VLDB 2026 Research / reviewers in the wild / expert
Rudolf Ferenc
dblp:f/RudolfFerenc
· DBLP profile ↗
62ranked-venue papers
8as first author
11since 2021 · last 2025
0000-0001-8897-7403ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 46 · 8 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 15 · 2 since 2021Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Identifying Helpful Context for LLM-based Vulnerability Repair: A Preliminary StudyabstractRecent advancements in large language models (LLMs) have shown promise for automated vulnerability detection and repair in software systems. This paper investigates the performance of GPT-4o in repairing Java vulnerabilities from a widely used dataset (Vul4J), exploring how different contextual information affects automated vulnerability repair (AVR) capabilities. We compare the latest GPT-4o’s performance against previous results with GPT-4 using identical prompts. We evaluated nine additional prompts crafted by us that contain various contextual information such as CWE or CVE information, and manually extracted code contexts. Each prompt was executed three times on 42 vulnerabilities, and the resulting fix candidates were validated using Vul4J’s automated testing framework. Our results show that GPT-4o performed 11.9% worse on average than GPT-4 with the same prompt, but was able to fix 10.5% more distinct vulnerabilities in the three runs together. CVE information significantly improved repair rates, while the length of the task description had minimal impact. Combining CVE guidance with manually extracted code context resulted in the best performance. Using our Top-3 prompts together, GPT-4o repaired 26 (62%) vulnerabilities at least once, outperforming both the original baseline (40%) and its reproduction (45%), suggesting that ensemble prompt strategies could improve vulnerability repair in zero-shot settings. Gabor Antal, Bence Bogenfürst, Rudolf Ferenc, Péter Hegedüs |
EASE | 3 |
| 2025 | Leveraging GPT-4 for Vulnerability-Witnessing Unit Test GenerationabstractIn the life-cycle of software development, testing plays a crucial role in quality assurance. Proper testing not only increases code coverage and prevents regressions but it can also ensure that any potential vulnerabilities in the software are identified and effectively fixed. However, creating such tests is a complex, resource-consuming manual process. To help developers and security experts, this paper explores the automatic unit test generation capability of one of the most widely used large language models, GPT-4, from the perspective of vulnerabilities. We examine a subset of the VUL4J dataset containing real vulnerabilities and their corresponding fixes to determine whether GPT-4 can generate syntactically and/or semantically correct unit tests based on the code before and after the fixes as evidence of vulnerability mitigation. We focus on the impact of code contexts, the effectiveness of GPT-4’s self-correction ability, and the subjective usability of the generated test cases. Our results indicate that GPT-4 can generate syntactically correct test cases 66.5% of the time without domain-specific pre-training. Although the semantic correctness of the fixes could be automatically validated in only 7. 5% of the cases, our subjective evaluation shows that GPT-4 generally produces test templates that can be further developed into fully functional vulnerability-witnessing tests with relatively minimal manual effort. Gabor Antal, Dénes Bán, Martin Isztin, Rudolf Ferenc, Péter Hegedüs |
EASE | 4 |
| 2024 | Reality Check: Assessing GPT-4 in Fixing Real-World Software VulnerabilitiesabstractDiscovering and mitigating software vulnerabilities is a challenging task. These vulnerabilities are often caused by simple, otherwise (and in other contexts) harmless code snippets (e.g., unchecked path traversal). Large Language Models (LLMs) promise to revolutionize not just human-machine interactions but various software engineering tasks as well, including the automatic repair of vulnerabilities. However, currently, it is hard to assess the performance, robustness, and reliability of these models as most of their evaluation has been done on small, synthetic examples. In our work, we systematically evaluate the automatic vulnerability fixing capabilities of GPT-4, a popular LLM, using a database of real-world Java vulnerabilities, Vul4J. We expect the model to provide fixes for vulnerable methods, which we evaluate manually and based on unit test results included in the Vul4J database. GPT-4 provided perfect fixes consistently for at least 12 out of the total 46 examined vulnerabilities, which could be applied as is. In an additional 5 cases, the provided textual instructions would help to fix the vulnerabilities in a practical scenario (despite the provided code being incorrect). Our findings, similar to others, also show that prompting has a significant effect. Zoltán Ságodi, Gabor Antal, Bence Bogenfürst, Martin Isztin, Péter Hegedüs, Rudolf Ferenc |
EASE | 6 |
| 2024 | On the Usefulness of Python Structural Pattern Matching: An Empirical StudyabstractAs the important role of software in our modern world becomes more and more evident, the need for more complex data structures is increasing. Structural pattern matching has become an elegant technique for simplifying complex conditionallogic in the source code in modern programming languages. It provides an easy and concise way to destructure complex data and enables making decisions based on its structure, ultimately improving code readability. In the context of Python, a language renowned for its simplicity, structural pattern matching was a missing feature until October 2021. Finally, the feature is shipped in Python 3.10, allowing developers to exploit the potential of structural pattern matching. Instead of traditional conditional branching and endless type checking, structural pattern matching offers a more straightforward way to handle data. In this paper, we investigate the usefulness of this relatively new Python feature by involving 65 participants in a code review experiment. The participants (coming from diverse programming backgrounds) were presented with pairs of code snippets (one using structural pattern matching while the other using traditional conditional branching), each addressing the same task. They had to choose which code they preferred using a 4- point Likert scale based on three criteria: readability, modifiability, and personal preference. In the vast majority of cases, developers preferred code with structural pattern matching, but there were certain contexts in which a significant proportion of developers preferred the original code. Norbert Vándor, Gabor Antal, Péter Hegedüs, Rudolf Ferenc |
SANER | 4 |
