Hakan Erdogmus

dblp:e/HakanErdogmus · also M. Hakan Erdogmus · DBLP profile ↗
← Back
23ranked-venue papers
9as first author
5since 2021 · last 2025
0000-0002-7987-5621ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 21 · 8 first-author · 5 since 2021Databases, data management, data science and information retrieval · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1Theory of computation · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 DevScholar: A Reuse-Based Approach for Evaluating Developer Contribution
Yahya Elnouby, Selen Uysal, Umut Cihan, Hakan Erdogmus, Eray Tüzün
SEAA (3)4
2023 Tenet: A Flexible Framework for Machine-Learning-based Vulnerability Detection
abstract
Software vulnerability detection (SVD) aims to identify potential security weaknesses in software. SVD systems have been rapidly evolving from those being based on testing, static analysis, and dynamic analysis to those based on machine learning (ML). Many ML-based approaches have been proposed, but challenges remain: training and testing datasets contain duplicates, and building customized end-to-end pipelines for SVD is time-consuming. We present Tenet, a modular framework for building end-to-end, customizable, reusable, and automated pipelines through a plugin-based architecture that supports SVD for several deep learning (DL) and basic ML models. We demonstrate the applicability of Tenet by building practical pipelines performing SVD on real-world vulnerabilities.
Eduard Pinconschi, Sofia Reis, Rui Abreu 0001, Hakan Erdogmus, Corina Pasareanu, Limin Jia 0001
CAIN5
2022 SECOM: Towards a convention for security commit messages
abstract
One way to detect and assess software vulnerabilities is by extracting security-related information from commit messages. Automating the detection and assessment of vulnerabilities upon security commit messages is still challenging due to the lack of structured and clear messages. We created a convention, called SECOM, for security commit messages that structure and include bits of security-related information that are essential for detecting and assessing vulnerabilities for both humans and tools. The full convention and details are available here: https://tqrg.github.io/secom/.
Sofia Reis, Rui Abreu 0001, Hakan Erdogmus, Corina Pasareanu
MSR3
2022 Cleaning ground truth data in software task assignment
K. Ayberk Tecimer, Eray Tüzün, Cansu Moran, Hakan Erdogmus
Inf. Softw. Technol.4
2021 Detection and Elimination of Systematic Labeling Bias in Code Reviewer Recommendation Systems
abstract
Reviewer selection in modern code review is crucial for effective code reviews. Several techniques exist for recommending reviewers appropriate for a given pull request (PR). Most code reviewer recommendation techniques in the literature build and evaluate their models based on datasets collected from real projects using open-source or industrial practices. The techniques invariably presume that these datasets reliably represent the “ground truth.”
K. Ayberk Tecimer, Eray Tüzün, Hamdi Dibeklioglu, Hakan Erdogmus
EASE4
2019 Introduction to Selected Papers from SPIN 2017
Hakan Erdogmus, Klaus Havelund
Int. J. Softw. Tools Technol. Transf.1
2018 Lightweight source code monitoring with Triggr
abstract
Existing tools for monitoring the quality of codebases modified by multiple developers tend to be centralized and inflexible. These tools increase the visibility of quality by producing effective reports and visualizations when a change is made to the codebase and triggering alerts when undesirable situations occur. However, their configuration is invariably both (a) centrally managed in that individual maintainers cannot define local rules to receive customized feedback when a change occurs in a specific part of the code in which they are particularly interested, and (b) coarse-grained in that analyses cannot be turned on and off below the file level. Triggr, the tool proposed in this paper, addresses these limitations by allowing distributed, customized, and fine-grained monitoring. It is a lightweight re-implementation of our previous tool, CodeAware, which adopts the same paradigm. The tool listens on a codebase’s shared repository using an event-based approach, and can send alerts to subscribed developers based on rules defined locally by them. Triggr is open-source and available at https://github.com/lyzerk/Triggr. A demonstration video can be found at https://youtu.be/qQs9aDwXJjY.
