitment changes and possible compensations to/from creditor agents. To evaluate the proposal, the paper also presents the results of an experimental study with a simulated STS, which confirms that success rates for achieving stakeholder goals and overall trade off utility can be improved significantly by incorporating evolving commitments to support STS adaptation. Xin Peng 0001, Yijun Yu 0001, John Mylopoulos, Wenyun Zhao |
ICECCS | 3 |
| 2014 | Integrating adaptive user interface capabilities in enterprise applicationsabstractMany existing enterprise applications are at a mature stage in their development and are unable to easily benefit from the usability gains offered by adaptive user interfaces (UIs). Therefore, a method is needed for integrating adaptive UI capabilities into these systems without incurring a high cost or significantly disrupting the way they function. This paper presents a method for integrating adaptive UI behavior in enterprise applications based on CEDAR, a model-driven, service-oriented, and tool-supported architecture for devising adaptive enterprise application UIs. The proposed integration method is evaluated with a case study, which includes establishing and applying technical metrics to measure several of the method’s properties using the open-source enterprise application OFBiz as a test-case. The generality and flexibility of the integration method are also evaluated based on an interview and discussions with practitioners about their real-life projects. Pierre A. Akiki, Arosha K. Bandara, Yijun Yu 0001 |
ICSE | 3 |
| 2014 | Self-adaptation through incremental generative model transformations at runtimeabstractA self-adaptive system uses runtime models to adapt its architecture to the changing requirements and contexts. However, there is no one-to-one mapping between the requirements in the problem space and the architectural elements in the solution space. Instead, one refined requirement may crosscut multiple architectural elements, and its realization involves complex behavioral or structural interactions manifested as architectural design decisions. In this paper we propose to combine two kinds of self-adaptations: requirements-driven self-adaptation, which captures requirements as goal models to reason about the best plan within the problem space, and architecture-based self-adaptation, which captures architectural design decisions as decision trees to search for the best design for the desired requirements within the contextualized solution space. Following these adaptations, component-based architecture models are reconfigured using incremental and generative model transformations. Compared with requirements-driven or architecture-based approaches, the case study using an online shopping benchmark shows promise that our approach can further improve the effectiveness of adaptation (e.g. system throughput in this case study) and offer more adaptation flexibility. Bihuan Chen 0001, Xin Peng 0001, Yijun Yu 0001, Bashar Nuseibeh, Wenyun Zhao |
ICSE | 3 |
| 2014 | Adaptive Sharing for Online Social Networks: A Trade-off Between Privacy Risk and Social BenefitabstractOnline social networks such as Facebook allow users to control which friend sees what information, but it can be a laborious process for users to specify every receiver for each piece of information they share. Therefore, users usually group their friends into social circles, and select the most appropriate social circle to share particular information with. However, social circles are not formed for setting privacy policies, and even the most appropriate social circle still cannot adapt to the changes of users' privacy requirements influenced by the changes in context. This problem drives the need for better privacy control which can adaptively filter the members in a selected social circle to satisfy users' requirements while maintaining users' social needs. To enable such adaptive sharing, this paper proposes a utility-based trade-off framework that models users' concerns (i.e. Potential privacy risks) and incentives of sharing (i.e. Potential social benefits), and quantifies users' requirements as a trade-off between these two types of utilities. By balancing these two metrics, our framework suggests a subset of a selected circle that aims to maximise users' overall utility of sharing. Numerical simulation results compare the outcome of three sharing strategies in randomly changing contexts. Mu Yang, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh |
TrustCom | 2 |
| 2014 | Uncertainty handling in goal-driven self-optimization - Limiting the negative effect on adaptation
Bihuan Chen 0001, Xin Peng 0001, Yijun Yu 0001, Wenyun Zhao |
J. Syst. Softw. | 3 |
| 2013 | Issues in representing domain-specific concerns in model-driven engineeringabstractThe integration of domain-specific concepts in a model-driven engineering (MDE) approach raises a number of interesting research questions. There are two possibilities to represent these concepts. The first one focuses on models that contain domain-specific concepts only, i.e. domain-specific modelling languages (DSML). The second one advocates the integration of domain-specific concepts in general-purpose models, using what we will refer to in this paper as domain-specific modelling annotation languages (DSMAL). In this position paper, we argue that each approach is particularly suited for specific activities and specific actors, and show how they can be developed and used together. We also highlight the challenges created by the use of two representations, such as the evaluation of models OCL constraints and the synchronisation between the two representations. As an illustration, we present rbacUML, our approach for integrating role-based access control (RBAC) concepts into an MDE approach. Lionel Montrieux, Yijun Yu 0001, Michel Wermelinger, Zhenjiang Hu 0002 |
MiSE | 2 |
| 2013 | INVocD: identifier name vocabulary datasetabstractINVocD is a database of the identifier name declarations and vocabulary found in 60 FLOSS Java projects where the source code structure is recorded and the identifier name vocabulary is made directly available, offering advantages for identifier name research over conventional source code models. The database has been used to support a range of research projects from identifier name analysis to concept location, and provides many opportunities to researchers. INVocD may be downloaded from http://oro.open.ac.uk/36992. Simon Butler 0001, Michel Wermelinger, Yijun Yu 0001, Helen Sharp |
MSR | 3 |
