VLDB 2026 Research / reviewers in the wild / expert
John C. Grundy
dblp:g/JohnCGrundy · also John Grundy 0001
· DBLP profile ↗
401ranked-venue papers
33as first author
191since 2021 · last 2026
0000-0003-4928-7076ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 301 · 29 first-author · 158 since 2021Human-computer interaction and ubiquitous computing · 49 · 2 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 18 · 9 since 2021Databases, data management, data science and information retrieval · 16 · 2 first-author · 4 since 2021Systems, architecture and hardware · 14 · 1 first-author · 8 since 2021Artificial intelligence and machine learning · 6 · 3 since 2021Computer networks · 4 · 4 since 2021Security and privacy · 4 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | SSG: Logit-Balanced Vocabulary Partitioning for LLM WatermarkingabstractWatermarking has emerged as a promising technique for tracing the authorship of content generated by large language models (LLMs).Among existing approaches, the KGW scheme is particularly attractive due to its versatility, efficiency, and effectiveness in natural language generation.However, KGW's effectiveness degrades significantly under low-entropy settings such as code generation and mathematical reasoning.A crucial step in the KGW method is random vocabulary partitioning, which enables adjustments to token selection based on specific preferences.Our study revealed that the nexttoken probability distribution plays an critical role in determining how much, or even whether, we can modify token selection and, consequently, the effectiveness of watermarking.We refer to this characteristic, associated with the probability distribution of each token prediction, as watermark strength.In cases of random vocabulary partitioning, the lower bound of watermark strength is dictated by the nexttoken probability distribution.However, we found that, by redesigning the vocabulary partitioning algorithm, we can potentially raise this lower bound.In this paper, we propose SSG (Sort-then-Split by Groups), a method that partitions the vocabulary into two logit-balanced subsets.This design lifts the lower bound of watermark strength for each token prediction, thereby improving watermark detectability.Experiments on code generation and mathematical reasoning datasets demonstrate the effectiveness of SSG.The source code is available at https://github.com/AllenG-L/SSG. Chenxi Gu, Xiaoning Du 0001, John C. Grundy |
ACL (1) | 3 |
| 2026 | Fractured Awareness: Why Platform Privacy Systems Are Accepted More than They Are Understood
Omar Haggag, John C. Grundy, Mohan Baruwal Chhetri |
ENASE (1) | 2 |
| 2026 | Virtual Reality, Real Challenges: Lessons Learnt from a VR Deployment In-the-WildabstractVirtual Reality (VR) offers immersive, experiential learning experiences in computing education, however, its successful integration in classrooms require navigating a range of practical organizational and pedagogical challenges. This poster presents insights drawn from post-hoc educator interviews, and researcher reflections, who collaboratively deployed an 'in-the-wild' VR-based lesson in a higher education IT Professional Practice course. Our findings highlight several planning, logistical and class orchestration aspects that influence VR integration, rarely captured in controlled VR studies. We also draw attention to the importance of research aspects such as establishing partnerships with teaching teams, being flexible with classroom dynamics, educator safety and iterative refinements for sustainable VR integration. These findings can provide practical guidance for computing educators and researchers seeking to implement or study VR in authentic contexts. Ruchi Sembey, Roberto Martínez-Maldonado, John C. Grundy |
ITiCSE (2) | 3 |
| 2026 | VR immersion: An Experiential approach to teach Accessibility and Inclusion in Computing EducationabstractIn this paper, we present teaching material and resources designed as part of a research project aiming to investigate how computing educators operationalize the delivery of Virtual Reality (VR) based lessons to teach accessibility and inclusion in an undergraduate IT Professional Practice course in an Australian research-intensive university. The material, first employed across seven, 2-hour applied sessions in Semester 1, 2024, was offered to 390 students by a teaching team of 15 staff members and it has been iteratively refined and offered to 2350 students by 87 teachers over four semesters since then. In post-lesson interviews, educators perceived mixed impacts on student learning highlighting enhanced engagement and awareness alongside challenges related to uneven student reception and relevance. They commended the VR team's clear planning and hands?on support for enabling smooth in-class delivery. Ruchi Sembey, Roberto Martínez-Maldonado, John C. Grundy, Andrew Junor, Sadia Nawaz |
ITiCSE (2) | 3 |
| 2026 | Towards integrated dashboards for better management of human-centric issues in software development
Liam Todd, Kashumi Madampe, Hourieh Khalajzadeh, Mojtaba Shahin, John C. Grundy |
Autom. Softw. Eng. | 5 |
| 2026 | Understanding the influence of motivation on requirements engineering-related activitiesabstractAbstract Context: Requirements Engineering (RE)-related activities are critical in developing quality software and one of the most human-dependent processes in software engineering (SE). Hence, identifying the impact of diverse human-related aspects on RE is crucial in the SE context. Objective: Our study explores the impact of one of the most influential human aspects, motivation on RE, aiming to deepen understanding and provide practical guidance. Method: By conducting semi-structured interviews with 21 RE-involved practitioners, we developed a theory using socio-technical grounded theory (STGT) that explains the contextual, causal, and intervening conditions influencing motivation in RE-related activities. Result: We identified strategies to enhance motivating situations or mitigate demotivating ones, and the consequences resulting from applying these strategies. Conclusion: Our findings offer actionable insights for software practitioners to manage the influence of motivation on RE and help researchers further investigate its role across various SE contexts in the future. Dulaji Hidellaarachchi, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
Empir. Softw. Eng. | 2 |
| 2026 | User-centric requirements prioritization in mHealth applications: Insights from a Discrete Choice ExperimentabstractContext: Mobile health (mHealth) applications are widely used for chronic disease management, but usability and accessibility challenges persist due to the diverse needs of users. Adaptive User Interfaces (AUIs) offer a promising approach to personalizing interactions and improving user experience. However, their adoption remains limited, partly due to a lack of understanding of how users perceive and evaluate different adaptation strategies. Addressing this gap is crucial for advancing user-centered design and requirements engineering in software systems for health contexts. Objective: This study identifies key factors influencing user preferences and trade-offs in mHealth adaptation design. Method: A Discrete Choice Experiment (DCE) was conducted with 186 participants living with chronic conditions who regularly use mHealth applications. Each participant completed a series of choice tasks, selecting their preferred adaptation designs from scenarios composed of six attributes with varying levels. A mixed logit model was applied to examine preference heterogeneity. Subgroup analyses were also conducted to explore variations in preferences across age, gender, health condition, and coping mechanism. Results: Participants preferred adaptation designs that preserved usability, offered controllability, introduced changes infrequently, and applied small-scale modifications. Conversely, adaptations affecting frequently used functions and those involving caregiver input were generally viewed less favorably. These findings highlight key trade-offs that influence user acceptance of adaptive mHealth interfaces. Conclusion: This study employs a data-driven approach to quantify user preferences, identify key trade-offs, and reveal variations across demographic and behavioral subgroups through preference heterogeneity modeling. These insights provide actionable guidance for designing more user-centered adaptive interfaces and contribute to advancing requirements prioritization practices in software engineering—particularly in the context of health technologies. Wei Wang 0376, Hourieh Khalajzadeh, John C. Grundy, Anuradha Madugalla, Humphrey O. Obie |
Inf. Softw. Technol. | 3 |
| 2026 | An empirical study on low-code programming using traditional vs large language model support
Yongkun Liu, Jiachi Chen, Tingting Bi, John C. Grundy, Yanlin Wang 0001, Jianxing Yu, Ting Chen 0002, Yutian Tang, Zibin Zheng |
J. Syst. Softw. | 4 |
| 2026 | Designing Adaptive User Interfaces for mHealth Applications Targeting Chronic Disease: A User-Centered ApproachabstractMobile Health (mHealth) applications have demonstrated considerable potential in supporting chronic disease self-management; however, they remain underutilized due to low engagement, limited accessibility, and poor long-term adherence. These issues are particularly prominent among users with chronic disease, whose needs and capabilities vary widely. To address this, Adaptive User Interfaces (AUIs) offer a dynamic solution by tailoring interface features to users’ preferences, health status, and contexts. This article presents a two-stage study to develop and validate actionable AUI design guidelines for mHealth applications. In stage one , an AUI prototype was evaluated through focus groups, interviews, and a standalone survey, revealing key user challenges and preferences. These insights informed the creation of an initial set of guidelines. In stage two , the guidelines were refined based on feedback from 20 end users and evaluated by 43 software practitioners through two surveys. This process resulted in nine finalized guidelines. To assess real-world relevance, a case study of four mHealth applications was conducted, with findings supported by user reviews highlighting the utility of the guidelines in identifying critical adaptation issues. This study offers actionable, evidence-based guidelines that help software practitioners design AUI in mHealth to better support individuals managing chronic diseases. Wei Wang 0376, John C. Grundy, Hourieh Khalajzadeh, Anuradha Madugalla, Humphrey O. Obie |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2026 | RepoTransBench: A Real-World Multilingual Benchmark for Repository-Level Code TranslationabstractRepository-level code translation refers to translating an entire code repository from one programming language to another while preserving the functionality of the source repository. Many benchmarks have been proposed to evaluate the performance of such code translators. However, previous benchmarks mostly provide fine-grained samples, focusing at either code snippet, function, or file-level code translation. Such benchmarks do not accurately reflect real-world demands, where entire repositories often need to be translated, involving longer code length and more complex functionalities. To address this gap, we propose a new benchmark, named RepoTransBench, which is a real-world multilingual repository-level code translation benchmark featuring 1,897 real-world repository samples across 13 language pairs with automatically executable test suites. Besides, we introduce RepoTransAgent, a general agent framework to perform repository-level code translation. We evaluate both our benchmark’s challenges and agent’s effectiveness using several methods and backbone LLMs, revealing that repository-level translation remains challenging, where the best-performing method achieves only a 32.8% success rate. Furthermore, our analysis reveals that translation difficulty varies significantly by language pair direction, with dynamic-to-static language translation being much more challenging than the reverse direction (achieving below 10% vs. static-to-dynamic at 45-63%). Finally, we conduct a detailed error analysis and highlight current LLMs’ deficiencies in repository-level code translation, which could provide a reference for further improvements. We provide the code and data athttps://github.com/DeepSoftwareAnalytics/RepoTransBench. Yanli Wang 0001, Yanlin Wang 0001, Suiquan Wang, Daya Guo, Jiachi Chen, John C. Grundy, Xilin Liu 0001, Yuchi Ma, Mingzhi Mao, Hongyu Zhang 0002, Zibin Zheng |
IEEE Trans. Software Eng. | 6 |
| 2026 | Identifying and Mitigating API Misuse in Large Language ModelsabstractAPI misuse in code generated by large language models (LLMs) presents a serious and growing challenge in software development. While LLMs demonstrate impressive code generation capabilities, their interactions with complex library APIs are often error-prone, potentially leading to software failures and vulnerabilities. In this paper, we conduct a large-scale study of API misuse patterns in LLM-generated code, analyzing both method selection and parameter usage across Python and Java, using three representative LLMs (StarCoder-7B, Qwen2.5-Coder-7B, and GitHub Copilot). Based on extensive manual annotation of 3,209 method-level and 3,492 parameter-level misuses, we identify and categorize four recurring misuse types by building on and refining prior API misuse taxonomies. Our evaluation of three widely used LLMs, StarCoder-7B, Qwen2.5-Coder-7B, and GitHub Copilot, reveals persistent challenges in API usage, particularly hallucination and intent misalignment. To address these issues, we propose Dr.Fix, an LLM-based automatic repair approach guided by our taxonomy. Dr.Fix improves repair accuracy compared to baseline prompting and existing repair methods, with gains of up to 38.4 BLEU and 40% in exact match on benchmark datasets. This work offers important insights into the current limitations of LLMs in API usage and provides insights into current limitations and points to directions for improving automated misuse repair in code generation systems. Terry Yue Zhuo, Junda He, Jiamou Sun, Zhenchang Xing, David Lo 0001, John C. Grundy, Xiaoning Du 0001 |
IEEE Trans. Software Eng. | 6 |
| 2025 | Understanding VR Accessibility Practices of VR ProfessionalsabstractAccessibility is a crucial concept in Virtual Reality (VR), pivotal for meeting the needs of users, including those with disabilities.In recent years, there has been an increasing focus of VR products on enhancing the accessibility of a diverse range of digital content.Despite this growing attention from the VR community, there is a serious lack of empirical research on how VR practitioners consider VR accessibility.This includes their understanding of and insights into VR accessibility challenges and practices in the VR software development life cycle.In this paper, we aim to address these gaps using a mixed-methods approach.Specifically, we conducted interviews with 21 VR practitioners (incl.3D modelers, developers, technical directors, and product managers) and surveyed 202 VR practitioner respondents from VR-related industries.Our findings outline the insights and challenges they face concerning VR accessibility practices in the software development life cycle.Furthermore, our findings shed light on the challenges faced by practitioners concerning VR accessibility and the reasons why it often goes unconsidered.As far as we know, this is the first comprehensive report about the understanding of accessibility in the VR software development life cycle from practitioners' perspectives.We hope this paper will help VR practitioners better understand the practices, challenges, and potential solutions related to VR accessibility. Yi Wang 0119, Xiao Liu 0004, Chetan Arora 0002, John C. Grundy, Thuong N. Hoang |
CHI | 4 |
| 2025 | Understanding Students' Experience and Perception of Gender Bias in a Software Engineering Education EnvironmentabstractThe Software Engineering (SE) workforce is still man-dominated, and there are still fewer women students graduating from Computer Science/Software Engineering (CS/SE) courses in most countries. Two major reasons are fewer women enrolling in CS/SE courses and a lower percentage of those women who enrolled completing courses. We wanted to investigate the second reason - the experiences of students within the CS/SE education environment to identify key issues that need improvement to increase women student recruitment and completion. We interviewed 18 CS / SE students to explore their experiences. We requested they review selected SE education content to understand the perception of gender diversity within the SE education environment. Our findings indicate that many women students feel excluded by several behavioural aspects of their fellow men students, as well as by some teachers. We found that gender-biased language and stereotypical images make women students feel more excluded. From the experiences and opinions of our participants, we propose recommendations for higher education CS/SE teachers, universities and researchers to improve gender inclusion in SE teaching environments. Tanjila Kanij, Jonny Low, John C. Grundy |
CSEE&T | 3 |
| 2025 | How Are We Doing With Using AI-Based Programming Assistants For Privacy-Related Code Generation? The Developers' ExperienceabstractWith generative AI becoming widespread, the existence of AI-based programming assistants for developers is no surprise. Developers increasingly use them for their work, including generating code to fulfil the data protection requirements (privacy) of the apps they build. We wanted to know if the reality is the same as expectations of AI-based programming assistants when trying to fulfil software privacy requirements, and the challenges developers face when using AI-based programming assistants and how these can be improved. To this end, we conducted a survey with 51 professional developers worldwide. We found that AI-based programming assistants need to be improved in order for developers to better trust them with generating code that ensures privacy. In this paper, we provide some recommendations including model and system-level improvements and some key further research directions to improve AI-based programming assistants for developing secure code. Kashumi Madampe, John C. Grundy, Nalin Arachchilage |
EASE | 2 |
| 2025 | A User-Centered Design Approach to Develop a Privacy Awareness Application
Anika Tabassum Era, Tanjila Kanij, John C. Grundy, Md. Al Mamun |
ENASE | 3 |
| 2025 | An Innovative Approach to Represent Tacit Knowledge of Fishing with Knowledge Graphs
Tanjila Kanij, Shafia Husna, Afzal Azeem Chowdhary, Misita Anwar, Md Khalid Hossain, John C. Grundy |
ENASE | 6 |
| 2025 | Automated Test Generation For Smart Contracts via On-Chain Test Case Augmentation and MigrationabstractPre-deployment testing has become essential to ensure the functional correctness of smart contracts. However, since smart contracts are stateful programs integrating many different functionalities, manually writing test cases to cover all potential usages requires significant effort from developers, leading to insufficient testing and increasing risks in practice. Although several testing techniques for smart contracts have been proposed, they primarily focus on detecting common low-level vulnerabilities such as re-entrancy, rather than generating expressive and function-relevant test cases that can reduce manual testing efforts. To bridge the gap, we propose Solmigrator, an automated technique designed to generate expressive and representative test cases for smart contracts. To our knowledge, Solmigrator is the first migration-based test generation technique for smart contracts, which extracts test cases from real-world usages of on-chain contracts and migrates them to test newly developed smart contracts with similar functionalities. Given a target smart contract to be tested and an on-chain similar source smart contract, Solmigrator first transforms the on-chain usage of the source contract into off-chain executable test cases based on on-chain transaction replay and dependency analysis. It then employs fine-grained static analysis to migrate the augmented test cases from the source to the target smart contract. We built a prototype of Solmigrator and have evaluated it on real-world smart contracts within the two most popular categories, ERC20 and ERC721. Our evaluation results demonstrate that Solmigrator effectively extracts test cases from existing on-chain smart contracts and accurately migrates them across different smart contracts, achieving an average precision of 96.3% and accuracy of 93.6%. Furthermore, the results indicate that these migrated test cases effectively cover common key functionalities of the target smart contracts. This provides promising evidence that real-world usages of existing smart contracts can be transformed into effective test cases for other newly developed smart contracts. Jiashuo Zhang 0001, Jiachi Chen, John C. Grundy, Jianbo Gao 0003, Yanlin Wang 0001, Ting Chen 0002, Zhi Guan, Zhong Chen 0001 |
ICSE | 3 |
| 2025 | Understanding Practitioners' Perspectives on Monitoring Machine Learning SystemsabstractGiven the inherent non-deterministic nature of machine learning (ML) systems, their behavior in production environments can lead to unforeseen and potentially dangerous outcomes. For a timely detection of unwanted behavior and to prevent organizations from financial and reputational damage, monitoring these systems is essential. This paper explores the strategies, challenges, and improvement opportunities for monitoring ML systems from the practitioners' perspective. We conducted a global survey of 91 ML practitioners to collect diverse insights into current monitoring practices for ML systems. We aim to complement existing research through our qualitative and quantitative analyses, focusing on prevalent runtime issues, industrial monitoring and mitigation practices, key challenges, and desired enhancements in future monitoring tools. Our findings reveal that practitioners frequently struggle with runtime issues related to declining model performance, exceeding latency, and security violations. While most prefer automated monitoring for its increased efficiency, many still rely on manual approaches due to the complexity or lack of appropriate automation solutions. Practitioners report that the initial setup and configuration of monitoring tools is often complicated and challenging, particularly when integrating with ML systems and setting alert thresholds. Moreover, practitioners find that monitoring adds extra workload, strains resources, and causes alert fatigue. The desired improvements from the practitioners' perspective are: automated generation and deployment of monitors, improved support for performance and fairness monitoring, and recommendations for resolving runtime issues. These insights offer valuable guidance for the future development of ML monitoring tools that are better aligned with practitioners' needs. Hira Naveed, John C. Grundy, Chetan Arora 0002, Hourieh Khalajzadeh, Omar Haggag |
ICSME | 2 |
| 2025 | IntentContinuum: Using LLMs to Support Intent-Based Computing Across the Compute ContinuumabstractThe increasing proliferation of loT devices and AI applications has created a demand for scalable and efficient computing solutions, particularly for applications requiring real-time processing. The compute continuum integrates edge and cloud resources to meet this need, balancing the low-latency demands of the edge with the high computational power of the cloud. However, managing resources in such a distributed environment presents challenges due to the diversity and complexity of these systems. Traditional resource management methods, often relying on heuristic algorithms, struggle to manage the increasing complexity, scale, and dynamics of these systems, as well as adapt to dynamic workloads and changing network conditions. Moreover, designing such approaches is often time-intensive and highly tailored to specific applications, demanding deep expertise. In this paper, we introduce a novel framework for intent-driven resource management in the compute continuum, using large language models (LLMs) to help automate decision-making processes. Our framework ensures that user-defined intents - such as achieving the required response times for time-critical applications - are consistently fulfilled. In the event of an intent violation, our system performs root cause analysis by examining system data to identify and address issues. This approach reduces the need for human intervention and enhances system reliability, offering a more dynamic and efficient solution for resource management in distributed environments. Negin Akbari, John C. Grundy, Muhammad Aamir Cheema, Adel Nadjaran Toosi |
ICWS | 2 |
| 2025 | A comparative study between android phone and TV apps
Yonghui Liu 0001, Xiao Chen 0002, Yue Liu 0011, Pingfan Kong, Tegawendé F. Bissyandé, Jacques Klein, Xiaoyu Sun 0002, Li Li 0029, Chunyang Chen 0001, John C. Grundy |
Autom. Softw. Eng. | 10 |
| 2025 | EmoReflex: an AI-powered emotion-centric developer insights platformabstractAbstract There has been great interest in better understanding software engineer emotions during development. But how to do this? We built a prototype AI-powered Emotion-centric Developer Insights Platform, EmoReflex, to support developers to report and reflect how they feel when working on various tasks across different metrics. It also assists their managers to get insights into their team’s emotional health, and provides them with recommendations to guide them handle the team’s emotional wellbeing. We present our tool prototype and evaluation results generated by a user study conducted with two user groups consisting of twenty developers and twenty managers. We present some design implications derived from our user study that can be used to inform design decisions in emotion-centric software development tools. Kashumi Madampe, John C. Grundy, Ellen Welstead-Cloud, Vinh Tuan Huynh, Linh Doan, William Lay, Sayed Hashim |
Autom. Softw. Eng. | 2 |
| 2025 | Adaptive and accessible user interfaces for seniors through model-driven engineeringabstractAbstract The use of diverse mobile applications among senior users is becoming increasingly widespread. However, many of these apps contain accessibility problems that result in negative user experiences for seniors. A key reason is that software practitioners often lack the time or resources to address the broad spectrum of age-related accessibility and personalisation needs. As current developer tools and practices encourage one-size-fits-all interfaces with limited potential to address the diversity of senior needs, there is a growing demand for approaches that support the systematic creation of adaptive, accessible app experiences. To this end, we present AdaptForge , a novel model-driven engineering (MDE) approach that enables advanced design-time adaptations of mobile application interfaces and behaviours tailored to the accessibility needs of senior users. AdaptForge uses two domain-specific languages (DSLs) to address age-related accessibility needs. The first model defines users’ context-of-use parameters, while the second defines conditional accessibility scenarios and corresponding UI adaptation rules. These rules are interpreted by an MDE workflow to transform an app’s original source code into personalised instances. We also report evaluations with professional software developers and senior end-users, demonstrating the feasibility and practical utility of AdaptForge . Shavindra Wickramathilaka, John C. Grundy, Kashumi Madampe, Omar Haggag |
Autom. Softw. Eng. | 2 |
| 2025 | Engineering support for adaptations in information graphics for disabled communities: A study with public space indoor mapsabstractAbstract Most software applications contain graphics such as charts, diagrams and maps. Currently, these graphics are designed with a “one size fits all" approach and do not cater to the needs of people with disabilities. Therefore, when using software with graphics, a colour-impaired user may struggle to interpret graphics with certain colours, and a person with dyslexia may struggle to read the text labels in the graphic. Our research addresses this issue by developing a framework that generates adaptive and accessible information graphics for multiple disabilities. Uniquely, the approach also serves people with multiple simultaneous disabilities. To achieve these, we used a case study of public space floorplans presented via a web tool and worked with four disability groups: people with low vision, colour blindness, dyslexia and mobility impairment. Our research involved gathering requirements from 3 accessibility experts and 80 participants with disabilities, developing a system to generate adaptive graphics that address the identified requirements, and conducting an evaluation with a total of 99 participants with disabilities. The evaluation showed that users found our solution easy to use and suitable for most of their requirements. The study also provides recommendations for front-end developers on engineering accessible graphics for their software and discusses the implications of our work on society from the perspective of public space owners and end users. Anuradha Madugalla, Yutan Huang, John C. Grundy, Min Hee Cho, Lasith Koswatta Gamage, Y. P. Lau, Tristan Leao, Sam Thiele |
Empir. Softw. Eng. | 3 |
| 2025 | An analysis of privacy regulations and user concerns of finance mobile applicationsabstractContext: Financial applications handle sensitive data, including personal details, banking information, and transaction histories, making them prime targets for cyber-attacks. As privacy concerns grow, users and regulators are increasingly analyzing how these apps manage data in different legal contexts. Objective: This study examines user privacy concerns and assesses the impact of privacy regulations on mobile financial applications in Germany, Australia, and the United States. It aims to evaluate how laws such as the GDPR in the EU, the Privacy Act in Australia, and various U.S. state and federal laws shape app privacy policies. Additionally, the study explores the readability and accessibility of privacy policies. Methods: User reviews from app stores were analyzed to identify recurring privacy issues and regional differences in concerns. The study also reviewed privacy laws in the EU, Australia, and the U.S. to assess their influence on financial app policies. To analyze the user-friendliness of privacy documents, a readability analysis was conducted using the Flesch Reading Ease score and estimated reading times. Results: The findings revealed that users are highly concerned about the handling of their data, with significant demand for greater transparency and more robust privacy protections. Regional differences in privacy concerns were identified, with varying levels of engagement with privacy issues in each region. The study also found significant discrepancies in the readability of privacy policies, with many policies proving too complex for the average user to understand. Conclusion: The study concludes that financial app developers need to simplify their privacy policies and improve transparency to build user trust. It also emphasizes the need for stronger regulatory frameworks to address evolving privacy challenges. Recommendations are made for developers and policymakers to enhance data protection and improve user experience in financial services. Omar Haggag, Alessandro Pedace, Shidong Pan, John C. Grundy |
Inf. Softw. Technol. | 4 |
| 2025 | Accessibility of low-code approaches: A systematic literature reviewabstractModel-driven approaches are increasingly used in different domains, such as education, finance and app development, in order to involve non-developers in the software development process. Such tools are hugely dependent on visual elements and thus might not be accessible for users with specific challenges, e.g., visual impairments. To locate and analyse existing literature on the accessibility of low-code approaches, their strengths and weaknesses and key directions for future research. We carried out a systematic literature review and searched through five leading databases for primary studies. We used both quantitative and qualitative methods for data synthesis. After reviewing and filtering 918 located studies, and conducting both backward and forward snowballing, we identified 38 primary studies that were included in our analysis. We found most papers focusing on accessibility of visual languages and block-based programming. Limited work has been done on improving low code programming environment accessibility. The findings of this systematic literature review will assist researchers and developers in understanding the accessibility issues in low-code approaches and what has been done so far to develop accessible approaches. Hourieh Khalajzadeh, John C. Grundy |
Inf. Softw. Technol. | 2 |
| 2025 | Who uses personas in requirements engineering: The practitioners' perspectiveabstractContext: Personas are commonly employed in software projects to better understand end-users needs. Despite their frequent usage, there is a limited understanding of their practical application and effectiveness. Objective: This paper aims to investigate the current practices, methods, and challenges associated with using personas in software development. Methods: A two-step investigation was conducted, comprising interviews with 26 software developers, UI/UX designers, business analysts, and product managers, along with a survey of 203 practitioners. Results: The findings reveal variations in the frequency and effectiveness of personas across different software projects and IT companies. Additionally, the study highlights the challenges practitioners face when using personas and the reasons for not using them. Notably, the research shows that some human aspects (e.g., the needs of users with disabilities), often assumed to be a key feature of personas, are frequently not considered for various reasons in requirements engineering. Conclusions: The study provides actionable insights for practitioners to overcome challenges in using personas during the requirements engineering stages. Furthermore, it identifies areas for future research to enhance the effectiveness of personas in software development. Yi Wang 0119, Chetan Arora 0002, Xiao Liu 0004, Thuong N. Hoang, Vasudha Malhotra, Ben Cheng, John C. Grundy |
Inf. Softw. Technol. | 7 |
| 2025 | Requirements engineering for older adult digital health software: A systematic literature reviewabstractGrowth of the older adult population has led to an increasing interest in technology-supported aged care. However the area has some challenges such as lack of care givers and limitations in understanding the emotional, social, physical, and mental well-being needs of older adults. Furthermore, there is a gap in the understanding between younger developers and ageing people of their requirements from digital systems. Digital health can play an important role supporting older adults’ well-being, emotional requirements, and social needs. We carried out a systematic review of the literature on RE for older adult digital health software. This was necessary to show the representatives of the current stage of understanding the needs of older adults in aged care digital health. Using established guidelines we developed a protocol, followed by the systematic search of eight databases. This resulted in 69 primary studies of high relevance, which were subsequently subjected to data extraction, synthesis, and reporting. This systematic literature review highlights key RE processes used in digital health software for older people. It explored the key features developed for many digital solutions, utilization of technology for older user well-being and care, and the evaluations of proposed solutions. The review also identified key limitations found in existing primary studies that inspire future research opportunities. Our results indicate that requirements gathering and understanding have a significant variation between different studies. The differences are in the quality, depth, and techniques adopted for requirement gathering and this reason for these differences is largely due to uneven adoption of RE methods. John C. Grundy, Anuradha Madugalla |
Inf. Softw. Technol. | 2 |
| 2025 | Managing technical debt in a multidisciplinary data intensive software team: An observational case studyabstractContext: There is an increase in the investment and development of data-intensive (DI) solutions — systems that manage large amounts of data. Without careful management, this growing investment will also grow associated technical debt (TD). Delivery of DI solutions requires a multidisciplinary skill set, but there is limited knowledge about how multidisciplinary teams develop DI systems and manage TD. Objective: This research contributes empirical, practice based insights about multidisciplinary DI team TD management practices. Method: This research was conducted as an exploratory observation case study . We used socio-technical grounded theory (STGT) for data analysis to develop concepts and categories that articulate TD and TDs debt management practices. Results: We identify TD that the DI team deals with, in particular technical data components debt and pipeline debt. We explain how the team manages the TD, assesses TD, what TD treatments they consider and how they implement TD treatments to fit sprint capacity constraints. Conclusion: We align our findings to existing TD and TDM taxonomies, discuss their implications and highlight the need for new implementation patterns and tool support for multidisciplinary DI teams. Ulrike Maria Graetsch, Rashina Hoda, Hourieh Khalajzadeh, Mojtaba Shahin, John C. Grundy |
J. Syst. Softw. | 5 |
| 2025 | The role of humour in software engineering - A literature review and preliminary taxonomyabstractHumour has long been recognized as a key factor in enhancing creativity, group effectiveness, and employee well-being across various domains. However, its occurrence and impact within software engineering (SE) teams remains under-explored. This paper introduces a comprehensive, literature review-based taxonomy exploring the characterisation and use of humour in SE teams, with the goal of boosting productivity, improving communication, and fostering a positive work environment while emphasising the responsible use of humour to mitigate its potential negative impacts. Drawing from a wide array of studies in psychology, sociology, and organizational behavior, our proposed framework categorizes humour into distinct theories, styles, models, and scales, offering SE professionals and researchers a structured approach to understanding humour in their work. This study also addresses the unique challenges of applying humour in SE, highlighting its potential benefits while acknowledging the need for further empirical validation in this context. Ultimately, our study aims to pave the way for more cohesive, creative, and psychologically supportive SE environments through the strategic use of humour. Dulaji Hidellaarachchi, John C. Grundy, Rashina Hoda |
J. Syst. Softw. | 2 |
| 2025 | Assessing gender bias in the software used in computer science and software engineering educationabstractWomen are underrepresented in Computer Science (CS)/ Software Engineering (SE) and other technology related degrees. As undergraduates, they are also less likely to persist with CS/SE studies than men enrolled in those same courses. Gender correlated differences in personal characteristics, behaviour, and preferences mean that course design decisions may introduce unintended bias. To address this issue, we drew inspiration from the GenderMag method. GenderMag uses personas with evidence-based gender differences in problem-solving traits to detect usability issues in software. In this paper we investigate the personal qualities of CS and SE students, and how these influence their CS/SE learning journey. A series of persona development workshops were held to gather an extensive and unique qualitative dataset capturing the prior experiences, preferences, learning styles, motivations, goals, frustrations, and constraints of CS/SE students. Gender differences were used to construct preliminary male and female student personas. These personas were used in cognitive walkthroughs of software applications commonly used in education, and their performance compared to GenderMag’s Tim and Abi. While the student personas were less effective and lacked specificity compared to Abi, they were able to identify issues not detectable with GenderMag. Furthermore, the findings show the utility of persona development workshops as a data collection method and introduce a comprehensive list of CS/SE student qualities that may inspire future investigations. • Identified differences in learning styles, motivations, goals, and frustrations. • Developed male and female CS/SE student persona. • Successful application of GenderMag with new personas on education software. • New personas could detect issues that existing GenderMag personas overlooked. • New CS/SE student persona can complement GenderMag persona. Lyndsey O'brien, Tanjila Kanij, John C. Grundy |