Alim Ozdemir, Ayse Tosun Misirli, Hakan Erdogmus, Rui Abreu 0001
ASE3
2017 Guest editorial for special section on success and failure in software engineering
Mika Mäntylä, Magne Jørgensen, Paul Ralph, Hakan Erdogmus
Empir. Softw. Eng.4
2017 An industry experiment on the effects of test-driven development on external quality and productivity
Ayse Tosun Misirli, Óscar Dieste Tubío, Davide Fucci, Sira Vegas, Burak Turhan, Hakan Erdogmus, Adrián Santos, Markku Oivo, Kimmo Toro, Janne Järvinen, Natalia Juristo Juzgado
Empir. Softw. Eng.6
2017 A Dissection of the Test-Driven Development Process: Does It Really Matter to Test-First or to Test-Last?
abstract
Background: Test-driven development (TDD) is a technique that repeats short coding cycles interleaved with testing. The developer first writes a unit test for the desired functionality, followed by the necessary production code, and refactors the code. Many empirical studies neglect unique process characteristics related to TDD iterative nature. Aim: We formulate four process characteristic: sequencing, granularity, uniformity, and refactoring effort. We investigate how these characteristics impact quality and productivity in TDD and related variations. Method: We analyzed 82 data points collected from 39 professionals, each capturing the process used while performing a specific development task. We built regression models to assess the impact of process characteristics on quality and productivity. Quality was measured by functional correctness. Result: Quality and productivity improvements were primarily positively associated with the granularity and uniformity. Sequencing, the order in which test and production code are written, had no important influence. Refactoring effort was negatively associated with both outcomes. We explain the unexpected negative correlation with quality by possible prevalence of mixed refactoring. Conclusion: The claimed benefits of TDD may not be due to its distinctive test-first dynamic, but rather due to the fact that TDD-like processes encourage fine-grained, steady steps that improve focus and flow.
Davide Fucci, Hakan Erdogmus, Burak Turhan, Markku Oivo, Natalia Juristo Juzgado
IEEE Trans. Software Eng.2
2016 Small Polygon Compression
abstract
We introduce a compression technique for small polygons. The main application is to embed compressed polygons in emergency alert messages that have strict length restrictions, as in the case of Wireless Emergency Alert messages. We transform polygon coordinates to sets of integers and are able to compress them to between 10.4% and 25.6% of original length reducing original polygon lengths from 43-331 characters to 9-61 characters. The compression technique introduced in this work takes advantage of a strongly skewed polygon coordinate distribution.
Abhinav Jauhri, Martin L. Griss, Hakan Erdogmus
DCC3
2015 CodeAware: Sensor-Based Fine-Grained Monitoring and Management of Software Artifacts
abstract
Current continuous integration (CI) tools, although extensible, can be limiting in terms of flexibility. In particular, artifact analysis capabilities available through plug in mechanisms are both coarse-grained and centralized. To address this limitation, this paper introduces a new paradigm, Code Aware, for distributed and fine-grained artifact analysis. Code Aware is an ecosystem inspired by sensor networks, consisting of monitors and actuators, aimed at improving code quality and team productivity. Code ware's vision entails (a) the ability to probe software artifacts of any granularity and localization, from variables to classes or files to entire systems, (b) the ability to perform both static and dynamic analyses on these artifacts, and (c) the ability to describe targeted remediation actions, for example to notify interested developers, through automated actuators. We provide motivational examples for the use of Code Aware that leverage current CI solutions, sketch the architecture of its underlying ecosystem, and outline research challenges.
Rui Abreu 0001, Hakan Erdogmus, Alexandre Perez
ICSE (2)2
2010 Cost effectiveness analysis in software engineering
abstract
The tutorial presented an approach that leverages well-known economic and financial concepts for evaluating the cost effectiveness of software development processes and techniques. Software engineering studies often report separately on the costs and benefits of a phenomenon of interest, and rarely adequately address the combined bottom line implications. In particular, tensions between quality and productivity are hard to reconcile, making objective, high-level insights elusive. To address this need, the tutorial focused on quantitative methods for synthesizing co-dependent cost-benefit effects and analyzing the resulting behaviors.