| 2013 | Requirements-driven adaptive digital forensicsabstractWe propose the use of forensic requirements to drive the automation of a digital forensics process. We augment traditional reactive digital forensics processes with proactive evidence collection and analysis activities, and provide immediate investigative suggestions before an investigation starts. These activities adapt depending on suspicious events, which in turn might require the collection and analysis of additional evidence. The reactive activities of a traditional digital forensics process are also adapted depending on the investigation findings. Liliana Pasquale, Yijun Yu 0001, Mazeiar Salehie, Luca Cavallaro, Thein Than Tun, Bashar Nuseibeh |
RE | 2 |
| 2013 | Requirements-Driven Self-Repairing against Environmental FailuresabstractSelf-repairing approaches have been proposed to alleviate the runtime requirements satisfaction problem by switching to appropriate alternative solutions according to the feedback monitored. However, little has been done formally on analyzing the relations between specific environmental failures and corresponding repairing decisions, making it a challenge to derive a set of alternative solutions to withstand possible environmental failures at runtime. To address these challenges, we propose a requirements-driven self-repairing approach against environmental failures, which combines both development-time and runtime techniques. At the development phase, in a stepwise manner, we formally analyze the issue of self-repairing against environmental failures with the support of the model checking technique, and then design a sufficient and necessary set of alternative solutions to withstand possible environmental failures. The runtime part is a runtime self-repairing mechanism that monitors the operating environment for unsatisfiable situations, and makes self-repairing decisions among alternative solutions in response to the detected environmental failures. Rui-Zhi Dong, Xin Peng 0001, Yijun Yu 0001, Wenyun Zhao |
TASE | 3 |
| 2013 | Specifying software features for composition: A tool-supported approach
Thein Than Tun, Robin C. Laney, Yijun Yu 0001, Bashar Nuseibeh |
Comput. Networks | 3 |
| 2013 | Resolving vulnerability identification errors using security requirements on business process modelsabstractPurpose In any information security risk assessment, vulnerabilities are usually identified by information‐gathering techniques. However, vulnerability identification errors – wrongly identified or unidentified vulnerabilities – can occur as uncertain data are used. Furthermore, businesses' security needs are not considered sufficiently. Hence, security functions may not protect business assets sufficiently and cost‐effectively. This paper aims to resolve vulnerability errors by analysing the security requirements of information assets in business process models. Design/methodology/approach Business process models have been selected for use, because there is a close relationship between business process objectives and risks. Security functions are evaluated in terms of the information flow of business processes regarding their security requirements. The claim that vulnerability errors can be resolved was validated by comparing the results of a current risk assessment approach with the proposed approach. The comparison is conducted both at three entities of an insurance company, as well as through a controlled experiment within a survey among security professionals. Findings Vulnerability identification errors can be resolved by explicitly evaluating security requirements in the course of business; this is not considered in current assessment methods. Originality/value It is shown that vulnerability identification errors occur in practice. With the explicit evaluation of security requirements, identification errors can be resolved. Risk assessment methods should consider the explicit evaluation of security requirements. Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh |
Inf. Manag. Comput. Secur. | 3 |
| 2013 | Improving feature location using structural similarity and iterative graph mapping
Xin Peng 0001, Zhenchang Xing, Yijun Yu 0001, Wenyun Zhao |
J. Syst. Softw. | 4 |
| 2012 | Maintaining invariant traceability through bidirectional transformationsabstractFollowing the “convention over configuration” paradigm, model-driven development (MDD) generates code to implement the “default” behaviour that has been specified by a template separate from the input model, reducing the decision effort of developers. For flexibility, users of MDD are allowed to customise the model and the generated code in parallel. A synchronisation of changed model or code is maintained by reflecting them on the other end of the code generation, as long as the traceability is unchanged. However, such invariant traceability between corresponding model and code elements can be violated either when (a) users of MDD protect custom changes from the generated code, or when (b) developers of MDD change the template for generating the default behaviour. A mismatch between user and template code is inevitable as they evolve for their own purposes. In this paper, we propose a two-layered invariant traceability framework that reduces the number of mismatches through bidirectional transformations. On top of existing vertical (model↔code) synchronisations between a model and the template code, a horizontal (code↔code) synchronisation between user and template code is supported, aligning the changes in both directions. Our blinkit tool is evaluated using the data set available from the CVS repositories of a MDD project: Eclipse MDT/GMF. Yijun Yu 0001, Zhenjiang Hu 0002, Soichiro Hidaka, Hiroyuki Kato, Lionel Montrieux |
ICSE | 1 |
| 2012 | Stateful requirements monitoring for self-repairing socio-technical systemsabstractSocio-technical systems consist of human, hardware and software components that work in tandem to fulfill stakeholder requirements. By their very nature, such systems operate under uncertainty as components fail, humans act in unpredictable ways, and the environment of the system changes. Self-repair refers to the ability of such systems to restore fulfillment of their requirements by relying on monitoring, reasoning, and diagnosing on the current state of individual requirements. Self-repair is complicated by the multi-agent nature of socio-technical systems, which demands that requirements monitoring and self-repair be done in a decentralized fashion. In this paper, we propose a stateful requirements monitoring approach by maintaining an instance of a state machine for each requirement, represented as a goal, with runtime monitoring and compensation capabilities. By managing the interactions between the state machines, our approach supports hierarchical goal reasoning in both upward and downward directions. We have implemented a customizable Java framework that supports experimentation by simulating a socio-technical system. Results from our experiments suggest effective and precise support for a wide range of self-repairing decisions in a socio-technical setting. Lingxiao Fu, Xin Peng 0001, Yijun Yu 0001, John Mylopoulos, Wenyun Zhao |