| 2022 | A Vulnerability Introducing Commit Dataset for Java: An Improved SZZ based ApproachabstractIn the domain of vulnerability detection from the source code by applying static analysis, the number and quality of available datasets for creating and testing security analysis methods is quite low.To be precise, there are already several public datasets containing vulnerability fixing commits; however, vulnerability introducing commit datasets are scarce, which would be essential for creating and validating just-in-time vulnerability detection approaches.In this paper, we propose an SZZ (an algorithm originally developed to find bug introducing commits) based method with a specific filtering mechanism to create vulnerability introducing commit datasets from vulnerability fixes.The filtering phase involves measuring a relevance score for each vulnerability introducing commit candidates based on commit similarities.We generated a novel Java vulnerability introducing dataset from the existing project-KB repository to demonstrate our algorithm's capabilities.We also showcase the generated database and the effectiveness of our filtering method through several hand-picked examples from the dataset. INTRODUCTIONMany software engineering-related tasks, such as quality assurance or testing, are now aided by machine learning, which relies heavily on the abundance of data.Most of these tasks are typically based on machine learning, therefore the availability of datasets is crucial to train reliably and to get a generally wellperforming model.Fortunately, when the goal is related to vulnerability fixes, there are already well established datasets that can be relied on.These datasets typically contain validated code changes (i.e.commits) that fix a particular vulnerability described in a Common Vulnerabilities and Exposures (CVE) (MITRE Corporation, v 21) entry, a publicly disclosed security vulnerability in a software system.One such dataset is published as part of the repository "project-KB" (project kaybee) (Ponta et al., 2019) maintained by SAP. Tamás Aladics, Péter Hegedüs, Rudolf Ferenc |
ICSOFT | 3 |
| 2022 | An End-to-End Framework for Repairing Potentially Vulnerable Source CodeabstractNowadays, program development is getting easier and easier as the various IDE tools provide advice on what to write in the program. But it is not enough to implement a solution to a problem; it is also important that the non-functional properties, like the quality or security of the code, are appropriate in all aspects. One of the most widely used techniques to ensure quality is testing. If the tests fail, one can fix the code immediately. However, security issues are unexpected cases when implementing the program, which is why we do not write tests for them in advance. In many cases, security-relevant bugs can not only cause financial loss but also put human lives at risk, so detecting and fixing them is an important step for the reliability and quality of the program. The tool presented in this paper aims to generate automatic code repairs to potential vulnerabilities in the program. By integrating the recommended fixes, one can easily harden the security of their program early in the development process. A case study on six open-source Java subject systems showed that we were able to generate viable repair patches for 57 out of the 81 detected security issues (70%). For certain types (e.g., revealing private references of mutable objects), our tool reached close to perfect performance. Judit Jász, Péter Hegedüs, Ákos Milánkovich, Rudolf Ferenc |
SCAM | 4 |
| 2022 | Don't DIY: Automatically transform legacy Python code to support structural pattern matchingabstractAs data becomes more and more complex as technology evolves, the need to support more complex data types in programming languages has grown. However, without proper storage and manipulation capabilities, handling such data can result in hard-to-read, difficult-to-maintain code. Therefore, programming languages continuously evolve to provide more and more ways to handle complex data. Python 3.10 introduced structural pattern matching, which serves this exact purpose: we can split complex data into relevant parts by examining its structure, and store them for later processing. Previously, we could only use the traditional conditional branching, which could have led to long chains of nested conditionals. Maintaining such code fragments can be cumbersome. In this paper, we present a complete framework to solve the aforementioned problem. Our software is capable of examining Python source code and transforming relevant conditionals into structural pattern matching. Moreover, it is able to handle nested conditionals and it is also easily extensible, thus the set of possible transformations can be easily increased. Balázs Rózsa, Gabor Antal, Rudolf Ferenc |
SCAM | 3 |
| 2021 | Bug Prediction Using Source Code Embedding Based on Doc2Vec
Tamás Aladics, Judit Jász, Rudolf Ferenc |
ICCSA (7) | 3 |
| 2021 | Assessing Ensemble Learning Techniques in Bug Prediction
Zsolt János Szamosvölgyi, Endre Tamás Váradi, Zoltán Tóth, Judit Jász, Rudolf Ferenc |
ICCSA (7) | 5 |
| 2021 | Improving Vulnerability Prediction of JavaScript Functions using Process MetricsabstractDue to the growing number of cyber attacks against computer systems, we need to pay special attention to the security of our software systems. In order to maximize the effectiveness, excluding the human component from this process would be a huge breakthrough. The first step towards this is to automatically recognize the vulnerable parts in our code. Researchers put a lot of effort into creating machine learning models that could determine if a given piece of code, or to be more precise, a selected function, contains any vulnerabilities or not. We aim at improving the existing models, building on previous results in predicting vulnerabilities at the level of functions in JavaScript code using the well-known static source code metrics. In this work, we propose to include several so-called process metrics (e.g., code churn, number of developers modifying a file, or the age of the changed source code) into the set of features, and examine how they affect the performance of the function-level JavaScript vulnerability prediction models. We can confirm that process metrics significantly improve the prediction power of such models. On average, we observed a 8.4% improvement in terms of F-measure (from 0.764 to 0.848), 3.5% improvement in terms of precision (from 0.953 to 0.988) and a 6.3% improvement in terms of recall (from 0.697 to 0.760). Tamás Viszkok, Péter Hegedüs, Rudolf Ferenc |
ICSOFT | 3 |
| 2021 | BUGSJS: a benchmark and taxonomy of JavaScript bugsabstractSummary JavaScript is a popular programming language that is also error‐prone due to its asynchronous, dynamic, and loosely typed nature. In recent years, numerous techniques have been proposed for analyzing and testing JavaScript applications. However, our survey of the literature in this area revealed that the proposed techniques are often evaluated on different datasets of programs and bugs. The lack of a commonly used benchmark limits the ability to perform fair and unbiased comparisons for assessing the efficacy of new techniques. To fill this gap, we propose BugsJS, a benchmark of 453 real, manually validated JavaScript bugs from 10 popular JavaScript server‐side programs, comprising 444k lines of code (LOC) in total. Each bug is accompanied by its bug report, the test cases that expose it, as well as the patch that fixes it. We extended BugsJS with a rich web interface for visualizing and dissecting the bugs' information, as well as a programmable API to access the faulty and fixed versions of the programs and to execute the corresponding test cases, which facilitates conducting highly reproducible empirical studies and comparisons of JavaScript analysis and testing tools. Moreover, following a rigorous procedure, we performed a classification of the bugs according to their nature. Our internal validation shows that our taxonomy is adequate for characterizing the bugs in BugsJS. We discuss several ways in which the resulting taxonomy and the benchmark can help direct researchers interested in automated testing of JavaScript applications. © 2021 The Authors. Software Testing, Verification & Reliability published by John Wiley & Sons, Ltd. Péter Gyimesi, Béla Vancsics, Andrea Stocco 0001, Davood Mazinanian, Árpád Beszédes, Rudolf Ferenc, Ali Mesbah 0001 |
