VLDB 2026 Research / reviewers in the wild / expert
Bahman Zamani
dblp:82/4850
· DBLP profile ↗
26ranked-venue papers
3as first author
13since 2021 · last 2026
0000-0001-6424-1442ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 21 · 2 first-author · 10 since 2021Security and privacy · 2 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Systems, architecture and hardware · 1Databases, data management, data science and information retrieval · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | HarmonyCAS: A model-driven framework for facilitating interoperability in context-aware systems
Hamed Barangi, Shekoufeh Kolahdouz Rahimi, Bahman Zamani, Hossein Moradi |
J. Syst. Softw. | 3 |
| 2026 | A Formal Lens on Android Permissions System: Modeling, Verification, and Exploitation Using LLMs and Model CheckingabstractThe Android Permissions System (APS) is a permission-based access control mechanism that controls the applications’ access to protected resources such as user contacts and GPS locations. The evolution of APS—as a critical component of Android—has made the user experience more convenient. However, the vulnerabilities and attacks targeting the APS indicate that its thorough security analysis is essential to ensure system security and to protect user information. Although previous works applied formal methods to verify the security of APS, its new capabilities, such as One-Time Permissions (OTPs), have not yet been studied. In this article, we present a model checking approach for security verification of APS that supports OTPs. We use Large Language Models in a Chain-of-Thought process to assist in extracting the behavior of APS from its documentation and source code to design a formal model and a set of security properties. Then we use the TLC model checker to verify the security properties against the model. We analyze the APS in both Android 6 and Android 11 and we succeed in discovering a previously known vulnerability in Android 6 as well as a new vulnerability in OTPs in Android 11 named Permanent Permission Access (PPA). We also implement an exploit code to show that PPA leads to permanent illegal access to sensitive resources. Our experiments show that the developed exploit app works on the latest versions of Android too (including Android 15). Besides, we propose the required fix to mitigate the vulnerability. Amirhosein Sayyadabdi, Behrouz Tork Ladani, Bahman Zamani |
ACM Trans. Priv. Secur. | 3 |
| 2025 | RAIDAD: A model-driven framework for automated and agile development of IoT data analysis software
Mohsen Gholami, Bahman Zamani, Behrouz Shahgholi Ghahfarokhi |
Inf. Softw. Technol. | 2 |
| 2025 | CoMPers: A configurable conflict management framework for personalized collaborative modeling
Mohammadreza Sharbaf, Bahman Zamani, Gerson Sunyé |
J. Syst. Softw. | 2 |
| 2024 | A comprehensive framework for inter-app ICC security analysis of Android apps
Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani |
Autom. Softw. Eng. | 2 |
| 2023 | Maaker: A framework for detecting and defeating evasion techniques in Android malware
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani |
J. Inf. Secur. Appl. | 3 |
| 2023 | Conflict management techniques for model merging: a systematic mapping review
Mohammadreza Sharbaf, Bahman Zamani, Gerson Sunyé |
Softw. Syst. Model. | 2 |
| 2023 | A model-based framework for inter-app Vulnerability analysis of Android applicationsabstractAbstract Android users install various apps, such as banking apps, on their smart devices dealing with user‐sensitive information. The Android framework, via Inter‐Component Communication (ICC) mechanism, ensures that app components (inside the same app or on different apps) can communicate. The literature works have shown that this mechanism can cause security issues, such as app security policy violations, especially in the case of Inter‐App Communication (IAC). Despite the plethora of research on detecting security issues in IAC, detection techniques face fundamental ICC challenges for improving the precision of static analysis. Challenges include providing comprehensive and scalable modeling of app specification, capturing all potential ICC paths, and enabling more effective IAC analysis. To overcome such challenges, in this paper, we propose a framework called VAnDroid2, as an extension of our previous work, to address the security issues in multiple components at both intra‐ and inter‐app analysis levels. VAnDroid2, based on Model‐Driven Reverse Engineering, has extended our previous work as per following: (1) providing a comprehensive Intermediate Representation (IR) of the app which supports extracting all the ICC information from the app, (2) extracting high‐level representations of the apps and their interactions by omitting the details that are not relevant to inter‐app security analysis, and (3) enabling more effective IAC security analysis. This framework is implemented as an Eclipse‐based tool. The results of evaluating VAnDroid2 w.r.t. correctness, scalability, and run‐time performance, and comparing with state‐of‐the‐art analysis tools well indicate that VAnDroid2 is a promising framework in the field of Android inter‐app security analysis. Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani, Jacques Klein, Tegawendé F. Bissyandé |