RE | 3 |
| 2012 | Privacy arguments: Analysing selective disclosure requirements for mobile applicationsabstractPrivacy requirements for mobile applications offer a distinct set of challenges for requirements engineering. First, they are highly dynamic, changing over time and locations, and across the different roles of agents involved and the kinds of information that may be disclosed. Second, although some general privacy requirements can be elicited a priori, users often refine them at runtime as they interact with the system and its environment. Selectively disclosing information to appropriate agents is therefore a key privacy management challenge, requiring carefully formulated privacy requirements amenable to systematic reasoning. In this paper, we introduce privacy arguments as a means of analysing privacy requirements in general and selective disclosure requirements (that are both content- and context-sensitive) in particular. Privacy arguments allow individual users to express personal preferences, which are then used to reason about privacy for each user under different contexts. At runtime, these arguments provide a way to reason about requirements satisfaction and diagnosis. Our proposed approach is demonstrated and evaluated using the privacy requirements of BuddyTracker, a mobile application we developed as part of our overall research programme. Thein Than Tun, Arosha K. Bandara, Blaine A. Price, Yijun Yu 0001, Charles B. Haley, Inah Omoronyia, Bashar Nuseibeh |
RE | 4 |
| 2012 | Self-tuning of software systems through dynamic quality tradeoff and value-based feedback control loop
Xin Peng 0001, Bihuan Chen 0001, Yijun Yu 0001, Wenyun Zhao |
J. Syst. Softw. | 3 |
| 2012 | Analysing monitoring and switching problems for adaptive systems
Mohammed Salifu, Yijun Yu 0001, Arosha K. Bandara, Bashar Nuseibeh |
J. Syst. Softw. | 2 |
| 2011 | Improving the Tokenisation of Identifier Names
Simon Butler 0001, Michel Wermelinger, Yijun Yu 0001, Helen Sharp |
ECOOP | 3 |
| 2011 | Iterative context-aware feature locationabstractLocating the program element(s) relevant to a particular feature is an important step in efficient maintenance of a software system. The existing feature location techniques analyze each feature independently and perform a one-time analysis after being provided an initial input. As a result, these techniques are sensitive to the quality of the input, and they tend to miss the nonlocal interactions among features. In this paper, we propose to address the proceeding two issues in feature location using an iterative context-aware approach. The underlying intuition is that the features are not independent of each other, and the structure of source code resembles the structure of features. The distinguishing characteristics of the proposed approach are: 1) it takes into account the structural similarity between a feature and a program element to determine their relevance; 2) it employs an iterative process to propagate the relevance of the established mappings between a feature and a program element to the neighboring features and program elements. Our initial evaluation suggests the proposed approach is more robust and can significantly increase the recall of feature location with a slight decrease in precision. Xin Peng 0001, Zhenchang Xing, Yijun Yu 0001, Wenyun Zhao |
ICSE | 4 |
| 2011 | Mining java class naming conventionsabstractClass names represent the concepts implemented in object-oriented source code and are key elements in program comprehension and, thus, software maintenance. Programming conventions often state that class names should be noun-phrases, but there is little further guidance for developers on the composition of class names. Other researchers have observed that the majority of Java class identifier names are composed of one or more nouns preceded, optionally, by one or more adjectives. However, no detailed analysis of class identifier name structure has been undertaken that could be leveraged to support program comprehension activities. We investigate the lexical and syntactic composition of Java class identifier names in two ways. Firstly, as others have done for C function and Java method names, we identify conventional patterns found in the use of parts of speech. Secondly, we identify the origin of words used in class names within the name of any super class and implemented interfaces to identify patterns of class name construction related to inheritance. Through the analysis of 120,000 unique class names found in 60 open source projects we identify both common and project specific class naming conventions. We apply this knowledge in a case study of the mind-mapping tool Freemind to investigate whether class names that follow unconventional naming schemes are candidates for refactoring either a name refactoring that conforms to established naming conventions within the code base, or refactoring of the class that results in conventionally named classes. Simon Butler 0001, Michel Wermelinger, Yijun Yu 0001, Helen Sharp |
ICSM | 3 |
| 2011 | Maleku: An evolutionary visual software analysis tool for providing insights into software evolutionabstractSoftware maintenance is a complex process that requires the understanding and comprehension of software project details. It involves the understanding of the evolution of the software project, hundreds of software components and the relationships among software items in the form of inheritance, interface implementation, coupling and cohesion. Consequently, the aim of evolutionary visual software analytics is to support software project managers and developers during software maintenance. It takes into account the mining of evolutionary data, the subsequent analysis of the results produced by the mining process for producing evolution facts, the use of visualizations supported by interaction techniques and the active participation of users. Hence, this paper proposes an evolutionary visual software analytics tool for the exploration and comparison of project structural, interface implementation and class hierarchy data, and the correlation of structural data with metrics, as well as socio-technical relationships. Its main contribution is a tool that automatically retrieves evolutionary software facts and represent them using a scalable visualization design. Antonio González 0006, Roberto Therón, Francisco J. García-Peñalvo, Michel Wermelinger, Yijun Yu 0001 |