Softw. Test. Verification Reliab. | 6 |
| 2020 | An automatically created novel bug dataset and its validation in bug predictionabstractBugs are inescapable during software development due to frequent code changes, tight deadlines, etc.; therefore, it is important to have tools to find these errors. One way of performing bug identification is to analyze the characteristics of buggy source code elements from the past and predict the present ones based on the same characteristics, using e.g. machine learning models. To support model building tasks, code elements and their characteristics are collected in so-called bug datasets which serve as the input for learning. We present the BugHunter Dataset: a novel kind of automatically constructed and freely available bug dataset containing code elements (files, classes, methods) with a wide set of code metrics and bug information. Other available bug datasets follow the traditional approach of gathering the characteristics of all source code elements (buggy and non-buggy) at only one or more pre-selected release versions of the code. Our approach, on the other hand, captures the buggy and the fixed states of the same source code elements from the narrowest timeframe we can identify for a bug’s presence, regardless of release versions. To show the usefulness of the new dataset, we built and evaluated bug prediction models and achieved F-measure values over 0.74. Rudolf Ferenc, Péter Gyimesi, Gábor Gyimesi, Zoltán Tóth, Tibor Gyimóthy |
J. Syst. Softw. | 1 |
| 2020 | A public unified bug dataset for java and its assessment regarding metrics and bug predictionabstractAbstract Bug datasets have been created and used by many researchers to build and validate novel bug prediction models. In this work, our aim is to collect existing public source code metric-based bug datasets and unify their contents. Furthermore, we wish to assess the plethora of collected metrics and the capabilities of the unified bug dataset in bug prediction. We considered 5 public datasets and we downloaded the corresponding source code for each system in the datasets and performed source code analysis to obtain a common set of source code metrics. This way, we produced a unified bug dataset at class and file level as well. We investigated the diversion of metric definitions and values of the different bug datasets. Finally, we used a decision tree algorithm to show the capabilities of the dataset in bug prediction. We found that there are statistically significant differences in the values of the original and the newly calculated metrics; furthermore, notations and definitions can severely differ. We compared the bug prediction capabilities of the original and the extended metric suites (within-project learning). Afterwards, we merged all classes (and files) into one large dataset which consists of 47,618 elements (43,744 for files) and we evaluated the bug prediction model build on this large dataset as well. Finally, we also investigated cross-project capabilities of the bug prediction models and datasets. We made the unified dataset publicly available for everyone. By using a public unified dataset as an input for different bug prediction related investigations, researchers can make their studies reproducible, thus able to be validated and verified. Rudolf Ferenc, Zoltán Tóth, Gergely Ladányi, István Siket, Tibor Gyimóthy |
Softw. Qual. J. | 1 |
| 2019 | Systematic Comparison of Six Open-source Java Call Graph Construction ToolsabstractCall graphs provide the groundwork for numerous analysis algorithms and tools.However, in practice, their construction may have several ambiguities, especially for object-oriented programming languages like Java.The characteristics of the call graphs -which are influenced by building requirements such as scalability, efficiency, completeness, and precision -can greatly affect the output of the algorithms utilizing them.Therefore, it is important for developers to know a well-defined set of criteria based on which they can choose the most appropriate call graph builder tool for their static analysis applications.In this paper, we studied and compared six static call graph creator tools for Java.Our aim was to identify linguistic and technical properties that might induce differences in the generated call graphs besides the obvious differences caused by the various call graph construction algorithms.We evaluated the tools on multiple real-life open-source Java systems and performed a quantitative and qualitative assessment of the resulting graphs.We have shown how different outputs could be generated by the different tools.By manually analyzing the differences found on larger programs, we also found differences that we did not expect based on our preliminary assumptions. Judit Jász, István Siket, Edit Pengo, Zoltán Ságodi, Rudolf Ferenc |
ICSOFT | 5 |
| 2019 | BugsJS: a Benchmark of JavaScript BugsabstractJavaScript is a popular programming language that is also error-prone due to its asynchronous, dynamic, and loosely-typed nature. In recent years, numerous techniques have been proposed for analyzing and testing JavaScript applications. However, our survey of the literature in this area revealed that the proposed techniques are often evaluated on different datasets of programs and bugs. The lack of a commonly used benchmark limits the ability to perform fair and unbiased comparisons for assessing the efficacy of new techniques. To fill this gap, we propose BugsJS, a benchmark of 453 real, manually validated JavaScript bugs from 10 popular JavaScript server-side programs, comprising 444k LOC in total. Each bug is accompanied by its bug report, the test cases that detect it, as well as the patch that fixes it. BugsJS features a rich interface for accessing the faulty and fixed versions of the programs and executing the corresponding test cases, which facilitates conducting highly-reproducible empirical studies and comparisons of JavaScript analysis and testing tools. Péter Gyimesi, Béla Vancsics, Andrea Stocco 0001, Davood Mazinanian, Árpád Beszédes, Rudolf Ferenc, Ali Mesbah 0001 |
ICST | 6 |