J. Syst. Softw. | 3 |
| 2025 | A cross-continental analysis of how regional cues shape top stack overflow contributors
Elijah Zolduoarrati, Sherlock A. Licorish, John C. Grundy |
J. Syst. Softw. | 3 |
| 2025 | Privacy Bills of Materials (PriBOM): A Transparent Privacy Information Inventory for Collaborative Privacy Notice Generation in Mobile App DevelopmentabstractPrivacy regulations mandate that developers must provide authentic and comprehensive privacy notices, e.g., privacy policies or labels, to inform users of their apps’ privacy practices. However, due to a lack of knowledge of privacy requirements, developers often struggle to create accurate privacy notices, especially for sophisticated mobile apps with complex features and in crowded development teams. To address these challenges, we introduce PriBOM (Privacy Bills of Materials), a systematic software engineering approach that leverages different development team roles to better capture and coordinate mobile app privacy information. PriBOM facilitates transparency-centric privacy documentation and specific privacy notice creation, enabling traceability and trackability of privacy practices. We present a pre-fill of PriBOM based on static analysis and privacy notice analysis techniques. We explore the perceived usefulness of PriBOM through a human evaluation with 150 diverse participants. The role of PriBOM in enhancing privacy-related communication is well received with 83.33% agreement, suggesting that PriBOM could serve as a significant solution for providing privacy support in DevOps for mobile apps. Zhen Tao 0001, Shidong Pan, Zhenchang Xing, Xiaoyu Sun 0002, Omar Haggag, John C. Grundy, Liming Zhu 0001 |
Proc. Priv. Enhancing Technol. | 6 |
| 2025 | Software Engineering by and for Humans in an AI EraabstractThe landscape of software engineering is undergoing a transformative shift driven by advancements in machine learning, Artificial Intelligence (AI), and autonomous systems. This roadmap article explores how these technologies are reshaping the field, positioning humans not only as end users but also as critical components within expansive software ecosystems. We examine the challenges and opportunities arising from this human-centered paradigm, including ethical considerations, fairness, and the intricate interplay between technical and human factors. By recognizing humans at the heart of the software lifecycle—spanning professional engineers, end users, and end user developers—we emphasize the importance of inclusivity, human-aligned workflows, and the seamless integration of AI-augmented socio-technical systems. As software systems evolve to become more intelligent and human-centric, software engineering practices must adapt to this new reality. This article provides a comprehensive examination of this transformation, outlining current trends, key challenges, and opportunities that define the emerging research and practice landscape, and envisioning a future where software engineering and AI work synergistically to place humans at the core of the ecosystem. Silvia Abrahão, John C. Grundy, Mauro Pezzè, Margaret-Anne D. Storey, Damian A. Tamburri |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2025 | Demystifying React Native Android Apps for Static AnalysisabstractReact Native, an open source framework, simplifies cross-platform app development by allowing JavaScript-side code to interact with native-side code. Previous studies disregarded React Native, resulting in insufficient static analysis of React Native app code. This study initiates the investigation of challenges when statically analyzing React Native apps. We propose ReuNify to improve Soot-based static analysis coverage for JavaScript-side and native-side code. ReuNify converts Hermes bytecode to Soot’s intermediate representation. Hermes bytecode, compiled from JavaScript code and integrated into React Native apps, possesses a unique syntax that eludes current JavaScript analyzers. Additionally, we investigate opcode distribution and conduct in-depth analyses of the usage of opcode between popular apps and malware. We also propose a benchmark consisting of 97 control flow-related cases to validate the control flow recovery of the generated intermediate representation. Furthermore, we model the cross-language communication mechanisms of React Native to expand the static analysis coverage for native-side code. Our evaluation demonstrates that ReuNify enables an average increase of 84% in reached nodes within the callgraph and further identifies an average of two additional privacy leaks in taint analysis. In summary, this article demonstrates that ReuNify significantly improves the static analysis for the React Native Android apps. Yonghui Liu 0001, Xiao Chen 0002, Jordan Samhi, John C. Grundy, Chunyang Chen 0001, Li Li 0029 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2025 | Better Supporting Human Aspects in Mobile eHealth Apps: Development and Validation of Enhanced GuidelinesabstracteHealth apps are mobile apps that help in self-management of critical illnesses, provide home-based disease management, and assist with personalized care through education, sensing, and interaction. Users of eHealth apps are naturally very diverse in terms of their human aspects, e.g., their emotional reactions to the apps, varying language proficiency, socioeconomic status, educational level, cognitive style, physical and mental challenges, gender, age, and personality. Unfortunately, many eHealth apps do not take these user differences sufficiently into account, making them ineffective or even unusable. This article presents our enhanced and actionable guidelines developed to better support human aspects in mobile eHealth apps. Some of these guidelines are specific, such as collecting minimal personal data or requirements, while others are more generic, applicable specifically to eHealth apps. We discuss how key human aspects, such as usability, accessibility, reliability, and validity, as well as diverse user issues can be addressed in practice with real-life eHealth app examples. We then collected feedback from expert mobile app developers, software engineers, and other relevant eHealth app stakeholders to assess the usefulness and applicability of the proposed guidelines and to identify areas where further refinement and development are needed. Md. Shamsujjoha, John C. Grundy, Qinghua Lu 0001, Hourieh Khalajzadeh, Li Li 0029 |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2025 | Manifestations of Empathy in Software Engineering: How, Why, and When It MattersabstractEmpathy plays a crucial role in software engineering (SE), influencing collaboration, communication, and decision-making. While prior research has highlighted the importance of empathy in SE, there is limited understanding of how empathy manifests in SE practice, what motivates SE practitioners to demonstrate empathy, and the factors that influence empathy in SE work. Our study explores these aspects through 22 interviews and a large scale survey with 116 software practitioners. Our findings provide insights into the expression of empathy in SE, the drivers behind empathetic practices, SE activities where empathy is perceived as useful or less relevant, and the other factors that influence empathy. In addition, we offer practical implications for SE practitioners and researchers, offering a deeper understanding of how to effectively integrate empathy into SE processes. Hashini Gunatilake, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
IEEE Trans. Software Eng. | 2 |
| 2024 | iContinuum: An Emulation Toolkit for Intent-Based Computing Across the Edge-to-Cloud ContinuumabstractThe Internet of Things (IoT) has led to a surge in smart devices, generating vast volumes of data. Cloud computing offers scalability but does not suffice for many real-time and privacy-sensitive IoT applications. This limitation has prompted a blend of both edge and cloud resources, creating the need for seamless integration, known as the “compute continuum“. Testing applications and resource management techniques within this continuum is vital but can be very complex. Simulation and emulation are preferred methods, with emulation providing more accurate representations of real-world environments. In this paper, we introduce iContinuum, a novel emulation toolkit facilitating an intent-based platform for edge-to-cloud testing and experimentation. Leveraging Software-Defined Networking (SDN) and containerization, iContinuum enables experimentation and performance evaluation while aligning application requirements with actual performance. We present our detailed architecture, implementation, and evaluation of iContinuum, showcasing how our proposed toolkit bridges the gap between simulation and real-world deployment within compute continuum environments, and further demonstrate the effectiveness of Intent-Based Scheduling through a specific use case. Negin Akbari, Adel Nadjaran Toosi, John C. Grundy, Hourieh Khalajzadeh, Mohammad Sadegh Aslanpour, Shashikant Ilager |
CLOUD | 3 |
| 2024 | GustosonicSense: Towards understanding the design of playful gustosonic eating experiencesabstractThe pleasure that often comes with eating can be further enhanced with intelligent technology, as the field of human-food interaction suggests. However, knowledge on how to design such pleasure-supporting eating systems is limited. To begin filling this knowledge gap, we designed “GustosonicSense”, a novel gustosonic eating system that utilizes wireless earbuds for sensing different eating and drinking actions with a machine learning algorithm and trigger playful sounds as a way to facilitate pleasurable eating experiences. We present the findings from our design and a study that revealed how we can support the "stimulation", "hedonism", and "reflexivity" for playful human-food interactions. Ultimately, with our work, we aim to support interaction designers in facilitating playful experiences with food. Yan Wang 0057, Humphrey O. Obie, Zhuying Li 0001, Flora D. Salim, John C. Grundy, Florian 'Floyd' Mueller |
CHI | 5 |
| 2024 | An Analysis of Privacy Issues and Policies of eHealth AppsabstractAn Analysis of Privacy Issues and Policies of eHealth Apps Omar Haggag, John C. Grundy, Mohamed Almorsy |
ENASE | 2 |
| 2024 | Towards Enhancing Mobile App Reviews: A Structured Approach to User Review Entry, Analysis and VerificationabstractWe propose an approach to address the shortcomings of current mobile app review systems on platforms such as the Apple App Store and Google Play. Currently, these platforms lack review categorisation and authentication of genuine user feedback, posing significant barriers for app developers and users. We propose an approach combining socio-technical grounded theory (STGT) and advanced natural language processing (NLP) tools such as GPT-4 to analyse user reviews, providing deeper insights into app functionalities, problems, and ultimately, user satisfaction. An interactive UI prototype is presented to demonstrate the use of structured, verified feedback. This includes a novel review submission process with categorisation/tagging and a”verified download” tag to ensure review authenticity. The goal of our approach is to enhance the app ecosystem by assisting developers in prioritising improvements and enabling users to make informed choices, encouraging a more robust and user-centric digital marketplace. Omar Haggag, John C. Grundy, Rashina Hoda |
ENASE | 2 |
| 2024 | Unlocking Adaptive User Experience with Generative AIabstractDeveloping user-centred applications that address diverse user needs requires rigorous user research. This is time, effort and cost-consuming. With the recent rise of generative AI techniques based on Large Language Models (LLMs), there is a possibility that these powerful tools can be used to develop adaptive interfaces. This paper presents a novel approach to develop user personas and adaptive interface candidates for a specific domain using ChatGPT. We develop user personas and adaptive interfaces using both ChatGPT and a traditional manual process and compare these outcomes. To obtain data for the personas we collected data from 37 survey participants and 4 interviews in collaboration with a not-for-profit organisation. The comparison of ChatGPT generated content and manual content indicates promising results that encourage using LLMs in the adaptive interfaces design process. Yutan Huang, Tanjila Kanij, Anuradha Madugalla, Shruti Mahajan, Chetan Arora 0002, John C. Grundy |
ENASE | 6 |
| 2024 | CRAFTER: A Persona Generation Tool for Requirements EngineeringabstractPersonas, a user characterisation, have been widely used in requirements engineering (RE) to enhance the understanding of end-users and their needs. However, the persona generation process is time-consuming and demands familiarity with a user-centered approach. The central issue lies in existing tools for automatically generating personas, which are restricted to generating persona templates and provide limited user control to tailor personas according to their specific needs. This paper introduces CRAFTER, a persona generation tool that uses Large Language Models (GPT-3.5 model). This tool not only automates persona creation but also offers recommendations to users for generating personas tailored to their requirements. The study involved an online questionnaire with 19 respondents who utilised the tool, providing feedback that indicated the tool’s sufficiency for persona generation while identifying areas for improvement. Beyond its primary function, CRAFTER stands out by providing guidance to requirements engineers throughout the persona creation process. The tool grants users the flexibility to customise personas based on their specific requirements, acknowledging the crucial human subjectivity in persona development. Additionally, CRAFTER promotes persona reusability, allowing users to save and reuse generated personas for future projects. Devi Karolita, John C. Grundy, Tanjila Kanij, Humphrey O. Obie, Jennifer McIntosh 0001 |
ENASE | 2 |
| 2024 | Identifying Smart Contract Security Issues in Code Snippets from Stack OverflowabstractSmart contract developers frequently seek solutions to developmental challenges on Q&A platforms such as Stack Overflow (SO). Although community responses often provide viable solutions, the embedded code snippets can also contain hidden vulnerabilities. Integrating such code directly into smart contracts may make them susceptible to malicious attacks. We conducted an online survey and received 74 responses from smart contract developers. The results of this survey indicate that the majority (86.4%) of participants do not sufficiently consider security when reusing SO code snippets. Despite the existence of various tools designed to detect vulnerabilities in smart contracts, these tools are typically developed for analyzing fully-completed smart contracts and thus are ineffective for analyzing typical code snippets as found on SO. We introduce SOChecker, the first tool designed to identify potential vulnerabilities in incomplete SO smart contract code snippets. SOChecker first leverages a fine-tuned Llama2 model for code completion, followed by the application of symbolic execution methods for vulnerability detection. Our experimental results, derived from a dataset comprising 897 code snippets collected from smart contract-related SO posts, demonstrate that SOChecker achieves an F1 score of 68.2%, greatly surpassing GPT-3.5 and GPT-4 (20.9% and 33.2% F1 Scores respectively). Our findings underscore the need to improve the security of code snippets from Q&A websites. Jiachi Chen, Chong Chen 0002, John C. Grundy, Yanlin Wang 0001, Ting Chen 0002, Zibin Zheng |
ISSTA | 4 |
| 2024 | Model-less Is the Best Model: Generating Pure Code Implementations to Replace On-Device DL ModelsabstractRecent studies show that on-device deployed deep learning (DL) models, such as those of Tensor Flow Lite (TFLite), can be easily extracted from real-world applications and devices by attackers to generate many kinds of adversarial and other attacks. Although securing deployed on-device DL models has gained increasing attention, no existing methods can fully prevent these attacks. Traditional software protection techniques have been widely explored. If on-device models can be implemented using pure code, such as C++, it will open the possibility of reusing existing robust software protection techniques. However, due to the complexity of DL models, there is no automatic method that can translate DL models to pure code. To fill this gap, we propose a novel method, CustomDLCoder, to automatically extract on-device DL model information and synthesize a customized executable program for a wide range of DL models. CustomDLCoder first parses the DL model, extracts its backend computing codes, configures the extracted codes, and then generates a customized program to implement and deploy the DL model without explicit model representation. The synthesized program hides model information for DL deployment environments since it does not need to retain explicit model representation, preventing many attacks on the DL model. In addition, it improves ML performance because the customized code removes model parsing and preprocessing steps and only retains the data computing process. Our experimental results show that CustomDLCoder improves model security by disabling on-device model sniffing. Compared with the original on-device platform (i.e., TFLite), our method can accelerate model inference by 21.0% and 24.3% on x86-64 and ARM64 platforms, respectively. Most importantly, it can significantly reduce memory consumption by 68.8% and 36.0% on x86-64 and ARM64 platforms, respectively. Mingyi Zhou, Xiang Gao 0012, John C. Grundy, Chunyang Chen 0001, Xiao Chen 0002, Li Li 0029 |
ISSTA | 4 |
| 2024 | What Makes a High-Quality Training Dataset for Large Language Models: A Practitioners' PerspectiveabstractLarge Language Models (LLMs) have demonstrated remarkable performance in various application domains, largely due to their self-supervised pre-training on extensive high-quality text datasets. However, despite the importance of constructing such datasets, many leading LLMs lack documentation of their dataset construction and training procedures, leaving LLM practitioners with a limited understanding of what makes a high-quality training dataset for LLMs. To fill this gap, we initially identified 18 characteristics of high-quality LLM training datasets, as well as 10 potential data pre-processing methods and 6 data quality assessment methods, through detailed interviews with 13 experienced LLM professionals. We then surveyed 219 LLM practitioners from 23 countries across 5 continents. We asked our survey respondents to rate the importance of these characteristics, provide a rationale for their ratings, specify the key data pre-processing and data quality assessment methods they used, and highlight the challenges encountered during these processes. From our analysis, we identified 13 crucial characteristics of high-quality LLM datasets that receive a high rating, accompanied by key rationale provided by respondents. We also identified some widely-used data pre-processing and data quality assessment methods, along with 7 challenges encountered during these processes. Based on our findings, we discuss the implications for researchers and practitioners aiming to construct high-quality training datasets for optimizing LLMs. Xiao Yu 0008, Zexian Zhang, Feifei Niu, Xing Hu 0008, Xin Xia 0001, John C. Grundy |
ASE | 6 |
| 2024 | DynaMO: Protecting Mobile DL Models through Coupling Obfuscated DL OperatorsabstractDeploying deep learning (DL) models on mobile applications (Apps) has become ever-more popular. However, existing studies show attackers can easily reverse-engineer mobile DL models in Apps to steal intellectual property or generate effective attacks. A recent approach, Model Obfuscation, has been proposed to defend against such reverse engineering by obfuscating DL model representations, such as weights and computational graphs, without affecting model performance. These existing model obfuscation methods use static methods to obfuscate the model representation, or they use half-dynamic methods but require users to restore the model information through additional input arguments. However, these static methods or half-dynamic methods cannot provide enough protection for on-device DL models. Attackers can use dynamic analysis to mine the sensitive information in the inference codes as the correct model information and intermediate results must be recovered at runtime for static and half-dynamic obfuscation methods. We assess the vulnerability of the existing obfuscation strategies using an instrumentation method and tool, DLModelExplorer, that dynamically extracts correct sensitive model information (i.e., weights, computational graph) at runtime. Experiments show it achieves very high attack performance (e.g., 98.76% of weights extraction rate and 99.89% of obfuscating operator classification rate). To defend against such attacks based on dynamic instrumentation, we propose DynaMO, a Dynamic Model Obfuscation strategy similar to Homomorphic Encryption. The obfuscation and recovery process can be done through simple linear transformation for the weights of randomly coupled eligible operators, which is a fully dynamic obfuscation strategy. Experiments show that our proposed strategy can dramatically improve model security compared with the existing obfuscation strategies, with only negligible overheads for on-device models. Our prototype tool is publicly available at https://github.com/zhoumingyi/DynaMO. Mingyi Zhou, Xiang Gao 0012, Xiao Chen 0002, Chunyang Chen 0001, John C. Grundy, Li Li 0029 |
ASE | 5 |
| 2024 | Towards Runtime Monitoring for Responsible Machine Learning using Model-driven EngineeringabstractMachine learning (ML) components are used heavily in many current software systems, but developing them responsibly in practice remains challenging. 'Responsible ML' refers to developing, deploying and maintaining ML-based systems that adhere to human-centric requirements, such as fairness, privacy, transparency, safety, accessibility, and human values. Meeting these requirements is essential for maintaining public trust and ensuring the success of ML-based systems. However, as changes are likely in production environments and requirements often evolve, design-time quality assurance practices are insufficient to ensure such systems' responsible behavior. Runtime monitoring approaches for ML-based systems can potentially offer valuable solutions to address this problem. Many currently available ML monitoring solutions overlook human-centric requirements due to a lack of awareness and tool support, the complexity of monitoring human-centric requirements, and the effort required to develop and manage monitors for changing requirements. We believe that many of these challenges can be addressed by model-driven engineering. In this new ideas paper, we present an initial meta-model, model-driven approach, and proof of concept prototype for runtime monitoring of human-centric requirements violations, thereby ensuring responsible ML behavior. We discuss our prototype, current limitations and propose some directions for future work. Hira Naveed, John C. Grundy, Chetan Arora 0002, Hourieh Khalajzadeh, Omar Haggag |
MODELS | 2 |
| 2024 | Lessons Learned from Persona Usage in Requirements Engineering PracticeabstractPersonas, as a tool for characterising end-users, are widely utilised in requirements engineering (RE), primarily to enhance the understanding of end-users and their needs. However, the efficacy of persona usage in RE practice remains inadequately explored. To bridge this gap, we conducted an interview-based study with 22 international RE experts. These experts shared their experiences in utilising personas for RE-related tasks. Through thematic analysis of the collected insights, we propose recommendations for the effective creation and integration of personas in RE tasks. Our suggestions for efficient persona usage in RE emphasise the necessity of direct human interaction throughout persona development, while also con-sidering project constraints. We recommend creating personas that reflect the needs and preferences of persona consumers regarding the information included and the presentation style. Additionally, fostering organisational awareness of the benefits of personas in understanding targeted end-users is crucial. Lastly, we highlight the importance of the interpersonal skills required by requirements engineers to support the successful incorporation of personas in RE. Devi Karolita, John C. Grundy, Tanjila Kanij, Jennifer McIntosh 0001, Humphrey O. Obie |
RE | 2 |
| 2024 | The struggle is real! The agony of recruiting participants for empirical software engineering studiesabstractEmpirical software engineering researchers are committed to investigating better ways of improving software engineering practice. To do this, gathering data about software professionals’ experiences and perspectives on the researched topic is crucial. However, in the last decade, our experience of recruiting software professionals as potential participants in our studies has met with fluctuating success. Therefore, we had to explore multiple possibilities when recruiting participants. This cost us more effort and time than anticipated. In this paper, we briefly discuss the challenges we faced when recruiting participants for empirical research in software engineering, the solutions we implemented to address these challenges, and a concise list of strategies for garnering the interest of potential participants. Kashumi Madampe, John C. Grundy, Rashina Hoda, Humphrey O. Obie |
VL/HCC | 2 |
| 2024 | End-Users vs Software Practitioners: Recruitment Challenges and Strategies in Software Engineering ResearchabstractThis paper shares insights from our first-hand experience with key recruitment challenges encountered in software engineering research, focusing on two distinct participant groups: end-users and software practitioners. By conducting a reflective analysis, we emphasise the particular challenges we faced when engaging these groups during empirical study recruitment phases. Significant challenges we faced in recruiting end-users include ensuring authenticity, maintaining engagement, achieving demographic diversity, and addressing privacy concerns. Conversely, we faced different challenges when recruiting software practitioners, including sourcing the right expertise, utilising online recruiting platforms, navigating time constraints, aligning incentives, obtaining a representative sample, and coordinating with remote and distributed teams. By detailing the strategies we employed to address these challenges, this paper contributes practical knowledge to enhance the efficacy and inclusiveness of research practices, ultimately fostering more robust software engineering research outcomes. Wei Wang 0376, Dulaji Hidellaarachchi, John C. Grundy, Hourieh Khalajzadeh, Humphrey O. Obie, Anuradha Madugalla |
VL/HCC | 3 |
| 2024 | Development of an Adaptive User Support System Based on Multimodal Large Language ModelsabstractAs software systems become more complex, some users find it challenging to use these tools efficiently, leading to frustration and decreased productivity. We tackle the shortcomings of conventional user support mechanisms in software and aim to create and assess a user support system that integrates Multimodal Large Language Models (MLLMs) for producing support messages. Our system initially segments the user interface to serve as a reference for selection and requests users to specify their preferences for support messages. Following this, the system creates personalised user support messages for each individual. We propose that user support systems enhanced with MLLMs can provide more efficient and bespoke assistance compared to conventional methods. Wei Wang 0376, Lin Li 0066, Shavindra Wickramathilaka, John C. Grundy, Hourieh Khalajzadeh, Humphrey O. Obie, Anuradha Madugalla |
VL/HCC | 4 |
| 2024 | Angels or demons: investigating and detecting decentralized financial traps on ethereum smart contracts
Jiachi Chen, Xin Xia 0001, David Lo 0001, John C. Grundy, Zhipeng Gao 0002, Ting Chen 0002 |
Autom. Softw. Eng. | 5 |
| 2024 | AIBugHunter: A Practical tool for predicting, classifying and repairing software vulnerabilitiesabstractAbstract Many Machine Learning(ML)-based approaches have been proposed to automatically detect, localize, and repair software vulnerabilities. While ML-based methods are more effective than program analysis-based vulnerability analysis tools, few have been integrated into modern Integrated Development Environments (IDEs), hindering practical adoption. To bridge this critical gap, we propose in this article AIBugHunter , a novel Machine Learning-based software vulnerability analysis tool for C/C++ languages that is integrated into the Visual Studio Code (VS Code) IDE. AIBugHunter helps software developers to achieve real-time vulnerability detection, explanation, and repairs during programming. In particular, AIBugHunter scans through developers’ source code to (1) locate vulnerabilities, (2) identify vulnerability types, (3) estimate vulnerability severity, and (4) suggest vulnerability repairs. We integrate our previous works (i.e., LineVul and VulRepair) to achieve vulnerability localization and repairs. In this article, we propose a novel multi-objective optimization (MOO)-based vulnerability classification approach and a transformer-based estimation approach to help AIBugHunter accurately identify vulnerability types and estimate severity. Our empirical experiments on a large dataset consisting of 188K+ C/C++ functions confirm that our proposed approaches are more accurate than other state-of-the-art baseline methods for vulnerability classification and estimation. Furthermore, we conduct qualitative evaluations including a survey study and a user study to obtain software practitioners’ perceptions of our AIBugHunter tool and assess the impact that AIBugHunter may have on developers’ productivity in security aspects. Our survey study shows that our AIBugHunter is perceived as useful where 90% of the participants consider adopting our AIBugHunter during their software development. Last but not least, our user study shows that our AIBugHunter can enhance developers’ productivity in combating cybersecurity issues during software development. AIBugHunter is now publicly available in the Visual Studio Code marketplace. Chakkrit Tantithamthavorn, Trung Le 0001, Yuki Kume, Van Nguyen 0002, Dinh Q. Phung, John C. Grundy |
Empir. Softw. Eng. | 7 |
| 2024 | The Impact of Personality on Requirements Engineering Activities: A Mixed-Methods Study
Dulaji Hidellaarachchi, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
Empir. Softw. Eng. | 2 |
| 2024 | Challenges, adaptations, and fringe benefits of conducting software engineering research with human participants during the COVID-19 pandemicabstractAbstract The COVID-19 pandemic changed the way we live, work and the way we conduct research. With the restrictions of lockdowns and social distancing, various impacts were experienced by many software engineering researchers, especially whose studies depend on human participants. We conducted a mixed methods study to understand the extent of this impact. Through a detailed survey with 89 software engineering researchers working with human participants around the world and a further nine follow-up interviews, we identified the key challenges faced, the adaptations made, and the surprising fringe benefits of conducting research involving human participants during the pandemic. Our findings also revealed that in retrospect, many researchers did not wish to revert to the old ways of conducting human-orienfted research. Based on our analysis and insights, we share recommendations on how to conduct remote studies with human participants effectively in an increasingly hybrid world when face-to-face engagement is not possible or where remote participation is preferred. Anuradha Madugalla, Tanjila Kanij, Rashina Hoda, Dulaji Hidellaarachchi, Aastha Pant, Samia Ferdousi, John C. Grundy |
Empir. Softw. Eng. | 7 |
| 2024 | How do software practitioners perceive human-centric defects?abstractContext: Human-centric software design and development prioritises the way users prefer to complete their jobs, rather than expecting users to adapt to the software. Software users can have different genders, ages, cultures, languages, disabilities, socioeconomic statuses, and educational backgrounds, among many other differences. Due to the inherently varied nature of these differences and their impact on software usage, preferences and issues of users can vary, resulting in user-specific defects that we term as ‘human-centric defects’ (HCDs). Objective: This research aims to understand the perception and current management practices of such HCDs by software practitioners, identify key challenges in reporting, understanding and fixing them, and provide recommendations to improve HCDs management in software engineering. Methods: We conducted a survey and interviews with software engineering practitioners to gauge their knowledge and experience on HCDs and the defect tracking process. Results: We analysed fifty (50) survey- and ten (10) interview-responses from SE practitioners and identified that there are multiple gaps in the current management of HCDs in software engineering practice. There is a lack of awareness regarding human-centric aspects, causing them to be lost or under-appreciated during software development. Our results revealed that handling HCDs could be improved by following a better feedback process with end-users, a more descriptive taxonomy, and suitable automation. Conclusion: HCDs, given their diverse end-user base, present a major challenge to software practitioners. In the software engineering domain, research on HCDs has been limited and requires effort from research and practice communities to create awareness and support for human-centric aspects. Vedant Chauhan, Chetan Arora 0002, Hourieh Khalajzadeh, John C. Grundy |
Inf. Softw. Technol. | 4 |
| 2024 | The impact of human aspects on the interactions between software developers and end-users in software engineering: A systematic literature reviewabstractResearch on human aspects within the field of software engineering (SE) has been steadily gaining prominence in recent years. These human aspects have a significant impact on SE due to the inherently interactive and collaborative nature of the discipline. In this paper, we present a systematic literature review (SLR) on human aspects affecting developer-user interactions. The objective of this SLR is to plot the current landscape of primary studies by examining the human aspects that influence developer-user interactions, their implications, interrelationships, and how existing studies address these implications. We conducted this SLR following the guidelines proposed by Kitchenham et al. We performed a comprehensive search in six digital databases, and an exhaustive backward and forward snowballing process. We selected 46 primary studies for data extraction. We identified various human aspects affecting developer-user interactions in SE, assessed their interrelationships, identified their positive impacts and mitigation strategies for negative effects. We present specific recommendations derived from the identified research gaps. Our findings suggest the importance of leveraging positive effects and addressing negative effects in developer-user interactions through the implementation of effective mitigation strategies. These insights may benefit software practitioners for effective user interactions, and the recommendations proposed by this SLR may aid the research community in further human aspects related studies. Hashini Gunatilake, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
Inf. Softw. Technol. | 2 |
| 2024 | Model driven engineering for machine learning components: A systematic literature reviewabstractMachine Learning (ML) has become widely adopted as a component in many modern software applications. Due to the large volumes of data available, organizations want to increasingly leverage their data to extract meaningful insights and enhance business profitability. ML components enable predictive capabilities, anomaly detection, recommendation, accurate image and text processing, and informed decision-making. However, developing systems with ML components is not trivial; it requires time, effort, knowledge, and expertise in ML, data processing, and software engineering. There have been several studies on the use of model-driven engineering (MDE) techniques to address these challenges when developing traditional software and cyber–physical systems. Recently, there has been a growing interest in applying MDE for systems with ML components. The goal of this study is to further explore the promising intersection of MDE with ML (MDE4ML) through a systematic literature review (SLR). Through this SLR, we wanted to analyze existing studies, including their motivations, MDE solutions, evaluation techniques, key benefits and limitations. Our SLR is conducted following the well-established guidelines by Kitchenham. We started by devising a protocol and systematically searching seven databases, which resulted in 3,934 papers. After iterative filtering, we selected 46 highly relevant primary studies for data extraction, synthesis, and reporting. We analyzed selected studies with respect to several areas of interest and identified the following: 1) the key motivations behind using MDE4ML; 2) a variety of MDE solutions applied, such as modeling languages, model transformations, tool support, targeted ML aspects, contributions and more; 3) the evaluation techniques and metrics used; and 4) the limitations and directions for future work. We also discuss the gaps in existing literature and provide recommendations for future research. This SLR highlights current trends, gaps and future research directions in the field of MDE4ML, benefiting both researchers and practitioners. Hira Naveed, Chetan Arora 0002, Hourieh Khalajzadeh, John C. Grundy, Omar Haggag |
Inf. Softw. Technol. | 4 |
| 2024 | Developer and End-User Perspectives on Addressing Human Aspects in Mobile eHealth AppsabstracteHealth apps are mobile apps that help in self-management of critical illnesses, provide home-based disease management, and help with personalized care. Users of eHealth apps are naturally very diverse in terms of their human aspects, e.g., their age, gender, emotional reactions to the apps, cognitive style, physical and mental challenges. Unfortunately, many eHealth apps do not take these user differences sufficiently into account, making them ineffective or even unusable. This paper reports a study from eHealth app stakeholders’ – developers and end-users – perspectives on critical challenges and benefits of better incorporating human aspects into eHealth app development and usage. We also investigate how different human aspects are being addressed by developers, which ones are the most important for different user groups, and which ones are currently missing/poorly handled. A mixed-method approach that integrates qualitative and quantitative research was used for this study. We gathered and analyzed data from 240 online survey responses and 25 detailed interviews within the same study and validated the results. We report key issues encountered in eHealth app design, difficulty in addressing different human aspects, areas requiring further research and practical assistance, and recommend our findings to best address these challenges. We found addressing human aspects throughout the app development life-cycle is beneficial for more effective eHealth apps. Our findings also suggest the need for improved standards and guidelines, better developer-user collaborative culture, and better human aspects education to produce more effective eHealth apps. This paper investigates current approaches used in the eHealth app domain that take into account the human aspects of app users. The paper guides eHealth app stakeholders, future researchers, academia and industry partners be aware of human aspects related challenges and improve produce apps. Md. Shamsujjoha, John C. Grundy, Hourieh Khalajzadeh, Qinghua Lu 0001, Li Li 0029 |
Inf. Softw. Technol. | 2 |