ICSM | 5 |
| 2011 | Specifying and detecting meaningful changes in programsabstractSoftware developers are often interested in particular changes in programs that are relevant to their current tasks: not all changes to evolving software are equally important. However, most existing differencing tools, such as diff, notify developers of more changes than they wish to see. In this paper, we propose a technique to specify and automatically detect only those changes in programs deemed meaningful, or relevant, to a particular development task. Using four elementary annotations on the grammar of any programming language, namely Ignore, Order, Prefer and Scope, developers can specify, with limited effort, the type of change they wish to detect. Our algorithms use these annotations to transform the input programs into a normalised form, and to remove clones across different normalised programs in order to detect non-trivial and relevant differences. We evaluate our tool on a benchmark of programs to demonstrate its improved precision compared to other differencing approaches. Yijun Yu 0001, Thein Than Tun, Bashar Nuseibeh |
ASE | 1 |
| 2011 | Are your sites down? Requirements-driven self-tuning for the survivability of Web systemsabstractRunning in a highly uncertain and greatly complex environment, Web systems cannot always provide full set of services with optimal quality, especially when work loads are high or subsystem failures are frequent. Hence, it is significant to continuously maintain a high satisfaction level of survivability, hereafter survivability assurance, while relaxing or sacrificing certain quality or functional requirements that are not crucial to the survival of the entire system. After giving a value-based interpretation to survivability assurance to facilitate a quantitative analysis, we propose a requirements-driven self-tuning method for the survivability assurance of Web systems. Maintaining an enriched and live goal model, our method adapts to runtime tradeoff decisions made by our PID (proportional-integral-derivative) controller and goal-oriented reasoner for both quality and functional requirements. The goal-based configuration plans produced by the reasoner is carried out on the live goal model, and then mapped into system architectural configurations. Experiments on an online shopping system are conducted to validate the effectiveness of the proposed method. Bihuan Chen 0001, Xin Peng 0001, Yijun Yu 0001, Wenyun Zhao |
RE | 3 |
| 2011 | Risk and argument: A risk-based argumentation method for practical securityabstractWhen showing that a software system meets certain security requirements, it is often necessary to work with formal and informal descriptions of the system behavior, vulnerabilities, and threats from potential attackers. In earlier work, Haley et al. [1] showed structured argumentation could deal with such mixed descriptions. However, incomplete and uncertain information, and limited resources force practitioners to settle for good-enough security. To deal with these conditions of practice, we extend the method of Haley et al. with risk assessment. The proposed method, RISA (RIsk assessment in Security Argumentation), uses public catalogs of security expertise to support the risk assessment, and to guide the security argumentation in identifying rebuttals and mitigations for security requirements satisfaction. We illustrate RISA with a realistic example of PIN Entry Device. Virginia N. L. Franqueira, Thein Than Tun, Yijun Yu 0001, Roel J. Wieringa, Bashar Nuseibeh |
RE | 3 |
| 2011 | OpenArgue: Supporting argumentation to evolve secure software systemsabstractWhen software systems are verified against security requirements, formal and informal arguments provide a structure for organizing the software artifacts. Our recent work on the evolution of security-critical software systems demonstrates that our argumentation technique is useful in limiting the scope of change and in identifying changes to security properties. In support of this work, we have developed OpenArgue, a tool for syntax checking, visualizing, formalizing, and reasoning about incremental arguments. OpenArgue has been integrated with requirements engineering tools for Problem Frames and i∗, and applied to an Air Traffic Management (ATM) case study. Yijun Yu 0001, Thein Than Tun, Alessandra Tedeschi, Virginia N. L. Franqueira, Bashar Nuseibeh |
RE | 1 |
| 2011 | Problem Analysis of Traditional IT-Security Risk Assessment Methods - An Experience Report from the Insurance and Auditing Domain
Stefan Taubenberger, Jan Jürjens, Yijun Yu 0001, Bashar Nuseibeh |
SEC | 3 |
| 2011 | Tool support for UML-based specification and verification of role-based access control propertiesabstractIt has been argued that security perspectives, of which access control is one, should be taken into account as early as possible in the software development process. Towards that goal, we present in this paper a tool supporting our modelling approach to specify and verify access control in accordance to the NIST standard Role-Based Access Control (RBAC). RBAC is centred on mapping users to their roles in an organisation, to make access control permissions easier to set and maintain. Our modelling approach uses only standard UML mechanisms, like metamodels and OCL constraints, and improves on existing approaches in various ways: designers don't have to learn new languages or adopt new tools or methodologies; user-role and role-permission assignments can be specified separately to be reused across models; access control is specified over class and activity diagrams, including 'anti-scenarios'; access control is automatically verified. The tool is built on top of an existing modelling IDE and allows for automatic verification of models according to our RBAC modelling approach, while providing users with the ability to easily identify and correct errors in the model when they are detected. Lionel Montrieux, Michel Wermelinger, Yijun Yu 0001 |
SIGSOFT FSE | 3 |