| 2019 | Poster: Supporting JavaScript Experimentation with BugsJSabstractIn our recent work, we proposed BUGSJS, a benchmark of several hundred bugs from popular JavaScript server-side programs. In this abstract paper, we report the results of our initial evaluation in adopting BUGSJS to support an experiment in fault localization. First, we describe how BUGSJS facilitated accessing the information required to perform the experiment, namely, test case code, their outcomes, their associated code coverage and related bug information. Second, we illustrate how BUGSJS can be improved to further enable easier application to fault localization research, for instance, by filtering out failing test cases that do not directly contribute to a bug. We hope that our preliminary results will foster researchers in using BUGSJS to enable highly-reproducible empirical studies and comparisons of JavaScript analysis and testing tools. Béla Vancsics, Péter Gyimesi, Andrea Stocco 0001, Davood Mazinanian, Árpád Beszédes, Rudolf Ferenc, Ali Mesbah 0001 |
ICST | 6 |
| 2019 | Challenges of SonarQube Plug-In MaintenanceabstractThe SONARQUBETMplatform is a widely used open-source tool for continuous code quality management. It provides an API to extend the platform with plug-ins to upload additional data or to enrich its functionalities. The SourceMeter plug-in for SONARQUBETMplatform integrates the SourceMeter static source code analyzer tool into the SONARQUBETMplatform, i.e., uploads the analysis results and extends the GUI to be able to present the new results. The first version of the plug-in was released in 2015 and was compatible with the corresponding SONARQUBETMversion. However, the platform - and what is more important, its API - have evolved a lot since then, therefore the plug-in had to be adapted to the new API. It was not just a slight adjustment, though, because we had to redesign and reimplement the whole UI and, at the same time, perform significant alterations in other parts of the plug-in as well. Besides, we examined the effect of the API evolution on other open-source plug-ins and found that most of them still remain compatible with the latest version, even if they have not been updated alongside the underlying API modifications. The reason for this is that these plug-ins use only a small part of the API that have not changed over time. Bence Barta, Gunter Manz, István Siket, Rudolf Ferenc |
SANER | 4 |
| 2019 | Prediction models for performance, power, and energy efficiency of software executed on heterogeneous hardware
Dénes Bán, Rudolf Ferenc, István Siket, Ákos Kiss 0001, Tibor Gyimóthy |
J. Supercomput. | 2 |
| 2018 | [Research Paper] Static JavaScript Call Graphs: A Comparative StudyabstractThe popularity and wide adoption of JavaScript both at the client and server side makes its code analysis more important than ever before. Most of the algorithms for vulnerability analysis, coding issue detection, or type inference rely on the call graph representation of the underlying program. Despite some obvious advantages of dynamic analysis, static algorithms should also be considered for call graph construction as they do not require extensive test beds for programs and their costly execution and tracing. In this paper, we systematically compare five widely adopted static algorithms - implemented by the npm call graph, IBM WALA, Google Closure Compiler, Approximate Call Graph, and Type Analyzer for JavaScript tools - for building JavaScript call graphs on 26 WebKit SunSpider benchmark programs and 6 real-world Node.js modules. We provide a performance analysis as well as a quantitative and qualitative evaluation of the results. We found that there was a relatively large intersection of the found call edges among the algorithms, which proved to be 100% precise. However, most of the tools found edges that were missed by all others. ACG had the highest precision followed immediately by TAJS, but ACG found significantly more call edges. As for the combination of tools, ACG and TAJS together covered 99% of the found true edges by all algorithms, while maintaining a precision as high as 98%. Only two of the tools were able to analyze up-to-date multi-file Node.js modules due to incomplete language features support. They agreed on almost 60% of the call edges, but each of them found valid edges that the other missed. Gabor Antal, Péter Hegedüs, Zoltán Tóth, Rudolf Ferenc, Tibor Gyimóthy |
SCAM | 4 |
| 2018 | Empirical evaluation of software maintainability based on a manually validated refactoring dataset
Péter Hegedüs, István Kádár, Rudolf Ferenc, Tibor Gyimóthy |
Inf. Softw. Technol. | 3 |
| 2017 | Empirical study on refactoring large-scale industrial systems and its effects on maintainability
Gábor Szoke, Gabor Antal, Csaba Nagy 0001, Rudolf Ferenc, Tibor Gyimóthy |
J. Syst. Softw. | 4 |
| 2016 | Assessment of the Code Refactoring Dataset Regarding the Maintainability of Methods
István Kádár, Péter Hegedüs, Rudolf Ferenc, Tibor Gyimóthy |
ICCSA (4) | 3 |
| 2016 | A Public Bug Database of GitHub Projects and Its Application in Bug Prediction
Zoltán Tóth, Péter Gyimesi, Rudolf Ferenc |
ICCSA (4) | 3 |
| 2016 | Transforming C++11 Code to C++03 to Support Legacy Compilation EnvironmentsabstractNewer technologies - programming languages, environments, libraries - change very rapidly. However, various internal and external constraints often prevent projects from quickly adopting to these changes. Customers may require specific platform compatibility from a software vendor, for example. In this work, we deal with such an issue in the context of the C++ programming language. Our industrial partner is required to use SDKs that support only older C++ language editions. They, however, would like to allow their developers to use the newest language constructs in their code. To address this problem, we created a source code transformation framework to automatically backport source code written according to the C++11 standard to its functionally equivalent C++03 variant. With our framework developers are free to exploit the latest language features, while production code is still built by using a restricted set of available language constructs. This paper reports on the technical details of the transformation engine, and our experiences in applying it on two large industrial code bases and four open-source systems. Our solution is freely available and open-source. Gabor Antal, David Havas, István Siket, Árpád Beszédes, Rudolf Ferenc, József Mihalicza |
SCAM | 5 |
| 2016 | A Code Refactoring Dataset and Its Assessment Regarding Software MaintainabilityabstractIt is very common in various fields that there is a gap between theoretical results and their practical applications. This is true for code refactoring as well, which has a solid theoretical background while being used in development practice at the same time. However, more and more studies suggest that developers perform code refactoring entirely differently than the theory would suggest. Our paper encourages the further investigation of code refactorings in practice by providing an excessive open dataset of source code metrics and applied refactorings through several releases of 7 open-source systems. As a first step of processing this dataset, we examined the quality attributes of the refactored source code classes and the values of source code metrics improved by those refactorings. Our early results show that lower maintainability indeed triggers more code refactorings in practice and these refactorings significantly decrease complexity, code lines, coupling and clone metrics. However, we observed a decrease in comment related metrics in the refactored code. István Kádár, Péter Hegedüs, Rudolf Ferenc, Tibor Gyimóthy |