| 2024 | Enhancing understanding and addressing gender bias in IT/SE job advertisementsabstractThe majority of Information Technology (IT)/Software Engineering (SE) professionals are male. A potential reason for the low number of female IT/SE professionals might be that the roles and the way they are advertised are biased towards male candidates. The aim of this research is to collect information about the present state of practice of gender inclusiveness within IT/SE job advertisements and how, if needed, we might improve this. We conducted a survey of hiring managers and IT/SE professionals (who are employed in IT/SE roles). The survey collected their general views on gender bias within job advertisements. According to their opinions, job advertisements are often biased towards male candidates. Based on the review and suggestions from our participants we developed a set of recommendations to help hiring managers design more gender inclusive SE job advertisements. This will be a first step toward developing a gender balanced SE workforce. Tanjila Kanij, John C. Grundy, Jennifer McIntosh 0001 |
J. Syst. Softw. | 2 |
| 2024 | Emerging technologies in higher education assessment and feedback practices: A systematic literature reviewabstractThe use of Emerging Technologies, such as Artificial Intelligence (AI), Learning Analytics (LA) and Extended Reality (XR) applications, in higher education has proliferated in recent times, as these technologies are considered to have a significant impact on the future of postsecondary teaching and learning. We wanted to find out the emerging technologies used in computing education, its evaluation and effectiveness, and limitations and gaps for future research. We carried out a Systematic Literature Review study on the use of Emerging Technologies in higher education computing education to identify the state of the art in the use of these three groups of technologies for assessment and feedback practices. After systematic search and filtering from a search pool of 3038 studies published between 2016 and 2021, we selected 38 articles for detailed meta-analysis. Our findings reveal that 71% of the reviewed studies are journal articles, 50% studies focus on learning analytics, and the majority of the studies employ quantitative approaches. The results from this systematic review suggest that XR technologies have received least attention to date in computing education (amongst the emerging technologies considered for the review) and there is a lack of frameworks for design, evaluation and use of emerging technologies in higher education. The findings of this review will be beneficial for researchers and educators to obtain an in-depth understanding of the main areas of application of emerging technologies in higher education computing education, an inventory of emerging technology tools used for assessment and feedback, effectiveness indicators, and evaluation approaches that have been used. For evidence-based guidance on future assessment and feedback practices using emerging technologies, we also present a brief research agenda, drawing attention to the need to trial more XR, focus on formative assessment and feedback practices, better understand impact of human-centric issues and take more thoughtful consideration of ethics in the use of emerging technologies in computing education. Ruchi Sembey, Rashina Hoda, John C. Grundy |
J. Syst. Softw. | 3 |
| 2024 | Understanding the quality and evolution of Android app build systemsabstractAbstract Build systems are used to transform static source code into executable software. They play a crucial role in modern software development and maintenance. As such, much research effort has been invested in understanding the quality and evolution of build systems, including Apache ANT, Apache Maven, and Make‐based ones. However, the quality and evolution of build systems for mobile apps, such as on the Android platform, have not as yet been investigated in detail. Mobile app development, and the Android development context in particular, impose unique constrains, such as different device conditions and capabilities. It presents unique challenges, such as frequently upgraded Android frameworks, which those who implement and maintain build systems must tackle. In this paper, we present an exploratory empirical study of the build systems of 5222 Android projects to better understand their quality and evolution. We (a) study the build technology choices that Android developers make (Gradle being recommended and the most popular choice), (b) explore the sustainability of the official Gradle build system (parts of build files are updated more frequent that others and the update of the special Gradle plugin would induce unrecommended configurations), and (c) analyze the quality of Gradle scripts for Android apps—more than a half of the open‐source Android apps cannot be successfully built due to five common root causes. Li Li 0029, Kui Liu 0001, Shane McIntosh, John C. Grundy |
J. Softw. Evol. Process. | 5 |
| 2024 | Market Manipulation of Cryptocurrencies: Evidence from Social Media and Transaction DataabstractThe cryptocurrency market cap has experienced a great increase in recent years. However, large price fluctuations demonstrate the need for governance structures and identify whether there are market manipulations. In this article, we conduct three analyses—social media data analysis, blockchain data analysis, and price bubble analysis—to investigate whether market manipulation exists on Bitcoin, Ethereum, and Dogecoin platforms. Social media data analysis aims to find the reasons for price fluctuations. Blockchain data analysis is used to find detailed behavior of the manipulators. Price bubble analysis is used to investigate the relation between price fluctuation and manipulators’ behavior. By using the three analyses, we show that market manipulation exists on Bitcoin, Ethereum, and Dogecoin. However, market manipulation of Bitcoin is limited, and for most of Bitcoin’s price fluctuations, we found other explanations. The price for Ethereum is the most sensitive to technical updates. Technical companies/teams usually hype some new concepts (e.g., ICO, DeFi), which causes a price spike. The price of Dogecoin has a high correlation with Elon Musk’s X (formerly known as Twitter) activity, showing that influential individuals have the ability to manipulate its prices. In addition, the poor monetary liquidity of Dogecoin allows some users to manipulate its price. Wen Li 0017, Lingfeng Bao, Jiachi Chen, John C. Grundy, Xin Xia 0001, Xiaohu Yang 0001 |
ACM Trans. Internet Techn. | 4 |
| 2024 | Enablers and Barriers of Empathy in Software Developer and User Interactions: A Mixed Methods Case StudyabstractSoftware engineering (SE) requires developers to collaborate with stakeholders, and understanding their emotions and perspectives is often vital. Empathy is a concept characterising a person’s ability to understand and share the feelings of another. However, empathy continues to be an under-researched human aspect in SE. We studied how empathy is practised between developers and end users using a mixed methods case study. We used an empathy test, observations, and interviews to collect data and socio-technical grounded theory and descriptive statistics to analyse data. We identified the nature of awareness required to trigger empathy and enablers of empathy. We discovered barriers to empathy and a set of potential strategies to overcome these barriers. We report insights on emerging relationships and present a set of recommendations and potential future works on empathy and SE for software practitioners and SE researchers. Hashini Gunatilake, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2024 | Large Language Models for Software Engineering: A Systematic Literature ReviewabstractLarge Language Models (LLMs) have significantly impacted numerous domains, including Software Engineering (SE). Many recent publications have explored LLMs applied to various SE tasks. Nevertheless, a comprehensive understanding of the application, effects, and possible limitations of LLMs on SE is still in its early stages. To bridge this gap, we conducted a Systematic Literature Review (SLR) on LLM4SE, with a particular focus on understanding how LLMs can be exploited to optimize processes and outcomes. We selected and analyzed 395 research articles from January 2017 to January 2024 to answer four key Research Questions (RQs). In RQ1, we categorize different LLMs that have been employed in SE tasks, characterizing their distinctive features and uses. In RQ2, we analyze the methods used in data collection, pre-processing, and application, highlighting the role of well-curated datasets for successful LLM for SE implementation. RQ3 investigates the strategies employed to optimize and evaluate the performance of LLMs in SE. Finally, RQ4 examines the specific SE tasks where LLMs have shown success to date, illustrating their practical contributions to the field. From the answers to these RQs, we discuss the current state-of-the-art and trends, identifying gaps in existing research, and highlighting promising areas for future study. Our artifacts are publicly available at https://github.com/security-pride/LLM4SE_SLR . Xinyi Hou, Yanjie Zhao 0001, Yue Liu 0011, Zhou Yang 0003, Kailong Wang 0001, Li Li 0029, Xiapu Luo, David Lo 0001, John C. Grundy, Haoyu Wang 0001 |
ACM Trans. Softw. Eng. Methodol. | 9 |
| 2024 | Automated Mapping of Adaptive App GUIs from Phones to TVsabstractWith the increasing interconnection of smart devices, users often desire to adopt the same app on quite different devices for identical tasks, such as watching the same movies on both their smartphones and TVs. However, the significant differences in screen size, aspect ratio, and interaction styles make it challenging to adapt Graphical User Interfaces (GUIs) across these devices. Although there are millions of apps available on Google Play, only a few thousand are designed to support smart TV displays. Existing techniques to map a mobile app GUI to a TV either adopt a responsive design, which struggles to bridge the substantial gap between phone and TV, or use mirror apps for improved video display, which requires hardware support and extra engineering efforts. Instead of developing another app for supporting TVs, we propose a semi-automated approach to generate corresponding adaptive TV GUIs, given the phone GUIs as the input. Based on our empirical study of GUI pairs for TVs and phones in existing apps, we synthesize a list of rules for grouping and classifying phone GUIs, converting them to TV GUIs, and generating dynamic TV layouts and source code for the TV display. Our tool is not only beneficial to developers but also to GUI designers, who can further customize the generated GUIs for their TV app development. An evaluation and user study demonstrate the accuracy of our generated GUIs and the usefulness of our tool. Han Hu 0011, Ruiqi Dong, John C. Grundy, Thai Minh Nguyen, Huaxiao Liu, Chunyang Chen 0001 |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2024 | Automatically Detecting Incompatible Android APIsabstractFragmentation is a serious problem in the Android ecosystem, which is mainly caused by the fast evolution of the system itself and the various system customizations. Many efforts have attempted to mitigate its impact via approaches to automatically pinpointing compatibility issues in Android apps. We conducted a literature review to identify all the currently available approaches to addressing this issue. Within the nine identified approaches, the four issue detection tools and one incompatible API harvesting tool could be successfully executed. We tried to reproduce them based on their original datasets and then empirically compared those approaches against common datasets. Our experimental results show that existing tool capabilities are quite distinct with only a small overlap in the compatibility issues being identified. Moreover, these detection tools commonly detect compatibility issues via two separate steps including incompatible APIs gathering and compatibility issues (induced by the incorrect invocations of the identified incompatible APIs) determination. To help developers better identify compatibility issues in Android apps, we developed a new approach, AndroMevol , to systematically spot incompatible APIs as they play a crucial role in issue detection. AndroMevol was able to pinpoint 397,678 incompatible APIs against the full history of the official Android framework and 52 customized Android frameworks spanning five popular device manufacturers. Our approach could enhance the ability of the state-of-the-art detection tools by identifying many more incompatible APIs that may cause compatibility issues in Android apps and foster more advanced approaches to pinpointing all types of compatibility issues. Yanjie Zhao 0001, Mattia Fazzini, Haipeng Cai, John C. Grundy, Li Li 0029 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2024 | A First Look at Dark Mode in Real-world Android AppsabstractAndroid apps often have a “dark mode” option used in low-light situations, for those who find the conventional color palette problematic, or because of personal preferences. Typically developers add a dark mode option for their apps with different backgrounds, text, and sometimes iconic forms. We wanted to understand the actual provision of this dark mode in real-world Android apps through an empirical study of posts from Stack Overflow and real-world Android app analysis. Using these approaches, we identified the aspects of dark mode that developers implemented as well as the key difficulties they experienced in implementing it. We performed a quantitative analysis using open-coding of more than 300 discussion threads to create a taxonomy regarding the aspects discussed by developers with respect to dark mode in Android. Our quantitative analysis of over 6,000 Android apps highlights which dark mode features are typically provided in Android apps and which aspects developers care about during dark mode design. We also examined four app development support tools to see how well they aid Android app development for dark mode. From our analysis, we distilled some key lessons to guide further research and actions in aiding developers with supporting users who require such assistive features. For example, developers should be aware of the potential risks in using unsuitable dark mode design schema and researchers should take dark mode features into consideration when developing app development support tools. Suyu Ma, Chunyang Chen 0001, Hourieh Khalajzadeh, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2024 | Supporting Emotional Intelligence, Productivity and Team Goals while Handling Software Requirements ChangesabstractBackground: Research shows that emotional intelligence (EI) should be used alongside cognitive intelligence during requirements change (RC) handling in Software Engineering (SE), especially in agile settings. Objective: We wanted to study the role of EI in-depth during RC handling. Method: We conducted a mixed-methods study (an interview study followed by a survey study) with 124 software practitioners. Findings: We found the causal condition, intervening condition and causes lead to key direct consequences of regulating own emotions, managing relationships, and extended consequences of sustaining productivity, setting and sustaining team goals. We found several strategies of supporting EI during RC handling. Further, we found strong correlations between six strategies and one being aware of own emotions, regulating own emotions, sustaining team productivity, and setting and sustaining team goals. Conclusion: Empathising with others and tracking commitments and decisions as a team are key strategies that have strong correlations between managing emotions, between sustaining team productivity, and between setting and sustaining team goals. To the best of our knowledge, the framework we present in this paper is the first theoretical framework on EI in SE research. We provide recommendations for software practitioners to consider during RC handling. Kashumi Madampe, Rashina Hoda, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2024 | Deep Domain Adaptation With Max-Margin Principle for Cross-Project Imbalanced Software Vulnerability DetectionabstractSoftware vulnerabilities (SVs) have become a common, serious, and crucial concern due to the ubiquity of computer software. Many AI-based approaches have been proposed to solve the software vulnerability detection (SVD) problem to ensure the security and integrity of software applications (in both the development and testing phases). However, there are still two open and significant issues for SVD in terms of (i) learning automatic representations to improve the predictive performance of SVD, and (ii) tackling the scarcity of labeled vulnerability datasets that conventionally need laborious labeling effort by experts. In this paper, we propose a novel approach to tackle these two crucial issues. We first exploit the automatic representation learning with deep domain adaptation for SVD. We then propose a novel cross-domain kernel classifier leveraging the max-margin principle to significantly improve the transfer learning process of SVs from imbalanced labeled into imbalanced unlabeled projects. Our approach is the first work that leverages solid body theories of the max-margin principle, kernel methods, and bridging the gap between source and target domains for imbalanced domain adaptation (DA) applied in cross-project SVD . The experimental results on real-world software datasets show the superiority of our proposed method over state-of-the-art baselines. In short, our method obtains a higher performance on F1-measure, one of the most important measures in SVD, from 1.83% to 6.25% compared to the second highest method in the used datasets. Van Nguyen 0002, Trung Le 0001, Chakkrit Tantithamthavorn, John C. Grundy, Dinh Q. Phung |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2024 | What Makes a Good TODO Comment?abstractSoftware development is a collaborative process that involves various interactions among individuals and teams. TODO comments in source code play a critical role in managing and coordinating diverse tasks during this process. However, this study finds that a large proportion of open-source project TODO comments are left unresolved or take a long time to be resolved. About 46.7% of TODO comments in open-source repositories are of low-quality (e.g., TODOs that are ambiguous, lack information, or are useless to developers). This highlights the need for better TODO practices. In this study, we investigate four aspects regarding the quality of TODO comments in open-source projects: (1) the prevalence of low-quality TODO comments; (2) the key characteristics of high-quality TODO comments; (3) how are TODO comments of different quality managed in practice; and (4) the feasibility of automatically assessing TODO comment quality. Examining 2,863 TODO comments from Top100 GitHub Java repositories, we propose criteria to identify high-quality TODO comments and provide insights into their optimal composition. We discuss the lifecycle of TODO comments with varying quality. To assist developers, we construct deep learning-based methods that show promising performance in identifying the quality of TODO comments, potentially enhancing development efficiency and code quality. Haoye Wang, Zhipeng Gao 0002, Tingting Bi, John C. Grundy, Xinyu Wang 0001, Minghui Wu 0001, Xiaohu Yang 0001 |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2024 | Just-In-Time TODO-Missed Commits DetectionabstractTODO comments play an important role in helping developers to manage their tasks and communicate with other team members. TODO comments are often introduced by developers as a type of technical debt, such as a reminder to add/remove features or a request to optimize the code implementations. These can all be considered as notifications for developers to revisit regarding the current suboptimal solutions. TODO comments often bring short-term benefits – higher productivity or shorter development cost – and indicate attention needs to be paid for the long-term software quality. Unfortunately, due to their lack of knowledge or experience and/or the time constraints, developers sometimes may forget or even not be aware of suboptimal implementations. The loss of the TODO comments for these suboptimal solutions may hurt the software quality and reliability in the long-term. Therefore it is beneficial to remind the developers of the suboptimal solutions whenever they change the code. In this work, we refer this problem to the task of detectingTODO-missed commits, and we propose a novel approach named TDReminder(TODO commentReminder) to address the task. With the help of TDReminder, developers can identify possible missing TODO commits just-in-time when submitting a commit. Our approach has two phases: offline training and online inference. We first embed code change and commit message into contextual vector representations using two neural encoders respectively. The association between these representations is learned by our model automatically.In the online inference phase, TDReminderleverages the trained model to compute the likelihood of a commit being aTODO-missed commit. We evaluate TDReminderon datasets crawled from 10k popular Python and Java repositories in GitHub respectively. Our experimental results show that TDReminderoutperforms a set of benchmarks by a large margin inTODO-missed commitsdetection. Moreover, to better help developers use TDReminderin practice, we have incorporated Large Language Models (LLMs) with our approach to provide explainable recommendations. The user study shows that our tool can effectively inform developers not only “when” to add TODOs, but also “where” and “what” TODOs should be added, verifying the value of our tool in practical application. Haoye Wang, Zhipeng Gao 0002, Xing Hu 0008, David Lo 0001, John C. Grundy, Xinyu Wang 0001 |
IEEE Trans. Software Eng. | 5 |
| 2024 | Adaptive user interfaces in systems targeting chronic disease: a systematic literature reviewabstractAbstract eHealth technologies have been increasingly used to foster proactive self-management skills for patients with chronic diseases. However, it is challenging to provide each user with their desired support due to the dynamic and diverse nature of the chronic disease and its impact on users. Many such eHealth applications support aspects of “adaptive user interfaces”—interfaces that change or can be changed to accommodate the user and usage context differences. To identify the state of the art in adaptive user interfaces in the field of chronic diseases, we systematically located and analysed 48 key studies in the literature with the aim of categorising the key approaches used to date and identifying limitations, gaps, and trends in research. Our data synthesis is based on the data sources used for interface adaptation, the data collection techniques used to extract the data, the adaptive mechanisms used to process the data, and the adaptive elements generated at the interface. The findings of this review will aid researchers and developers in understanding where adaptive user interface approaches can be applied and necessary considerations for employing adaptive user interfaces to different chronic disease-related eHealth applications. Wei Wang 0376, Hourieh Khalajzadeh, John C. Grundy, Anuradha Madugalla, Jennifer McIntosh 0001, Humphrey O. Obie |
User Model. User Adapt. Interact. | 3 |
| 2023 | Motive Metrics: A Jira Plug-In for Personality, Motivation and Performance TrackingabstractRequirements Engineering (RE) is an essential part of Software Engineering (SE). As RE activities rely heavily on people, the success of RE is influenced by the human aspects of the team involved. In this research, we develop a prototype application, called Motive Metrics, to improve RE activities by allowing managers to track developers’ personality and motivation and monitor their impact on developer performance and satisfaction. The tool takes the form of an extension to Jira and was developed through rapid prototyping. The effectiveness and usability of the tool were evaluated by student teams split into managers and team members. When evaluating Motive Metrics, 45.5% of participants rated 4 out of 5 for the application’s effectiveness in capturing personalities, but only 9.1% of participants rated 4 out of 5 for capturing motivations. Motive Metrics is likely ineffective in monitoring satisfaction and performance, as 45% of participants rated 1 out of 5 in comfort in sharing their responses. Our evaluation results also show that Motive Metrics might not be beneficial in tracking the influence of motivation on the outcome but slightly more beneficial in tracking the influence of personality on RE task performance. An Cao, Jie Xiang Fan, Akash Saggar, Kunj Dave, Sharan Sharabinth, Jiten Verma, Dulaji Hidellaarachchi, John C. Grundy |
COMPSAC | 8 |
| 2023 | An Empathetic Approach to Human-Centric Requirements Engineering Using Virtual RealityabstractPeople who use software applications are different, including with significant cognitive differences such as neurodiversity. Capturing requirements for software that addresses these cognitive differences is hard for software engineers, especially when they do not have the same cognitive challenges. We wanted to explore the use of virtual reality (VR) in assisting software engineers to better understand the perspectives of the end user for the purpose of human-centric requirements elicitation, with a focus on users with attention-deficit/hyperactivity disorder (ADHD). We developed an immersive VR prototype using a virtual gym environment and fitness app as a concrete motivating example scenario. We carried out an evaluation of requirements identification for ADHD fitness app users by instructing participants to complete activities whilst under visual and auditory distractions similar to various documented symptoms of ADHD. Results indicated an increase in understanding the perspectives of someone with ADHD and an awareness of potential challenges with software not intentionally designed for ADHD users. Improved requirements for our target fitness app resulted that better take into account these diverse user needs. Nicholas Chong, Emmanuel Chu, Adrian Nadonza, Sienna Marie Rodriguez, Sothearith Tith, Jin Shan, John C. Grundy, Yi Wang 0119, Ben Cheng, Thuong N. Hoang |
COMPSAC | 7 |
| 2023 | An Approach to Generating Diverse Personas for Children and the Elderly for Software DevelopmentabstractChildren and elderly users typically interact very differently with the same software interfaces. These should be taken into consideration while designing and developing software that will be used by these users. In order to better understand the characteristics of children and elderly users of software, we systematically reviewed the relevant literature. We identified different facets of children and the elderly that are relevant to their interaction with the software. The facets for children are- Special needs children, Interaction with technology and General characteristics. Facets for elderly users are- Technical proficiency, Interaction with technology, Technology expectations and General characteristics. We developed a tool with different descriptions of those facets collected from our review. We collected feedback on the tool from experts and refined the tool accordingly. The personas generated using the tool can be used as is or can be extended by adding more context-specific information to the personas. The tool will help designers and developers of software interfaces to better understand the requirements of these user groups and to incorporate their specific needs during design and development. This will result in reducing biases arising from age-related facets and help to create more inclusive software. Tanjila Kanij, Xiaojiao Du, John C. Grundy, Anuradha Madugalla, Devi Karolita |
COMPSAC | 3 |
| 2023 | Requirements Elicitation and Modelling of Artificial Intelligence Systems: An Empirical StudyabstractArtificial Intelligence (AI) systems have gained significant traction in the recent past, creating new challenges in requirements engineering (RE) when building AI software systems. RE for AI practices have not been studied much and have scarce empirical studies. Additionally, many AI software solutions tend to focus on the technical aspects and ignore human-centered values. In this paper, we report on a case study for eliciting and modeling requirements using our framework and a supporting tool for human-centred RE for AI systems. Our case study is a mobile health application for encouraging type-2 diabetic people to reduce their sedentary behavior. We conducted our study with three experts from the app team - a software engineer, a project manager and a data scientist. We found in our study that most human-centered aspects were not originally considered when developing the first version of the application. We also report on other insights and challenges faced in RE for the health application, e.g., frequently changing requirements. Khlood Ahmad, Mohamed Almorsy, Chetan Arora 0002, John C. Grundy, Muneera Bano |
ENASE | 4 |
| 2023 | What's in a Persona? A Preliminary Taxonomy from Persona Use in Requirements EngineeringabstractPersonas have been widely used during requirements engineering-related tasks. However, the presentation, composition, level of details and other characteristics varies greatly by domain of use. To better understand these, we formed a curated set of nearly 100 personas from 41 academic papers and analysed their similarities and differences. We then used our analysis to formulate a preliminary taxonomy of personas used for Requirements Engineering-related tasks. We describe our key findings from our analysis with examples, our preliminary taxonomy, and discuss ways the taxonomy can be used and further improved. Devi Karolita, John C. Grundy, Tanjila Kanij, Humphrey O. Obie, Jennifer McIntosh 0001 |
ENASE | 2 |
| 2023 | Extracting Queryable Knowledge Graphs from User Stories: An Empirical EvaluationabstractExtracting Queryable Knowledge Graphs from User Stories: An Empirical Evaluation Ayodeji Ladeinde, Chetan Arora 0002, Hourieh Khalajzadeh, Tanjila Kanij, John C. Grundy |
ENASE | 5 |
| 2023 | mHealthSwarm: A Unified Platform for mHealth ApplicationsabstractMobile health (mHealth) applications are ubiquitous and offer several benefits such as easier access to one's health and wellness data through smartphones. However, their growth in popularity has also introduced several challenges for both end-users and developers. Users face challenges around the poor user experience (UX) introduced by the need to install several apps and limited customizability which is exacerbated by the limited control over app functionality. While features common across different apps may not directly affect individual developers, the fact that one app may provide a better implementation of features leads to wasted developer effort. A single platform that can satisfy all user needs does not currently exist, and given the diversity of the mHealth domain, a single app would be far too complex if it existed. In this paper, we present a new approach and a platform for mHealth apps - micro-mHealth apps, and we discuss them as an alternative to the current mHealth app development model, which we believe could improve the current state of mHealth app development and adoption. We are currently evaluating our prototype with several micro-mHealth apps built using common features in the mHealth apps available in commercial app stores. Ben Joseph Philip, Yasmeen Anjeer Alshehhi, Mohamed Almorsy, Scott Barnett, Alessio Bonti, John C. Grundy |
ENASE | 6 |
| 2023 | ModelObfuscator: Obfuscating Model Information to Protect Deployed ML-Based SystemsabstractMore and more edge devices and mobile apps are leveraging deep learning (DL) capabilities. Deploying such models on devices – referred to as on-device models – rather than as remote cloud-hosted services, has gained popularity because it avoids transmitting user’s data off of the device and achieves high response time. However, on-device models can be easily attacked, as they can be accessed by unpacking corresponding apps and the model is fully exposed to attackers. Recent studies show that attackers can easily generate white-box-like attacks for an on-device model or even inverse its training data. To protect on-device models from white-box attacks, we propose a novel technique called model obfuscation. Specifically, model obfuscation hides and obfuscates the key information – structure, parameters and attributes – of models by renaming, parameter encapsulation, neural structure obfuscation, shortcut injection, and extra layer injection. We have developed a prototype tool ModelObfuscator to automatically obfuscate on-device TFLite models. Our experiments show that this proposed approach can dramatically improve model security by significantly increasing the difficulty of parsing models’ inner information, without increasing the latency of DL models. Our proposed on-device model obfuscation has the potential to be a fundamental technique for on-device model deployment. Our prototype tool is publicly available at https://github.com/zhoumingyi/ModelObfuscator. Mingyi Zhou, Xiang Gao 0012, Jing Wu 0021, John C. Grundy, Xiao Chen 0002, Chunyang Chen 0001, Li Li 0029 |
ISSTA | 4 |
| 2023 | ReuNify: A Step Towards Whole Program Analysis for React Native Android AppsabstractReact Native is a widely-used open-source frame-work that facilitates the development of cross-platform mobile apps. The framework enables JavaScript code to interact with native-side code, such as Objective-C/Swift for iOS and Java/Kotlin for Android, via a communication mechanism provided by React Native. However, previous research and tools have overlooked this mechanism, resulting in incomplete analysis of React Native app code. To address this limitation, we have developed REUNIFY, a prototype tool that integrates the JavaScript and native-side code of React Native apps into an intermediate language that can be processed by the Soot static analysis framework. By doing so, REUNIFY enables the generation of a comprehensive model of the app's behavior. Our evaluation indicates that, by leveraging REUNIFY, the Soot-based framework can improve its coverage of static analysis for the 1,007 most popular React Native Android apps, augmenting the number of lines of Jimple code by 70%. Additionally, we observed an average increase of 84% in new nodes reached in the callgraph for these apps, after integrating REUNIFY. When REUNIFY is used for taint flow analysis, an average of two additional privacy leaks were identified. Overall, our results demonstrate that REUNIFY significantly enhances the Soot-based framework's capability to analyze React Native Android apps. Yonghui Liu 0001, Xiao Chen 0002, John C. Grundy, Chunyang Chen 0001, Li Li 0029 |
ASE | 4 |
| 2023 | Multi-Modal Emotion Recognition for Enhanced Requirements Engineering: A Novel ApproachabstractRequirements engineering (RE) plays a crucial role in developing software systems by bridging the gap between stakeholders' needs and system specifications. However, effective communication and elicitation of stakeholder requirements can be challenging, as traditional RE methods often overlook emotional cues. This paper introduces a multi-modal emotion recognition platform (MEmoRE) to enhance the requirements engineering process by capturing and analyzing the emotional cues of stakeholders in real-time. MEmoRE leverages state-of-the-art emotion recognition techniques, integrating facial expression, vocal intonation, and textual sentiment analysis to comprehensively understand stakeholder emotions. This multimodal approach ensures the accurate and timely detection of emotional cues, enabling requirements engineers to tailor their elicitation strategies and improve overall communication with stakeholders. We further intend to employ our platform for later RE stages, such as requirements reviews and usability testing. By integrating multi-modal emotion recognition into requirements engineering, we aim to pave the way for more empathetic, effective, and successful software development processes. We performed a preliminary evaluation of our platform. This paper reports on the platform design, preliminary evaluation, and future development plan as an ongoing project. Ben Cheng, Chetan Arora 0002, Xiao Liu 0004, Thuong N. Hoang, Yi Wang 0119, John C. Grundy |
RE | 6 |
| 2023 | LazyCow: A Lightweight Crowdsourced Testing Tool for Taming Android FragmentationabstractAndroid fragmentation refers to the increasing variety of Android devices and operating system versions. Their number make it impossible to test an app on every supported device, resulting in many device compatibility issues and leading to poor user experiences. To mitigate this, a number of works that automatically detect compatibility issues have been proposed. However, current state-of-the-art techniques can only be used to detect specific types of compatibility issues (i.e., compatibility issues caused by API signature evolution), i.e., many other essential categories of compatibility issues are still unknown. For instance, customised OS versions on real devices and semantic OS modifications could result in severe compatibility issues that are difficult to detect statically. In order to address this research gap and facilitate the prospect of taming Android frag- mentation through crowdsourced efforts, we propose LazyCow, a novel, lightweight, crowdsourced testing tool. Our experimental results involving thousands of test cases on real Android devices demonstrate that LazyCow is effective at autonomously identifying and validating API-induced compatibility issues. The source code of both client side and server side are all made publicly available in our artifact package. A demo video of our tool is available at https://www.youtube.com/watch?v=_xzWv_mo5xQ. Xiaoyu Sun 0002, Xiao Chen 0002, Yonghui Liu 0001, John C. Grundy, Li Li 0029 |
ESEC/SIGSOFT FSE | 4 |
| 2023 | C³: Code Clone-Based Identification of Duplicated ComponentsabstractReinventing the wheel is a detrimental programming practice in software development that frequently results in the introduction of duplicated components. This practice not only leads to increased maintenance and labor costs but also poses a higher risk of propagating bugs throughout the system. Despite numerous issues introduced by duplicated components in software, the identification of component-level clones remains a significant challenge that existing studies struggle to effectively tackle. Specifically, existing methods face two primary limitations that are challenging to overcome: 1) Measuring the similarity between different components presents a challenge due to the significant size differences among them; 2) Identifying functional clones is a complex task as determining the primary functionality of components proves to be difficult. Yanming Yang, Ying Zou 0001, Xing Hu 0008, David Lo 0001, Chao Ni 0001, John C. Grundy, Xin Xia 0001 |
ESEC/SIGSOFT FSE | 6 |
| 2023 | Empirical Observations on Requirements Engineering Practices in PalestineabstractRequirements Engineering (RE) is critical to the success of software development projects. Industrial software projects that apply poor RE practices usually suffer from severe quality challenges and even project failures. Even though RE has been drawing more attention in the literature, there is a lack of empirical evidence of RE practices and challenges at industrial contexts. To address this we carried out a study to evaluate the perspectives of software engineers on their RE practices to understand more about how software engineers approach RE process and what are the challenges they face. We conducted a multi-case study by interviewing 8 participants from 5 software development companies in Palestine. Our results show that for all the RE process seems to be fairly systematic with whole team involvement. Further, the agile RE model is the dominant model, and over half reported that key challenges are caused by issues that originated from the client side. Finally, we highlight interesting future RE research from the perspective of industrial practitioners. Samer Zein, Norsaremah Salleh, John C. Grundy |
SoMeT | 3 |
| 2023 | Adaptive User Interfaces for Software Supporting Chronic DiseasesabstractThe rising prevalence of chronic diseases necessitates effective self-management strategies. mHealth interventions have shown promise in supporting self-management, but their under-utilization remains a challenge. Individuals with chronic diseases exhibit significant variations in their conditions, severity levels, and associated complications, highlighting the need for more tailored approaches. Adaptive User Interfaces (AUIs) can be used as a solution to address the diverse and dynamic needs of individuals with chronic diseases. We have created an AUI prototype based on existing literature, incorporating presentation, content, and behaviour adaptation. Our user study employs a mixed-method research approach to gather insights from users by interacting with our prototype. The future plans of the study aim to utilise insights obtained from the data analysis to automatically generate AUIs using a model-driven approach. Wei Wang 0376, Hourieh Khalajzadeh, John C. Grundy, Anuradha Madugalla |
