VLDB 2026 Research / reviewers in the wild / expert
Abhishek Tiwari 0001
dblp:91/1861-1
· DBLP profile ↗
17ranked-venue papers
6as first author
11since 2021 · last 2026
0000-0001-8415-5410ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 13 · 4 first-author · 11 since 2021Security and privacy · 4 · 2 first-authorTheory of computation · 1 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Towards Analyzing N-Language Polyglot Programs
Jyoti Prakash, Abhishek Tiwari 0001, Mikkel Baun Kjærgaard |
SANER | 2 |
| 2026 | A Measurement Study on the Adoption of Pledges and Unveils in the OpenBSD Operating SystemabstractThe paper presents a longitudinal measurement study on the adoption of the pledge and unveil system calls in OpenBSD. These system calls are used to sandbox programs and libraries. Given a dataset covering 19 releases, many programs and libraries were modified to use the system calls already before their introductions in official releases. The adoption rates have also steadily grown; a linear trend provides a coarse but sensible heuristic. Although particularly programs residing in /usr/bin and /usr/sbin have been modified to use the system calls, the sizes of programs and libraries do not correlate well with the amounts of pledge and unveil system calls invoked. Regarding the pledges made, standard input and output operations have frequently been requested, although the full fine-grained arsenal offered by pledge has generally been utilized in OpenBSD. The same observation is seen in that particularly read operations to given paths have frequently been unveiled. All in all, the measurement results indicate that the adoption of system call minimization and sandboxing techniques is not necessarily as troublesome as has often been discussed in the literature. Jukka Ruohonen, Krzysztof Sierszecki, Abhishek Tiwari 0001 |
SANER | 3 |
| 2026 | PrevaRank: Ranking plausible patches by historic feature frequenciesabstractAutomated program repair (APR) techniques have achieved conspicuous progress, and are now capable of producing genuinely correct fixes in scenarios that were well beyond their capabilities only a few years ago. Nevertheless, even when an APR technique can find a correct fix for a bug, it still runs the risk of ranking the fix lower than other patches that are plausible (they pass all available tests) but incorrect. This can seriously hurt the technique’s practical effectiveness, as the user will have to peruse a larger number of patches before finding the correct one. This paper presents PrevaRank , a technique that ranks plausible patches produced by any APR technique according to their feature similarity with historic programmer-written fixes for similar bugs. PrevaRank implements simple heuristics, which help make it scalable and applicable to any APR tool that produces plausible patches. In our experimental evaluation, after training PrevaRank on the fix history of 81 open-source Java projects, we used it to rank patches produced by 8 Java APR tools on 168 Defects4J bugs. PrevaRank consistently improved the ranking of correct fixes: for example, it ranked a correct fix within the top-3 positions in 27% more cases than the original tools did. Other experimental results indicate that PrevaRank works robustly with a variety of APR tools and bugs, with negligible overhead. • Ranks APR patches via category-conditioned syntactic frequency patterns. • Improves top-3 correct-patch placement by +27% over tools’ native order. • Evaluated on 168 Defects4J bugs, 8 tools, 23,032 plausible patches. Shifat Sahariar Bhuiyan, Abhishek Tiwari 0001, Yu Pei 0001, Carlo A. Furia |
J. Syst. Softw. | 2 |
| 2025 | Modular unification of unilingual pointer analyses to multilingual FFI-based programsabstractModular analysis of polyglot applications is challenging because flows of heap objects must be resolved across language boundaries. The state-of-the-art analyses for polyglot applications have two fundamental limitations. First, they assume explicit boundaries between the guest and the host language to determine inter-language dataflows. Second, they rely on specific analyses of the host and guest languages. The former assumption is impractical concerning recent advancements in polyglot programming techniques, while the latter disregards advances in pointer analysis of the underlying languages. In this work, we propose to extend existing pointer analyses with a novel summary specialization technique that unifies points-to sets across language boundaries. Our novel technique leverages combinations of host and guest analyses with minor modifications. We demonstrate the efficacy and generalizability of our approach by evaluating it with two polyglot language models: Java-C communication via Android's NDK and Java-Python communication in GraalVM. Jyoti Prakash, Abhishek Tiwari 0001, Christian Hammer 0001 |
Sci. Comput. Program. | 2 |