SANER | 3 |
| 2016 | Designing and Developing Automated Refactoring Transformations: An Experience ReportabstractThere are several challenges which should be kept in mind during the design and development phases of a refactoring tool, and one is that developers have several expectations that are quite hard to satisfy. In this report, we present our experiences of a two-year project where we attempted to create an automatic refactoring tool. In this project, we worked with five software development companies that wanted to improve the maintainability of their products. The project was designed to take into account the expectations of the developers of these companies and consisted of three main stages: a manual refactoring phase, a tool building phase, and an automatic refactoring phase. Throughout these stages we collected the opinions of the developers and faced several challenges on how to automate refactoring transformations, which we present and summarize. Gábor Szoke, Csaba Nagy 0001, Rudolf Ferenc, Tibor Gyimóthy |
SANER | 3 |
| 2015 | Code Ownership: Impact on Maintainability
Csaba Faragó, Péter Hegedüs, Rudolf Ferenc |
ICCSA (5) | 3 |
| 2015 | Characterization of Source Code Defects by Data Mining Conducted on GitHub
Péter Gyimesi, Gábor Gyimesi, Zoltán Tóth, Rudolf Ferenc |
ICCSA (5) | 4 |
| 2015 | Adding Constraint Building Mechanisms to a Symbolic Execution Engine Developed for Detecting Runtime Errors
István Kádár, Péter Hegedüs, Rudolf Ferenc |
ICCSA (5) | 3 |
| 2015 | Comparison of Static Analysis Tools for Quality Measurement of RPG Programs
Zoltán Tóth, László Vidács, Rudolf Ferenc |
ICCSA (5) | 3 |
| 2015 | Do automatic refactorings improve maintainability? An industrial case studyabstractRefactoring is often treated as the main remedy against the unavoidable code erosion happening during software evolution. Studies show that refactoring is indeed an elemental part of the developers' arsenal. However, empirical studies about the impact of refactorings on software maintainability still did not reach a consensus. Moreover, most of these empirical investigations are carried out on open-source projects where distinguishing refactoring operations from other development activities is a challenge in itself. We had a chance to work together with several software development companies in a project where they got extra budget to improve their source code by performing refactoring operations. Taking advantage of this controlled environment, we collected a large amount of data during a refactoring phase where the developers used a (semi)automatic refactoring tool. By measuring the maintainability of the involved subject systems before and after the refactorings, we got valuable insights into the effect of these refactorings on large-scale industrial projects. All but one company, who applied a special refactoring strategy, achieved a maintainability improvement at the end of the refactoring phase, but even that one company suffered from the negative impact of only one type of refactoring. Gábor Szoke, Csaba Nagy 0001, Péter Hegedüs, Rudolf Ferenc, Tibor Gyimóthy |
ICSME | 4 |
| 2015 | Cumulative code churn: Impact on maintainabilityabstractIt is a well-known phenomena that the source code of software systems erodes during development, which results in higher maintenance costs in the long term. But can we somehow narrow down where exactly this erosion happens? Is it possible to infer the future erosion based on past code changes? Do modifications performed on frequently changing code have worse effect on software maintainability than those affecting less frequently modified code? In this study we investigated these questions and the results indicate that code churn indeed increases the pace of code erosion. We calculated cumulative code churn values and maintainability changes for every version control commit operation of three open-source and one proprietary software system. With the help of Wilcoxon rank test we compared the cumulative code churn values of the files in commits resulting maintainability increase with those of decreasing the maintainability. In the case of three systems the test showed very strong significance and in one case it resulted in strong significance (p-values 0.00235, 0.00436, 0.00018 and 0.03616). These results support our preliminary assumption that modifying high-churn code is more likely to decrease the overall maintainability of a software system, which can be thought of as the generalization of the already known phenomena that code churn results in higher number of defects. Csaba Faragó, Péter Hegedüs, Rudolf Ferenc |
SCAM | 3 |
| 2015 | FaultBuster: An automatic code smell refactoring toolsetabstractOne solution to prevent the quality erosion of a software product is to maintain its quality by continuous refac-toring. However, refactoring is not always easy. Developers need to identify the piece of code that should be improved and decide how to rewrite it. Furthermore, refactoring can also be risky; that is, the modified code needs to be re-tested, so developers can see if they broke something. Many IDEs offer a range of refactorings to support so-called automatic refactoring, but tools which are really able to automatically refactor code smells are still under research. In this paper we introduce FaultBuster, a refactoring toolset which is able to support automatic refactoring: identifying the problematic code parts via static code analysis, running automatic algorithms to fix selected code smells, and executing integrated testing tools. In the heart of the toolset lies a refactoring framework to control the analysis and the execution of automatic algorithms. FaultBuster provides IDE plugins to interact with developers via popular IDEs (Eclipse, Netbeans and IntelliJ IDEA). All the tools were developed and tested in a 2-year project with 6 software development companies where thousands of code smells were identified and fixed in 5 systems having altogether over 5 million lines of code. Gábor Szoke, Csaba Nagy 0001, Lajos Jeno Fülöp, Rudolf Ferenc, Tibor Gyimóthy |
SCAM | 4 |
| 2015 | A software quality model for RPGabstractThe IBM i mainframe was designed to manage business applications for which the reliability and quality is a matter of national security. The RPG programming language is the most frequently used one on this platform. The maintainability of the source code has big influence on the development costs, probably this is the reason why it is one of the most attractive, observed and evaluated quality characteristic of all. For improving or at least preserving the maintainability level of software it is necessary to evaluate it regularly. In this study we present a quality model based on the ISO/IEC 25010 international standard for evaluating the maintainability of software systems written in RPG. As an evaluation step of the quality model we show a case study in which we explain how we integrated the quality model as a continuous quality monitoring tool into the business processes of a mid-size software company which has more than twenty years of experience in developing RPG applications. Gergely Ladányi, Zoltán Tóth, Rudolf Ferenc, Tibor Keresztesi |