VL/HCC | 3 |
| 2023 | Are Mobile Advertisements in Compliance with App's Age Group?abstractAs smartphones and mobile apps permeate every aspect of people’s lives, children are accessing mobile devices at an increasingly younger age. The inescapable exposure of advertisements in mobile apps to children has grown alarmingly. Mobile advertisements are placed by advertisers and subsequently distributed by ad SDKs, under the rare control of app developers and app markets’ content ratings. Indeed, content that is objectionable and harmful to children’s mental health has been reported to appear in advertising, such as pornography. However, few studies have yet concentrated on automatically and comprehensively identifying such kid-unsuitable mobile advertising. In this paper, we first characterize the regulations for mobile ads relating to children. We then propose our novel automated dynamic analysis framework, named AdRambler, that attempts to collect ad content throughout the lifespan of mobile ads and identify their inappropriateness for child app users. Using AdRambler, we conduct a large-scale (25,000 mobile apps) empirical investigation and reveal the non-incidental presence of inappropriate ads in apps with child-included target audiences. We collected 11,270 ad views and identified 1,289 ad violations (from 775 apps) of child user regulations, with roughly half of the app promotions not in compliance with host apps’ content ratings. Our finding indicates that even certified ad SDKs could still propagate inappropriate advertisements. We further delve into the question of accountability for the presence of inappropriate advertising and provide concrete suggestions for all stakeholders to take action for the benefit of children. Yanjie Zhao 0001, Tianming Liu 0002, Haoyu Wang 0001, Yepang Liu 0001, John C. Grundy, Li Li 0029 |
WWW | 5 |
| 2023 | Automated detection, categorisation and developers' experience with the violations of honesty in mobile appsabstractAbstract Human values such as honesty, social responsibility, fairness, privacy, and the like are things considered important by individuals and society. Software systems, including mobile software applications (apps), may ignore or violate such values, leading to negative effects in various ways for individuals and society. While some works have investigated different aspects of human values in software engineering, this mixed-methods study focuses on honesty as a critical human value. In particular, we studied (i) how to detect honesty violations in mobile apps, (ii) the types of honesty violations in mobile apps, and (iii) the perspectives of app developers on these detected honesty violations. We first develop and evaluate 7 machine learning (ML) models to automatically detect violations of the value of honesty in app reviews from an end-user perspective. The most promising was a Deep Neural Network model with F1 score of 0.921. We then conducted a manual analysis of 401 reviews containing honesty violations and characterised honesty violations in mobile apps into 10 categories: unfair cancellation and refund policies; false advertisements; delusive subscriptions; cheating systems; inaccurate information; unfair fees; no service; deletion of reviews; impersonation; and fraudulent-looking apps. A developer survey and interview study with mobile developers then identified 7 key causes behind honesty violations in mobile apps and 8 strategies to avoid or fix such violations. The findings of our developer study also articulate the negative consequences that honesty violations might bring for businesses, developers, and users. Finally, the app developers’ feedback shows that our prototype ML-based models can have promising benefits in practice. Humphrey O. Obie, Hung Du, Kashumi Madampe, Mojtaba Shahin, Idowu Ilekura, John C. Grundy, Li Li 0029, Jon Whittle 0001, Burak Turhan, Hourieh Khalajzadeh |
Empir. Softw. Eng. | 6 |
| 2023 | Privacy for IoT: Informed consent management in Smart BuildingsabstractSmart Buildings (SBs) employ the latest IoT technologies to automate building operations and services with the objective of increasing operational efficiency, maximising occupant comfort, and minimising environmental impact. However, these smart devices – mostly cloud-based – can capture and share a variety of sensitive and private data about the occupants, exposing them to various privacy threats. Given the non-intrusive nature of these devices, individuals typically have little or no awareness of the data being collected about them. Even if they do and claim to care about their privacy, they fail to take the necessary steps to safeguard it due to the convenience offered by the IoT devices. This discrepancy between user attitude and actual behaviour is known as the ‘privacy paradox’. To address this tension between data privacy, consent and convenience, this paper proposes a novel solution for informed consent management in shared smart spaces. Our proposed Informed Consent Management Engine (ICME) (a) increases user awareness about the data being collected by the IoT devices in the SB environment, (b) provides fine-grained visibility into privacy conformance and compliance by these devices, and (c) enables informed and confident privacy decision-making, through digital nudging. This study provides a reference architecture for ICME that can be used to implement diverse end-user consent management solutions for smart buildings. A proof-of-concept prototype is also implemented to demonstrate how ICME works in a shared smart workplace. Our proposed solution is validated by conducting expert interviews with 15 highly experienced industry professionals and academic researchers to understand the strengths, limitations, and potential improvements of the proposed system. Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig |
Future Gener. Comput. Syst. | 2 |
| 2023 | Requirements engineering for artificial intelligence systems: A systematic mapping study
Khlood Ahmad, Mohamed Almorsy, Chetan Arora 0002, Muneera Bano, John C. Grundy |
Inf. Softw. Technol. | 5 |
| 2023 | Use of personas in Requirements Engineering: A systematic mapping study
Devi Karolita, Jennifer McIntosh 0001, Tanjila Kanij, John C. Grundy, Humphrey O. Obie |
Inf. Softw. Technol. | 4 |
| 2023 | Systematic reviews in mobile app software engineering: A tertiary studyabstractContext: A number of secondary studies in the form of systematic reviews and systematic mapping studies exist in the area of mobile application software engineering. Objective: The focus of this paper is to provide an overview and analysis of these secondary studies of mobile app software engineering for researchers and practitioners. Method: We conducted a systematic tertiary study following the guidelines by Kitchenham et al. to classify and analyze secondary studies in this area. Results: After going through several filtration steps, we identified 24 secondary studies addressing major software engineering phases, such as initiation, requirements engineering , design, development and testing. The majority of the secondary studies focused on testing and design phases. Specific research topics addressed by the included studies were: usability evaluation , test automation, context-aware testing, cloud-based development, architectural models , effort and size estimation models, defect prediction , and GUI testing. We found that the trend in secondary studies is towards more specific areas of mobile application software engineering such as architectural design models, context-aware testing, testing of non-functional requirements, mobile cloud computing , and intelligent mobile applications. Research directions and some identified practices for practitioners were also identified. Conclusions: Mobile application software engineering is an active research area. The area can benefit from additional research in terms of secondary studies targeting evolution, maintenance, requirements engineering, and cross-platform mobile application development. Additionally, some of the secondary studies identify some useful practices for practitioners. Samer Zein, Norsaremah Salleh, John C. Grundy |
Inf. Softw. Technol. | 3 |
| 2023 | Empathy models and software engineering - A preliminary analysis and taxonomy
Hashini Gunatilake, John C. Grundy, Ingo Mueller 0001, Rashina Hoda |
J. Syst. Softw. | 2 |
| 2023 | Human-centric software engineering - Approaches, technologies, and applications
Xiao Liu 0004, Kelly Blincoe, Mohan Baruwal Chhetri, John C. Grundy |
J. Syst. Softw. | 4 |
| 2023 | Towards automated Android app internationalisation: An exploratory study
Qingxin Xia, Kui Liu 0001, Juncai Guo 0003, Xin Wang 0114, Jin Liu 0016, John C. Grundy, Li Li 0029 |
J. Syst. Softw. | 7 |
| 2023 | Online User and Power Allocation in Dynamic NOMA-Based Mobile Edge ComputingabstractThis study tackles the online user allocation problem in mobile edge computing (MEC) systems powered by non-orthogonal multiple access. App vendors need to determine a proper wireless channel in a base station/edge server and sufficient transmit power for every user. We consider a stochastic MEC system where users arrive and depart over time. When an edge server runs out of computing resources, some users will have to wait until the resources become available again, which incurs an allocation delay cost. This cost is often not investigated in many studies, which also do not consider a multi-cell, multi-channel system as we do in this work, due to its complexity. We aim to minimize the allocation delay and transmit power costs, increasing the system’s energy efficiency. To achieve this objective while guaranteeing users’ data rate requirements over time, we adopt the Lyapunov framework to convert this long-term optimization problem into a series of subproblems to be solved in every time slot. To solve the aforementioned subproblems efficiently, we present a distributed game theory-based approach. The proposed algorithm is theoretically evaluated and experimentally demonstrated to outperform several baseline and state-of-the-art methods, highlighting the significance of systematic consideration for both computation and communication aspects of this problem. Phu Lai, Qiang He 0001, Feifei Chen 0001, Mohamed Almorsy, John G. Hosking, John C. Grundy, Yun Yang 0001 |
IEEE Trans. Mob. Comput. | 6 |
| 2023 | OL-MEDC: An Online Approach for Cost-Effective Data Caching in Mobile Edge Computing SystemsabstractMobile Edge Computing (MEC) has emerged to overcome the inability of cloud computing to offer low latency services. It allows popular data to be cached on edge servers deployed within users' geographic proximity. However, the storage resources on edge servers are constrained due to their limited physical sizes. Existing studies of edge caching have predominantly focused on maximizing caching performance from the mobile network operator's perspective, e.g., maximizing data retrieval success rate, minimizing system energy consumption, balancing the overall caching workload, etc. App vendors, as key stakeholders in MEC systems, need to maximize the caching revenue, considering the cost incurred and the benefit produced. We investigate this novel Mobile Edge Data Caching (MEDC) problem from the app vendor's perspective, and prove its NP-hardness. We then propose Online MEDC (OL-MEDC), an approach that formulates MEDC strategies for app vendors, without requiring future information about data demands. Its performance is theoretically analyzed and experimentally evaluated. The experimental results demonstrate that OL-MEDC outperforms state-of-the-art approaches by at least 20.41\% on average. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Athman Bouguettaya, Hai Jin 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2023 | I Know What You Are Searching for: Code Snippet Recommendation from Stack Overflow PostsabstractStack Overflow has been heavily used by software developers to seek programming-related information. More and more developers use Community Question and Answer forums, such as Stack Overflow, to search for code examples of how to accomplish a certain coding task. This is often considered to be more efficient than working from source documentation, tutorials, or full worked examples. However, due to the complexity of these online Question and Answer forums and the very large volume of information they contain, developers can be overwhelmed by the sheer volume of available information. This makes it hard to find and/or even be aware of the most relevant code examples to meet their needs. To alleviate this issue, in this work, we present a query-driven code recommendation tool, named Que2Code , that identifies the best code snippets for a user query from Stack Overflow posts. Our approach has two main stages: (i) semantically equivalent question retrieval and (ii) best code snippet recommendation. During the first stage, for a given query question formulated by a developer, we first generate paraphrase questions for the input query as a way of query boosting and then retrieve the relevant Stack Overflow posted questions based on these generated questions. In the second stage, we collect all of the code snippets within questions retrieved in the first stage and develop a novel scheme to rank code snippet candidates from Stack Overflow posts via pairwise comparisons. To evaluate the performance of our proposed model, we conduct a large-scale experiment to evaluate the effectiveness of the semantically equivalent question retrieval task and best code snippet recommendation task separately on Python and Java datasets in Stack Overflow. We also perform a human study to measure how real-world developers perceive the results generated by our model. Both the automatic and human evaluation results demonstrate the promising performance of our model, and we have released our code and data to assist other researchers. Zhipeng Gao 0002, Xin Xia 0001, David Lo 0001, John C. Grundy, Zhenchang Xing |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2023 | The Influence of Human Aspects on Requirements Engineering-related Activities: Software Practitioners' PerspectiveabstractRequirements Engineering (RE)-related activities require high collaboration between various roles in software engineering (SE), such as requirements engineers, stakeholders, developers, and so on. Their demographics, views, understanding of technologies, working styles, communication and collaboration capabilities make RE highly human-dependent. Identifying how “human aspects” —such as motivation, domain knowledge, communication skills, personality, emotions, culture, and so on—might impact RE-related activities would help us improve RE and SE in general. This study aims at better understanding current industry perspectives on the influence of human aspects on RE-related activities, specifically focusing on motivation and personality, by targeting software practitioners involved in RE-related activities. Our findings indicate that software practitioners consider motivation, domain knowledge, attitude, communication skills and personality as highly important human aspects when involved in RE-related activities. A set of factors were identified as software practitioners’ key motivational factors when involved in RE-related activities, along with important personality characteristics to have when involved in RE. We also identified factors that made individuals less effective when involved in RE-related activities and obtained some feedback on measuring individuals’ performance when involved in RE. The findings from our study suggest various areas needing more investigation, and we summarise a set of key recommendations for further research. Dulaji Hidellaarachchi, John C. Grundy, Rashina Hoda, Ingo Mueller 0001 |
ACM Trans. Softw. Eng. Methodol. | 2 |
| 2023 | Demystifying Hidden Sensitive Operations in Android AppsabstractSecurity of Android devices is now paramount, given their wide adoption among consumers. As researchers develop tools for statically or dynamically detecting suspicious apps, malware writers regularly update their attack mechanisms to hide malicious behavior implementation. This poses two problems to current research techniques: static analysis approaches, given their over-approximations, can report an overwhelming number of false alarms, while dynamic approaches will miss those behaviors that are hidden through evasion techniques. We propose in this work a static approach specifically targeted at highlighting hidden sensitive operations (HSOs), mainly sensitive data flows. The prototype version of HiSenDroid has been evaluated on a large-scale dataset of thousands of malware and goodware samples on which it successfully revealed anti-analysis code snippets aiming at evading detection by dynamic analysis. We further experimentally show that, with FlowDroid, some of the hidden sensitive behaviors would eventually lead to private data leaks. Those leaks would have been hard to spot either manually among the large number of false positives reported by the state-of-the-art static analyzers, or by dynamic tools. Overall, by putting the light on hidden sensitive operations, HiSenDroid helps security analysts in validating potentially sensitive data operations, which would be previously unnoticed. Xiaoyu Sun 0002, Xiao Chen 0002, Li Li 0029, Haipeng Cai, John C. Grundy, Jordan Samhi, Tegawendé F. Bissyandé, Jacques Klein |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2023 | Dealing With Data Challenges When Delivering Data-Intensive Software SolutionsabstractThe predicted increase in demand for data-intensive solution development is driving the need for software, data, and domain experts to effectively collaborate in multi-disciplinary data-intensive software teams (MDSTs). We conducted a socio-technical grounded theory study through interviews with 24 practitioners in MDSTs to better understand the challenges these teams face when delivering data-intensive software solutions. The interviews provided perspectives across different types of roles including domain, data and software experts, and covered different organisational levels from team members, team managers to executive leaders. We found that the key concern for these teams is dealing with data-related challenges. In this article, we present a theory of dealing with data challenges that explains thechallengesfaced by MDSTs including gaining access to data, aligning data, understanding data, and resolving data quality issues; thecontextin andconditionunder which these challenges occur, thecausesthat lead to the challenges, and the relatedconsequencessuch as having to conduct remediation activities, inability to achieve expected outcomes and lack of trust in the delivered solutions. We also identifiedcontingenciesor strategies applied to address the challenges including high-level strategic approaches such as implementing data governance, implementing new tools and techniques such as data quality visualisation and monitoring tools, as well as building stronger teams by focusing on people dynamics, communication skill development and cross-skilling. Our findings have direct implications for practitioners and researchers to better understand the landscape of data challenges and how to deal with them. Ulrike Maria Graetsch, Hourieh Khalajzadeh, Mojtaba Shahin, Rashina Hoda, John C. Grundy |
IEEE Trans. Software Eng. | 5 |
| 2023 | Supporting Developers in Addressing Human-Centric Issues in Mobile AppsabstractFailure to consider the characteristics, limitations, and abilities of diverse end-users during mobile app development may lead to problems for end-users, such as accessibility and usability issues. We refer to this class of problems ashuman-centric issues. Despite their importance, there is a limited understanding of the types of human-centric issues that are encountered by end-users and taken into account by the developers of mobile apps. In this paper, we examine what human-centric issues end-users report through Google App Store reviews, what human-centric issues are a topic of discussion for developers on GitHub, and whether end-users and developers discuss the same human-centric issues. We then investigate whether an automated tool might help detect such human-centric issues and whether developers would find such a tool useful. To do this, we conducted an empirical study by extracting and manually analysing a random sample of 1,200 app reviews and 1,200 issue comments from 12 diverse projects that exist on both Google App Store and GitHub. Our analysis led to a taxonomy of human-centric issues that characterises human-centric issues into three-high level categories: App Usage, Inclusiveness, and User Reaction. We then developed machine learning and deep learning models that are promising in automatically identifying and classifying human-centric issues from app reviews and developer discussions. A survey of mobile app developers shows that the automated detection of human-centric issues has practical applications. Guided by our findings, we highlight some implications and possible future work to further understand and better incorporate addressing human-centric issues into mobile app development. Hourieh Khalajzadeh, Mojtaba Shahin, Humphrey O. Obie, Pragya Agrawal, John C. Grundy |
IEEE Trans. Software Eng. | 5 |
| 2023 | A Framework for Emotion-Oriented Requirements Change Handling in Agile Software EngineeringabstractBackground:Requirements Changes (RCs) – the additions/modifications/deletions of functional/non-functional requirements in software products – are challenging for software practitioners to handle. Handling some changes may significantly impact the emotions of the practitioners.Objective:We wanted to know the key challenges that make RC handling difficult, how these impact the emotions of software practitioners, what influences their RC handling, and how RC handling can be made less emotionally challenging.Method:We followed a mixed-methods approach. We conducted two survey studies, with 40 participants and 201 participants respectively. The presentation of key quantitative data was followed by descriptive statistical analysis, and the qualitative data was analysed using Strauss–Corbinian Grounded Theory, and Socio–Technical Grounded Theory analysis techniques.Findings:We found (1) several key factors that make RC handling an emotional challenge, (2) varying emotions that practitioners feel when it is challenging to handle RCs, (3) how stakeholders, including practitioners themselves, peers, managers and customers, influence the RC handling and how practitioners feel due to the stakeholder influence, and (4) practices that can be used to better handle RCs.Conclusion:Some challenges are technical and some are social which also belong to aspects of agile practice, emotional intelligence, and likely belong to cognitive intelligence. Therefore, to better handle RCs with positive emotions in socio–technical environments, agility, emotional intelligence, and cognitive intelligence need to work in synergy with each other. Kashumi Madampe, Rashina Hoda, John C. Grundy |
IEEE Trans. Software Eng. | 3 |
| 2023 | The Emotional Roller Coaster of Responding to Requirements Changes in Software EngineeringabstractBackground:A preliminary study we conducted showed that software practitioners respond to requirements changes (RCs) with different emotions, and that their emotions vary at stages of the RC handling life cycle, such asreceiving, developing,anddeliveringRCs. Furthermore, such developer emotions have direct linkages to cognition, productivity, and decision making. Therefore, it is important to gain a comprehensive understanding the role of emotions in a critical scenarios like handling RCs.Objective:We wanted to study how practitionersemotionallyrespond to RCs.Method:We conducted a world-wide survey with the participation of 201 software practitioners. In our survey, we used the Job-related Affective Well-being Scale (JAWS) and open-ended questions to capture participants’ emotions when handling RCs in their work and query about the different circumstances when they feel these emotions. We used a combined approach of statistical analysis, JAWS, and Socio-Technical Grounded Theory (STGT)for Data Analysisto analyse our survey data.Findings:We identified (1) emotional responses to RCs, i.e., the most commonemotionsfelt by practitioners when handling RCs; (2) differentstimuli– such as the RC, the practitioner, team, manager, customer – that trigger these emotions through their own different characteristics; (3)emotion dynamics, i.e., the changes in emotions during the RC handling life cycle; (4)RC stageswhere particular emotions are triggered; and (5)time related aspectsthat regulate the emotion dynamics.Conclusion:Practitioners are not pleased with receiving RCs all the time. Last minute RCs introduced closer to a deadline especially violate emotional well-being of practitioners. We present some practical recommendations for practitioners to follow, including a dual-purpose emotion-centric decision guide to help decide when to introduce or accept an RC, and some future key research directions. Kashumi Madampe, Rashina Hoda, John C. Grundy |
IEEE Trans. Software Eng. | 3 |
| 2023 | Taming Android Fragmentation Through Lightweight Crowdsourced TestingabstractAndroid fragmentation refers to the overwhelming diversity of Android devices and OS versions. These lead to the impossibility of testing an app on every supported device, leaving a number of compatibility bugs scattered in the community and thereby resulting in poor user experiences. To mitigate this, our fellow researchers have designed various works to automatically detect such compatibility issues. However, the current state-of-the-art tools can only be used to detect specific kinds of compatibility issues (i.e., compatibility issues caused by API signature evolution), i.e., many other essential types of compatibility issues are still unrevealed. For example, customized OS versions on real devices and semantic changes of OS could lead to serious compatibility issues, which are non-trivial to be detected statically. To this end, we propose a novel, lightweight, crowdsourced testing approach, to fill this research gap and enable the possibility of taming Android fragmentation through crowdsourced efforts. Specifically, crowdsourced testing is an emerging alternative to conventional mobile testing mechanisms that allow developers to test their products on real devices to pinpoint platform-specific issues. Experimental results on thousands of test cases on real-world Android devices show that is effective in automatically identifying and verifying API-induced compatibility issues. Also, after investigating the user experience through qualitative metrics, users' satisfaction provides strong evidence that is useful and welcome in practice. Xiaoyu Sun 0002, Xiao Chen 0002, Yonghui Liu 0001, John C. Grundy, Li Li 0029 |
IEEE Trans. Software Eng. | 4 |
| 2023 | APIMatchmaker: Matching the Right APIs for Supporting the Development of Android AppsabstractAndroid developers are often faced with the need to learn how to use different APIs suitable for their projects. Automated API recommendation approaches have been invented to help fill this gap, and these have been demonstrated to be useful to some extent. Unfortunately, most state-of-the-art works are not proposed for Android developers, and the ones dedicated to Android app development often suffer from high redundancy and poor run-time performance, or do not target the problem of recommending API usage patterns. To address this gap we propose to the community a new tool, namelyAPIMatchmaker, to recommend API usages by learning directly from similar real-world Android apps. Unlike existing recommendation approaches, which leverage a single context to find similar projects, we innovatively introduce a multi-dimensional, context-aware, collaborative filtering approach to better achieve the purpose. Specifically, in addition to code similarity, we also take app descriptions (or topics) into consideration to ensure that similar apps also provide similar functions. We evaluateAPIMatchmakeron a large number of real-world Android apps and observe thatAPIMatchmakeryields a high success rate in recommending APIs for Android apps under development, and it is also able to outperform the state-of-the-art. Yanjie Zhao 0001, Li Li 0029, Haoyu Wang 0001, Qiang He 0001, John C. Grundy |
IEEE Trans. Software Eng. | 5 |
| 2022 | A Curated Personas and Design Guidelines Tool for Better Supporting Diverse End-usersabstractMany work and living activities in modern society are increasingly dependent on web and app software. However, much existing software lacks consideration of many diverse end-user characteristics, such as age, mental and physical challenges, language proficiency, culture, socio-economic status, educational attainment and so on. Many developers do not have lived experience of most of these challenges, fail to empathise with those who have them, and lack knowledge of how to address them in their software design and evaluation activities. To address this issue, we designed a curated persona and design guidelines tool to help developers consider and address diverse end-user needs during the software development process. Our tool helps software development teams to take a more holistic view of human nature and diverse end-uses during the software development cycle and to design software with multiple diverse end-user needs in mind. Our evaluation with 23 real world software developers shows that the use of such human-centric persona and guideline tools in the early stages of software development can help to reduce software end-user bias and increase software accessibility. Zichuan Zhang, John C. Grundy, Tanjila Kanij |
COMPSAC | 6 |
| 2022 | Human Values Violations in Stack Overflow: An Exploratory StudyabstractA growing number of software-intensive systems are being accused of violating or ignoring human values (e.g., privacy, inclusion, and social responsibility), and this poses great difficulties to individuals and society. Such violations often occur due to the solutions employed and decisions made by developers of such systems that are misaligned with user values. Stack Overflow is the most popular Q&A website among developers to share their issues, solutions (e.g., code snippets), and decisions during software development. We conducted an exploratory study to investigate the occurrence of human values violations in Stack Overflow posts. As comments under posts are often used to point out the possible issues and weaknesses of the posts, we analyzed 2,000 Stack Overflow comments and their corresponding posts (1,980 unique questions or answers) to identify the types of human values violations and the reactions of Stack Overflow users to such violations. Our study finds that 315 out of 2,000 comments contain concerns indicating their associated posts (313 unique posts) violate human values. Leveraging Schwartz’s theory of basic human values as the most widely used values model, we show that hedonism and benevolence are the most violated value categories. We also find the reaction of Stack Overflow commenters to perceived human values violations is very quick, yet the majority of posts (76.35%) accused of human values violation do not get downvoted at all. Finally, we find that the original posters rarely react to the concerns of potential human values violations by editing their posts. At the same time, they usually are receptive when responding to these comments in follow-up comments of their own. Sara Krishtul, Mojtaba Shahin, Humphrey O. Obie, Hourieh Khalajzadeh, Fan Gai, Ali Rezaei Nasab, John C. Grundy |
EASE | 7 |
| 2022 | Evaluation of an Augmented Reality Approach to Better Understanding Diverse End User Website Usage ChallengesabstractEnd users with disabilities face many limitations with online accessibility. Efforts to tackle the problems of testing for these problems have not yet been sufficient. In this paper we describe an evaluation of Funkify, an augmented reality tool to simulate diverse end users’ experiences and challenges when interacting with software. The research evaluates the tool’s effectiveness for software engineers use in emulating four diverse end user challenges using a heuristics-based evaluation and cognitive walk-throughs on three target websites. Our results show that the tool successfully simulates the target personas’ challenges varying extent, with some noticeable limitations. We provide suggestions for extensions to Funkify as well as AR tools in general. Minh Hieu Vu, Joshua (Shuki) Wyman, John C. Grundy |
ENASE | 3 |
| 2022 | Formulating Interference-aware Data Delivery Strategies in Edge Storage SystemsabstractNetworked edge servers constitute an edge storage system in edge computing (EC). Upon users’ requests, data must be delivered from edge servers in the system or from the cloud to users. Existing studies of edge storage systems have unfortunately neglected the fact that an excessive number of users accessing the same edge server for data may impact users’ data rates seriously due to the wireless interference. Thus, users must first be allocated to edge servers properly for ensuring their data rates. After that, requested data can be delivered to users to minimize their average data delivery latency. In this paper, we formulate this Interference-aware Data Delivery at the network Edge (IDDE) problem, and demonstrate its NP-hardness. To tackle it effectively and efficiently, we propose IDDE-G, a novel approach that first finds a Nash equilibrium as the strategy for allocating users. Then, it finds an approximate strategy for delivering requested data to allocated users. We analyze the performance of IDDE-G theoretically and evaluate its performance experimentally to demonstrate the effectiveness and efficiency of IDDE-G on solving the IDDE problem. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Fang Dong 0001 |
ICPP | 5 |
| 2022 | Towards Automatically Repairing Compatibility Issues in Published Android AppsabstractThe heavy fragmentation of the Android ecosystem has led to severe compatibility issues with apps, including those that crash at runtime or cannot be installed on certain devices but work well on other devices. To address this problem, various approaches have been proposed to detect and fix compatibility issues automatically. However, these all come with various limitations on fixing the compatibility issues, e.g., can only fix one specific type of issues, cannot deal with multi-invocation issues in a single line and issues in released apps. To overcome these limitations, we propose a generic approach that aims at fixing more types of compatibility issues in released Android apps. To this end, our prototype tool, RepairDroid, provides a generic app patch description language for users to create fix templates for compatibility issues. The created templates will then be leveraged by RepairDroid to automatically fix the corresponding issue at the bytecode level (e.g., right before users install the app). RepairDroid can support template creations for OS-induced, device-specific and inter-callback compatibility issues detected by three state-of-the-art approaches. Our experimental results show that RepairDroid can fix 7,660 out of 8,976 compatibility issues in 1,000 randomly selected Google Play apps. RepairDroid is generic to configure new compatibility issues and outperforms the state-of-the-art on effectively repairing compatibility issues in released Android apps. Yanjie Zhao 0001, Li Li 0029, Kui Liu 0001, John C. Grundy |
ICSE | 4 |
| 2022 | Automatically detecting API-induced compatibility issues in Android apps: a comparative analysis (replicability study)abstractFragmentation is a serious problem in the Android ecosystem. This problem is mainly caused by the fast evolution of the system itself and the various customizations independently maintained by different smartphone manufacturers. Many efforts have attempted to mitigate its impact via approaches to automatically pinpoint compatibility issues in Android apps. Unfortunately, at this stage, it is still unknown if this objective has been fulfilled, and the existing approaches can indeed be replicated and reliably leveraged to pinpoint compatibility issues in the wild. We, therefore, propose to fill this gap by first conducting a literature review within this topic to identify all the available approaches. Among the nine identified approaches, we then try our best to reproduce them based on their original datasets. After that, we go one step further to empirically compare those approaches against common datasets with real-world apps containing compatibility issues. Experimental results show that existing tools can indeed be reproduced, but their capabilities are quite distinct, as confirmed by the fact that there is only a small overlap of the results reported by the selected tools. This evidence suggests that more efforts should be spent by our community to achieve sound compatibility issues detection. Yanjie Zhao 0001, Haipeng Cai, Mattia Fazzini, John C. Grundy, Li Li 0029 |
ISSTA | 5 |
| 2022 | A First Look at CI/CD Adoptions in Open-Source Android AppsabstractContinuous Integration (CI) and Continuous Delivery (CD) have been demonstrated to be effective in facilitating software building, testing, and deployment. Many research studies have investigated and subsequently improved their working processes. Unfortunately, such research efforts have largely not touched on the usage of CI/CD in the development of Android apps. We fill this gap by conducting an exploratory study of CI/CD adoption in open-source Android apps. We start by collecting a set of 84,475 open-source Android apps from the most popular three online code hosting sites, namely Github, GitLab, and Bitbucket. We then look into those apps and find that (1) only around 10% of apps have leveraged CI/CD services, i.e., the majority of open-source Android apps are developed without accessing CI/CD services, (2) a small number of apps (291) has even adopted multiple CI/CD services, (3) nearly half of the apps adopted CI/CD services have not really used them, and (4) CI/CD services are useful to improve the popularity of projects. Xiaoyu Sun 0002, Yanjie Zhao 0001, Yonghui Liu 0001, John C. Grundy, Li Li 0029 |
ASE | 5 |
| 2022 | Mining Android API Usage to Generate Unit Test Cases for Pinpointing Compatibility IssuesabstractDespite being one of the largest and most popular projects, the official Android framework has only provided test cases for less than 30% of its APIs. Such a poor test case coverage rate has led to many compatibility issues that can cause apps to crash at runtime on specific Android devices, resulting in poor user experiences for both apps and the Android ecosystem. To mitigate this impact, various approaches have been proposed to automatically detect such compatibility issues. Unfortunately, these approaches have only focused on detecting signature-induced compatibility issues (i.e., a certain API does not exist in certain Android versions), leaving other equally important types of compatibility issues unresolved. In this work, we propose a novel prototype tool, JUnitTestGen, to fill this gap by mining existing Android API usage to generate unit test cases. After locating Android API usage in given real-world Android apps, JUnitTestGen performs inter-procedural backward data-flow analysis to generate a minimal executable code snippet (i.e., test case). Experimental results on thousands of real-world Android apps show that JUnitTestGen is effective in generating valid unit test cases for Android APIs. We show that these generated test cases are indeed helpful for pinpointing compatibility issues, including ones involving semantic code changes. Xiaoyu Sun 0002, Xiao Chen 0002, Yanjie Zhao 0001, John C. Grundy, Li Li 0029 |
ASE | 5 |
| 2022 | Do Customized Android Frameworks Keep Pace with Android?abstractTo satisfy varying customer needs, device vendors and OS providers often rely on the open-source nature of the Android OS and offer customized versions of the Android OS. When a new version of the Android OS is released, device vendors and OS providers need to merge the changes from the Android OS into their customizations to account for its bug fixes, security patches, and new features. Because developers of customized OSs might have made changes to code locations that were also modified by the developers of the Android OS, the merge task can be characterized by conflicts, which can be time-consuming and error-prone to resolve. Mattia Fazzini, John C. Grundy, Li Li 0029 |
MSR | 3 |