| 2011 | Run-Time Security Traceability for Evolving SystemsabstractSecurity-critical systems are challenging to design and implement correctly and securely. A lot of vulnerabilities have been found in current software systems both at the specification and the implementation levels. This paper presents a comprehensive approach for model-based security assurance. Initially, it allows one to formally verify the design models against high-level security requirements such as secrecy and authentication on the specification level, and helps to ensure that their implementation adheres to these properties, if they express a system's run-time behaviour. As such, it provides a traceability link from the design model to its implementation by which the actual system can then be verified against the model while it executes. This part of our approach relies on a technique also known as run-time verification. The extra effort for it is small as most of the computation is automated; however, additional resources at run-time may be required. If during run-time verification a security weakness is uncovered, it can be removed using aspect-oriented security hardening transformations. Therefore, this approach also supports the evolution of software since the traceability mapping is updated when refactoring operations are regressively performed using our tool-supported refactoring technique. The proposed method has been applied to the Java-based implementation Jessie of the Internet security protocol SSL, in which a security weakness was detected and fixed using our approach. We also explain how the traceability link can be transformed to the official implementation of the Java secure sockets extension that was recently made open source by Sun. Andreas Bauer 0002, Jan Jürjens, Yijun Yu 0001 |
Comput. J. | 3 |
| 2011 | Assessing architectural evolution: a case study
Michel Wermelinger, Yijun Yu 0001, Angela Lozano, Andrea Capiluppi |
Empir. Softw. Eng. | 2 |
| 2011 | Analyzing evolution of variability in a software product line: From contexts and requirements to features
Xin Peng 0001, Yijun Yu 0001, Wenyun Zhao |
Inf. Softw. Technol. | 2 |
| 2010 | Variability Modeling for Product Line Viewpoints IntegrationabstractModern software product line development uses viewpoints to capture the needs of various stakeholders without resorting to a single complex model. Comparing and integrating different viewpoints help to gain insights into the product line and to derive products. Recent research has proposed conflict resolution rules for handling variability in the integration process. However, one benefit viewpoints bring is to tolerate inconsistency until the rationales about variability are better understood. In this paper, we propose a method for modeling variability when product line viewpoints are consolidated. Our method takes advantage of a lattice ordering to support late binding of variability and stakeholder traceability. We apply our method to viewpoints derived from the mobile phone domain, and show how delayed commitment can support product line evolution and product derivation. Nan Niu, Juha Savolainen, Yijun Yu 0001 |
COMPSAC | 3 |
| 2010 | Tool support for code generation from a UMLsec propertyabstractS.357-358 Lionel Montrieux, Jan Jürjens, Charles B. Haley, Yijun Yu 0001, Pierre-Yves Schobbens, Hubert Toussaint |
ASE | 4 |
| 2010 | Self-Tuning of Software Systems Through Goal-based Feedback Loop ControlabstractQuality requirements of a software system cannot be optimally met, especially when it is running in an uncertain and changing environment. In principle, a controller at runtime can monitor the change impact on quality requirements of the system, update the expectations and priorities from the environment, and take reasonable actions to improve the overall satisfaction. In practice, however, existing controllers are mostly designed for tuning low-level performance indicators rather than high-level requirements. By linking the overall satisfaction to a business value indicator as feedback, we propose a control theoretic self-tuning method that can dynamically adjust the tradeoff decisions among different quality requirements. A preference-based reasoning algorithm is involved to configure hard goals accordingly to guide the following architecture reconfiguration. Xin Peng 0001, Bihuan Chen 0001, Yijun Yu 0001, Wenyun Zhao |
RE | 3 |
| 2009 | Towards a Problem Oriented Engineering Theory of Pattern-Oriented Analysis and DesignabstractIn this position paper, we present an initial Problem Oriented Engineering foundation for a small part of Pattern-Oriented Analysis and Design (POAD). We argue for the interpretation of software design patterns as instructions for transforming quality requirements into an architecture and a 'stress test'; and show, incidentally, how to reuse an existing software component and its justification in a new development. Jerry Overton, Jon G. Hall, Lucia Rapanotti, Yijun Yu 0001 |
COMPSAC (2) | 4 |
| 2009 | AVT Vector: A Quantitative Security Requirements Evaluation Approach Based on Assets, Vulnerabilities and Trustworthiness of EnvironmentabstractSecurity requirements analysis is gaining growing attention as new vulnerabilities and threats are emerging on daily basis, the systematic evaluation of security requirements is of utmost importance among the various decisions to be made related to security. This short contribution proposes using a 3-dimensional vector for quantitative evaluation of security requirements, which takes into account the importance of assets to be protected, the vulnerability of the system and the trustworthiness of environment. Lin Liu 0001, Yijun Yu 0001, Zhi Jin 0001 |
RE | 3 |
| 2009 | Are Your Lights Off? Using Problem Frames to Diagnose System FailuresabstractThis paper reports on our experience of investigating the role of software systems in the power blackout that affected parts of the United States and Canada on 14 August 2003. Based on a detailed study of the official report on the blackout, our investigation has aimed to bring out requirements engineering lessons that can inform development practices for dependable software systems. Since the causes of failures are typically rooted in the complex structures of software systems and their world contexts, we have deployed and evaluated a framework that looks beyond the scope of software and into its physical context, directing attention to places in the system structures where failures are likely to occur. We report that (i) Problem Frames were effective in diagnosing the causes of failures and documenting the causes in a schematic and accessible way, and (ii) errors in addressing the concerns of biddable domains, model building problems, and monitoring problems had contributed to the blackout. Thein Than Tun, Michael Jackson 0001, Robin C. Laney, Bashar Nuseibeh, Yijun Yu 0001 |
RE | 5 |
| 2009 | Early Identification of Problem Interactions: A Tool-Supported Approach
Thein Than Tun, Yijun Yu 0001, Robin C. Laney, Bashar Nuseibeh |
REFSQ | 2 |
| 2009 | Monitoring and diagnosing software requirements
Yiqiao Wang 0001, Sheila A. McIlraith, Yijun Yu 0001, John Mylopoulos |
Autom. Softw. Eng. | 3 |
| 2008 | Automated Analysis of Permission-Based Security Using UMLsec
Jan Jürjens, Jörg Schreck, Yijun Yu 0001 |
FASE | 3 |