SANER | 3 |
| 2015 | Performance comparison of query-based techniques for anti-pattern detection
Zoltán Ujhelyi, Gábor Szoke, Ákos Horváth 0001, Norbert Istvan Csiszár, László Vidács, Dániel Varró, Rudolf Ferenc |
Inf. Softw. Technol. | 7 |
| 2014 | Recognizing Antipatterns and Analyzing Their Effects on Software Maintainability
Dénes Bán, Rudolf Ferenc |
ICCSA (5) | 2 |
| 2014 | Service Layer for IDE Integration of C/C++ Preprocessor Related Analysis
Richárd Dévai, László Vidács, Rudolf Ferenc, Tibor Gyimóthy |
ICCSA (5) | 3 |
| 2014 | The Impact of Version Control Operations on the Quality Change of the Source Code
Csaba Faragó, Péter Hegedüs, Rudolf Ferenc |
ICCSA (5) | 3 |
| 2014 | A Case Study of Refactoring Large-Scale Industrial Systems to Efficiently Improve Source Code Quality
Gábor Szoke, Csaba Nagy 0001, Rudolf Ferenc, Tibor Gyimóthy |
ICCSA (5) | 3 |
| 2014 | Source Meter Sonar Qube Plug-inabstractThe SourceMeter Sonar Qube plug-in is an extension of Sonar Qube, an open-source platform for managing code quality made by Sonar Source S.A, Switzerland. The plug-in extends the built-in Java code analysis engine of Sonar Qube with Front End ART's high-end Java code analysis engine. Most of Sonar Qubes original analysis results are replaced (including the detected source code duplications), while the range of available analyses is extended with a number of additional metrics and issue detectors. Additionally, the plug-in offers new GUI features on the Sonar Qube dashboard and drilldown views, making the Sonar Qube user experience more comfortable and the work with the tool more productive. Rudolf Ferenc, Laszlo Lango, István Siket, Tibor Gyimóthy, Tibor Bakota |
SCAM | 1 |
| 2014 | Bulk Fixing Coding Issues and Its Effects on Software Quality: Is It Worth Refactoring?abstractThe quality of a software system is mostly defined by its source code. Software evolves continuously, it gets modified, enhanced, and new requirements always arise. If we do not spend time periodically on improving our source code, it becomes messy and its quality will decrease inevitably. Literature tells us that we can improve the quality of our software product by regularly refactoring it. But does refactoring really increase software quality? Can it happen that a refactoring decreases the quality? Is it possible to recognize the change in quality caused by a single refactoring operation? In our paper, we seek answers to these questions in a case study of refactoring large-scale proprietary software systems. We analyzed the source code of 5 systems, and measured the quality of several revisions for a period of time. We analyzed 2 million lines of code and identified nearly 200 refactoring commits which fixed over 500 coding issues. We found that one single refactoring only makes a small change (sometimes even decreases quality), but when we do them in blocks, we can significantly increase quality, which can result not only in the local, but also in the global improvement of the code. Gábor Szoke, Gabor Antal, Csaba Nagy 0001, Rudolf Ferenc, Tibor Gyimóthy |
SCAM | 4 |
| 2013 | A Methodology and Framework for Automatic Layout Independent GUI Testing of Applications Developed in Magic xpa
Daniel Fritsi, Csaba Nagy 0001, Rudolf Ferenc, Tibor Gyimóthy |
ICCSA (2) | 3 |
| 2013 | A Semi-automatic Usability Evaluation Framework
Kornél Muhi, Gábor Szoke, Lajos Jeno Fülöp, Rudolf Ferenc, Ágoston Berger |
ICCSA (2) | 4 |
| 2013 | A retrospective view of software maintenance and reengineering research - a selection of papers from European Conference on Software Maintenance and Reengineering 2010abstractSUMMARY As a summary of past, current, and future trends in software maintenance and reengineering research, we give in this editorial a retrospective look from the past 14 years to now. We provide insight on how software maintenance has evolved and on the most important research topics presented in the series of the European Conference on Software Maintenance and Reengineering. Copyright © 2011 John Wiley & Sons, Ltd. Rafael Capilla, Juan C. Dueñas, Rudolf Ferenc |
J. Softw. Evol. Process. | 3 |
| 2013 | Introduction to the Special Issue of the 13th European Conference on Software Maintenance and Reengineering (CSMR 2009)abstractS.111-112 Rudolf Ferenc, Jens Knodel, Andreas Winter 0001 |
J. Softw. Evol. Process. | 1 |
| 2012 | A cost model based on software maintainabilityabstractIn this paper we present a maintainability based model for estimating the costs of developing source code in its evolution phase. Our model adopts the concept of entropy in thermodynamics, which is used to measure the disorder of a system. In our model, we use maintainability for measuring disorder (i.e. entropy) of the source code of a software system. We evaluated our model on three proprietary and two open source real world software systems implemented in Java, and found that the maintainability of these evolving software is decreasing over time. Furthermore, maintainability and development costs are in exponential relationship with each other. We also found that our model is able to predict future development costs with high accuracy in these systems. Tibor Bakota, Péter Hegedüs, Gergely Ladányi, Peter Kortvelyesi, Rudolf Ferenc, Tibor Gyimóthy |
ICSM | 5 |
| 2012 | Introduction to the Software Quality and Maintainability special issue
Yiannis Kanellopoulos, Rudolf Ferenc |
Softw. Qual. J. | 2 |
| 2011 | Complexity Measures in 4GL Environment
Csaba Nagy 0001, László Vidács, Rudolf Ferenc, Tibor Gyimóthy, Ferenc Kocsis |
ICCSA (5) | 3 |
| 2011 | A probabilistic software quality modelabstractIn order to take the right decisions in estimating the costs and risks of a software change, it is crucial for the developers and managers to be aware of the quality attributes of their software. Maintainability is an important characteristic defined in the ISO/IEC 9126 standard, owing to its direct impact on development costs. Although the standard provides definitions for the quality characteristics, it does not define how they should be computed. Not being tangible notions, these characteristics are hardly expected to be representable by a single number. Existing quality models do not deal with ambiguity coming from subjective interpretations of characteristics, which depend on experience, knowledge, and even intuition of experts. This research aims at providing a probabilistic approach for computing high-level quality characteristics, which integrate expert knowledge, and deal with ambiguity at the same time. The presented method copes with “goodness” functions, which are continuous generalizations of threshold based approaches, i.e. instead of giving a number for the measure of goodness, it provides a continuous function. Two different systems were evaluated using this approach, and the results were compared to the opinions of experts involved in the development. The results show that the quality model values change in accordance with the maintenance activities, and they are in a good correlation with the experts' expectations. Tibor Bakota, Péter Hegedüs, Peter Kortvelyesi, Rudolf Ferenc, Tibor Gyimóthy |
ICSM | 4 |