| 2022 | On the Violation of Honesty in Mobile Apps: Automated Detection and CategoriesabstractHuman values such as integrity, privacy, curiosity, security, and honesty are guiding principles for what people consider important in life. Such human values may be violated by mobile software applications (apps), and the negative effects of such human value violations can be seen in various ways in society. In this work, we focus on the human value of honesty. We present a model to support the automatic identification of violations of the value of honesty from app reviews from an end-user perspective. Beyond the automatic detection of honesty violations by apps, we also aim to better understand different categories of honesty violations expressed by users in their app reviews. The result of our manual analysis of our honesty violations dataset shows that honesty violations can be characterised into ten categories: unfair cancellation and refund policies; false advertisements; delusive subscriptions; cheating systems; inaccurate information; unfair fees; no service; deletion of reviews; impersonation; and fraudulent-looking apps. Based on these results, we argue for a conscious effort in developing more honest software artefacts including mobile apps, and the promotion of honesty as a key value in software development practices. Furthermore, we discuss the role of app distribution platforms as enforcers of ethical systems supporting human values, and highlight some proposed next steps for human values in software engineering (SE) research. Humphrey O. Obie, Idowu Ilekura, Hung Du, Mojtaba Shahin, John C. Grundy, Li Li 0029, Jon Whittle 0001, Burak Turhan |
MSR | 5 |
| 2022 | Dynamic User Allocation in Stochastic Mobile Edge Computing SystemsabstractMobile edge computing (MEC) is a new distributed computing paradigm where edge servers are deployed at, or near cellular base stations in close proximity to end-users. This offers computing resources at the edge of the network, facilitating a highly accessible platform for real-time, latency-sensitive services. A typical MEC environment is highly stochastic with random user arrivals and departures over time. Here, we address the user allocation problem from a service provider’s perspective, who needs to allocate its users to the cloud or edge servers in a specific area. A user, who has a multi-dimensional resource requirement, can be allocated to either the remote cloud, which incurs a high latency, or an edge server, which results in a low latency but might require the user to wait in a queue. This study aims to achieve a controllable trade-off between performance (throughput) and several associated costs such as queuing delay and latency costs. We model this problem as a stochastic optimization problem, propose SUAC (Stochastic User AlloCation) – an online Lyapunov optimization-based algorithm, and prove its performance bounds. The experimental results demonstrate that SUAC outperforms existing approaches, effectively allocating users with a desired trade-off while keeping the system strongly stable. Phu Lai, Qiang He 0001, Xiaoyu Xia 0001, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
SERVICES | 6 |
| 2022 | An Empirical Study on How Well Do COVID-19 Information Dashboards Service Users' Information NeedsabstractCoronavirus disease 2019 (COVID-19) is an infectious disease caused by severe acute respiratory syndrome coronavirus 2 (SARS-CoV-2). Since its first being reported in December 2019, COVID-19 has spread quickly around the world, and becomes a global pandemic. Previous information sources have a number of problems when providing COVID-19 information web services. First, the information from government or traditional media (i.e., TV and newspaper) is not frequently updated. Second, different layers of the government (state and federal government) may provide contradictory information. Also, there are many rumours spread on social media, which makes it difficult for people to know who and what to trust. Finally, the current information about COVID-19 is fragmented. It takes effort for people to aggregate the information they need to see from different places. Han Wang 0023, Chunyang Chen 0001, John C. Grundy |
SERVICES | 4 |
| 2022 | RCM-extractor: an automated NLP-based approach for extracting a semi formal representation model from natural language requirements
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 4 |
| 2022 | A large scale analysis of mHealth app user reviewsabstractThe global mHealth app market is rapidly expanding, especially since the COVID-19 pandemic. However, many of these mHealth apps have serious issues, as reported in their user reviews. Better understanding their key user concerns would help app developers improve their apps' quality and uptake. While app reviews have been used to study user feedback in many prior studies, many are limited in scope, size and/or analysis. In this paper, we introduce a very large-scale study and analysis of mHealth app reviews. We extracted and translated over 5 million user reviews for 278 mHealth apps. These reviews were then classified into 14 different aspects/categories of issues reported. Several mHealth app subcategories were examined to reveal differences in significant areas of user concerns, and to investigate the impact of different aspects of mhealth apps on their ratings. Based on our findings, women's health apps had the highest satisfaction ratings. Fitness activity tracking apps received the lowest and most unfavourable ratings from users. Over half of users who reported troubles leading them to uninstall mHealth apps gave a 1-star rating. Half of users gave the account and logging aspect only one star due to faults and issues encountered while registering or logging in. Over a third of users who expressed privacy concerns gave the app a 1-star rating. However, only 6% of users gave apps a one-star rating due to UI/UX concerns. 20% of users reported issues with handling of user requests and internationalisation concerns. We validated our findings by manually analysing a sample of 1,000 user reviews from each investigated aspect/category. We developed a list of recommendations for mHealth apps developers based on our user review analysis. Omar Haggag, John C. Grundy, Mohamed Almorsy, Sherif Haggag |
Empir. Softw. Eng. | 2 |
| 2022 | A model-driven approach to reengineering processes in cloud computing
Mahdi Fahmideh, John C. Grundy, Ghassan Beydoun, Didar Zowghi, Willy Susilo, Davoud Mougouei |
Inf. Softw. Technol. | 2 |
| 2022 | Emotimonitor: A Trello power-up to capture and monitor emotions of Agile teams
Mohammed-Amr Abd El-Migid, Damon Cai, Thomas Niven, Jeffrey Vo, Kashumi Madampe, John C. Grundy, Rashina Hoda |
J. Syst. Softw. | 6 |
| 2022 | EdgeWorkflow: One click to test and deploy your workflow applications to the edgeabstractIn recent years, edge computing has become the ideal computing paradigm for various smart systems, such as smart logistics, smart health and smart transportation. This is due to its advantages including fast response times, energy efficiency and cost effectiveness over conventional cloud computing platforms. However, running complex computational scientific workflow tasks is still a very challenging issue at the edge, due to its typical three-layered computing environment consisting of an end device layer, an edge server layer, and a cloud server layer. A large number of recent studies have proposed different solutions for optimizing such computing resource management problems in an edge computing environment. However, since evaluation of most such studies is conducted through simulation, the effectiveness cannot be guaranteed in a real world environment. Therefore, to advance research on efficient execution and deployment problems for real world workflow applications using edge computing, an open-source edge workflow management system with comprehensive empirical evaluation capabilities is urgently required. This paper presents the first edge workflow system (named EdgeWorkflow) that is able to deploy user-created workflow applications to a real-world edge computing environment with “one-click” after optimizing the configuration with the simulation tool. With the aid of EdgeWorkflow, the user can automate the generation of specific edge computing environments, easily model and generate executable workflow applications with a visual modelling tool, effectively select various resource management methods included in the systems or apply their own resource management and task scheduling algorithms, efficiently monitor the statuses of computational tasks and obtain comprehensive reports on the execution results (such as those regarding time, cost and energy). We use an edge computing-based unmanned aerial vehicle (UAV) last-mile delivery system as a real-world case study, and a number of representative scientific workflows are employed for our experiments. Our experimental results show that EdgeWorkflow can effectively evaluate the performance of different resource management and workflow task scheduling algorithms and efficiently deploy and execute user-defined scientific workflow applications to user-specified edge computing environments. Jia Xu 0010, Xiao Liu 0004, Xuejun Li 0001, John C. Grundy, Yun Yang 0001 |
J. Syst. Softw. | 5 |
| 2022 | Survey and Analysis of Current End-User Data Analytics Tool SupportabstractThere has been a very large growth in interest in big data analytics to discover patterns and insights. A major challenge in this domain is the need to combine domain knowledge – what the data means (semantics) and what it is used for – with advanced data analytics and visualization techniques to mine and communicate important information from the huge volumes of raw data. Many data analytics tools have been developed for both research and practice to assist in specifying, integrating and deploying data analytics applications. However, delivering such big data analytics applications requires a capable team with different skillsets including data scientists, software engineers and domain experts. Such teams and skillsets usually take a long time to build and have high running costs. An alternative is to provide domain experts and data scientists – the end users – with tools they can use to create and deploy complex data analytics application solutions directly with less technical skills required. In this paper we present a survey and analysis of several current research and practice approaches to supporting data analytics for end-users, identifying key strengths, weaknesses and opportunities for future research. Hourieh Khalajzadeh, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
IEEE Trans. Big Data | 3 |
| 2022 | Cost-Effective App User Allocation in an Edge Computing EnvironmentabstractEdge computing is a new distributed computing paradigm extending the cloud computing paradigm, offering much lower end-to-end latency, as real-time, latency-sensitive applications can now be deployed on edge servers that are much closer to end-users than distant cloud servers. In edge computing, edge user allocation (EUA) is a critical problem for any app vendors, who need to determine which edge servers will serve which users. This is to satisfy application-specific optimization objectives, e.g., maximizing users’ overall quality of experience, minimizing system costs, and so on. In this article, we focus on the cost-effectiveness of user allocation solutions with two optimization objectives. The primary one is to maximize the number of users allocated to edge servers. The secondary one is to minimize the number of required edge servers, which subsequently reduces the operating costs for app vendors. We first model this problem as a bin packing problem and introduce an approach for finding optimal solutions. However, finding optimal solutions to the$\mathcal {NP}$-hard EUA problem in large-scale scenarios is intractable. Thus, we propose a heuristic to efficiently find sub-optimal solutions to large-scale EUA problems. Extensive experiments conducted on real-world data demonstrate that our heuristic can solve the EUA problem effectively and efficiently, outperforming the state-of-the-art and baseline approaches. Phu Lai, Qiang He 0001, John C. Grundy, Feifei Chen 0001, Mohamed Almorsy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Cloud Comput. | 3 |
| 2022 | Cost-Effective User Allocation in 5G NOMA-Based Mobile Edge Computing SystemsabstractMobile edge computing (MEC) allows edge servers to be placed at cellular base stations. App vendors like Uber and YouTube can rent computing resources and deploy latency-sensitive applications on edge servers for their users to access. Non-orthogonal multiple access (NOMA) is an emerging technique that facilitates the massive connectivity of 5G networks, further enhancing the capability of MEC. The edge user allocation (EUA) problem faces new challenges in 5G NOMA-based MEC systems. In this study, we investigate the EUA problem in a multi-cell multi-channel downlink power-domain NOMA-based MEC system. The main objective is to help mobile app vendors maximize their benefit by allocating maximum users to edge servers in a specific area at the lowest computing resource and transmit power costs. To this end, we introduce a decentralized game-theoretic approach to effectively select a channel and edge server for each user while fulfilling their resource and data rate requirements. We theoretically and experimentally evaluate our solution, which significantly outperforms various state-of-the-art and baseline approaches. Phu Lai, Qiang He 0001, Guangming Cui, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Mob. Comput. | 5 |
| 2022 | Accessibility in Software Practice: A Practitioner's PerspectiveabstractBeing able to access software in daily life is vital for everyone, and thus accessibility is a fundamental challenge for software development. However, given the number of accessibility issues reported by many users, e.g., in app reviews, it is not clear if accessibility is widely integrated into current software projects and how software projects address accessibility issues. In this article, we report a study of the critical challenges and benefits of incorporating accessibility into software development and design. We applied a mixed qualitative and quantitative approach for gathering data from 15 interviews and 365 survey respondents from 26 countries across five continents to understand how practitioners perceive accessibility development and design in practice. We got 44 statements grouped into eight topics on accessibility from practitioners’ viewpoints and different software development stages. Our statistical analysis reveals substantial gaps between groups, e.g., practitioners have Direct vs. Indirect accessibility relevant work experience when they reviewed the summarized statements. These gaps might hinder the quality of accessibility development and design, and we use our findings to establish a set of guidelines to help practitioners be aware of accessibility challenges and benefit factors. We suggest development teams put accessibility as a first-class consideration throughout the software development process, and we also propose some remedies to resolve the gaps between groups and to highlight key future research directions to incorporate accessibility into software design and development. Tingting Bi, Xin Xia 0001, David Lo 0001, John C. Grundy, Thomas Zimmermann 0001, Denae Ford |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2022 | Why Do Smart Contracts Self-Destruct? Investigating the Selfdestruct Function on EthereumabstractThe selfdestruct function is provided by Ethereum smart contracts to destroy a contract on the blockchain system. However, it is a double-edged sword for developers. On the one hand, using the selfdestruct function enables developers to remove smart contracts ( SCs ) from Ethereum and transfers Ethers when emergency situations happen, e.g., being attacked. On the other hand, this function can increase the complexity for the development and open an attack vector for attackers. To better understand the reasons why SC developers include or exclude the selfdestruct function in their contracts, we conducted an online survey to collect feedback from them and summarize the key reasons. Their feedback shows that 66.67% of the developers will deploy an updated contract to the Ethereum after destructing the old contract. According to this information, we propose a method to find the self-destructed contracts (also called predecessor contracts) and their updated version (successor contracts) by computing the code similarity. By analyzing the difference between the predecessor contracts and their successor contracts, we found five reasons that led to the death of the contracts; two of them (i.e., Unmatched ERC20 Token and Limits of Permission ) might affect the life span of contracts. We developed a tool named LifeScope to detect these problems. LifeScope reports 0 false positives or negatives in detecting Unmatched ERC20 Token . In terms of Limits of Permission , LifeScope achieves 77.89% of F-measure and 0.8673 of AUC in average. According to the feedback of developers who exclude selfdestruct functions, we propose suggestions to help developers use selfdestruct functions in Ethereum smart contracts better. Jiachi Chen, Xin Xia 0001, David Lo 0001, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2022 | On the Reproducibility and Replicability of Deep Learning in Software EngineeringabstractContext:Deep learning (DL) techniques have gained significant popularity among software engineering (SE) researchers in recent years. This is because they can often solve many SE challenges without enormous manual feature engineering effort and complex domain knowledge. Objective:Although many DL studies have reported substantial advantages over other state-of-the-art models on effectiveness, they often ignore two factors:(1) reproducibility—whether the reported experimental results can be obtained by other researchers using authors’ artifacts (i.e., source code and datasets) with the same experimental setup; and(2) replicability—whether the reported experimental result can be obtained by other researchers using their re-implemented artifacts with a different experimental setup. We observed that DL studies commonly overlook these two factors and declare them as minor threats or leave them for future work. This is mainly due to high model complexity with many manually set parameters and the time-consuming optimization process, unlike classical supervised machine learning (ML) methods (e.g., random forest). This study aims to investigate the urgency and importance of reproducibility and replicability for DL studies on SE tasks. Method:In this study, we conducted a literature review on 147 DL studies recently published in 20 SE venues and 20 AI (Artificial Intelligence) venues to investigate these issues. We also re-ran four representative DL models in SE to investigate important factors that may strongly affect the reproducibility and replicability of a study. Results:Our statistics show the urgency of investigating these two factors in SE, where only 10.2% of the studies investigate any research question to show that their models can address at least one issue of replicability and/or reproducibility. More than 62.6% of the studies do not even share high-quality source code or complete data to support the reproducibility of their complex models. Meanwhile, our experimental results show the importance of reproducibility and replicability, where the reported performance of a DL model could not be reproduced for an unstable optimization process. Replicability could be substantially compromised if the model training is not convergent, or if performance is sensitive to the size of vocabulary and testing data. Conclusion:It is urgent for the SE community to provide a long-lasting link to a high-quality reproduction package, enhance DL-based solution stability and convergence, and avoid performance sensitivity on different sampled data. Chao Liu 0014, Cuiyun Gao 0001, Xin Xia 0001, David Lo 0001, John C. Grundy, Xiaohu Yang 0001 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2022 | Predictive Models in Software Engineering: Challenges and OpportunitiesabstractPredictive models are one of the most important techniques that are widely applied in many areas of software engineering. There have been a large number of primary studies that apply predictive models and that present well-performed studies in various research domains, including software requirements, software design and development, testing and debugging, and software maintenance. This article is a first attempt to systematically organize knowledge in this area by surveying a body of 421 papers on predictive models published between 2009 and 2020. We describe the key models and approaches used, classify the different models, summarize the range of key application areas, and analyze research results. Based on our findings, we also propose a set of current challenges that still need to be addressed in future work and provide a proposed research road map for these opportunities. Yanming Yang, Xin Xia 0001, David Lo 0001, Tingting Bi, John C. Grundy, Xiaohu Yang 0001 |
ACM Trans. Softw. Eng. Methodol. | 5 |
| 2022 | Data, User and Power Allocations for Caching in Multi-Access Edge ComputingabstractIn the multi-access edge computing (MEC) environment, app vendors’ data can be cached on edge servers to ensure low-latency data retrieval. Massive users can simultaneously access edge servers with high data rates through flexible allocations of transmit power. The ability to manage networking resources offers unique opportunities to app vendors but also raises unprecedented challenges. To ensure fast data retrieval for users in the MEC environment, edge data caching must take into account the allocations of data, users, and transmit power jointly. We make the first attempt to study the Data, User, and Power Allocation (DUPA$^3$) problem, aiming to serve the most users and maximize their overall data rate. First, we formulate the DUPA$^3$problem and prove its$\mathcal {NP}$-completeness. Then, we model the DUPA$^3$problem as a potential DUPA$^3$game admitting at least one Nash equilibrium and propose a two-phase game-theoretic decentralized algorithm named DUPA$^3$Game to achieve the Nash equilibrium as the solution to the DUPA$^3$problem. To evaluate DUPA$^3$Game, we analyze its theoretical performance and conduct extensive experiments to demonstrate its effectiveness and efficiency. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, John C. Grundy, Mohamed Almorsy, Xiaolong Xu 0001, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 5 |
| 2022 | Formulating Cost-Effective Data Distribution Strategies Online for Edge Cache SystemsabstractEdge Computing (EC) enables a new kind of caching system in close geographic proximity to end-users by allowing app vendors to cache popular data on edge servers deployed at base stations. This edge cache system can better support latency-sensitive applications. However, transmitting data from the centralized cloud to the edge servers without proper transmission strategies may cost app vendors dearly. Cost-effective data distribution strategies are of particular importance for applications, whose data to be cached at the edge often changes dynamically. In this paper, we study thisOnline Edge Data Distribution(OEDD) problem, aiming to minimize app vendors’ total transmission cost, while ensuring low transmission latency in the long term. We first model this problem and prove its$\mathcal {NP}$-hardness. We then combine Lyapunov optimization and game theory to propose a novel Latency-Aware Online (LAO) approach for solving this OEDD problem over time in a distributed manner with provable performance guarantees. The evaluation of LAO based on a real-world dataset demonstrates that it can help app vendors formulate cost-effective edge data distribution strategies in an online manner. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Jun Shen 0001, Athman Bouguettaya, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2022 | Dynamic User Allocation in Stochastic Mobile Edge Computing SystemsabstractMobile edge computing (MEC) is a new distributed computing paradigm where edge servers are deployed at, or near cellular base stations in close proximity to end-users. This offers computing resources at the edge of the network, facilitating a highly accessible platform for real-time, latency-sensitive services. A typical MEC environment is highly stochastic with random user arrivals and departures over time. Here, we address the user allocation problem from a service provider's perspective, who needs to allocate its users to the cloud or edge servers in a specific area. A user, who has a multi-dimensional resource requirement, can be allocated to either the remote cloud, which incurs a high latency, or an edge server, which results in a low latency but might require the user to wait in a queue. This article aims to achieve a controllable trade-off between performance (throughput) and several associated costs such as queuing delay and latency costs. We model this problem as a stochastic optimization problem, propose SUAC (Stochastic User AlloCation) – an online Lyapunov optimization-based algorithm, and prove its performance bounds. The experimental results demonstrate that SUAC outperforms existing approaches, effectively allocating users with a desired trade-off while keeping the system strongly stable. Phu Lai, Qiang He 0001, Xiaoyu Xia 0001, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
IEEE Trans. Serv. Comput. | 6 |
| 2022 | An Empirical Study on How Well Do COVID-19 Information Dashboards Service Users' Information NeedsabstractThe ongoing COVID-19 pandemic highlights the importance of dashboards for providing critical real-time information. In order to enable people to obtain information in time and to understand complex statistical data, many developers have designed and implemented public-oriented COVID-19 “information dashboards” during the pandemic. However, development often takes a long time and developers are not clear about many people’s information needs, resulting in gaps between information needs and supplies. According to our empirical study and observations with popular developed COVID-19 dashboards, this seriously impedes information acquirement. Our study compares people’s needs on Twitter with existing information suppliers. We determine that despite the COVID-19 information that is currently on existing dashboards, people are also interested in the relationship between COVID-19 and other viruses, the origin of COVID-19, vaccine development, fake new about COVID-19, impact on women, impact on school/university, and impact on business. Most of these have not yet been well addressed. We also summarise the visualization and interaction patterns commonly applied in dashboards, finding key patterns between data and visualization as well as visualization and interaction. Our findings can help developers to better optimize their dashboard to meet people’s needs and make improvements to future crisis management dashboard development. Han Wang 0023, Chunyang Chen 0001, John C. Grundy |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Runtime Verification of Business Cloud Workflow Temporal ConformanceabstractBusiness cloud workflows are often designed with multiple time constraints for timely response to business requests. To ensure on-time completion of workflow instances, workflow temporal conformance state needs to be constantly monitored and verified at runtime. Considering the fact that there are a large number of workflow instances running in a parallel fashion in many business scenarios, conventional verification approaches for time-related properties based on temporal logic or timed Petri nets are not feasible due to the limitation of low efficiency at runtime. To address this issue, we propose a new approach to automated runtime verification of temporal conformance for parallel workflow instances in a cloud environment. In this article, instead of using response time to verify temporal conformance of every single workflow as in conventional strategies, workflow throughput is employed as the performance measurement to efficiently monitor a large number of parallel workflow instances. On this basis we present a novel conformance verification strategy. This strategy considers the effect of time delay propagation in the cloud workflow systems to accurately verify workflow runtime temporal conformance. Our verification strategy is implemented in a prototype cloud workflow system and the evaluation results show that it outperforms the state-of-the-art workflow temporal verification strategy. Haoyu Luo, Xiao Liu 0004, Jin Liu 0016, Yun Yang 0001, John C. Grundy |
IEEE Trans. Serv. Comput. | 5 |
| 2022 | Constrained App Data Caching Over Edge Server Graphs in Edge Computing EnvironmentabstractIn recent years, edge computing, as an extension of cloud computing, has emerged as a promising paradigm for powering a variety of applications demanding low latency, e.g., virtual or augmented reality, interactive gaming, real-time navigation, etc. In the edge computing environment, edge servers are deployed at base stations to offer highly-accessible computing capacities to nearby end-users, e.g., CPU, RAM, storage, etc. From a service provider’s perspective, caching app data on edge servers can ensure low latency in its users’ data retrieval. Given constrained cache spaces on edge servers due to their physical sizes, the optimal data caching strategy must minimize overall user latency. In this article, we formulate this Constrained Edge Data Caching (CEDC) problem as a constrained optimization problem from the service provider’s perspective and prove its$\mathcal {NP}$-hardness. We propose an optimal approach named CEDC-IP to solve this CEDC problem with the Integer Programming technique. We also provide an approximation algorithm named CEDC-A for finding approximate solutions to large-scale CEDC problems efficiently and prove its approximation ratio. CEDC-IP and CEDC-A are evaluated on a real-world data set. The results demonstrate that they significantly outperform four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001, Qiang He 0001 |
IEEE Trans. Serv. Comput. | 3 |
| 2022 | An Empirical Study of Release Note Production and Usage in PracticeabstractThe release note is one of the most important software artifacts that serves as a communication bridge between development teams and users. Release notes contain a set of crucial information, such as descriptions of enhancements, improvements, potential issues, development, evolution, testing, and maintenance of projects throughout the whole development life cycle. A comprehensive understanding of the characteristics of release notes and how to best document one for different targeted users would be highly beneficial. However, the release note is often neglected and has not to date been systematically investigated by researchers. In this paper, we conducted a descriptive case study to investigate release note production and usage in practice. We first performed a large scale empirical study of 32,425 release notes in 1,000 GitHub projects to understand the characteristics of real-world release notes, and eight categories of information identified that are normally documented in release notes. We then conducted interviews with 15 professionals and an online survey with 314 respondents to investigate their opinions on release notes in practice. Our results show that both release note producers and users consider that well-formed release notes impact software activities (e.g., software evolution) positively. We summarised 27 statements about release notes grouped into eight topics based on participants’ opinions. Our study uncovers significant discrepancies between release note producers and users in perceiving release notes. Based on these findings, we provide a set of release note production and usage guidelines for practitioners and highlight future research directions. Tingting Bi, Xin Xia 0001, David Lo 0001, John C. Grundy, Thomas Zimmermann 0001 |
IEEE Trans. Software Eng. | 4 |
| 2022 | Defining Smart Contract Defects on EthereumabstractSmart contractsare programs running on a blockchain. They are immutable to change, and hence can not be patched for bugs once deployed. Thus it is critical to ensure they are bug-free and well-designed before deployment. AContract defectis an error, flaw or fault in a smart contract that causes it to produce an incorrect or unexpected result, or to behave in unintended ways. The detection of contract defects is a method to avoid potential bugs and improve the design of existing code. Since smart contracts contain numerous distinctive features, such as thegas system. decentralized, it is important to find smart contract specified defects. To fill this gap, we collected smart-contract-related posts from Ethereum StackExchange, as well as real-world smart contracts. We manually analyzed these posts and contracts; using them to define 20 kinds ofcontract defects. We categorized them into indicating potential security, availability, performance, maintainability and reusability problems. To validate if practitioners consider these contract as harmful, we created an online survey and received 138 responses from 32 different countries. Feedback showed these contract defects are harmful and removing them would improve the quality and robustness of smart contracts. We manually identified our defined contract defects in 587 real world smart contract and publicly released our dataset. Finally, we summarized 5 impacts caused by contract defects. These help developers better understand the symptoms of the defects and removal priority. Jiachi Chen, Xin Xia 0001, David Lo 0001, John C. Grundy, Xiapu Luo, Ting Chen 0002 |
IEEE Trans. Software Eng. | 4 |
| 2022 | DefectChecker: Automated Smart Contract Defect Detection by Analyzing EVM BytecodeabstractSmart contracts are Turing-complete programs running on the blockchain. They are immutable and cannot be modified, even when bugs are detected. Therefore, ensuring smart contracts are bug-free and well-designed before deploying them to the blockchain is extremely important. A contract defect is an error, flaw or fault in a smart contract that causes it to produce an incorrect or unexpected result, or to behave in unintended ways. Detecting and removing contract defects can avoid potential bugs and make programs more robust. Our previous work defined 20 contract defects for smart contracts and divided them into five impact levels. According to our classification, contract defects with seriousness level between 1-3 can lead to unwanted behaviors, e.g., a contract being controlled by attackers. In this paper, we proposeDefectChecker, a symbolic execution-based approach and tool to detect eight contract defects that can cause unwanted behaviors of smart contracts on the Ethereum blockchain platform.DefectCheckercan detect contract defects from smart contracts’ bytecode. We verify the performance ofDefectCheckerby applying it to an open-source dataset. Our evaluation results show thatDefectCheckerobtains a high F-score (88.8 percent in the whole dataset) and only requires 0.15s to analyze one smart contract on average. We also appliedDefectCheckerto 165,621 distinct smart contracts on the Ethereum platform. We found that 25,815 of these smart contracts contain at least one of the contract defects that belongs to impact level 1-3, including some real-world attacks. Jiachi Chen, Xin Xia 0001, David Lo 0001, John C. Grundy, Xiapu Luo, Ting Chen 0002 |
IEEE Trans. Software Eng. | 4 |
| 2022 | Requirements of API Documentation: A Case Study into Computer Vision ServicesabstractUsing cloud-based computer vision services is gaining traction, where developers access AI-powered components through familiar RESTful APIs, not needing to orchestrate large training and inference infrastructures or curate/label training datasets. However, while these APIsseemfamiliar to use, their non-deterministic run-time behaviour and evolution is not adequately communicated to developers. Therefore, improving these services’ API documentation is paramount—more extensive documentation facilitates the development process of intelligent software. In a prior study, we extracted 34 API documentation artefacts from 21 seminal works, devising a taxonomy of five key requirements to produce quality API documentation. We extend this study in two ways. First, by surveying 104 developers of varying experience to understand what API documentation artefacts are ofmost valueto practitioners. Second, identifying which of these highly-valued artefacts are or are not well-documented through a case study in the emerging computer vision service domain. We identify: (i) several gaps in the software engineering literature, where aspects of API documentation understanding is/is not extensively investigated; and (ii) where industry vendors (in contrast) document artefacts to better serve their end-developers. We provide a set of recommendations to enhance intelligent software documentation for both vendors and the wider research community. Alex Cummaudo, Rajesh Vasa, John C. Grundy, Mohamed Almorsy |
IEEE Trans. Software Eng. | 3 |
| 2022 | Software Engineering for Internet of Things: The Practitioners' PerspectiveabstractInternet of Things based systems (IoT systems for short) are becoming increasingly popular across different industrial domains and their development is rapidly increasing to provide value-added services to end-users and citizens. Little research to date uncovers the core development process lifecycle needed for IoT systems, and thus software engineers find themselves unprepared and unfamiliar with this new genre of system development. To ameliorate this gap, we conducted a mixed quantitative and qualitative research study where we derived a conceptual process framework from the extant literature on IoT, through which 27 key tasks for incorporation into the development processes of IoT systems were identified. The framework was then validated by the means of a survey of 127 IoT practitioners from 35 countries across 6 continents with 15 different industry backgrounds. Our research provides an understanding of the most important development process tasks and informs both software engineering practitioners and researchers of the challenges and recommendations related to the development of next-generation of IoT systems. Mahdi Fahmideh, Aakash Ahmad, Ali Behnaz, John C. Grundy, Willy Susilo |
IEEE Trans. Software Eng. | 4 |
| 2022 | Diversified Third-Party Library Prediction for Mobile App DevelopmentabstractThe rapid growth of mobile apps has significantly promoted the use of third-party libraries in mobile app development. However, mobile app developers are now facing the challenge of finding useful third-party libraries for improving their apps, e.g., to enhance user interfaces, to add social features, etc. An effective approach is to leverage collaborative filtering (CF) to predict useful third-party libraries for developers. We employed Matrix Factorization (MF) approaches - the classic CF-based prediction approaches - to make the predictions based on a total of 31,432 Android apps from Google Play. However, our investigation shows that there is a significant lack of diversity in the prediction results - a small fraction of popular third-party libraries dominate the prediction results while most other libraries are ill-served. The low diversity in the prediction results limits the usefulness of the prediction because it lacks novelty and serendipity which are much appreciated by mobile app developers. In order to increase the diversity in the prediction results, we designed an innovative MF-based approach, namely LibSeek, specifically for predicting useful third-party libraries for mobile apps. It employs an adaptive weighting mechanism to neutralize the bias caused by the popularity of third-party libraries. In addition, it introduces neighborhood information, i.e., information about similar apps and similar third-party libraries, to personalize the predictions for individual apps. The experimental results show that LibSeek can significantly diversify the prediction results, and in the meantime, increase the prediction accuracy. Qiang He 0001, Bo Li 0103, Feifei Chen 0001, John C. Grundy, Xin Xia 0001, Yun Yang 0001 |
IEEE Trans. Software Eng. | 4 |