Hakan Erdogmus
ICSE (2)1
2010 Operational definition and automated inference of test-driven development with Zorro
Hongbing Kou, Philip M. Johnson, Hakan Erdogmus
Autom. Softw. Eng.3
2007 A cost effectiveness indicator for software development
abstract
Product quality, development productivity, and staffing needs are main cost drivers in software development. The paper proposes a cost-effectiveness indicator that combines these drivers using an economic criterion.
Hakan Erdogmus
ESEM1
2005 On the Effectiveness of the Test-First Approach to Programming
abstract
Test-driven development (TDD) is based on formalizing a piece of functionality as a test, implementing the functionality such that the test passes, and iterating the process. This paper describes a controlled experiment for evaluating an important aspect of TDD: in TDD, programmers write functional tests before the corresponding implementation code. The experiment was conducted with undergraduate students. While the experiment group applied a test-first strategy, the control group applied a more conventional development technique, writing tests after the implementation. Both groups followed an incremental process, adding new features one at a time and regression testing them. We found that test-first students on average wrote more tests and, in turn, students who wrote more tests tended to be more productive. We also observed that the minimum quality increased linearly with the number of programmer tests, independent of the development strategy employed.
Hakan Erdogmus, Maurizio Morisio, Marco Torchiano
IEEE Trans. Software Eng.1
2004 The Sixth International Workshop on Economics-Driven Software Engineering Research (EDSER-6)
Hakan Erdogmus, Jyrki Kontio, Michael A. Cusumano, David Raffo
ICSE1
2002 Software engineering economics: background, current practices, and future directions
abstract
The field of software economics seeks to develop technical theories, guidelines, and practices of software development based on sound, established, and emerging models of value and value-creation---adapted to the domain of software development as necessary. The premise of the field is that software development is an ongoing investment activity---in which developers and managers continually make investment decisions requiring the expenditure of valuable resources, such as time, talent, and money. The overriding aim of this activity is to maximize the value added subject to an equitable distribution among the participating stakeholders. The goal of the tutorial is to expose the audience to this line of thinking and introduce the tools pertinent to its pursuit. The tutorial is designed to be self-contained and will cover concepts from introductory to advanced. Both practitioners and researchers with an interest in the impact of value considerations in software decision-making will benefit from attending it.This tutorial is offered in conjunction with the Fourth International Workshop on Economics-Driven Software Engineering Research (EDSER-4). The tutorial is meant in part to enable those who would like to participate in the workshop, but who might not possess the requisite background, to come up to speed.
Hakan Erdogmus, Barry W. Boehm, Warren Harrison, Donald J. Reifer, Kevin J. Sullivan
ICSE1
2002 The fourth international workshop on economics-driven software engineering research (EDSER-4)
abstract
No abstract available.
Warren Harrison, Hakan Erdogmus, Rick Kazman
ICSE2
2002 International Workshop on Reuse Economics
John M. Favaro, Hakan Erdogmus, Klaus Schmid
ICSR2
1996 On the Operational Semantics of Nondeterminism and Divergence
Hakan Erdogmus, Robert Johnston, Michael J. Ferguson
Theor. Comput. Sci.1
1990 An Approach to Specifying and Synthesizing Communicating Processes
Hakan Erdogmus, Robert de B. Johnston
FORTE1
1990 On the Specification and Synthesis of Communicating Processes
abstract
An objective methodology for the specification and synthesis of communicating processes is presented. It is demonstrated that algebraic operators can be used to formulate communicating processes in terms of behavioral constraints and that the corresponding state-machine-type process descriptions can be derived automatically or synthesized from these formulations. The behavioral constraints serve as high-level specifications for communicating processes. These constraints indicate the desired behavior of a process, possibly embedded in a system, by defining its range. The proposed approach is shown to be applicable to a common problem which concerns the synthesis of the central module serving a number of clients in a specific distributed system configuration.>
Hakan Erdogmus, Robert Johnston
IEEE Trans. Software Eng.1