| 2010 | MAGISTER: Quality assurance of Magic applications for software developers and end usersabstractNowadays there are many tools and methods available for source code quality assurance based on static analysis, but most of these tools focus on traditional software development techniques with 3GL languages. Besides procedural languages, 4GL programming languages such as Magic 4GL and Progress are widely used for application development. All these languages lie outside the main scope of analysis techniques. In this paper we present MAGISTER, which is a quality assurance framework for applications being developed in Magic, a 4GL application development solution created by Magic Software Enterprises. MAGISTER extracts data using static analysis methods from applications being developed in different versions of Magic (v5-9 and uniPaaS). The extracted data (including metrics, rule violations and dependency relations) is presented to the user via a GUI so it can be queried and visualized for further analysis. It helps software developers, architects and managers through the full development cycle by performing continuous code scans and measurements. Csaba Nagy 0001, László Vidács, Rudolf Ferenc, Tibor Gyimóthy, Ferenc Kocsis |
ICSM | 3 |
| 2010 | New Conceptual Coupling and Cohesion Metrics for Object-Oriented SystemsabstractThe paper presents two novel conceptual metrics for measuring coupling and cohesion in software systems. Our first metric, Conceptual Coupling between Object classes (CCBO), is based on the well-known CBO coupling metric, while the other metric, Conceptual Lack of Cohesion on Methods (CLCOM5), is based on the LCOM5 cohesion metric. One advantage of the proposed conceptual metrics is that they can be computed in a simpler (and in many cases, programming language independent) way as compared to some of the structural metrics. We empirically studied CCBO and CLCOM5 for predicting fault-proneness of classes in a large open source system and compared these metrics with a host of existing structural and conceptual metrics for the same task. As the result, we found that the proposed conceptual metrics, when used in conjunction, can predict bugs nearly as precisely as the 58 structural metrics available in the Columbus source code quality framework and can be effectively combined with these metrics to improve bug prediction. Bela Ujhazi, Rudolf Ferenc, Denys Poshyvanyk, Tibor Gyimóthy |
SCAM | 2 |
| 2009 | Modeling class cohesion as mixtures of latent topicsabstractThe paper proposes a new measure for the cohesion of classes in object-oriented software systems. It is based on the analysis of latent topics embedded in comments and identifiers in source code. The measure, named as maximal weighted entropy, utilizes the latent Dirichlet allocation technique and information entropy measures to quantitatively evaluate the cohesion of classes in software. This paper presents the principles and the technology that stand behind the proposed measure. Two case studies on a large open source software system are presented. They compare the new measure with an extensive set of existing metrics and use them to construct models that predict software faults. The case studies indicate that the novel measure captures different aspects of class cohesion compared to the existing cohesion measures and improves fault prediction for most metrics, which are combined with maximal weighted entropy. Yixun Liu, Denys Poshyvanyk, Rudolf Ferenc, Tibor Gyimóthy, Nikos Chrisochoides |
ICSM | 3 |
| 2009 | Using information retrieval based coupling measures for impact analysis
Denys Poshyvanyk, Andrian Marcus, Rudolf Ferenc, Tibor Gyimóthy |
Empir. Softw. Eng. | 3 |
| 2008 | Using the Conceptual Cohesion of Classes for Fault Prediction in Object-Oriented SystemsabstractHigh cohesion is a desirable property of software as it positively impacts understanding, reuse, and maintenance. Currently proposed measures for cohesion in Object-Oriented (OO) software reflect particular interpretations of cohesion and capture different aspects of it. Existing approaches are largely based on using the structural information from the source code, such as attribute references, in methods to measure cohesion. This paper proposes a new measure for the cohesion of classes in OO software systems based on the analysis of the unstructured information embedded in the source code, such as comments and identifiers. The measure, named the Conceptual Cohesion of Classes (C3), is inspired by the mechanisms used to measure textual coherence in cognitive psychology and computational linguistics. This paper presents the principles and the technology that stand behind the C3 measure. A large case study on three open source software systems is presented which compares the new measure with an extensive set of existing metrics and uses them to construct models that predict software faults. The case study shows that the novel measure captures different aspects of class cohesion compared to any of the existing cohesion measures. In addition, combining C3 with existing structural cohesion metrics proves to be a better predictor of faulty classes when compared to different combinations of structural cohesion metrics. Andrian Marcus, Denys Poshyvanyk, Rudolf Ferenc |
IEEE Trans. Software Eng. | 3 |
| 2007 | Clone Smells in Software EvolutionabstractAlthough source code cloning (copy&paste programming) represents a significant threat to the maintainability of a software system, problems usually start to arise only when the system evolves. Most of the related research papers tackle the question of finding code clones in one particular version of the software only, leaving the dynamic behavior of the clones out of consideration. Eliminating these clones in large software systems often seems absolutely hopeless, as there might exist several thousands of them. Alternatively, tracking the evolution of individual clones can be used to identify those occurrences that could really cause problems in the future versions. In this paper we present an approach for mapping clones from one particular version of the software to another one, based on a similarity measure. This mapping is used to define conditions under which clones become suspicious (or "smelly") compared to their other occurrences. Accordingly, these conditions introduce the notion of dynamic clone smells. The usefulness of these smells is validated on the Mozilla Firefox internet browser, where the approach was able to find specific bugs that resulted from neglecting earlier copy&paste activities. Tibor Bakota, Rudolf Ferenc, Tibor Gyimóthy |
ICSM | 2 |
| 2006 | Towards Portable Metrics-based Models for Software Maintenance ProblemsabstractThe usage of software metrics for various purposes has become a hot research topic in academia and industry (e.g. detecting design patterns and bad smells, studying change-proneness, quality and maintainability, predicting faults). Most of these topics have one thing in common: they are all using some kind of metrics-based models to achieve their goal. Unfortunately, only few researchers have tested these models on unknown software systems so far. This paper tackles the question, which metrics are suitable for preparing portable models (which can be efficiently applied to unknown software systems). We have assessed several metrics on four large software systems and we found that the well-known RFC and WMC metrics differentiate the analyzed systems fairly well. Consequently, these metrics cannot be used to build portable models, while the CBO, LCOM and LOC metrics behave similarly on all systems, so they seem to be suitable for this purpose Tibor Bakota, Rudolf Ferenc, Tibor Gyimóthy, Claudio Riva, Jianli Xu |