Softw. Pract. Exp. | 2 |
| 2022 | HealMA: a model-driven framework for automatic generation of IoT-based Android health monitoring applications
Maryam Mehrabi, Bahman Zamani, Abdelwahab Hamou-Lhadj |
Autom. Softw. Eng. | 2 |
| 2021 | ALBA: a model-driven framework for the automatic generation of android location-based apps
Mohammadali Gharaat, Mohammadreza Sharbaf, Bahman Zamani, Abdelwahab Hamou-Lhadj |
Autom. Softw. Eng. | 3 |
| 2021 | CGenProg: Adaptation of cartesian genetic programming with migration and opposite guesses for automatic repair of software regression faults
Alireza Khalilian 0001, Ahmad Baraani-Dastjerdi, Bahman Zamani |
Expert Syst. Appl. | 3 |
| 2021 | MEGDroid: A model-driven event generation framework for dynamic android malware analysis
Hayyan Hasan, Behrouz Tork Ladani, Bahman Zamani |
Inf. Softw. Technol. | 3 |
| 2021 | MUPPIT: a method for using proper patterns in model transformations
Mahsa Panahandeh, Mohammad Hamdaqa, Bahman Zamani, Abdelwahab Hamou-Lhadj |
Softw. Syst. Model. | 3 |
| 2020 | CaaSSET: A Framework for Model-Driven Development of Context as a Service
Hossein Moradi, Bahman Zamani, Kamran Zamanifar |
Future Gener. Comput. Syst. | 2 |
| 2020 | SEET: Symbolic Execution of ETL Transformations
Banafsheh Azizi, Bahman Zamani, Shekoufeh Kolahdouz Rahimi |
J. Syst. Softw. | 2 |
| 2020 | Lossless compaction of model execution traces
Fazilat Hojaji, Bahman Zamani, Abdelwahab Hamou-Lhadj, Tanja Mayerhofer, Erwan Bousse |
Softw. Syst. Model. | 2 |
| 2020 | Configurable three-way model mergingabstractSummary Software development is a collaborative activity that requires teams of software engineers to cooperate and work in parallel on versions of models. However, model management techniques such as model differencing, merging, and versioning have turned out to be difficult challenges, due to the complexity of operations and graph‐like nature of models. Therefore, a well‐developed support for model merging process, as well as conflict management, is highly desired. This paper presents a novel process for model merging, called the Epsilon‐based Three‐way Merging Process (E3MP) process. Model merging is a significant problem where there are different versions of a system model amongst modeler teams. E3MP includes three components implemented into the Epsilon framework. First, modelers can define domain‐specific rules that customize the merging process. Second, E3MP enables an automated method for syntactic and semantic conflict detection amongst different versions of the system model. Third, E3MP puts forward a pattern‐based approach for conflict resolution. We applied two generic benchmarks to assess conflict detection and resolution capabilities of our approach and carried out an initial scalability evaluation for the model merge with large models and large change sets. The results of our experiments revealed that the proposed process allows generating consistent and semantically correct merged models. Mohammadreza Sharbaf, Bahman Zamani |
Softw. Pract. Exp. | 2 |
| 2019 | Model execution tracing: a systematic mapping study
Fazilat Hojaji, Tanja Mayerhofer, Bahman Zamani, Abdelwahab Hamou-Lhadj, Erwan Bousse |
Softw. Syst. Model. | 3 |
| 2019 | A model-driven framework for developing multi-agent systems in emergency response environments
Samaneh Hoseindoost, Tahereh Adamzadeh, Bahman Zamani, Afsaneh Fatemi |
Softw. Syst. Model. | 3 |