| 2024 | Automated Repair of Information Flow Security in Android Implicit Inter-App CommunicationabstractAbstract Android’s intents provide a form of inter-app communication with implicit, capability-based matching of senders and receivers. Such kind of implicit addressing provides some much-needed flexibility but also increases the risk of introducing information flow security bugs and vulnerabilities—as there is no standard way to specify what permissions are required to access the data sent through intents, so that it is handled properly. To mitigate such risks of intent-based communication, this paper introduces IntentRepair, an automated technique to detect such information flow security leaks and to automatically repair them. IntentRepair first finds sender and receiver modules that may communicate via intents, and such that the sender sends sensitive information that the receiver forwards to a public channel. To prevent this flow, IntentRepair patches the sender so that it also includes information about the permissions needed to access the data; and the receiver so that it will only disclose the sensitive information if it possesses the required permissions. We evaluated a prototype implementation of IntentRepair on 869 Android open-source apps, showing that it is effective in automatically detecting and repairing information flow security bugs that originate in implicit intent-based communication, introducing only a modest overhead in terms of patch size. Abhishek Tiwari 0001, Jyoti Prakash, Carlo A. Furia |
FM (1) | 1 |
| 2024 | Challenges of Multilingual Program Specification and Analysis
Carlo A. Furia, Abhishek Tiwari 0001 |
ISoLA (3) | 2 |
| 2024 | Reproducing Timing-Dependent GUI Flaky Tests in Android Apps via a Single Event DelayabstractFlaky tests hinder the development process by exhibiting uncertain behavior in regression testing. A flaky test may pass in some runs and fail in others while running on the same code version. The non-deterministic outcome frequently misleads the developers into debugging non-existent faults in the code. To effectively debug the flaky tests, developers need to reproduce them. The industry de facto to reproduce flaky tests is to rerun them multiple times. However, rerunning a flaky test numerous times is time and resource-consuming. This work presents a technique for rapidly and reliably reproducing timing-dependent GUI flaky tests, acknowledged as the most common type of flaky tests in Android apps. Our insight is that flakiness in such tests often stems from event racing on GUI data. Given stack traces of a failure, our technique employs dynamic analysis to infer event races likely leading to the failure and reproduces it by selectively delaying only relevant events involved in these races. Thus, our technique can efficiently reproduce a failure within minimal test runs. The experiments conducted on 80 timing-dependent flaky tests collected from 22 widely-used Android apps show our technique is efficient in flaky test failure reproduction. Out of the 80 flaky tests, our technique could successfully reproduce 73 within 1.71 test runs on average. Notably, it exhibited extremely high reliability by consistently reproducing the failure for 20 runs. Xiaobao Cai, Yongjiang Wang, Abhishek Tiwari 0001, Xin Peng 0001 |
ISSTA | 4 |
| 2023 | Demand-driven Information Flow Analysis of WebView in Android Hybrid AppsabstractAndroid hybrid apps augment native apps with web and inter-language communication capabilities. These apps facilitate the integration of web components, including JavaScript, into native apps. Besides, they allow a two-way communication where JavaScript can utilize functionality shared by the native side (Java). However, due to operational differences between Java and JavaScript, the semantics of this communication are complex. Tracking information flows via this communication channel, i.e., between these heterogeneous platforms, becomes intricate.Multiple approaches have been proposed to analyze hybrid apps. However, most of them focus on specific classes of web-induced vulnerabilities or provide rudimentary tracking of specific information flows via this communication channel. This work proposes a demand-driven analysis to comprehensively track information flow violations from the native side to JavaScript and vice-versa. To this end, our framework selectively creates data flow summaries of the shared native-side code based on its usage in the corresponding JavaScript code. We demonstrate the efficacy of our approach by applying it to various benchmarks and large-scale apps. Abhishek Tiwari 0001, Jyoti Prakash, Christian Hammer 0001 |
ISSRE | 1 |
| 2023 | Hippodrome: Data Race Repair Using Static Analysis SummariesabstractImplementing bug-free concurrent programs is a challenging task in modern software development. State-of-the-art static analyses find hundreds of concurrency bugs in production code, scaling to large codebases. Yet, fixing these bugs in constantly changing codebases represents a daunting effort for programmers, particularly because a fix in the concurrent code can introduce other bugs in a subtle way. In this work, we show how to harness compositional static analysis for concurrency bug detection, to enable a new Automated Program Repair (APR) technique for data races in large concurrent Java codebases. The key innovation of our work is an algorithm that translates procedure summaries inferred by the analysis tool for the purpose of bug reporting into small local patches that fix concurrency bugs (without introducing new ones). This synergy makes it possible to extend the virtues of compositional static concurrency analysis to APR, making our approacheffective(it can detect and fix many more bugs than existing tools for data race repair),scalable(it takes seconds to analyze and suggest fixes for sizeable codebases), andusable(generally, it does not require annotations from the users and can performcontinuousautomated repair). Our study, conducted on popular open-source