| 2022 | The Effects of Human Aspects on the Requirements Engineering Process: A Systematic Literature ReviewabstractRequirements Engineering (RE) requires the collaboration of various roles in SE, such as requirements engineers, stakeholders and other developers, and it is thus a very highly human dependent process in software engineering (SE). Identifying how“human aspects”– such as personality, motivation, emotions, communication, gender, culture and geographic distribution – might impact on the RE process would assist us in better supporting successful RE. The main objective of this paper is to systematically review primary studies that have investigated the effects of various human aspects on the RE process. We wanted to identify if any critical human aspects have been found, and what might be the relationships between different human aspects impacting the RE process. A systematic literature review (SLR) was conducted and identified 474 initial primary research studies. These were eventually filtered down to 74 relevant, high-quality primary studies. No primary study to date was found to focus on identifying what are the most influential human aspects on the RE process. Among the studied human aspects, the effects of communication have been considered in many studies of RE. Other human aspects such as personality, motivation and gender have mainly been investigated to date in relation to more general SE studies that include RE as one phase. Findings show that studying more than one human aspect together is beneficial, as this reveals relationships between various human aspects and how they together impact the RE process. However, the majority of these studied combinations of human aspects are unique. From 56.8 percent of studies that identified the effects of human aspects on RE, 40.5 percent identified the positive impact, 30.9 percent negative, 26.2 percent identified both impacts whereas 2.3 percent mentioned that there was no impact. This implies that a variety of human aspects positively or negatively affects the RE process and a well-defined theoretical analysis on the effects of different human aspects on RE remains to be defined and practically evaluated. The findings of this SLR help researchers who are investigating the impact of various human aspects on the RE process by identifying well-studied research areas, and highlight new areas that should be focused on in future research. Dulaji Hidellaarachchi, John C. Grundy, Rashina Hoda, Kashumi Madampe |
IEEE Trans. Software Eng. | 2 |
| 2022 | An Empirical Study of Model-Agnostic Techniques for Defect Prediction ModelsabstractSoftware analytics have empowered software organisations to support a wide range of improved decision-making and policy-making. However, such predictions made by software analytics to date have not been explained and justified. Specifically, current defect prediction models still fail to explain why models make such a prediction and fail to uphold the privacy laws in terms of the requirement to explain any decision made by an algorithm. In this paper, we empirically evaluate three model-agnostic techniques, i.e., two state-of-the-art Local Interpretability Model-agnostic Explanations technique (LIME) and BreakDown techniques, and our improvement of LIME with Hyper Parameter Optimisation (LIME-HPO). Through a case study of 32 highly-curated defect datasets that span across 9 open-source software systems, we conclude that (1) model-agnostic techniques are needed to explain individual predictions of defect models; (2) instance explanations generated by model-agnostic techniques are mostly overlapping (but not exactly the same) with the global explanation of defect models and reliable when they are re-generated; (3) model-agnostic techniques take less than a minute to generate instance explanations; and (4) more than half of the practitioners perceive that the contrastive explanations are necessary and useful to understand the predictions of defect models. Since the implementation of the studied model-agnostic techniques is available in both Python and R, we recommend model-agnostic techniques be used in the future. Jirayus Jiarpakdee, Chakkrit Tantithamthavorn, Khanh Hoa Dam, John C. Grundy |
IEEE Trans. Software Eng. | 4 |
| 2022 | A Faceted Taxonomy of Requirements Changes in Agile ContextsabstractBackground:Originally, developers aimed to identify most software requirements upfront in software development projects. However, agile methods explicitly encourage software requirements to be changed throughout development, i.e., many Requirements Changes (RCs) occur.Objective:The objective of this study is to better understand RCs and produce a taxonomy of RCs in agile contexts.Method:We ran a mixed-methods approach comprising a series of studies: an interview-based study (10 participants from New Zealand and Australia), a focused literature review, and an in-depth survey (40 participants world-wide).Results:Key characteristics of RCs in agile we found relate to differenttypesandforms, agile RCs have multiplereasonsandsources, they are brought by differentcarriers, and their emergence in agile is via a variety ofevents.Summary:The presented taxonomy provides a guide for software practitioners to use to help manage RC-related issues in agile contexts. Kashumi Madampe, Rashina Hoda, John C. Grundy |
IEEE Trans. Software Eng. | 3 |
| 2022 | Deep Just-In-Time Defect LocalizationabstractDuring software development and maintenance, defect localization is an essential part of software quality assurance. Even though different techniques have been proposed for defect localization, i.e., information retrieval (IR)-based techniques and spectrum-based techniques, they can only work after the defect has been exposed, which can be too late and costly to adapt to the newly introduced bugs in the daily development. To assist developers to detect bugs in time and avoid introducing them, just-in-time (JIT) bug localization techniques have been proposed, which is targeting to locate suspicious buggy code after a change commit has been submitted. In this paper, we propose a novel JIT defect localization approach, named DeepDL (Deep Learning-based defect localization), to locate defect code lines within a defect introducing change. DeepDL employs a neural language model to capture the semantics of the code lines, in this way, the naturalness of each code line can be learned and converted to a suspiciousness score. The core of our DeepDL is a deep learning-based neural language model. We train the neural language model with previous snapshots (history versions) of a project so that it can calculate the naturalness of a piece of code. In its application, for a given new code change, DeepDL automatically assigns a suspiciousness score to each code line and sorts these code lines in descending order of this score. The code lines at the top of the list are considered as potential defect locations. Our tool can assist developers efciently check buggy lines at an early stage, which is able to reduce the risk of introducing bugs in time and improve the developers condence in the reliability of their software. We conducted an extensive experiment on 14 open source Java projects with a total of 11,615 buggy changes. We evaluate the experimental results considering four evaluation metrics. The experimental results show that our method outperforms the state-of-the-art by a substantial margin. Fangcheng Qiu, Zhipeng Gao 0002, Xin Xia 0001, David Lo 0001, John C. Grundy, Xinyu Wang 0001 |
IEEE Trans. Software Eng. | 5 |
| 2022 | SQAPlanner: Generating Data-Informed Software Quality Improvement PlansabstractSoftware Quality Assurance (SQA) planning aims to define proactive plans, such as defining maximum file size, to prevent the occurrence of software defects in future releases. To aid this,defect prediction modelshave been proposed to generate insights as the most important factors that are associated with software quality. Such insights that are derived from traditional defect models are far from actionable—i.e., practitioners still do not know what they should do or avoid to decrease the risk of having defects, and what is the risk threshold for each metric. A lack of actionable guidance and risk threshold can lead to inefficient and ineffective SQA planning processes. In this paper, we investigate the practitioners’ perceptions of current SQA planning activities, current challenges of such SQA planning activities, and propose four types of guidance to support SQA planning. We then propose and evaluate our AI-Driven SQAPlanner approach, a novel approach for generating four types of guidance and their associated risk thresholds in the form of rule-based explanations for the predictions of defect prediction models. Finally, we develop and evaluate a visualization for our SQAPlanner approach. Through the use of qualitative survey and empirical evaluation, our results lead us to conclude that SQAPlanner is needed, effective, stable, and practically applicable. We also find that 80 percent of our survey respondents perceived that our visualization is more actionable. Thus, our SQAPlanner paves a way for novel research in actionable software analytics—i.e., generating actionable guidance on what should practitioners do and not do to decrease the risk of having defects to support SQA planning. Dilini Rajapaksha, Chakkrit Tantithamthavorn, Jirayus Jiarpakdee, Christoph Bergmeir, John C. Grundy, Wray L. Buntine |
IEEE Trans. Software Eng. | 5 |
| 2022 | DiffTech: Differencing Similar Technologies From Crowd-Scale Comparison DiscussionsabstractDevelopers use different technologies for many software development tasks. However, when faced with several technologies with comparable functionalities, it is not easy to select the most appropriate one, as trial and error comparisons among such technologies are time-consuming. Instead, developers can resort to expert articles, read official documents or ask questions in Q&A sites. However, it still remains difficult to get a comprehensive comparison as online information is often fragmented or contradictory. To overcome these limitations, we propose theDiffTechsystem that exploits crowdsourced discussions from Stack Overflow, and assists technology comparison with an informative summary of different aspects. We first build a large database of comparable technologies in software engineering by mining tags in Stack Overflow. We then locate comparative sentences about comparable technologies with natural language processing methods. We further mine prominent comparison aspects by clustering similar comparative sentences and representing each cluster with its keywords and aggregate the overall opinion towards the comparable technologies. Our evaluation demonstrates both the accuracy and usefulness of our model, and we have implemented our approach as a practical website for public use. Han Wang 0023, Chunyang Chen 0001, Zhenchang Xing, John C. Grundy |
IEEE Trans. Software Eng. | 4 |
| 2021 | Does Domain Change the Opinion of Individuals on Human Values? A Preliminary Investigation on eHealth Apps End-usersabstractThe elicitation of end-users& human values - such as freedom, honesty, transparency, etc - is important in the development of software systems. We carried out two preliminary Q-studies to understand (a) the general human value opinion types of eHealth applications (apps) end-users (b) the eHealth domain human value opinion types of eHealth apps end-users (c) whether there are differences between the general and eHealth domain opinion types. Our early results show three value opinion types using generic value instruments: (1) fun-loving, success-driven and independent end-user, (2) security-conscious, socially-concerned, and success-driven end-user, and (3) benevolent, success-driven, and conformist end-user. Our results also show two value opinion types using domain-specific value instruments: (1) security-conscious, reputable, and honest end-user, and (2) success-driven, reputable and pain-avoiding end-user. Given these results, consideration should be given to domain context in the design and application of values elicitation instruments. Humphrey O. Obie, Mojtaba Shahin, John C. Grundy, Burak Turhan, Li Li 0029, Jon Whittle 0001 |
APSEC | 3 |
| 2021 | Improving Human-Centric Software Defect Evaluation, Reporting, and FixingabstractDefect reporting customarily exists in most applications and web sites to support issue reporting by end users and for developers to receive actionable feedback. However, the impact of "human-centric" issues - such as age, gender, language, culture, physical and mental challenges, and socio-economic status - is often overlooked in the development process and during product inception and defect reporting. Most defect reporting tools lack necessary human-centric features to enable a challenged user to adequately navigate and report defects i.e. do not take into account the human differences between end users that cause defects for them in their software and make reporting of such defects difficult for them. Most defect reporting tools also lack sufficient defect report structuring, reporting guidance, and do not emphasize the possible perceived severity of the defect to developers from end users who are very different to them. If users are unable to report defects due to usability issues, this makes those same defect reports difficult to understand by the developer. In this paper, we aim to improve human-centric defect reporting by employing cognitive walkthrough with diverse end user personas, develop a prototype of an improved defect reporting tool, and evaluate the prototype’s defect reporting process from end user and developer perspectives. Our findings offer a foundation for improved human-centric defect evaluation, reporting and fixing. Kenny Huynh, Juvent Benarivo, Chew Da Xuan, Giridhar Gopal Sharma, Jeffrey Kang, Anuradha Madugalla, John C. Grundy |
COMPSAC | 7 |
| 2021 | A human-centric approach to building a smarter and better parking applicationabstractFinding a parking space can be very stressful and time consuming. A variety of different vehicle parking applications have been developed but many fail to support diverse end-users. We captured diverse human-centric issues from user reviews and literature, and then created personas that encompass a wide representative range of parking app user groups. Using these personas, user stories were created, categorized and parking app tasks prioritized. We used these to develop a prototype new "smart parking app". A cognitive walk-through was employed using each of the personas and user stories to evaluate the app. With more human-centric factors taken into account in the design and development of the app, we found that majority of the human-centric frustrations identified were resolved, when compared with a commonly used parking app. Chenlin Li, Yuting Yu, Jeremy Leckning, Weicheng Xing, Chun Long Fong, John C. Grundy, Devi Karolita, Jennifer McIntosh 0001, Humphrey O. Obie |
COMPSAC | 6 |
| 2021 | Impact of End User Human Aspects on Software Engineering
John C. Grundy |
ENASE | 1 |
| 2021 | Improving the Modelling of Human-centric Aspects of Software Systems: A Case Study of Modelling End User Age in Wirefame DesignsabstractTaking into account the diverse human aspects - gender, age, emotions, personality, language, culture, physical and mental challenges, etc - is critical towards achieving more human-centric design of software systems. Human-centric aspects affecting software have long been underestimated or even ignored as a result of the lack of in-depth capture and understanding during development. The use of technology has become the norm and the range of users has increased from just adults to children as well as seniors. Modelling frameworks are methods to represent the way a software system should be defined, and to date, little research has been done on age-related issues within modelling frameworks. In this paper, we investigate how human-centric aspects regarding age can be better modelled by extending these modelling frameworks. We introduce an extension to wireframe-based designs so that they can cater for decisions regarding age within the modelling framework. We have evaluated this modelling extension using multiple questionnaires as well as usability testing by using the extended age-modelling wireframe approach to design a news app. Questionnaires were used to evaluate the requirements of the users and developers for the extended wireframes. Our analysis shows that when using our extended wireframes, developers can cater for different user types and their accessibility needs easily and therefore users can use the prototypes with more ease. Aria YukFan Jim, Hyun Shim, Lionel Richie Wijaya, Rongbin Xu, Hourieh Khalajzadeh, John C. Grundy, Tanjila Kanij |
ENASE | 7 |
| 2021 | Automatic Solution Summarization for Crash BugsabstractThe causes of software crashes can be hidden anywhere in the source code and development environment. When encountering software crashes, recurring bugs that are discussed on Q&A sites could provide developers with solutions to their crashing problems. However, it is difficult for developers to accurately search for relevant content on search engines, and developers have to spend a lot of manual effort to find the right solution from the returned results. In this paper, we present CRASOLVER, an approach that takes into account both the structural information of crash traces and the knowledge of crash-causing bugs to automatically summarize solutions from crash traces. Given a crash trace, CRASOLVER retrieves relevant questions from Q&A sites by combining a proposed position dependent similarity - based on the structural information of the crash trace - with an extra knowledge similarity, based on the knowledge from official documentation sites. After obtaining the answers to these questions from the Q&A site, CRASOLVER summarizes the final solution based on a multi-factor scoring mechanism. To evaluate our approach, we built two repositories of Java and Android exception-related questions from Stack Overflow with size of 69,478 and 33,566 questions respectively. Our user study results using 50 selected Java crash traces and 50 selected Android crash traces show that our approach significantly outperforms four baselines in terms of relevance, usefulness, and diversity. The evaluation also confirms the effectiveness of the relevant question retrieval component in our approach for crash traces. Haoye Wang, Xin Xia 0001, David Lo 0001, John C. Grundy, Xinyu Wang 0001 |
ICSE | 4 |
| 2021 | AH-CID: A Tool to Automatically Detect Human-Centric Issues in App Reviews
Collins Mathews, Kenny Ye, Jake Grozdanovski, Marcus Marinelli, Hourieh Khalajzadeh, Humphrey O. Obie, John C. Grundy |
ICSOFT | 8 |
| 2021 | Information-theoretic Source Code Vulnerability HighlightingabstractSoftware vulnerabilities are a crucial and serious concern in the software industry and computer security. A variety of methods have been proposed to detect vulnerabilities in real-world software. Recent methods based on deep learning approaches for automatic feature extraction have improved software vulnerability identification compared with machine learning approaches based on hand-crafted feature extraction. However, these methods can usually only detect software vulnerabilities at a function or program level, which is much less informative because, out of hundreds (thousands) of code statements in a program or function, only a few core statements contribute to a software vulnerability. This requires us to find a way to detect software vulnerabilities at a fine-grained level. In this paper, we propose a novel method based on the concept of mutual information that can help us to detect and isolate software vulnerabilities at a fine-grained level (i.e., several statements that are highly relevant to a software vulnerability that include the core vulnerable statements) in both unsupervised and semi-supervised contexts. We conduct comprehensive experiments on real-world software projects to demonstrate that our proposed method can detect vulnerabilities at a fine-grained level by identifying several statements that mostly contribute to the vulnerability detection decision. Van Nguyen 0002, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung |
IJCNN | 5 |
| 2021 | Characterizing Sensor Leaks in Android AppsabstractWhile extremely valuable to achieve advanced functions, mobile phone sensors can be abused by attackers to implement malicious activities in Android apps, as experimentally demonstrated by many state-of-the-art studies. There is hence a strong need to regulate the usage of mobile sensors so as to keep them from being exploited by malicious attackers. However, despite the fact that various efforts have been put in achieving this, i.e., detecting privacy leaks in Android apps, we have not yet found approaches to automatically detect sensor leaks in Android apps. To fill the gap, we designed and implemented a novel prototype tool, Seeker, that extends the famous FlowDroid tool to detect sensor-based data leaks in Android apps. Seeker conducts sensor-focused static taint analyses directly on the Android apps' bytecode and reports not only sensor-triggered privacy leaks but also the sensor types involved in the leaks. Experimental results using over 40,000 real-world Android apps show that Seeker is effective in detecting sensor leaks in Android apps, and malicious apps are more interested in leaking sensor data than benign apps. Xiaoyu Sun 0002, Xiao Chen 0002, Kui Liu 0001, Sheng Wen, Li Li 0029, John C. Grundy |
ISSRE | 6 |
| 2021 | Checking App Behavior Against App Descriptions: What If There are No App Descriptions?abstractClassifying mobile apps based on their description is beneficial for several purposes. However, many app descriptions do not reflect app functionalities, whether accidentally or on purpose. Most importantly, these app classification methods do not work if the app description is unavailable. This paper investigates a Reverse Engineering-based Approach to Classify mobile apps using The data that exists in the app, called REACT. To validate the proposed REACT method, we use a large set of Android apps (24,652 apps in total). We also show REACTs' extendibility for malware/anomaly detection and prove its reliability and scalability. However, our analysis shows some limitations in REACT procedure and implementation, especially for similar feature based app grouping. We discuss the root cause of these failures, our key lessons learned, and some future enhancement ideas. We also share our REACT tools and reproduced datasets for the app market analyst, mobile app developers and software engineering research communities for further research purposes. Md. Shamsujjoha, John C. Grundy, Li Li 0029, Hourieh Khalajzadeh, Qinghua Lu 0001 |
ICPC | 2 |
| 2021 | SRCM: A Semi Formal Requirements Representation Model Enabling System Visualisation and Quality CheckingabstractSRCM: A semi formal requirements representation model enabling system visualisation and quality checking Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 4 |
| 2021 | RCM: Requirement Capturing Model for Automated Requirements FormalisationabstractMost existing automated requirements formalisation techniques require system engineers to (re)write their requirements using a set of predefined requirement templates with a fixed structure and known semantics to simplify the formalisation process. However, these techniques require understanding and memorising requirement templates, which are usually fixed format, limit requirements captured, and do not allow capture of more diverse requirements. To address these limitations, we need a reference model that captures key requirement details regardless of their structure, format or order. Then, using NLP techniques we can transform textual requirements into the reference model. Finally, using a suite of transformation rules we can then convert these requirements into formal notations. In this paper, we introduce the first and key step in this process, a Requirement Capturing Model (RCM) - as a reference model - to model the key elements of a system requirement regardless of their format, or order. We evaluated the robustness of the RCM model compared to 15 existing requirements representation approaches and a benchmark of 162 requirements. Our evaluation shows that RCM breakdowns support a wider range of requirements formats compared to the existing approaches. We also implemented a suite of transformation rules that transforms RCM-based requirements into temporal logic(s). In the future, we will develop NLP-based RCM extraction technique to provide end-to-end solution. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 4 |
| 2021 | RCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language RequirementsabstractRCM-Extractor: Automated Extraction of a Semi Formal Representation Model from Natural Language Requirements Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
MODELSWARD | 4 |
| 2021 | Practitioners' Perceptions of the Goals and Visual Explanations of Defect Prediction ModelsabstractSoftware defect prediction models are classifiers that are constructed from historical software data. Such software defect prediction models have been proposed to help developers optimize the limited Software Quality Assurance (SQA) resources and help managers develop SQA plans. Prior studies have different goals for their defect prediction models and use different techniques for generating visual explanations of their models. Yet, it is unclear what are the practitioners' perceptions of (1) these defect prediction model goals, and (2) the model-agnostic techniques used to visualize these models. We conducted a qualitative survey to investigate practitioners' perceptions of the goals of defect prediction models and the model-agnostic techniques used to generate visual explanations of defect prediction models. We found that (1) 82%-84% of the respondents perceived that the three goals of defect prediction models are useful; (2) LIME is the most preferred technique for understanding the most important characteristics that contributed to a prediction of a file, while ANOVA/VarImp is the second most preferred technique for understanding the characteristics that are associated with software defects in the past. Our findings highlight the significance of investigating how to improve the understanding of defect prediction models and their predictions. Hence, model-agnostic techniques from explainable AI domain may help practitioners to understand defect prediction models and their predictions. Jirayus Jiarpakdee, Chakkrit Tantithamthavorn, John C. Grundy |
MSR | 3 |
| 2021 | What's up with Requirements Engineering for Artificial Intelligence Systems?abstractIn traditional approaches to building software systems (that do not include an Artificial Intelligent (AI) or Machine Learning (ML) component), Requirements Engineering (RE) activities are well-established and researched. However, building software systems with one or more AI components may depend heavily on data with limited or no insight into the system’s workings. Therefore, engineering such systems poses significant new challenges to RE. Our search showed that literature has focused on using AI to manage RE activities, with limited research on RE for AI (RE4AI). Our study’s main objective was to investigate current approaches in writing requirements for AI/ML systems, identify available tools and techniques used to model requirements, and find existing challenges and limitations. We performed a Systematic Literature Review (SLR) of current RE4AI methods and identified 27 primary studies. Using these studies, we analysed the key tools and techniques used to specify and model requirements and found several challenges and limitations of existing RE4AI practices. We further provide recommendations for future research, based on our analysis of the primary studies and mapping to industry guidelines in Google PAIR). The SLR findings highlighted that present RE applications were not adaptive to manage most AI/ML systems and emphasised the need to provide new techniques and tools to support RE4AI. Khlood Ahmad, Muneera Bano, Mohamed Almorsy, Chetan Arora 0002, John C. Grundy |
RE | 5 |
| 2021 | DBRG: Description-Based Non-Quality Requirements GeneratorabstractRequirements quality checking is a key process in requirements engineering. For complex and large scale systems, it is recommended to use automated requirements quality checking tools because of the size and complexity of requirements. However, such tools are typically evaluated on a small set of manually curated requirements. This limitation affects the comprehensiveness and reliability of the evaluation and leaves several possible quality issues undetected. In this paper, we de-scribe a novel quality-checking-oriented synthesised requirements generator. We provide an input description language so that several quality checking issues and scenarios can be defined. The generator utilises an input dictionary of nouns and verb frames, and generates requirements sentences complying to a user-defined description of a quality affected requirement. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 4 |
| 2021 | Enhancing NL Requirements Formalisation Using a Quality Checking ModelabstractThe formalisation of natural language (NL) requirements is a challenging problem because NL is inherently vague and imprecise. Existing formalisation approaches only support requirements adhering to specific boilerplates or templates, and are affected by the requirements quality issues. Several quality models are developed to assess the quality of NL requirements. However, they do not focus on the quality issues affecting the formalisability of requirements. Such issues can greatly compromise the operation of complex systems and even lead to catastrophic consequences or loss of life (in case of critical systems). In this paper, we propose a requirements quality checking approach utilising natural language processing (NLP) analysis. The approach assesses the quality of the requirements against a quality model that we developed to enhance the formalisability of NL requirements. We evaluate the effectiveness of our approach by comparing the formalisation efficiency of a recent automatic formalisation technique before and after utilising our approach. The results show an increase of approximately 15% in the F-measure (from 83.8% to 98%). Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 4 |
| 2021 | ARF: Automatic Requirements Formalisation ToolabstractFormal verification techniques enable the detection of complex quality issues within system specifications. However, the majority of system requirements are usually specified in natural language (NL). Manual formalisation of NL requirements is an error-prone and labour-intensive process requiring strong mathematical expertise, and can be infeasible for large numbers of requirements. Existing automatic formalisation techniques usually support heavily constrained natural language relying on requirement boilerplates or templates. In this paper, we introduce ARF: Automatic Requirements Formalisation Tool. ARF can automatically transform free-format natural language requirements into temporal logic based formal notations. This is achieved through two steps: 1) extraction of key requirement attributes into an intermediate representation (RCM: Requirement Capturing Model), and 2) transformation rules that convert requirements from the RCM format to formal notations. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
RE | 4 |
| 2021 | CORG: A Component-Oriented Synthetic Textual Requirements Generator
Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
REFSQ | 4 |
| 2021 | Requirements Formality Levels Analysis and Transformation of Formal Notations into Semi-formal and Informal Notations (S)abstractIt is pivotal to have well-specified requirements to eliminate errors at an early stage of the system development life cycle.Some quality standards recommend the use of formal methods -mandate requirements to be expressed in formal notations -to detect errors.However, formal notations are not suitable for non-experts and may not be understood by all the stakeholder.To fix this, bidirectional transformations among requirement representation levels are required to maintain traceability and facilitate the communication of requirements among all the involved parties.This paper reflects on the different formality levels of requirements specifications including: informal, semi-formal, and formal notations.In addition, an automated multi-layer transformation approach is proposed to enable bi-directional transformation among requirements levels. Aya Zaki-Ismail, Mohamed Osama, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
SEKE | 4 |
| 2021 | Constrained App Data Caching over Edge Server Graphs in Edge Computing EnvironmentabstractEdge computing has emerged as a promising paradigm for powering a huge number of applications requiring low latency, e.g., real-time navigation, interactive gaming, virtual or augmented reality, etc. Edge computing offers highly accessible computing and storage resources, including CPU, storage and bandwidth, by deploying edge servers at base stations. With more users accessing edge apps, a huge number of data will be transmitted via edge servers between users’ devices and remote cloud servers. A service provider can cache its app data on edge servers to ensure the low data retrieval latency of its users. Due to the physical size limits of edge servers, the optimal data caching strategy must minimize overall user latency with consideration of constrained cache spaces on edge servers. From the service provider’s perspective, we formulate this Constrained Edge Data Caching (CEDC) problem and prove the NP-hardness of this CEDC problem. After that, we propose CEDC-IP, an optimal approach solved by the Integer Programming technique, to find optimal solutions to this CEDC problem. We also propose CEDC-A, an approximation algorithm with theoretical guarantee, to find approximate solutions to large-scale CEDC problems efficiently. Finally, we conduct extensive experiments on a widely-used real-world data set, and the experimental results demonstrate that both CEDC-IP and CEDC-A significantly outperform the other four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001, Qiang He 0001 |
SERVICES | 3 |
| 2021 | Automating the removal of obsolete TODO commentsabstractTODO comments are very widely used by software developers to describe their pending tasks during software development. However, after performing the task developers sometimes neglect or simply forget to remove the TODO comment, resulting in obsolete TODO comments. These obsolete TODO comments can confuse development teams and may cause the introduction of bugs in the future, decreasing the software's quality and maintainability. Manually identifying obsolete TODO comments is time-consuming and expensive. It is thus necessary to detect obsolete TODO comments and remove them automatically before they cause any unwanted side effects. In this work, we propose a novel model, named TDCleaner, to identify obsolete TODO comments in software projects. TDCleaner can assist developers in just-in-time checking of TODO comments status and avoid leaving obsolete TODO comments. Our approach has two main stages: offline learning and online prediction. During offline learning, we first automatically establish training samples and leverage three neural encoders to capture the semantic features of TODO comment, code change and commit message respectively. TDCleaner then automatically learns the correlations and interactions between different encoders to estimate the final status of the TODO comment. For online prediction, we check a TODO comment's status by leveraging the offline trained model to judge the TODO comment's likelihood of being obsolete. We built our dataset by collecting TODO comments from the top-10,000 Python and Java Github repositories and evaluated TDCleaner on them. Extensive experimental results show the promising performance of our model over a set of benchmarks. We also performed an in-the-wild evaluation with real-world software projects, we reported 18 obsolete TODO comments identified by TDCleaner to Github developers and 9 of them have already been confirmed and removed by the developers, demonstrating the practical usage of our approach. Zhipeng Gao 0002, Xin Xia 0001, David Lo 0001, John C. Grundy, Thomas Zimmermann 0001 |
ESEC/SIGSOFT FSE | 4 |
| 2021 | Code2Que: a tool for improving question titles from mined code snippets in stack overflowabstractStack Overflow is one of the most popular technical Q&A sites used by software developers. Seeking help from Stack Overflow has become an essential part of software developers’ daily work for solving programming-related questions. Although the Stack Overflow community has provided quality assurance guidelines to help users write better questions, we observed that a significant number of questions submitted to Stack Overflow are of low quality. In this paper, we introduce a new web-based tool, Code2Que, which can help developers in writing higher quality questions for a given code snippet. Code2Que consists of two main stages: offline learning and online recommendation. In the offline learning phase, we first collect a set of good quality ⟨code snippet, question⟩ pairs as training samples. We then train our model on these training samples via a deep sequence-to-sequence approach, enhanced with an attention mechanism, a copy mechanism and a coverage mechanism. In the online recommendation phase, for a given code snippet, we use the offline trained model to generate question titles to assist less experienced developers in writing questions more effectively. To evaluate Code2Que, we first sampled 50 low quality ⟨code snippet, question⟩ pairs from the Python and Java datasets on Stack Overflow. Then we conducted a user study to evaluate the question titles generated by our approach as compared to human-written ones using three metrics: Clearness, Fitness and Willingness to Respond. Our experimental results show that for a large number of low-quality questions in Stack Overflow, Code2Que can improve the question titles in terms of Clearness, Fitness and Willingness measures. Zhipeng Gao 0002, Xin Xia 0001, David Lo 0001, John C. Grundy, Yuan-Fang Li |
ESEC/SIGSOFT FSE | 4 |
| 2021 | Embedding app-library graph for neural third party library recommendationabstractThe mobile app marketplace has fierce competition for mobile app developers, who need to develop and update their apps as soon as possible to gain first mover advantage. Third-party libraries (TPLs) offer developers an easier way to enhance their apps with new features. However, how to find suitable candidates among the high number and fast-changing TPLs is a challenging problem. TPL recommendation is a promising solution, but unfortunately existing approaches suffer from low accuracy in recommendation results. To tackle this challenge, we propose GRec, a graph neural network (GNN) based approach, for recommending potentially useful TPLs for app development. GRec models mobile apps, TPLs, and their interactions into an app-library graph. It then distills app-library interaction information from the app-library graph to make more accurate TPL recommendations. To evaluate GRec’s performance, we conduct comprehensive experiments based on a large-scale real-world Android app dataset containing 31,432 Android apps, 752 distinct TPLs, and 537,011 app-library usage records. Our experimental results illustrate that GRec can significantly increase the prediction accuracy and diversify the prediction results compared with state-of-the-art methods. A user study performed with app developers also confirms GRec's usefulness for real-world mobile app development. Bo Li 0103, Qiang He 0001, Feifei Chen 0001, Xin Xia 0001, Li Li 0029, John C. Grundy, Yun Yang 0001 |
ESEC/SIGSOFT FSE | 6 |
| 2021 | ICME: an informed consent management engine for conformance in smart building environmentsabstractSmart buildings can reveal highly sensitive insights about their inhabitants and expose them to new privacy threats and vulnerabilities. Yet, convenience overrides privacy concerns and most people remain ignorant about this issue. We propose a novel Informed Consent Management Engine (ICME) that aims to: (a) increase users’ awareness about privacy issues and data collection practices in their smart building environments, (b) provide fine-grained visibility into privacy conformance and infringement by these devices, (c) recommend and visualise corrective user actions through ”digital nudging”, and (d) support the monitoring and management of personal data disclosure in a shared space. We present a reference architecture for ICME that can be used by software engineers to implement diverse end-user consent management solutions for smart buildings. We also provide a proof-of-concept prototype to demonstrate how the ICME approach works in a shared smart workplace. Demo: https://youtu.be/5y6CdyWAdgY Chehara Pathmabandu, John C. Grundy, Mohan Baruwal Chhetri, Zubair A. Baig |
ESEC/SIGSOFT FSE | 2 |
| 2021 | A Toolkit for Building More Adaptable User Interfaces for Vision-Impaired UsersabstractMost prior research into adaptable and adaptive user interfaces primarily focuses on facilitating consistent user experiences across devices and pays less attention to facilitating universal access for diverse end users. We address this shortcoming by developing adaptable user interface components for a category of diverse users, the vision impaired. This paper presents a framework that supports run time adaptation of web components to suit vision impaired users by using a set of adaptable, reusable widgets. We developed a prototype using these components and evaluated its effectiveness. Our results show that an such an adaptable user interface provides significant benefit in many key W3C accessibility areas, helping to make the web more accessible for diverse end users. Calvin Luy, Jeremy Law, Lily Ho, Richard Matheson, Tracey Cai, Anuradha Madugalla, John C. Grundy |
VL/HCC | 7 |