| 2019 | VAnDroid: A framework for vulnerability analysis of Android applications using a model-driven reverse engineering techniqueabstractSummary Android is extensively used worldwide by mobile application developers. Android provides applications with a message passing system to communicate within and between them. Due to the risks associated with this system, it is vital to detect its unsafe operations and potential vulnerabilities. To achieve this goal, a new framework, called VAnDroid, based on Model Driven Reverse Engineering (MDRE), is presented that identifies security risks and vulnerabilities related to the Android application communication model. In the proposed framework, some security‐related information included in an Android app is automatically extracted and represented as a domain‐specific model. Then, it is used for analyzing security configurations and identifying vulnerabilities in the corresponding application. The proposed framework is implemented as an Eclipse‐based tool, which automatically identifies the Intent Spoofing and Unauthorized Intent Receipt as two attacks related to the Android application communication model. To evaluate the tool, it has been applied to several real‐world Android applications, including 20 apps from Google Play and 110 apps from the F‐Droid repository. VAnDroid is also compared with several existing analysis tools, and it is shown that it has a number of key advantages over those tools specifically regarding its high correctness, scalability, and usability in discovering vulnerabilities. The results well indicate the effectiveness and capacity of the VAnDroid as a promising approach in the field of Android security. Atefeh Nirumand, Bahman Zamani, Behrouz Tork Ladani |
Softw. Pract. Exp. | 2 |
| 2018 | EVL+Strace: a novel bidirectional model transformation approach
Leila Samimi-Dehkordi, Bahman Zamani, Shekoufeh Kolahdouz Rahimi |
Inf. Softw. Technol. | 2 |
| 2017 | A model-based framework for automatic generation of a pattern language verifierabstractSummary Design patterns solve recurring design problems. One of the best practices, to solve a whole problem in a specific context, is to apply patterns in the form of a collection of related patterns, ie, a pattern language (PL). However, with the rapid growth of the number of patterns and their interrelationships in PLs and because manual verification of the applied PLs is a tedious and error‐prone task, when designing in PL‐based fashion, there is a need for tool support to verify the applied PLs. In our previous work, aimed at automating the development process of PL verification tools, a PL formalism was presented. This paper, based on the presented formalism, describes a framework called Pattern Language Verifier Generator (PLVGen) that automatically generates a pattern language verifier (PLV) for any given PL assuming its constituent patterns are represented in the Unified Modeling Language (UML). Using a modelware approach, two metamodels named pattern language specification language (PLSL) and pattern specification language (PSL) are developed to model the given PL and its patterns, respectively. By getting the models of a PL and its patterns, PLVGen automatically generates an epsilon validation language (EVL) module representing the expected PLV. By launching PLV, the applied PL on a UML model will be verified. To evaluate the applicability of PLVGen in practice, we automatically generated three PLVs. The statistics regarding the generated PLVs, as case studies, illustrate the scalability of PLVGen. Compared with similar tools, the generated PLVs are more portable, transparent, and free of ambiguities. Alireza Rouhi, Bahman Zamani |
Softw. Pract. Exp. | 2 |
| 2016 | Towards a formal model of patterns and pattern languages
Alireza Rouhi, Bahman Zamani |
Inf. Softw. Technol. | 2 |
| 2013 | Pattern Language Verification in Model Driven Design
Bahman Zamani, Gregory Butler |
Inf. Sci. | 1 |
| 2009 | Describing Pattern Languages for Checking Design ModelsabstractMany designers use the patterns of a pattern language in creating the design model. In designing with patterns, there are three aspects of the pattern language that must be taken into consideration: structural, syntactic, and semantic. That means, the patterns must be applied correctly, the relationship between patterns must be correct, and the design model must be semantically correct. The syntactic aspect is important for pattern languages due to the fact that the patterns in a pattern language are interconnected via several relationships. To achieve automatic design model checking, the three aspects of a pattern language must be precisely defined. We propose formalisms for representing the structural, syntactic, and semantic aspects of a pattern language. As our case study, we select a pattern language in the domain of enterprise application architecture, and show how the pattern language is described using the proposed formalism. Bahman Zamani, Gregory Butler |
APSEC | 1 |
| 2008 | A Pattern Language Verifier for Web-Based Enterprise Applications
Bahman Zamani, Sahar Kayhani, Gregory Butler |
MoDELS | 1 |