projects, has confirmed that our tool automatically produces concurrency fixes similar to those proposed by the developers in the past. Andreea Costea, Abhishek Tiwari 0001, Sigmund Chianasta, Kishore R, Abhik Roychoudhury, Ilya Sergey |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2021 | Effects of Program Representation on Pointer Analyses - An Empirical StudyabstractAbstract Static analysis frameworks, such as Soot and Wala, are used by researchers to prototype and compare program analyses. These frameworks vary on heap abstraction, modeling library classes, and underlying intermediate program representation (IR). Often, these variations pose a threat to the validity of the results as the implications of comparing the same analysis implementation in different frameworks are still unexplored. Earlier studies have focused on the precision, soundness, and recall of the algorithms implemented in these frameworks; however, little to no work has been done to evaluate the effects of program representation. In this work, we fill this gap and study the impact of program representation on pointer analysis. Unfortunately, existing metrics are insufficient for such a comparison due to their inability to isolate each aspect of the program representation. Therefore, we define two novel metrics that measure these analyses’ precision after isolating the influence of class-hierarchy and intermediate representation. Our results establish that the minor differences in the class hierarchy and IR do not impact program analysis significantly. Besides, they reveal the sources of unsoundness that aid researchers in developing program analysis. Jyoti Prakash, Abhishek Tiwari 0001, Christian Hammer 0001 |
FASE | 2 |
| 2021 | Flaky test detection in Android via event order explorationabstractValidation of Android apps via testing is difficult owing to the presence of flaky tests. Due to non-deterministic execution environments, a sequence of events (a test) may lead to success or failure in unpredictable ways. In this work, we present an approach and tool FlakeScanner for detecting flaky tests through exploration of event orders. Our key observation is that for a test in a mobile app, there is a testing framework thread which creates the test events, a main User-Interface (UI) thread processing these events, and there may be several other background threads running asynchronously. For any event e whose execution involves potential non-determinism, we localize the earliest (latest) event after (before) which e must happen. We then efficiently explore the schedules between the upper/lower bound events while grouping events within a single statement, to find whether the test outcome is flaky. We also create a suite of subject programs called FlakyAppRepo (containing 33 widely-used Android projects) to study flaky tests in Android apps. Our experiments on the subject-suite FlakyAppRepo show FlakeScanner detected 45 out of 52 known flaky tests as well as 245 previously unknown flaky tests among 1444 tests. Abhishek Tiwari 0001, Xiao Liang Yu, Abhik Roychoudhury |
ESEC/SIGSOFT FSE | 2 |
| 2020 | A Large Scale Analysis of Android - Web Hybridization
Abhishek Tiwari 0001, Jyoti Prakash, Sascha Groß, Christian Hammer 0001 |
J. Syst. Softw. | 1 |
| 2019 | LUDroid: A Large Scale Analysis of Android - Web HybridizationabstractMany Android applications embed webpages via WebView components and execute JavaScript code within Android. Hybrid applications leverage dedicated APIs to load a resource and render it in WebView. Furthermore, Android objects can be shared with the JavaScript world. However, bridging the interfaces of the Android and JavaScript world might also incur severe security threats: Potentially untrusted webpages and their JavaScript might interfere with the Android environment and its access to native features. No general analysis is currently available to assess the implications of such hybrid apps bridging the two worlds. To understand the semantics and effects of hybrid apps, we perform a large-scale study on the usage of the hybridization APIs in the wild. We analyze and categorize the parameters to hybridization APIs for 7,500 randomly selected applications from the Google Playstore. Our results advance the general understanding of hybrid applications, as well as implications for potential program analyses, and the current security situation: We discover 6,375 flows of sensitive data from Android to JavaScript, out of which 82% could flow to potentially untrustworthy code. Our analysis identified 365 web pages embedding vulnerabilities and we exemplarily exploit them. Additionally, we discover 653 applications in which potentially untrusted Javascript code may interfere with (trusted) Android objects. Abhishek Tiwari 0001, Jyoti Prakash, Sascha Groß, Christian Hammer 0001 |
SCAM | 1 |
| 2019 | IIFA: Modular Inter-app Intent Information Flow Analysis of Android Applications
Abhishek Tiwari 0001, Sascha Groß, Christian Hammer 0001 |
SecureComm (2) | 1 |
| 2018 | PIAnalyzer: A Precise Approach for PendingIntent Vulnerability Analysis
Sascha Groß, Abhishek Tiwari 0001, Christian Hammer 0001 |
ESORICS (2) | 2 |
| 2018 | A Formal Logic Framework for the Automation of the Right to Be Forgotten
Abhishek Tiwari 0001, Fabian Bendun, Christian Hammer 0001 |
SecureComm (1) | 1 |
| 2017 | ThiefTrap - An Anti-theft Framework for Android
Sascha Groß, Abhishek Tiwari 0001, Christian Hammer 0001 |
SecureComm | 2 |