| 2008 | Design principles in architectural evolution: A case studyabstractWe wish to investigate how structural design principles are used in practice, in order to assess the utility and relevance of such principles to the maintenance of large, complex, long-lived, successful systems. In this paper we take Eclipse as the case study and check whether its architecture follows, throughout multiple releases, some principles proposed in the literature. Michel Wermelinger, Yijun Yu 0001, Angela Lozano |
ICSM | 2 |
| 2008 | Traceability for the maintenance of secure softwareabstractTraceability links among different software engineering artifacts make explicit how a software system was implemented to accommodate its requirements. For secure and dependable software system development, one must ensure the linked entities are truly traceable to each other and the links are updated to reflect true traceability among changed entities. However, traditional traceability relationships link recovery techniques are not accurate enough. To address this problem, we propose a traceability technique based on refactoring, which is then continuously integrated with other software maintenance activities. Applying our traceability technique to the proven SSL protocol design, we found a significant vulnerability bug in its open-source implementation. The results also demonstrate the level of accuracy and change resilience of our technique that enable reuse of the traceability-related analysis on different implementations. Yijun Yu 0001, Jan Jürjens, John Mylopoulos |
ICSM | 1 |
| 2008 | From Goals to High-Variability Software Design
Yijun Yu 0001, Alexei Lapouchnian, Sotirios Liaskos, John Mylopoulos, Julio César Sampaio do Prado Leite |
ISMIS | 1 |
| 2008 | Tools for Traceability in Secure Software DevelopmentabstractFor secure and dependable software system development, one must ensure that security requirements are truly traceable to design and implementation, and the traceability links can be updated accordingly to changed entities. To address this, we present a suite of security requirements analysis and traceability assurance tools and demonstrate how they are effectively integrated. Yijun Yu 0001, Jan Jürjens, Jörg Schreck |
ASE | 1 |
| 2008 | Analyzing the evolution of eclipse pluginsabstractEclipse is a good example of a modern component-based complex system that is designed for long-term evolution, due to its architecture of reusable and extensible components. This paper presents our preliminary results about the evolution of Eclipse's architecture, based on a lightweight and scalable analysis of the metadata in Eclipse's sources. We find that the development of Eclipse follows a systematic process: most architectural changes take place in milestones, and maintenance releases only make exceptional changes to component dependencies. We also found a stable architectural core that remains since the first release. Michel Wermelinger, Yijun Yu 0001 |
MSR | 2 |
| 2008 | Supporting Requirements Model Evolution throughout the System Life-CycleabstractRequirements models are essential not just during system implementation, but also to manage system changes post-implementation. Such models should be supported by a requirements model management framework that allows users to create, manage and evolve models of domains, requirements, code and other design-time artifacts along with traceability links between their elements. We propose a comprehensive framework which delineates the operations and elements necessary, and then describe a tool implementation which supports versioning goal models. Neil A. Ernst, John Mylopoulos, Yijun Yu 0001, Tien Nguyen |
RE | 3 |
| 2007 | Requirements-Driven Design and Configuration Management of Business Processes
Alexei Lapouchnian, Yijun Yu 0001, John Mylopoulos |
BPM | 2 |
| 2007 | Comparing Web Services with other Software ComponentsabstractSoftware metrics are vital for the management of software development, especially when a new technology is being adopted and established practices have yet to emerge. As a kind of software components, Web service technology has flourished and attracted a flurry of research activities. Despite the vast amount of research on mechanisms of Web services, there have been little investigations of the overall nature of existing Web services from a software component point of view. This paper is the first attempt to compare Web services with other software components in terms of established metrics in software engineering, including object oriented metrics and interface metrics. In this study we conclude that there are statistical differences between the interface, variable name and other OO metrics when one compares a large sample of Web services with typical OO systems. The distributions obtained give insight into the typical characteristics of Web services and can be used to identify candidates for wrapping into Web services. Yijun Yu 0001, Jianguo Lu, Juan Fernández-Ramil, Phil Yuan |
ICWS | 1 |
| 2007 | Tools for model-based security engineering: models vs. codeabstractWe present tools to support model-based security engineering at both the model and the code level. In the approach supported by these tools, one firstly specifies the security-critical part of the system (e.g. a crypto protocol) using the UML security extension UMLsec. The models are automatically verified for security properties using automated theorem provers. These are implemented within a framework that supports implementing verification routines, based on XMI output of the diagrams from UML CASE tools. Advanced users can use this open-source framework to implement verification routines for the constraints of self-defined security requirement Jan Jürjens, Yijun Yu 0001 |
ASE | 2 |
| 2007 | An automated approach to monitoring and diagnosing requirementsabstractMonitoring the satisfaction of software requirements and diagnosing what went wrong in case of failure is a hard problem that has received little attention in the Software and Requirement Engineering literature. To address this problem, we propose a framework adapted from artificial intelligence theories of action and diagnosis. Specifically, the framework monitors the satisfaction of software requirements and generates log data at a level of granularity that can be tuned adaptively at runtime depending on monitored feedback. When errors are found, the framework diagnoses the denial of the requirements and identifies problematic components. To support diagnostic reasoning, we transform the diagnostic problem into apropositional satisfiability (SAT) problem that can be solved by existing SAT solvers. We preprocess log data into a compact propositional encoding that better scales with problem size. The proposed theoretical framework has been implemented as a diagnosing component that will return sound and complete diagnoses accounting for observed aberrant system behaviors. Our solution is illustrated with two medium-sized publicly available case studies: a Web-based email client and an ATM simulation. Our experimental results demonstrate the feasibility of scaling our approach to medium-size software systems Yiqiao Wang 0001, Sheila A. McIlraith, Yijun Yu 0001, John Mylopoulos |