ICSM | 2 |
| 2005 | Design Pattern Mining Enhanced by Machine LearningabstractDesign patterns present good solutions to frequently occurring problems in object-oriented software design. Thus their correct application in a system's design may significantly improve its internal quality attributes such as reusability and maintainability. In software maintenance the existence of up-to-date documentation is crucial, so the discovery of as yet unknown design pattern instances can help improve the documentation. Hence a reliable design pattern recognition system is very desirable. However, simpler methods (based on pattern matching) may give imprecise results due to the vague nature of the patterns' structural description. In previous work we presented a pattern matching-based system using the Columbus framework with which we were able to find pattern instances from the source code by considering the patterns' structural descriptions only, and therefore we could not identify false hits and distinguish similar design patterns such as state and strategy. In the present work we use machine learning to enhance pattern mining by filtering out as many false hits as possible. To do so we distinguish true and false pattern instances with the help of a learning database created by manually tagging a large C++ system. Rudolf Ferenc, Árpád Beszédes, Lajos Jeno Fülöp, Janos Lele |
ICSM | 1 |
| 2005 | Empirical Validation of Object-Oriented Metrics on Open Source Software for Fault PredictionabstractOpen source software systems are becoming increasingly important these days. Many companies are investing in open source projects and lots of them are also using such software in their own work. But, because open source software is often developed with a different management style than the industrial ones, the quality and reliability of the code needs to be studied. Hence, the characteristics of the source code of these projects need to be measured to obtain more information about it. This paper describes how we calculated the object-oriented metrics given by Chidamber and Kemerer to illustrate how fault-proneness detection of the source code of the open source Web and e-mail suite called Mozilla can be carried out. We checked the values obtained against the number of bugs found in its bug database - called Bugzilla - using regression and machine learning methods to validate the usefulness of these metrics for fault-proneness prediction. We also compared the metrics of several versions of Mozilla to see how the predicted fault-proneness of the software system changed during its development cycle. Tibor Gyimóthy, Rudolf Ferenc, István Siket |
IEEE Trans. Software Eng. | 2 |
| 2004 | Fact Extraction and Code Auditing with Columbus and SourceAuditabstractAutomatic fact extraction from software systems is the fundamental building block in the process of understanding the relationships among a system's elements. We demonstrate the reverse engineering framework called Columbus which is able to automatically extract facts from C++ source code and how the extracted facts can be used in practice. We also mention a special-purpose tool that was developed on top of the Columbus framework. This tool, called SourceAudit, is a code auditor that is able to investigate source code and check it against rules that describe the preferred properties of the code. Rudolf Ferenc, Árpád Beszédes, Tibor Gyimóthy |
ICSM | 1 |
| 2004 | Extracting Facts from Open Source SoftwareabstractOpen source software systems are becoming increasingly important these days. Many companies are investing in open source projects and lots of them are also using such software in their own work. But because open source software is often developed without proper management, the quality and reliability of the code may be uncertain. The quality of the code needs to be measured and this can be done only with the help of proper tools. We describe a framework called Columbus with which we calculate the object oriented metrics validated by Basili et al. for illustrating how fault-proneness detection from the open source Web and e-mail suite called Mozilla can be done. We also compare the metrics of several versions of Mozilla to see how the predicted fault-proneness of the software system changed during its development. The Columbus framework has been further developed recently with a compiler wrapping technology that now gives us the possibility of automatically analyzing and extracting information from software systems without modifying any of the source code or makefiles. We also introduce our fact extraction process here to show what logic drives the various tools of the Columbus framework and what steps need to be taken to obtain the desired facts. Rudolf Ferenc, István Siket, Tibor Gyimóthy |
ICSM | 1 |
| 2003 | Mining Design Patterns from C++ Source CodeabstractDesign patterns are micro architectures that have proved to be reliable, easy-to implement and robust. There is a need in science and industry for recognizing these patterns. We present a new method for discovering design patterns in the source code. This method provides a precise specification of how the patterns work by describing basic structural information like inheritance, composition, aggregation and association, and as an indispensable part, by defining call delegation, object creation and operation overriding. We introduce a new XML-based language, the Design Pattern Markup Language (DPML), which provides an easy way for the users to modify pattern descriptions to suit their needs, or even to define their own patterns or just classes in certain relations they wish to find. We tested our method on four open-source systems, and found it effective in discovering design pattern instances. Zsolt Balanyi, Rudolf Ferenc |
ICSM | 2 |
| 2002 | Columbus - Reverse Engineering Tool and Schema for C++abstractOne of the most critical issues in large-scale software development and maintenance is the rapidly growing size and complexity of software systems. As a result of this rapid growth there is a need to better understand the relationships between the different parts of a large software system. In this paper we present a reverse engineering framework called Columbus that is able to analyze large C++ projects, and a schema for C++ that prescribes the form of the extracted data. The flexible architecture of the Columbus system with a powerful C++ analyzer and schema makes it a versatile and readily extendible toolset for reverse engineering. This tool is free for scientific and educational purposes and we fervently hope that it will assist academic persons in any research work related to C++ re- and reverse engineering. Rudolf Ferenc, Árpád Beszédes, Mikko Tarkiainen, Tibor Gyimóthy |
ICSM | 1 |