| 2021 | Human-Centric Issues in eHealth App Development and Usage: A Preliminary AssessmentabstractHealth-related mobile applications are known as eHealth apps. These apps make people more aware of their health, help during critical situations, provide home-based disease management, and monitor/support personalized care through sensing/interaction. eHealth app usage is rapidly increasing with a large number of new apps being developed. Unfortunately, many eHealth apps do not successfully adopt Human-Centric Issues (HCI) in the app development process and its deployment stages, leading them to become ineffective and not inclusive of diverse end-users. This paper provides an initial assessment of key human factors related to eHealth apps by literature review, existing guidelines analysis, and user studies. Preliminary results suggest that Usability, Accessibility, Reliability, Versatility, and User Experience are essential HCIs for eHealth apps, and need further attention from researchers and practitioners. Therefore, outcomes of this research will look to amend support for users, developers, and stakeholders of eHealth apps in the form of improved actionable guidelines, best practice examples, and evaluation techniques. The research also aims to trial the proposed solutions on real-world projects. Md. Shamsujjoha, John C. Grundy, Li Li 0029, Hourieh Khalajzadeh, Qinghua Lu 0001 |
SANER | 2 |
| 2021 | An efficient deadline constrained and data locality aware dynamic scheduling framework for multitenancy cloudsabstractSummary Scheduling and resource allocation in clouds is used to harness the power of the underlying resource pool. Service providers can meet quality of service (QoS) requirements of tenants specified in Service Level Agreements. Improving resource allocation ensures that all tenants will receive fairer access to system resources, which improves overall utilization and throughput. Real‐time applications and services require critical deadlines in order to guarantee QoS. A growing number of data‐intensive applications drive the optimization of scheduling through utilizing data locality in which the scheduler locates a task and ensures the task's relevant data to be on the same server. Choosing suitable scheduling mechanisms for running applications that support multitenancy has consistently been a major challenge. This work proposes a new adaptive Deadline constrained and Data locality aware Dynamic Scheduling Framework “ 3DSF“ that orchestrates different schedulers based on varied requirements. This framework considers tenants' deadline‐based QoS requirements, cloud system's performance and a method of resource allocation to improve resource utilization, system throughput and reduce jobs' completion time. 3DSF contains: (a) a real‐time, preemptive, deadline constrained job scheduler, (b) an optimized data locality aware scheduler, (c) an improved Dominant Resource Fairness greedy resource allocation approach, and (d) an adaptive suite to integrate above‐mentioned schedulers together. Jia Ru, Yun Yang 0001, John C. Grundy, Jacky W. Keung |
Concurr. Comput. Pract. Exp. | 3 |
| 2021 | Maintenance-related concerns for post-deployed Ethereum smart contract development: issues, techniques, and future challenges
Jiachi Chen, Xin Xia 0001, David Lo 0001, John C. Grundy, Xiaohu Yang 0001 |
Empir. Softw. Eng. | 4 |
| 2021 | A systematic review of scheduling approaches on multi-tenancy cloud platforms
Ru Jia, Yun Yang 0001, John C. Grundy, Jacky W. Keung |
Inf. Softw. Technol. | 3 |
| 2021 | Developing Mobile Applications Via Model Driven Development: A Systematic Literature Review
Md. Shamsujjoha, John C. Grundy, Li Li 0029, Hourieh Khalajzadeh, Qinghua Lu 0001 |
Inf. Softw. Technol. | 2 |
| 2021 | Icon2Code: Recommending code implementations for Android GUI components
Yanjie Zhao 0001, Li Li 0029, Xiaoyu Sun 0002, John C. Grundy |
Inf. Softw. Technol. | 5 |
| 2021 | A comprehensive comparative study of clustering-based unsupervised defect prediction models
Zhou Xu 0003, Li Li 0029, Meng Yan 0001, Jin Liu 0016, Xiapu Luo, John C. Grundy, Xiaohong Zhang 0002 |
J. Syst. Softw. | 6 |
| 2021 | Latexify Math: Mathematical Formula Markup Revision to Assist Collaborative Editing in Math Q&A SitesabstractCollaborative editing questions and answers plays an important role in quality control of Mathematics StackExchange which is a math Q&A Site. Our study of post edits in Mathematics Stack Exchange shows that there is a large number of math-related edits about latexifying formulas, revising LaTeX and converting the blurred math formula screenshots to LaTeX sequence. Despite its importance, manually editing one math-related post especially those with complex mathematical formulas is time-consuming and error-prone even for experienced users. To assist post owners and editors to do this editing, we have developed an edit-assistance tool, MathLatexEdit for formula latexification, LaTeX revision and screenshot transcription. We formulate this formula editing task as a translation problem, in which an original post is translated to a revised post. MathLatexEdit implements a deep learning based approach including two encoder-decoder models for textual and visual LaTeX edit recommendation with math-specific inference. The two models are trained on large-scale historical original-edited post pairs and synthesized screenshot-formula pairs. Our evaluation of MathLatexEdit not only demonstrates the accuracy of our model, but also the usefulness of MathLatexEdit in editing real-world posts which are accepted in Mathematics Stack Exchange. Suyu Ma, Chunyang Chen 0001, Hourieh Khalajzadeh, John C. Grundy |
Proc. ACM Hum. Comput. Interact. | 4 |
| 2021 | Technical Q8A Site Answer Recommendation via Question BoostingabstractSoftware developers have heavily used online question-and-answer platforms to seek help to solve their technical problems. However, a major problem with these technical Q8A sites is “answer hungriness,” i.e., a large number of questions remain unanswered or unresolved, and users have to wait for a long time or painstakingly go through the provided answers with various levels of quality. To alleviate this time-consuming problem, we propose a novel D EEP A NS neural network–based approach to identify the most relevant answer among a set of answer candidates. Our approach follows a three-stage process: question boosting, label establishment, and answer recommendation. Given a post, we first generate a clarifying question as a way of question boosting. We automatically establish the positive , neutral + , neutral - , and negative training samples via label establishment. When it comes to answer recommendation, we sort answer candidates by the matching scores calculated by our neural network–based model. To evaluate the performance of our proposed model, we conducted a large-scale evaluation on four datasets, collected from the real-world technical Q8A sites (i.e., Ask Ubuntu, Super User, Stack Overflow Python, and Stack Overflow Java). Our experimental results show that our approach significantly outperforms several state-of-the-art baselines in automatic evaluation. We also conducted a user study with 50 solved/unanswered/unresolved questions. The user-study results demonstrate that our approach is effective in solving the answer-hungry problem by recommending the most relevant answers from historical archives. Zhipeng Gao 0002, Xin Xia 0001, David Lo 0001, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2021 | Taming Reflection: An Essential Step Toward Whole-program Analysis of Android AppsabstractAndroid developers heavily use reflection in their apps for legitimate reasons. However, reflection is also significantly used for hiding malicious actions. Unfortunately, current state-of-the-art static analysis tools for Android are challenged by the presence of reflective calls, which they usually ignore. Thus, the results of their security analysis, e.g., for private data leaks, are incomplete, given the measures taken by malware writers to elude static detection. We propose a new instrumentation-based approach to address this issue in a non-invasive way. Specifically, we introduce to the community a prototype tool called DroidRA, which reduces the resolution of reflective calls to a composite constant propagation problem and then leverages the COAL solver to infer the values of reflection targets. After that, it automatically instruments the app to replace reflective calls with their corresponding Java calls in a traditional paradigm. Our approach augments an app so that it can be more effectively statically analyzable, including by such static analyzers that are not reflection-aware. We evaluate DroidRA on benchmark apps as well as on real-world apps, and we demonstrate that it can indeed infer the target values of reflective calls and subsequently allow state-of-the-art tools to provide more sound and complete analysis results. Xiaoyu Sun 0002, Li Li 0029, Tegawendé F. Bissyandé, Jacques Klein, Damien Octeau, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2021 | Context-aware Retrieval-based Deep Commit Message GenerationabstractCommit messages recorded in version control systems contain valuable information for software development, maintenance, and comprehension. Unfortunately, developers often commit code with empty or poor quality commit messages. To address this issue, several studies have proposed approaches to generate commit messages from commit diffs . Recent studies make use of neural machine translation algorithms to try and translate git diffs into commit messages and have achieved some promising results. However, these learning-based methods tend to generate high-frequency words but ignore low-frequency ones. In addition, they suffer from exposure bias issues, which leads to a gap between training phase and testing phase. In this article, we propose CoRec to address the above two limitations. Specifically, we first train a context-aware encoder-decoder model that randomly selects the previous output of the decoder or the embedding vector of a ground truth word as context to make the model gradually aware of previous alignment choices. Given a diff for testing, the trained model is reused to retrieve the most similar diff from the training set. Finally, we use the retrieval diff to guide the probability distribution for the final generated vocabulary. Our method combines the advantages of both information retrieval and neural machine translation. We evaluate CoRec on a dataset from Liu et al. and a large-scale dataset crawled from 10K popular Java repositories in Github. Our experimental results show that CoRec significantly outperforms the state-of-the-art method NNGen by 19% on average in terms of BLEU. Haoye Wang, Xin Xia 0001, David Lo 0001, Qiang He 0001, Xinyu Wang 0001, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2021 | On the Impact of Sample Duplication in Machine-Learning-Based Android Malware DetectionabstractMalware detection at scale in the Android realm is often carried out using machine learning techniques. State-of-the-art approaches such as DREBIN and MaMaDroid are reported to yield high detection rates when assessed against well-known datasets. Unfortunately, such datasets may include a large portion of duplicated samples, which may bias recorded experimental results and insights. In this article, we perform extensive experiments to measure the performance gap that occurs when datasets are de-duplicated. Our experimental results reveal that duplication in published datasets has a limited impact on supervised malware classification models. This observation contrasts with the finding of Allamanis on the general case of machine learning bias for big code. Our experiments, however, show that sample duplication more substantially affects unsupervised learning models (e.g., malware family clustering). Nevertheless, we argue that our fellow researchers and practitioners should always take sample duplication into consideration when performing machine-learning-based (via either supervised or unsupervised learning) Android malware detections, no matter how significant the impact might be. Yanjie Zhao 0001, Li Li 0029, Haoyu Wang 0001, Haipeng Cai, Tegawendé F. Bissyandé, Jacques Klein, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 7 |
| 2021 | Online Collaborative Data Caching in Edge ComputingabstractIn the edge computing (EC) environment, edge servers are deployed at base stations to offer highly accessible computing and storage resources to nearby app users. From the app vendor's perspective, caching data on edge servers can ensure low latency in app users' retrieval of app data. However, an edge server normally owns limited resources due to its limited size. In this article, we investigate the collaborative caching problem in the EC environment with the aim to minimize the system cost including data caching cost, data migration cost, and quality-of-service (QoS) penalty. We model this collaborative edge data caching problem (CEDC) as a constrained optimization problem and prove that it is NP-complete. We propose an online algorithm, called CEDC-O, to solve this CEDC problem during all time slots. CEDC-O is developed based on Lyapunov optimization, works online without requiring future information, and achieves provable close-to-optimal performance. CEDC-O is evaluated on a real-world data set, and the results demonstrate that it significantly outperforms four representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Cost-Effective App Data Distribution in Edge ComputingabstractEdge computing, as an extension of cloud computing, distributes computing and storage resources from centralized cloud to distributed edge servers, to power a variety of applications demanding low latency, e.g., IoT services, virtual reality, real-time navigation, etc. From an app vendor's perspective, app data needs to be transferred from the cloud to specific edge servers in an area to serve the app users in the area. However, according to the pay-as-you-go business model, distributing a large amount of data from the cloud to edge servers can be expensive. The optimal data distribution strategy must minimize the cost incurred, which includes two major components, the cost of data transmission between the cloud to edge servers and the cost of data transmission between edge servers. In the meantime, the delay constraint must be fulfilled - the data distribution must not take too long. In this article, we make the first attempt to formulate this Edge Data Distribution (EDD) problem as a constrained optimization problem from the app vendor's perspective and prove its NP-hardness. We propose an optimal approach named EDD-IP to solve this problem exactly with the Integer Programming technique. Then, we propose an O(k)-approximation algorithm named EDD-A for finding approximate solutions to largescale EDD problems efficiently. EDD-IP and EDD-A are evaluated on a real-world dataset and the results demonstrate that they significantly outperform three representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, John C. Grundy, Mohamed Almorsy, Hai Jin 0001 |
IEEE Trans. Parallel Distributed Syst. | 4 |
| 2021 | Automatic Feature Learning for Predicting Vulnerable Software ComponentsabstractCode flaws or vulnerabilities are prevalent in software systems and can potentially cause a variety of problems including deadlock, hacking, information loss and system failure. A variety of approaches have been developed to try and detect the most likely locations of such code vulnerabilities in large code bases. Most of them rely on manually designing code features (e.g., complexity metrics or frequencies of code tokens) that represent the characteristics of the potentially problematic code to locate. However, all suffer from challenges in sufficiently capturing both semantic and syntactic representation of source code, an important capability for building accurate prediction models. In this paper, we describe a new approach, built upon the powerful deep learning Long Short Term Memory model, to automatically learn both semantic and syntactic features of code. Our evaluation on 18 Android applications and the Firefox application demonstrates that the prediction power obtained from our learned features is better than what is achieved by state of the art vulnerability prediction models, for both within-project prediction and cross-project prediction. Khanh Hoa Dam, Truyen Tran 0001, Trang Pham, Shien Wee Ng, John C. Grundy, Aditya Ghose |
IEEE Trans. Software Eng. | 5 |
| 2021 | Checking Smart Contracts With Structural Code EmbeddingabstractSmart contracts have been increasingly used together with blockchains to automate financial and business transactions. However, many bugs and vulnerabilities have been identified in many contracts which raises serious concerns about smart contract security, not to mention that the blockchain systems on which the smart contracts are built can be buggy. Thus, there is a significant need to better maintain smart contract code and ensure its high reliability. In this paper, we propose an automated approach to learn characteristics of smart contracts in Solidity, which is useful for clone detection, bug detection and contract validation on smart contracts. Our new approach is based on word embeddings and vector space comparison. We parse smart contract code into word streams with code structural information, convert code elements (e.g., statements, functions) into numerical vectors that are supposed to encode the code syntax and semantics, and compare the similarities among the vectors encoding code and known bugs, to identify potential issues. We have implemented the approach in a prototype, named SmartEmbed,11.The anonymous replication packages can be accessed at:https://drive.google.com/file/d/1kauLT3y2IiHPkUlVx4FSTda-dVAyL4za/view?usp=sharing.and evaluated it with more than 22,000 smart contracts collected from the Ethereum blockchain. Results show that our tool can effectively identify many repetitive instances of Solidity code, where the clone ratio is around 90 percent. Code clones such as type-III or even type-IV semantic clones can also be detected accurately. Our tool can identify more than 1000 clone related bugs based on our bug databases efficiently and accurately. Our tool can also help to efficiently validate any given smart contract against a known set of bugs, which can help to improve the users’ confidence in the reliability of the contract. Zhipeng Gao 0002, Lingxiao Jiang, Xin Xia 0001, David Lo 0001, John C. Grundy |
IEEE Trans. Software Eng. | 5 |
| 2020 | Human-centric Software Engineering for Next Generation Cloud- and Edge-based Smart Living ApplicationsabstractHumans are a key part of software development, including customers, designers, coders, testers and end users. In this keynote talk I explain why incorporating human-centric issues into software engineering for next-generation applications is critical. I use several examples from our recent and current work on handling human-centric issues when engineering various `smart living' cloud- and edge-based software systems. This includes using human-centric, domain-specific visual models for non-technical experts to specify and generate data analysis applications; personality impact on aspects of software activities; incorporating end user emotions into software requirements engineering for smart homes; incorporating human usage patterns into emerging edge computing applications; visualising smart city-related data; reporting diverse software usability defects; and human-centric security and privacy requirements for smart living systems. I assess the usefulness of these approaches, highlight some outstanding research challenges, and briefly discuss our current work on new human-centric approaches to software engineering for smart living applications. John C. Grundy |
CCGRID | 1 |
| 2020 | Adapting Teaching of a Software Engineering Service Course Due to COVID-19abstractThe COVID-19 pandemic has impacted almost every sphere of life. Higher education in Australia was similarly majorly impacted, and due to the sudden necessity of ensuring physical distancing, on campus teaching became impossible. Most of the higher educational institutes in Australia moved to using a distance education mode to continue delivery of teaching with barely a few weeks warning. This article presents experiences moving a data structures and networking course taught to Software Engineering students at an Australian university during COVID-19 pandemic to online delivery. Due to the nature of the course and student cohort, a number of challenges were faced teaching the course in online mode compared to that for which it was designed. We summarize key lessons learned and propose some guidelines for future course design to take advantage of online learning while maintaining learning outcomes. Tanjila Kanij, John C. Grundy |
CSEE&T | 2 |
| 2020 | Towards Human-centric Model-driven Software EngineeringabstractMany current software systems suffer from a lack of consideration of the human differences between end users. This includes age, gender, language, culture, emotions, personality, education, physical and mental challenges, and so on. We describe our work looking to consider these characteristics by incorporation of human centric-issues throughout the model-driven engineering process lifecycle. We propose the use of the co-creational "living lab" model to better collect human-centric issues in the software requirements. We focus on modelling these human-centric factors using domain-specific visual languages, themselves humancentric modelling artefacts. We describe work to incorporate these human-centric issues into model-driven engineering design models, and to support both code generation and run-time adaptation to different user human factors. We discuss continuous evaluation of such human-centric issues in the produced software and feedback of user reported defects to requirements and model refinement. John C. Grundy, Hourieh Khalajzadeh, Jennifer McIntosh 0001 |
ENASE | 1 |
| 2020 | Visual Languages for Supporting Big Data Analytics DevelopmentabstractWe present BiDaML (Big Data Analytics Modeling Languages), an integrated suite of visual languages and supporting tool to help end-users with the engineering of big data analytics solutions. BiDaML, our visual notations suite, comprises six diagrammatic notations: brainstorming diagram, process diagram, technique diagrams, data diagrams, output diagrams and deployment diagram. BiDaML tool provides a platform for efficiently producing BiDaML visual models and facilitating their design, creation, code generation and integration with other tools. To demonstrate the utility of BiDaML, we illustrate our approach with a realworld example of traffic data analysis. We evaluate BiDaML using two types of evaluations, the physics of notations and a cognitive walkthrough with several target end-users e.g. data scientists and software engineers. Hourieh Khalajzadeh, Anj Simmons, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
ENASE | 4 |
| 2020 | Quality of Experience-Aware User Allocation in Edge Computing Systems: A Potential GameabstractAs many applications and services are moving towards a more human-centered design, app vendors are taking the quality of experience (QoE) increasingly seriously. End-to-end latency is a key factor that determines the QoE experienced by users, especially for latency-sensitive applications such as online gaming, health care, critical warning systems and so on. Recently, edge computing has emerged as a promising solution to the high latency problem. In an edge computing environment, edge servers are deployed at cellular base stations, offering processing power and low network latency to users within their geographic proximity. In this paper, we tackle the user allocation problem in edge computing from an app vendor's perspective, where the vendor needs to decide which edge servers to serve which users in a specific area. Also, the vendor must consider the various levels of quality of service (QoS) for its users. Each QoS level results in a different QoE level; thus, the app vendor needs to decide the QoS level for each user so that the overall user experience is maximized. To tackle the NP-hardness of this problem, we formulate it as a potential game then propose QoEGame, an effective and efficient game-theoretic approach that admits a Nash equilibrium as a solution to the user allocation problem. Being a distributed algorithm, QoEGame is able to fully utilize the distributed nature of edge computing. Finally, we theoretically and empirically evaluate the performance of QoEGame, which is illustrated to be significantly better than the state of the art and other baseline approaches. Phu Lai, Qiang He 0001, Guangming Cui, Feifei Chen 0001, Mohamed Almorsy, John C. Grundy, John G. Hosking, Yun Yang 0001 |
ICDCS | 6 |
| 2020 | Interpreting cloud computer vision pain-points: a mining study of stack overflowabstractIntelligent services are becoming increasingly more pervasive; application developers want to leverage the latest advances in areas such as computer vision to provide new services and products to users, and large technology firms enable this via RESTful APIs. While such APIs promise an easy-to-integrate on-demand machine intelligence, their current design, documentation and developer interface hides much of the underlying machine learning techniques that power them. Such APIs look and feel like conventional APIs but abstract away data-driven probabilistic behaviour---the implications of a developer treating these APIs in the same way as other, traditional cloud services, such as cloud storage, is of concern. The objective of this study is to determine the various pain-points developers face when implementing systems that rely on the most mature of these intelligent services, specifically those that provide computer vision. We use Stack Overflow to mine indications of the frustrations that developers appear to face when using computer vision services, classifying their questions against two recent classification taxonomies (documentation-related and general questions). We find that, unlike mature fields like mobile development, there is a contrast in the types of questions asked by developers. These indicate a shallow understanding of the underlying technology that empower such systems. We discuss several implications of these findings via the lens of learning taxonomies to suggest how the software engineering community can improve these services and comment on the nature by which developers use them. Alex Cummaudo, Rajesh Vasa, Scott Barnett, John C. Grundy, Mohamed Almorsy |
ICSE | 4 |
| 2020 | Score-Based Automatic Detection and Resolution of Syntactic Ambiguity in Natural Language RequirementsabstractThe quality of a delivered product relies heavily upon the quality of its requirements. Across many disciplines and domains, system and software requirements are mostly specified in natural language (NL). However, natural language is inherently ambiguous and inconsistent. Such intrinsic challenges can lead to misinterpretations and errors that propagate to the subsequent phases of the system development. Pattern-based natural language processing (NLP) techniques have been proposed to detect the ambiguity in requirements specifications. However, such approaches typically address specific cases or patterns and lack the versatility essential to detecting different cases and forms of ambiguity. In this paper, we propose an efficient and versatile automatic syntactic ambiguity detection technique for NL requirements. The proposed technique relies on filtering the possible scored interpretations of a given sentence obtained via Stanford CoreNLP library. In addition, it provides feedback to the user with the possible correct interpretations to resolve the ambiguity. Our approach incorporates four filtering pipelines on the input NL-requirements working in conjunction with the CoreNLP library to provide the most likely possible correct interpretations of a requirement. We evaluated our approach on a suite of datasets of 126 requirements and achieved 65% precision and 99% recall on average. Mohamed Osama, Aya Zaki-Ismail, Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSME | 4 |
| 2020 | Budgeted Data Caching based on k-Median in Mobile Edge ComputingabstractIn mobile edge computing (MEC), edge servers are deployed at base stations to provide highly accessible computational resources and storage capacities to nearby mobile devices. Caching data on edge servers can ensure the service quality and network latency for those mobile devices. However, an app vendor needs to ensure that the data caching cost does not exceed its data caching budget. In this paper, we present the budgeted edge data caching (BEDC) problem as a constrained optimization problem to maximize the overall reduction in data retrieval for all its app users within the budget, and prove that it is NP-hard. Then, we provide an approach named IP-BEDC for solving the BEDC problem optimally based on Integer Programming. We also provide an O(k) -approximation algorithm, namely α-BEDC, to find near-optimal solutions to the BEDC problems efficiently. Our proposed approaches are evaluated on a real-world data set and a synthesized data set. The results demonstrate that our approaches can solve the BEDC problem effectively and efficiently while significantly outperforming five representative approaches. Xiaoyu Xia 0001, Feifei Chen 0001, Guangming Cui, Mohamed Almorsy, John C. Grundy, Hai Jin 0001, Qiang He 0001 |
ICWS | 5 |
| 2020 | AndroZooOpen: Collecting Large-scale Open Source Android Apps for the Research CommunityabstractIt is critical for research to have an open, well-curated, representative set of apps for analysis. We present a collection of open-source Android apps collected from several sources, including Github. Our dataset, AndroZooOpen, currently contains over 45,000 app artefacts, a representative picture of Github-hosted Android apps. For apps released on Google Play, metadata including categories, ratings and user reviews, are also stored. We share this new dataset as part of our ongoing research to better support and enable new research topics involving Android app artefact analysis, and as a supplement dataset for AndroZoo, a well-known app collection of close-sourced Android apps. Li Li 0029, Yanjie Zhao 0001, Xiaoyu Sun 0002, John C. Grundy |
MSR | 5 |
| 2020 | Code Action Network for Binary Function Scope Identification
Van Nguyen 0002, Trung Le 0001, Tue Le, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung |
PAKDD (1) | 7 |
| 2020 | Deep Cost-Sensitive Kernel Machine for Binary Software Vulnerability Detection
Tuan Nguyen 0004, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung |
PAKDD (2) | 6 |
| 2020 | Dual-Component Deep Domain Adaptation: A New Approach for Cross Project Software Vulnerability Detection
Van Nguyen 0002, Trung Le 0001, Olivier Y. de Vel, Paul Montague, John C. Grundy, Dinh Q. Phung |
PAKDD (1) | 5 |
| 2020 | Beware the evolving 'intelligent' web service! an integration architecture tactic to guard AI-first componentsabstractIntelligent services provide the power of AI to developers via simple RESTful API endpoints, abstracting away many complexities of machine learning. However, most of these intelligent services---such as computer vision---continually learn with time. When the internals within the abstracted 'black box' become hidden and evolve, pitfalls emerge in the robustness of applications that depend on these evolving services. Without adapting the way developers plan and construct projects reliant on intelligent services, significant gaps and risks result in both project planning and development. Therefore, how can software engineers best mitigate software evolution risk moving forward, thereby ensuring that their own applications maintain quality? Our proposal is an architectural tactic designed to improve intelligent service-dependent software robustness. The tactic involves creating an application-specific benchmark dataset baselined against an intelligent service, enabling evolutionary behaviour changes to be mitigated. A technical evaluation of our implementation of this architecture demonstrates how the tactic can identify 1,054 cases of substantial confidence evolution and 2,461 cases of substantial changes to response label sets using a dataset consisting of 331 images that evolve when sent to a service. Alex Cummaudo, Scott Barnett, Rajesh Vasa, John C. Grundy, Mohamed Almorsy |
ESEC/SIGSOFT FSE | 4 |
| 2020 | Threshy: supporting safe usage of intelligent web servicesabstractIncreased popularity of ‘intelligent’ web services provides end-users with machine-learnt functionality at little effort to developers. However, these services require a decision threshold to be set which is dependent on problem-specific data. Developers lack a systematic approach for evaluating intelligent services and existing evaluation tools are predominantly targeted at data scientists for pre-development evaluation. This paper presents a workflow and supporting tool, Threshy, to help software developers select a decision threshold suited to their problem domain. Unlike existing tools, Threshy is designed to operate in multiple workflows including pre-development, pre-release, and support. Threshy is designed for tuning the confidence scores returned by intelligent web services and does not deal with hyper-parameter optimisation used in ML models. Additionally, it considers the financial impacts of false positives. Threshold configuration files exported by Threshy can be integrated into client applications and monitoring infrastructure. Demo: https://bit.ly/2YKeYhE. Alex Cummaudo, Scott Barnett, Rajesh Vasa, John C. Grundy |
ESEC/SIGSOFT FSE | 4 |
| 2020 | DiffTech: a tool for differencing similar technologies from question-and-answer discussionsabstractDevelopers can use different technologies for different software development tasks in their work. However, when faced with several technologies with comparable functionalities, it can be challenging for developers to select the most appropriate one, as trial and error comparisons among such technologies are time-consuming. Instead, developers resort to expert articles, read official documents or ask questions in Q&A sites for technology comparison. However, it is still very opportunistic whether they will get a comprehensive comparison, as online information is often fragmented, contradictory and biased. To overcome these limitations, we propose the DiffTech system that exploits the crowd sourced discussions from Stack Overflow, and assists technology comparison with an informative summary of different comparison aspects. We found 19,118 comparative sentences from 2,410 pairs of comparable technologies. We released our DiffTech website for public use. Our website attracts over 1800 users and we also receive some positive comments on social media. A walkthrough video of the tool demo: https://www.youtube.com/watch?v=ixX41DXRNsI Website link: https://difftech.herokuapp.com/ Han Wang 0023, Chunyang Chen 0001, Zhenchang Xing, John C. Grundy |
ESEC/SIGSOFT FSE | 4 |
| 2020 | End-User-Oriented Tool Support for Modeling Data Analytics RequirementsabstractBig data and analytics are increasingly used in different domains to gain insights and to improve decision-making. Developing big data analytics solutions is a complex task involving multidisciplinary teams and users - with no data science and programming background - to professional data scientists and software engineers. Different stakeholders work with a variety of data types, tasks and concepts in different languages from high- level domain concepts to low level programming languages and technical concepts. In order to advance the level of abstraction beyond low-level data analysis technical details, we demonstrate our BiDaML tool. BiDaML brings all stakeholders around one tool to specify, model and document their big data applications using a novel set of domain-specific visual languages (DSVLs). Hourieh Khalajzadeh, Anj Simmons, Mohamed Almorsy, John C. Grundy, John G. Hosking, Qiang He 0001 |
VL/HCC | 4 |
| 2020 | The Effect of Narration on User Comprehension and Recall of Information VisualisationsabstractInformation visualisation researchers have posited that author-driven narratives will allow information to be conveyed efficiently and argue for the adoption of storytelling techniques in information visualisation. However, there is limited work describing the effects of author-driven narratives in users' comprehension and memorability of visualisations in relation to interactive visualisations. Recommendations for author-driven visualisation stories are largely based on anecdotal reports or research from the arts, and not on studies in information visualisation. To investigate these issues, we carried out a study that compared purely author-driven narratives with interactive visualisations devoid of author narratives, in terms of comprehension and short-term and long-term memorability. We found that the presence of narration in author-driven stories significantly aided the understanding of information but had no significant effect on the long-term recall of information from visualisations. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VL/HCC | 5 |
| 2020 | QoE-aware user allocation in edge computing systems with dynamic QoS
Phu Lai, Qiang He 0001, Guangming Cui, Xiaoyu Xia 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
Future Gener. Comput. Syst. | 8 |
| 2020 | Graph-based data caching optimization for edge computing
Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, Phu Lai, Mohamed Almorsy, John C. Grundy, Hai Jin 0001 |
Future Gener. Comput. Syst. | 7 |
| 2020 | A revised open source usability defect classification taxonomy
Nor Shahida Mohamad Yusop, John C. Grundy, Jean-Guy Schneider, Rajesh Vasa |
Inf. Softw. Technol. | 2 |
| 2020 | Cost effective dynamic data placement for efficient access of social networks
Hourieh Khalajzadeh, Dong Yuan 0001, Bing Bing Zhou, John C. Grundy, Yun Yang 0001 |
J. Parallel Distributed Comput. | 4 |
| 2020 | Wireframe-based UI Design Search through Image AutoencoderabstractUI design is an integral part of software development. For many developers who do not have much UI design experience, exposing them to a large database of real-application UI designs can help them quickly build up a realistic understanding of the design space for a software feature and get design inspirations from existing applications. However, existing keyword-based, image-similarity-based, and component-matching-based methods cannot reliably find relevant high-fidelity UI designs in a large database alike to the UI wireframe that the developers sketch, in face of the great variations in UI designs. In this article, we propose a deep-learning-based UI design search engine to fill in the gap. The key innovation of our search engine is to train a wireframe image autoencoder using a large database of real-application UI designs, without the need for labeling relevant UI designs. We implement our approach for Android UI design search, and conduct extensive experiments with artificially created relevant UI designs and human evaluation of UI design search results. Our experiments confirm the superior performance of our search engine over existing image-similarity or component-matching-based methods and demonstrate the usefulness of our search engine in real-world UI design tasks. Jieshan Chen, Chunyang Chen 0001, Zhenchang Xing, Xin Xia 0001, Liming Zhu 0001, John C. Grundy, Jinshui Wang |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2020 | Generating Question Titles for Stack Overflow from Mined Code SnippetsabstractStack Overflow has been heavily used by software developers as a popular way to seek programming-related information from peers via the internet. The Stack Overflow community recommends users to provide the related code snippet when they are creating a question to help others better understand it and offer their help. Previous studies have shown that a significant number of these questions are of low-quality and not attractive to other potential experts in Stack Overflow. These poorly asked questions are less likely to receive useful answers and hinder the overall knowledge generation and sharing process. Considering one of the reasons for introducing low-quality questions in SO is that many developers may not be able to clarify and summarize the key problems behind their presented code snippets due to their lack of knowledge and terminology related to the problem, and/or their poor writing skills, in this study we propose an approach to assist developers in writing high-quality questions by automatically generating question titles for a code snippet using a deep sequence-to-sequence learning approach. Our approach is fully data-driven and uses an attention mechanism to perform better content selection, a copy mechanism to handle the rare-words problem and a coverage mechanism to eliminate word repetition problem. We evaluate our approach on Stack Overflow datasets over a variety of programming languages (e.g., Python, Java, Javascript, C# and SQL) and our experimental results show that our approach significantly outperforms several state-of-the-art baselines in both automatic and human evaluation. We have released our code and datasets to facilitate other researchers to verify their ideas and inspire the follow up work. Zhipeng Gao 0002, Xin Xia 0001, John C. Grundy, David Lo 0001, Yuan-Fang Li |