ASE | 3 |
| 2007 | Specifying Monitoring and Switching Problems in ContextabstractContext-aware applications monitor changes in their operating environment and switch their behaviour to keep satisfying their requirements. Therefore, they must be equipped with the capability to detect variations in their operating context and to switch behaviour in response to such variations. However, specifying monitoring and switching in such applications can be difficult due to their dependence on varying contextual properties which need to be made explicit. In this paper, we present a problem- oriented approach to represent and reason about contextual variability and assess its impact on requirements; to elicit and specif' concerns facing monitors and switchers, such as initialisation and interference; and to specify monitoring and switching behaviours that can detect changes and adapt in response. We illustrate our approach by applying it to a published case study. Mohammed Salifu, Yijun Yu 0001, Bashar Nuseibeh |
RE | 2 |
| 2007 | Tracing and Validating Goal AspectsabstractAspects promote a clear separation of concerns so that tangled and scattered concerns are modularized throughout software development. We propose a framework to trace aspects identified during goal-oriented requirements analysis to code and testing. Two types of checks are performed to validate the resulting system in light of stakeholders' crosscutting concerns. One ensures that systems with and without aspects have the same functionality defined by the hard goals. The other checks whether the weaved system with aspects indeed improves system qualities in terms of the degree of softgoal satisfaction. We demonstrate the approach using an open-source e-commerce platform. Yijun Yu 0001, Nan Niu, Bruno González-Baixauli, William Candillon, John Mylopoulos, Steve M. Easterbrook, Julio César Sampaio do Prado Leite, Gilles Vanwormhoudt |
RE | 1 |
| 2007 | Web Service Composition: A Reality Check
Jianguo Lu, Yijun Yu 0001, Debashis Roy, Deepa Saha |
WISE | 2 |
| 2006 | On Goal-based Variability Acquisition and AnalysisabstractWe introduce a variability-intensive approach to goal decomposition that is tailored to support requirements identification for highly customizable software. The approach is based on the semantic characterization of OR-decompositions of goals. We first show that each high-level goal can be associated with a set of concerns, in response to which, alternative refinements of the goal can be introduced. A text corpus relevant to the domain of discourse can be used to derive such variability concerns that are specific to the problem. In parallel, contextual facts that can vary while a goal is being fulfilled are modeled. Then, a high-variability goal model is constructed aiming at responding to the predefined variability concerns completely, while contextual factors are used to test whether it addresses all realistic background circumstances. We apply our approach in a study from the geriatric health care domain Sotirios Liaskos, Alexei Lapouchnian, Yijun Yu 0001, Eric S. K. Yu, John Mylopoulos |
RE | 3 |
| 2005 | Quality-Based Software Reuse
Julio César Sampaio do Prado Leite, Yijun Yu 0001, Lin Liu 0001, Eric S. K. Yu, John Mylopoulos |
CAiSE | 2 |
| 2005 | Improving the Build Architecture of Legacy C/C++ Software Systems
Homayoun Dayani-Fard, Yijun Yu 0001, John Mylopoulos, Periklis Andritsos |
FASE | 2 |
| 2005 | Reducing Build Time through Precompilations for Evolving Large SoftwareabstractLarge-scale legacy programs take long time to compile, thereby hampering productivity. This paper presents algorithms that reduce compilation time by analyzing syntactic dependencies in fine-grain program units, and by removing redundancies as well as false dependencies. These algorithms are combined with parallel compilation techniques (compiler farms, compiler caches), to further reduce build time. We demonstrate through experiments their effectiveness in achieving significant speedup for both fresh and incremental builds. Yijun Yu 0001, Homayoun Dayani-Fard, John Mylopoulos, Periklis Andritsos |
ICSM | 1 |
| 2005 | Configuring Common Personal Software: a Requirements-Driven ApproachabstractWe investigate the personalization capabilities of common personal software systems. We use a typical e-mail client as an example of such a system, and examine the configuration screens it offers to its users. We discover that each configuration value reflects each of the ways with which the user goals can be satisfied. Thus, we construct a goal model in which alternative ways for satisfying high level goals are matched with alternative system configurations. This way, automatic configuration of the system by reasoning about the overlaying goal model can be achieved. We find that the vast majority of the configuration options that refer to system functionality can be configured using this method, facilitating thereby the personalization tasks for users with no technical background, and ensuring, at the same time, consistency and meaningfulness in the configuration result. Sotirios Liaskos, Alexei Lapouchnian, Yiqiao Wang 0001, Yijun Yu 0001, Steve M. Easterbrook |
RE | 4 |
| 2005 | Reverse Engineering Goal Models from Legacy CodeabstractA reverse engineering process aims at reconstructing high-level abstractions from source code. This paper presents a novel reverse engineering methodology for recovering stakeholder goal models from both structured and unstructured legacy code. The methodology consists of the following major steps: 1) Refactoring source code by extracting methods based on comments; 2) Converting the refactored code into an abstract structured program through statechart refactoring and hammock graph construction; 3) Extracting a goal model from the structured program's abstract syntax tree; 4) Identifying nonfunctional requirements and derive soft goals based on the traceability between the code and the goal model. To illustrate this requirements recovery process, we refactor stakeholder goal models from two legacy software code bases: an unstructured Web-based email in PHP (SquirrelMail) and a structured email client system in Java (Columba). Yijun Yu 0001, Yiqiao Wang 0001, John Mylopoulos, Sotirios Liaskos, Alexei Lapouchnian, Julio César Sampaio do Prado Leite |
RE | 1 |
| 2005 | Making XML document markup internationalabstractIn name and in practice, the World-Wide Web (hereafter Web) is used around the World beyond English-speaking areas. This creates a tremendous need to internationalize standard terminology used in the technologies that make the Web possible. Existing efforts on XML internationalization (i18n) and localization (i10n) have focused on the content of XML documents instead of the terms used in markup (annotations) such as elements and attributes. The SGML standard ISO 8879 supports the use of Unicode (ISO 10646) throughout a document, including markups. However, most elements and attributes of XML documents are still defined in English, thereby limiting their use among non-English speakers. This paper presents an XSLT-based method that can completely localize the markup of XML documents into different natural languages. We also describe how the proposed technique can be applied to translation problems in programming (e.g. C and Java) or documentation (e.g. LATEX or other formatting languages) so that a program or a document can be converted to and from an XML format. Copyright © 2004 John Wiley & Sons, Ltd. Yijun Yu 0001, Jianguo Lu, John Mylopoulos, Weiwei Sun 0008, Jing-Hao Xue, Erik H. D'Hollander |
Softw. Pract. Exp. | 1 |
| 2004 | Non-Uniform Dependences Partitioned by Recurrence ChainsabstractNonuniform distance loop dependences are a known obstacle to find parallel iterations. To find the outermost loop parallelism in these "irregular" loops, a novel method is presented based on recurrence chains. The scheme organizes nonuniformly dependent iterations into lexicographically ordered monotonic chains. While the initial and final iterations of monotonic chains form two parallel sets, the remaining iterations form an intermediate set that can be partitioned further. When there is only one pair of coupled array references, the nonuniform dependences are represented by a single recurrence equation. In that case, the chains in the intermediate set do not bifurcate and each can be executed as a WHILE loop. The independent and the initial iterations of monotonic dependence chains constitute the outermost parallelism. The proposed approach compares favorably with other treatments of nonuniform dependences in the literature. When there are multiple recurrence equations, a dataflow parallel execution can be scheduled using the technique to find maximum loop parallelism. Yijun Yu 0001, Erik H. D'Hollander |
ICPP | 1 |
| 2004 | Performance Visualizations using XML RepresentationsabstractThe intermediate representation (IR) forms the information exchanged among different passes of program compilation. The intermediate format proposed for extensibility and persistence is written in XML. In this way, the program transformations that were internal to the compiler become visible. The hierarchical structure of XML makes a natural representation for the abstract syntax tree (AST). A compiler can parse the program source into an IR, then output it as an XML document. Separated by orthogonal namespaces, other IRs are also presented in the same XML document, gathering program information such as dependence vectors, transforming matrices, iteration spaces dependence graphs and cache reuse distances. This XML document can be exchanged between the compiler and program visualizers for parallelism and locality. Yijun Yu 0001, Kristof Beyls, Erik H. D'Hollander |
IV | 1 |
| 2004 | From Goals to Aspects: Discovering Aspects from Requirements Goal Models
Yijun Yu 0001, Julio César Sampaio do Prado Leite, John Mylopoulos |
RE | 1 |
| 2003 | A Cost-Efficient Scheduling Algorithm of On-Demand Broadcasts
Weiwei Sun 0008, Weibin Shi, Baile Shi, Yijun Yu 0001 |
Wirel. Networks | 4 |
| 2001 | Visualizing the Impact of the Cache on Program ExecutionabstractThe global cache misses ratio of a program does not reveal the time distribution of the memory reference patterns in detail. On the other hand, cache visualization is hampered by the huge amount of memory references to display. Therefore, many visualizers focus on a snapshot of the cache content, instead of viewing all memory transactions. A cache visualizer is introduced which presents the integral cache behavior of a program in several complementary views: the density view of the cache misses shows the hot spots of the program; the reuse distances view shows the data locality and its effect on performance; the histogram view shows the periodical patterns that occurs in the trace. In a number of experiments, the visualizer has been used to characterize the cache behavior and effectively improve the cache behavior and program performance. Yijun Yu 0001, Kristof Beyls, Erik H. D'Hollander |
IV | 1 |
| 2001 | A self-adaptive scheduling algorithm of on-demand broadcastsabstractIn mobile wireless systems data on air can be accessed by a large number of mobile users. Many of these applications such as wireless internets and traffic information systems are pull-based, that is, they respond to on-demand user requests. In this paper, we study the scheduling problems of on-demand broadcast environments. Traditionally, the response time of the requests has been used as a performance measure. In this paper we consider the performance as the average cost of request composed of three kinds of costs—access time cost, tuning time cost, and cost of handling failure request. Our main contribution is a self-adaptive scheduling algorithm named LDFC, which computes the delay cost of data item as the priority for broadcast. It performs well compared with some previous algorithms in this context. Weiwei Sun 0008, Weibin Shi, Baile Shi, Wenyun Ji, Yijun Yu 0001 |
MSWiM | 5 |
| 2000 | Partitioning Loops with Variable Dependence DistancesabstractA new technique to parallelize loops with variable distance vectors is presented. The method extends previous methods in two ways. First, the present method makes it possible for array subscripts to be any linear combination of all loop indices. The solutions to the linear dependence equations established from such array subscripts are characterized by a pseudo distance matrix (PDM). Second, it allows us to exploit loop parallelism from the PDM by applying unimodular and partitioning transformations that preserve the lexicographical order of the dependent iterations. The algorithms to derive the PDM, to find a suitable loop transformation and to generate parallel code are described, showing that it is possible to parallelize a wider range of loops automatically. Yijun Yu 0001, Erik H. D'Hollander |
ICPP | 1 |