ACM Trans. Softw. Eng. Methodol. | 3 |
| 2019 | A Deadline Constrained Preemptive Scheduler Using Queuing Systems for Multi-Tenancy CloudsabstractScheduling on clouds is required so that service providers can meet Quality of Service (QoS) requirements of tenants. Deadline is a major criterion in judging QoS. This work presents a real-time, preemptive, constrained scheduler using queuing theory - PDSonQueue - which enables better meetinhg of QoS requirements. PDSonQueue also shortens a job's completion time and improves system's throughput. PDSon-Queue, as a dynamic priority real-time greedy scheduler, builds a queuing-based mathematical model to accurately predict a job's execution and waiting time, where jobs arrive by following a stochastic process and request resources. Our scheduler introduces a novel "Earliest Maximal Waiting Time First (EMWTF)" concept to fine tune job scheduling to guarantee the job being accomplished within the deadline. Deadline constrained jobs are scheduled preemptively from low priority jobs with the intent of maximising the number of jobs completed within the deadlines, while allowing system's resources to be shared by other regular jobs. PDSonQueue integrates an improved Dominant Resource Fairness (DRF) greedy resource allocation approach to capture the essence of tenants' resource allocation and run as many jobs as possible. Our experimental results indicate that PDSonQueue can improve by at least 20% of deadline-based QoS rate, and by at least 30% for throughput. Jia Ru, Yun Yang 0001, John C. Grundy, Jacky W. Keung |
CLOUD | 3 |
| 2019 | A Highly Efficient Data Locality Aware Task Scheduler for Cloud-Based SystemsabstractScheduling tasks in the vicinity of stored data can significantly diminish network traffic. Scheduling optimisation can improve data locality by attempting to locate a task and its related data on the same node. Existing schedulers tend to ignore overhead and tradeoff between data transfer and task placement, and bandwidth consumption, by only emphasising data locality without considering other factors. We present a novel data locality aware scheduler for balancing time consumption and network bandwidth traffic - DLAforBT - to improve data locality for tasks and throughput, with the optimal placement policy exhibiting a threshold-based structure. DLAforBT uses bipartite graph modelling to represent data placement, adopts a judgment mechanism and a precise prediction model to determine moving data or moving computation. It integrates an improved Dominant Resource Fairness (DRF) resource allocation to capture tenants' resource allocation and run as many jobs as possible. DLAforBT improves by 16% of data locality rate, and 25% of throughput. Jia Ru, Yun Yang 0001, John C. Grundy, Jacky W. Keung |
CLOUD | 3 |
| 2019 | A Framework for Internet of Things Search Engines EngineeringabstractThe content of the Internet of Things (IoT), notably sensor data and virtual representation of physical devices, has been increasingly delivered via Web protocols and available on the World Wide Web (WWW). Internet of Things Search Engine (IoTSE) systems are catalytic to utilize this influx of data. They enable users to discover and retrieve relevant IoT content. While a general IoTSE system - the next "Google" - is beyond the horizon due to the vast diversity of IoT content and types of queries for them, specific IoTSE systems that target subsets of query types and IoT infrastructure are feasible and beneficial. A component-based engineering approach, in which prior IoTSE systems and research prototypes are reassembled as building blocks for new IoTSE systems, could be a time-and cost-effective solution to engineering IoTSE systems. This paper presents the design, implementation, and evaluation of a framework to facilitate a component-based approach to engineering IoTSE systems. As an evaluation, we developed eight IoTSE components and composed them into eight proof-of-concept IoTSE systems, using a reference implementation of the proposed framework. An analysis on Source Line of Code (SLOC) revealed that the complexity handled transparently by the IoTSE framework could account for over 90% of the code base of a simple IoTSE system. Nguyen Khoi Tran 0001, Muhammad Ali Babar 0001, Quan Z. Sheng, John C. Grundy |
APSEC | 4 |
| 2019 | What should I document? A preliminary systematic mapping study into API documentation knowledgeabstractBackground: Good API documentation facilitates the development process, improving productivity and quality. While the topic of API documentation quality has been of interest for the last two decades, there have been few studies to map the specific constructs needed to create a good document. In effect, we still need a structured taxonomy that captures such knowledge systematically.Aims: This study reports emerging results of a systematic mapping study. We capture key conclusions from previous studies that assess API documentation quality, and synthesise the results into a single framework.Method: By conducting a systematic review of 21 key works, we have developed a five dimensional taxonomy based on 34 categorised weighted recommendations.Results: All studies utilise field study techniques to arrive at their recommendations, with seven studies employing some form of interview and questionnaire, and four conducting documentation analysis. The taxonomy we synthesise reinforces that usage description details (code snippets, tutorials, and reference documents) are generally highly weighted as helpful in API documentation, in addition to design rationale and presentation.Conclusions: We propose extensions to this study aligned to developer utility for each of the taxonomy's categories. Alex Cummaudo, Rajesh Vasa, John C. Grundy |
ESEM | 3 |
| 2019 | Do Energy-Oriented Changes Hinder Maintainability?abstractEnergy efficiency is a crucial quality requirement for mobile applications. However, improving energy efficiency is far from trivial as developers lack the knowledge and tools to aid in this activity. In this paper we study the impact of changes to improve energy efficiency on the maintainability of Android applications. Using a dataset containing 539 energy efficiency-oriented commits, we measure maintainability – as computed by the Software Improvement Group's web-based source code analysis service Better Code Hub (BCH) – before and after energy efficiency-related code changes. Results show that in general improving energy efficiency comes with a significant decrease in maintainability. This is particularly evident in code changes to accommodate the Power Save Mode and Wakelock Addition energy patterns. In addition, we perform manual analysis to assess how real examples of energy-oriented changes affect maintainability. Our results help mobile app developers to 1) avoid common maintainability issues when improving the energy efficiency of their apps; and 2) adopt development processes to build maintainable and energy-efficient code. We also support researchers by identifying challenges in mobile app development that still need to be addressed. Luis Cruz 0002, Rui Abreu 0001, John C. Grundy, Li Li 0029, Xin Xia 0001 |
ICSME | 3 |
| 2019 | Losing Confidence in Quality: Unspoken Evolution of Computer Vision ServicesabstractThe following topics are dealt with: software maintenance; public domain software; program testing; source code (software); program debugging; software quality; program diagnostics; learning (artificial intelligence); mobile computing; data mining. Alex Cummaudo, Rajesh Vasa, John C. Grundy, Mohamed Almorsy, Andrew Cain |
ICSME | 3 |
| 2019 | SmartEmbed: A Tool for Clone and Bug Detection in Smart Contracts through Structural Code EmbeddingabstractEthereum has become a widely used platform to enable secure, Blockchain-based financial and business transactions. However, a major concern in Ethereum is the security of its smart contracts. Many identified bugs and vulnerabilities in smart contracts not only present challenges to the maintenance of blockchain, but also lead to serious financial loses. There is a significant need to better assist developers in checking smart contracts and ensuring their reliability. In this paper, we propose a web service tool, named SmartEmbed, which can help Solidity developers to find repetitive contract code and clone-related bugs in smart contracts. Our tool is based on code embeddings and similarity checking techniques. By comparing the similarities among the code embedding vectors for existing solidity code in the Ethereum blockchain and known bugs, we are able to efficiently identify code clones and clone-related bugs for any solidity code given by users, which can help to improve the users' confidence in the reliability of their code. In addition to the uses by individual developers, SmartEmbed can also be applied to studies of smart contracts in a large scale. When applied to more than 22K solidity contracts collected from the Ethereum blockchain, we found that the clone ratio of solidity code is close to 90%, much higher than traditional software, and 194 clone-related bugs can be identified efficiently and accurately based on our small bug database with a precision of 96%. Zhipeng Gao 0002, Vinoj Jayasundara 0001, Lingxiao Jiang, Xin Xia 0001, David Lo 0001, John C. Grundy |
ICSME | 6 |
| 2019 | Edge User Allocation with Dynamic Quality of Service
Phu Lai, Qiang He 0001, Guangming Cui, Xiaoyu Xia 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
ICSOC | 8 |
| 2019 | Graph-Based Optimal Data Caching in Edge Computing
Xiaoyu Xia 0001, Feifei Chen 0001, Qiang He 0001, Guangming Cui, Phu Lai, Mohamed Almorsy, John C. Grundy, Hai Jin 0001 |
ICSOC | 7 |
| 2019 | Merging Intelligent API Responses Using a Proportional Representation Approach
Tomohiro Ohtake, Alex Cummaudo, Mohamed Almorsy, Rajesh Vasa, John C. Grundy |
ICWE | 5 |
| 2019 | FogWorkflowSim: An Automated Simulation Toolkit for Workflow Performance Evaluation in Fog ComputingabstractWorkflow underlies most process automation software, such as those for product lines, business processes, and scientific computing. However, current Cloud Computing based workflow systems cannot support real-time applications due to network latency, which limits their application in many IoT systems such as smart healthcare and smart traffic. Fog Computing extends the Cloud by providing virtualized computing resources close to the End Devices so that the response time of accessing computing resources can be reduced significantly. However, how to most effectively manage heterogeneous resources and different computing tasks in the Fog is a big challenge. In this paper, we introduce "FogWorkflowSim" an efficient and extensible toolkit for automatically evaluating resource and task management strategies in Fog Computing with simulated user-defined workflow applications. Specifically, FogWorkflowSim is able to: 1) automatically set up a simulated Fog Computing environment for workflow applications; 2) automatically execute user submitted workflow applications; 3) automatically evaluate and compare the performance of different computation offloading and task scheduling strategies with three basic performance metrics, including time, energy and cost. FogWorkflowSim can serve as an effective experimental platform for researchers in Fog based workflow systems as well as practitioners interested in adopting Fog Computing and workflow systems for their new software projects. (Demo video: https://youtu.be/AsMovcuSkx8). Xiao Liu 0004, Lingmin Fan, Jia Xu 0010, Xuejun Li 0001, Lina Gong, John C. Grundy, Yun Yang 0001 |
ASE | 6 |
| 2019 | Lessons learned from using a deep tree-based model for software defect prediction in practiceabstractDefects are common in software systems and cause many problems for software users. Different methods have been developed to make early prediction about the most likely defective modules in large codebases. Most focus on designing features (e.g. complexity metrics) that correlate with potentially defective code. Those approaches however do not sufficiently capture the syntax and multiple levels of semantics of source code, a potentially important capability for building accurate prediction models. In this paper, we report on our experience of deploying a new deep learning tree-based defect prediction model in practice. This model is built upon the tree-structured Long Short Term Memory network which directly matches with the Abstract Syntax Tree representation of source code. We discuss a number of lessons learned from developing the model and evaluating it on two datasets, one from open source projects contributed by our industry partner Samsung and the other from the public PROMISE repository. Khanh Hoa Dam, Trang Pham, Shien Wee Ng, Truyen Tran 0001, John C. Grundy, Aditya Ghose, Taeksu Kim, Chul-Joo Kim |
MSR | 5 |
| 2019 | A Framework for Authoring Logically Ordered Visual Data StoriesabstractVisual data storytelling has gained widespread adoption as a means of communicating information visualisation. This is partly due to the increased interest in data journalism. Besides being engaging, it has been shown to foster better comprehension and memorability of information to target audiences. The visual data story authoring process involves several stages. However, current tools neither consolidate the visual data story creation process nor integrate the essential features, such as the recommendation of logically sequenced story pieces, for producing coherent narratives. This paper briefly demonstrates our approach and framework for supporting the creation of logically sequenced visual data stories. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VL/HCC | 5 |
| 2019 | Knowledge Graphing Git Repositories: A Preliminary StudyabstractKnowledge Graph, being able to connect information from a variety of sources, has become very famous in recent years since its creation in 2012 by Google. Researchers in our community have leveraged Knowledge Graph to achieve various purposes such as improving API caveats accessibilities, generating answers to developer questions, and reasoning common software weaknesses, etc. In this work, we would like to leverage the knowledge graph concept for helping developers and project managers to comprehend software repositories. To this end, we design and implement a prototype tool called GitGraph, which takes as input a Git repository and constructs automatically a knowledge graph associated with the repository. Our preliminary experimental results show that GitGraph can correctly generate knowledge graphs for Git projects and the generated graphs are also useful for users to comprehend the projects. More specifically, the knowledge graph, on one hand, provides a graphic interface that users can interactively explore the integrated artefacts such as commits and changed methods, while on the other hand, provides a convenient means for users to search for advanced relations between the different artefacts. Yanjie Zhao 0001, Haoyu Wang 0001, Lei Ma 0003, Li Li 0029, John C. Grundy |
SANER | 6 |
| 2019 | Automatic, highly accurate app permission recommendation
Zhongxin Liu 0002, Xin Xia 0001, David Lo 0001, John C. Grundy |
Autom. Softw. Eng. | 4 |
| 2019 | Is deep learning better than traditional approaches in tag recommendation for software information sites?
Pingyi Zhou, Jin Liu 0016, Xiao Liu 0004, Zijiang Yang 0006, John C. Grundy |
Inf. Softw. Technol. | 5 |
| 2019 | Emotion-oriented requirements engineering: A case study in developing a smart home system for the elderly
Maheswaree Kissoon Curumsing, Niroshinie Fernando, Mohamed Almorsy, Rajesh Vasa, Kon Mouzakis, John C. Grundy |
J. Syst. Softw. | 6 |
| 2019 | The influence of textual and verbal word-of-mouth on website usability and visual appeal
Milica Stojmenovic, Robert Biddle, John C. Grundy, Vivienne Farrell |
J. Supercomput. | 3 |
| 2019 | Neural Network-based Detection of Self-Admitted Technical Debt: From Performance to ExplainabilityabstractTechnical debt is a metaphor to reflect the tradeoff software engineers make between short-term benefits and long-term stability. Self-admitted technical debt (SATD), a variant of technical debt, has been proposed to identify debt that is intentionally introduced during software development, e.g., temporary fixes and workarounds. Previous studies have leveraged human-summarized patterns (which represent n-gram phrases that can be used to identify SATD) or text-mining techniques to detect SATD in source code comments. However, several characteristics of SATD features in code comments, such as vocabulary diversity, project uniqueness, length, and semantic variations, pose a big challenge to the accuracy of pattern or traditional text-mining-based SATD detection, especially for cross-project deployment. Furthermore, although traditional text-mining-based method outperforms pattern-based method in prediction accuracy, the text features it uses are less intuitive than human-summarized patterns, which makes the prediction results hard to explain. To improve the accuracy of SATD prediction, especially for cross-project prediction, we propose a Convolutional Neural Network-- (CNN) based approach for classifying code comments as SATD or non-SATD. To improve the explainability of our model’s prediction results, we exploit the computational structure of CNNs to identify key phrases and patterns in code comments that are most relevant to SATD. We have conducted an extensive set of experiments with 62,566 code comments from 10 open-source projects and a user study with 150 comments of another three projects. Our evaluation confirms the effectiveness of different aspects of our approach and its superior performance, generalizability, adaptability, and explainability over current state-of-the-art traditional text-mining-based methods for SATD classification. Xiaoxue Ren, Zhenchang Xing, Xin Xia 0001, David Lo 0001, Xinyu Wang 0001, John C. Grundy |
ACM Trans. Softw. Eng. Methodol. | 6 |
| 2018 | Optimal Edge User Allocation in Edge Computing with Variable Sized Vector Bin Packing
Phu Lai, Qiang He 0001, Mohamed Almorsy, Feifei Chen 0001, John G. Hosking, John C. Grundy, Yun Yang 0001 |
ICSOC | 6 |
| 2018 | PedaViz: Visualising Hour-Level Pedestrian ActivityabstractEffective visualisation plays a vital role in generating insights from data. The selection of graph types however, is highly dependent on the analysis tasks and data types at hand. For example, spatio-temporal visualisations encode changes in data over time and space. Although they have the potential of revealing overall tendencies and movement patterns, building effective spatio-temporal visualisations is challenging because it requires encoding all three attributes of spatio-temporal data i.e. thematic (values of attributes), temporal and spatial in a single visualisation. In this application design study, we present PedaViz for representing hour-level spatio-temporal attributes within a single visualisation; a 24-hour radial visual metaphor that encodes hour-level temporal and daily temperature attributes while utilising a thematic map display to present spatial attributes. The design was applied on city planning domain using Melbourne's pedestrian count and temperature data. Results of our preliminary user evaluation suggest that our visualisation is easily understandable by users; and supports users in carrying out selected analysis tasks. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy, Tomasz Bednarz |
VINCI | 5 |
| 2018 | DCTracVis: a system retrieving and visualizing traceability links between source code and documentation
John G. Hosking, John C. Grundy, Robert Amor |
Autom. Softw. Eng. | 3 |
| 2018 | FastTagRec: fast tag recommendation for software information sites
Jin Liu 0016, Pingyi Zhou, Zijiang Yang 0006, Xiao Liu 0004, John C. Grundy |
Autom. Softw. Eng. | 5 |
| 2018 | Recruitment, engagement and feedback in empirical software engineering studies in industrial contexts
Norsaremah Salleh, Rashina Hoda, Moon Ting Su, Tanjila Kanij, John C. Grundy |
Inf. Softw. Technol. | 5 |
| 2018 | Metric selection and anomaly detection for cloud operations using log and metric correlation analysis
Mostafa Farshchi, Jean-Guy Schneider, Ingo Weber, John C. Grundy |
J. Syst. Softw. | 4 |
| 2018 | Predicting Delivery Capability in Iterative Software DevelopmentabstractIterative software development has become widely practiced in industry. Since modern software projects require fast, incremental delivery for every iteration of software development, it is essential to monitor the execution of an iteration, and foresee a capability to deliver quality products as the iteration progresses. This paper presents a novel, data-driven approach to providing automated support for project managers and other decision makers in predicting delivery capability for an ongoing iteration. Our approach leverages a history of project iterations and associated issues, and in particular, we extract characteristics of previous iterations and their issues in the form of features. In addition, our approach characterizes an iteration using a novel combination of techniques including feature aggregation statistics, automatic feature learning using the Bag-of-Words approach, and graph-based complexity measures. An extensive evaluation of the technique on five large open source projects demonstrates that our predictive models outperform three common baseline methods in Normalized Mean Absolute Error and are highly accurate in predicting the outcome of an ongoing iteration. Morakot Choetkiertikul, Khanh Hoa Dam, Truyen Tran 0001, Aditya Ghose, John C. Grundy |
IEEE Trans. Software Eng. | 5 |
| 2017 | Analysis of the Textual Content of Mined Open Source Usability Defect ReportsabstractWriting a good usability defect report can be a tedious task, especially in identifying what important information should be included, and capturing the attention of software developers to fix them. This paper is a continuity of our previous studies investigating software development practitioners' day-to-day practices when dealing with usability defects. In this study, we mined 377 developer-tagged usability defect reports from Mozilla Thunderbird, Firefox for Android and Eclipse Platform to confirm what software development practitioners claimed to provide when reporting usability defects. We looked for the presence of key defect attributes - steps to reproduce, impact, software context, expected output, actual output, assumed causes, solution proposal and supplementary information. In addition, we analyzed the trend of different types of usability defects, correlation between usability defects and defect severity, and failure qualifier. Our findings demonstrate a mismatch between what software development practitioners claimed to provide when reporting usability defects, and the information that actually appears in the defect reports. The results of our research have important implications for software defect reporting, especially in designing more effective mechanisms for reporting usability defects. Nor Shahida Mohamad Yusop, Jean-Guy Schneider, John C. Grundy, Rajesh Vasa |
APSEC | 3 |
| 2017 | Efficient Keyword Search for Building Service-Based Systems Based on Dynamic Programming
Qiang He 0001, Rui Zhou 0001, Xuyun Zhang, Dayong Ye, Feifei Chen 0001, Shiping Chen 0001, John C. Grundy, Yun Yang 0001 |
ICSOC | 8 |
| 2017 | Testing Environment Emulation - A Model-based ApproachabstractModern enterprise software systems often need to interact with a large number of distributed and\nheterogeneous systems. As a result, integration testing has become a critical step in their software\ndevelopment lifecycle. Service virtualization is an emerging technique for creating testing environments with realistic executable models of server side production-like behaviours. However, building models in existing service virtualization approaches is very challenging, requiring either significant human effort or the availability of interactive tracing records. In this paper, we present a domain-specific modeling approach to generate complex, virtualized testing environments. Our approach allows domain experts to use a suite of domain-specific visual modeling languages to model key interface layers of applications at a high level of abstraction. These layered models are then transformed into a testing runtime environment for application integration testing. We have conducted a technical comparison with two other existing approaches and also carried out a user study. The user study demonstrated the acceptance of our new testing environment emulation approach from software testing experts and developers. John C. Grundy, Mohamed Almorsy, Iman Avazpour |
MODELSWARD | 2 |
| 2017 | PathRec: Visual Analysis of Travel Route RecommendationsabstractWe present an interactive visualisation tool for recommending travel trajectories. This system is based on new machine learning formulations and algorithms for the sequence recommendation problem. The system starts from a map-based overview, taking an interactive query as starting point. It then breaks down contributions from different geographical and user behavior features, and those from individual points-of-interest versus pairs of consecutive points on a route. The system also supports detailed quantitative interrogation by comparing a large number of features for multiple points. Effective trajectory visualisations can potentially benefit a large cohort of online map users and assist their decision-making. More broadly, the design of this system can inform visualisations of other structured prediction tasks, such as for sequences or trees. Dongwoo Kim 0002, Lexing Xie, Minjeong Shin, Aditya Krishna Menon, Cheng Soon Ong, Iman Avazpour, John C. Grundy |
RecSys | 8 |
| 2017 | Visualising melbourne pedestrian countabstractWe present a visualisation of Melbourne pedestrian count data and a visual metaphor for representing hour-level temporal dimension in this context. The pedestrian count data is captured from sensors located around the city. A visualisation web application is implemented that incorporates a thematic map of these sensor locations with a 24-hour clocklike polygon that shows pedestrian counts at every hour, and alongside a display of daily temperature. Our visualisation allows users to analyse how the city is used by pedestrians. Moreover, the design of our visualisation was driven by the type of analysis tasks carried out by city planners. The visualisation would help city planners better understand the dynamics of pedestrian activity within the city and aid them in urban management and design policy recommendation. Humphrey O. Obie, Caslon Chua, Iman Avazpour, Mohamed Almorsy, John C. Grundy |
VL/HCC | 5 |
| 2017 | MaramaAIC: tool support for consistency management and validation of requirements
Massila Kamalrudin, John G. Hosking, John C. Grundy |
Autom. Softw. Eng. | 3 |
| 2017 | Systematic literature reviews in agile software development: A tertiary study
Rashina Hoda, Norsaremah Salleh, John C. Grundy, Hui Mien Tee |
Inf. Softw. Technol. | 3 |
| 2017 | Keyword Search for Building Service-Based SystemsabstractWith the fast growth of applications of service-oriented architecture (SOA) in software engineering, there has been a rapid increase in demand for building service-based systems (SBSs) by composing existing Web services. Finding appropriate component services to compose is a key step in the SBS engineering process. Existing approaches require that system engineers have detailed knowledge of SOA techniques which is often too demanding. To address this issue, we propose Keyword Search for Service-based Systems (KS3), a novel approach that integrates and automates the system planning, service discovery and service selection operations for building SBSs based on keyword search. KS3 assists system engineers without detailed knowledge of SOA techniques in searching for component services to build SBSs by typing a few keywords that represent the tasks of the SBSs with quality constraints and optimisation goals for system quality, e.g., reliability, throughput and cost. KS3 offers a new paradigm for SBS engineering that can significantly save the time and effort during the system engineering process. We conducted large-scale experiments using two real-world Web service datasets to demonstrate the practicality, effectiveness and efficiency of KS3. Qiang He 0001, Rui Zhou 0001, Xuyun Zhang, Dayong Ye, Feifei Chen 0001, John C. Grundy, Yun Yang 0001 |
IEEE Trans. Software Eng. | 7 |
| 2017 | Reporting Usability Defects: A Systematic Literature ReviewabstractUsability defects can be found either by formal usability evaluation methods or indirectly during system testing or usage. No matter how they are discovered, these defects must be tracked and reported. However, empirical studies indicate that usability defects are often not clearly and fully described. This study aims to identify the state of the art in reporting of usability defects in the software engineering and usability engineering literature. We conducted a systematic literature review of usability defect reporting drawing from both the usability and software engineering literature from January 2000 until March 2016. As a result, a total of 57 studies were identified, in which we classified the studies into three categories: reporting usability defect information, analysing usability defect data and key challenges. Out of these, 20 were software engineering studies and 37 were usability studies. The results of this systematic literature review show that usability defect reporting processes suffer from a number of limitations, including: mixed data, inconsistency of terms and values of usability defect data, and insufficient attributes to classify usability defects. We make a number of recommendations to improve usability defect reporting and management in software engineering. Nor Shahida Mohamad Yusop, John C. Grundy, Rajesh Vasa |
IEEE Trans. Software Eng. | 2 |
| 2016 | Improving Cloud-Based Online Social Network Data Placement and ReplicationabstractOnline social networks make it more convenient for people to find and communicate with other people based on shared interests, ideas, association with different groups, etc. Common social networks such as Facebook and Twitter have hundreds of millions or even billions of users scattered all around the world sharing interconnected data. Users demand low latency access to not only their own data but also their friends' data, often very large, e.g. videos, pictures etc. However, social network service providers have a limited monetary capital to store every piece of data everywhere to minimise users' data access latency. Geo-distributed cloud services with virtually unlimited capabilities are suitable for large scale social networks data storage in different geographical locations. Key problems including how to optimally store and replicate these huge datasets and how to distribute the requests to different datacenters are addressed in this paper. A novel genetic algorithm-based approach is used to find a near-optimal number of replicas for every user's data and a near-optimal placement of replicas to minimise monetary cost while satisfying latency requirements for all users. Experiments on a Facebook dataset demonstrate our technique's effectiveness in outperforming other representative placement and replication strategies. Hourieh Khalajzadeh, Dong Yuan 0001, John C. Grundy, Yun Yang 0001 |
CLOUD | 3 |
| 2016 | What Influences Usability Defect Reporting? - A Survey of Software Development PractitionersabstractSoftware development organizations invest in test automation tools and methods to optimize defect discovery rates. The true value of these tools is realized when the defects are addressed before release, and hence good quality defect reports are critical. We describe a survey we conducted to better understand usability defect reporting, in particular, influences on the quality of usability defect reports. We analyze feedback from nearly 150 software developers and usability defect reporters and identify key determinants of quality defect reports, aspects of usability defects that are challenging to report and directions for future research into usability defect reporting tools to improve usability defect reports quality. Nor Shahida Mohamad Yusop, Jean-Guy Schneider, John C. Grundy, Rajesh Vasa |
APSEC | 3 |
| 2016 | Reporting usability defects: do reporters report what software developers need?abstractReporting usability defects can be a challenging task, especially in convincing the software developers that the reported defect actually requires attention. Stronger evidence in the form of specific details is often needed. However, research to date in software defect reporting has not investigated the value of capturing different information based on defect type. We surveyed practitioners in both open source communities and industrial software organizations about their usability defect reporting practices to better understand information needs to address usability defect reporting issues. Our analysis of 147 responses show that reporters often provide observed result, expected result and steps to reproduce when describing usability defects, similar to the way other types of defects are reported. However, reporters rarely provide usability-related information. In fact, reporters ranked cause of the problem is the most difficult information to provide followed by usability principle, video recoding, UI event trace and title. Conversely, software developers consider cause of the problem as the most helpful information for them to fix usability defects. Our statistical analysis reveals a substantial gap between what reporters provide and what software developers need when fixing usability defects. We propose some remedies to resolve this gap. Nor Shahida Mohamad Yusop, John C. Grundy, Rajesh Vasa |
EASE | 2 |
| 2016 | TeeVML: tool support for semi-automatic integration testing environment emulationabstractSoftware environment emulation provides a means for simulating an operational environment of a system. This process involves approximation of systems’ external behaviors and their communications with a system to be tested in the environment. Development of such an environment is a tedious task and involves complex low level coding. Model driven engineering is an avenue to raise the level of abstraction beyond programming by specifying solution directly using problem domain concepts. In this paper we propose a novel domain-specific modeling tool to generate complex testing environments. Our tool employs a suite of domain-specific visual modeling languages for modeling emulation environment at a high level of abstraction. These high level specifications are then automatically transformed to runtime environment for application integration testing, boosting development productivity and ease of use. The tool demonstration video can be accessed here: https://youtu.be/H3Vg20Juq80. John C. Grundy, Iman Avazpour, Mohamed Almorsy |
ASE | 2 |
| 2016 | An automated collaborative requirements engineering tool for better validation of requirementsabstractThis demo introduces an automated collaborative requirements engineering tool, called TestMEReq, which is used to promote effective communication and collaboration between client-stakeholders and requirements engineers for better requirements validation. Our tool is augmented with real time communication and collaboration support to allow multiple stakeholders to collaboratively validate the same set of requirements. We have conducted a user study focusing on validating requirements using TestMEReq with a few groups of requirements engineers and client stakeholders. The study shows that our automated tool support is able to assist requirements engineers to effectively communicate with client-stakeholders to better validate the requirements virtually in real time. (Demo video: https://www.youtube.com/watch?v=7sWLOx-N4Jo). M. Nor Aiza, Massila Kamalrudin, Safiah Sidek, Mark Robinson, John C. Grundy |
ASE | 5 |
| 2016 | DeepSoft: a vision for a deep model of softwareabstractAlthough software analytics has experienced rapid growth as a research area, it has not yet reached its full potential for wide industrial adoption. Most of the existing work in software analytics still relies heavily on costly manual feature engineering processes, and they mainly address the traditional classification problems, as opposed to predicting future events. We present a vision for DeepSoft, an end-to-end generic framework for modeling software and its development process to predict future risks and recommend interventions. DeepSoft, partly inspired by human memory, is built upon the powerful deep learning-based Long Short Term Memory architecture that is capable of learning long-term temporal dependencies that occur in software evolution. Such deep learned patterns of software can be used to address a range of challenging problems such as code and task recommendation and prediction. DeepSoft provides a new approach for research into modeling of source code, risk prediction and mitigation, developer modeling, and automatically generating code patches from bug reports. Khanh Hoa Dam, Truyen Tran 0001, John C. Grundy, Aditya Ghose |
SIGSOFT FSE | 3 |
| 2016 | An empirical study of user perceived usefulness and preference of open learner model visualisationsabstractMany higher education institutions have reformed their academic programmes to adopt unit learning outcomes. It is essential for effective learning management tools to support this fundamental transformation. We see the need for a tool that provides visualisations of Open Learner Models (OLM) and associated e-portfolio content to guide students in achieving intended learning outcomes, help evidence their learning and keep them engaged in their study. OLMs surface the relationship between learning activities and tasks, formative and summative assessment, and intended learning outcomes. We have developed and validated a set of candidate visualisations for such OLMs. We report key findings from our study in terms of potential users' feedback on our tool's support for tracking learning progress against learning outcomes. Our findings can inform and refine learning management systems. Check Yee Law, John C. Grundy, Rajesh Vasa, Andrew Cain |
VL/HCC | 2 |
| 2016 | A domain-specific visual modeling language for testing environment emulationabstractSoftware integration testing plays an increasingly important role as the software industry has experienced a major change from isolated applications to highly distributed computing environments. Conducting integration testing is a challenging task because it is often very difficult to replicate a real enterprise environment. Emulating testing environment is one of the key solutions to this problem. However, existing specification-based emulation techniques require manual coding of their message processing engines, therefore incurring high development cost. In this paper, we present a suite of domain-specific visual modeling languages to describe emulated testing enviroements at a high abstraction level. Our solution allows domain experts to model a testing environment from abstract interface layers. These layer models are then transformed to runtime environment for application testing. Our user study shows that our visual languages are easy to use, yet with sufficient expressive power to model complex testing applications. John C. Grundy, Iman Avazpour, Mohamed Almorsy |
VL/HCC | 2 |
| 2016 | A Cost/Benefit Approach to Performance AnalysisabstractMost performance engineering approaches focus on understanding the use of runtime resources. However such approaches do not quantify the value being provided in return for the consumption of these resources. Without such a measure it is not possible to compare the efficiency of these components (that is whether the runtime cost is reasonable given the benefit being provided). We have created an empirical approach that measures the value being provided by a code path in terms of the visible data it generates for the rest of the application. Combining this with traditional performance cost data, creates an efficiency measure for every code path in the application. We have evaluated our approach using the DaCapo benchmark suite, demonstrating our analysis allows us to quantify the efficiency of the code in each benchmark and find real optimisation opportunities, providing improvements of up to 36% in our case studies. David Maplesden, Ewan D. Tempero, John G. Hosking, John C. Grundy |
ICPE | 4 |
| 2016 | The effect of software engineers' personality traits on team climate and performance: A Systematic Literature Review
Arjumand Bano Soomro, Norsaremah Salleh, Emilia Mendes, John C. Grundy, Giles St. J. Burch, Azlin Nordin |
Inf. Softw. Technol. | 4 |
| 2016 | Usage-based chunking of Software Architecture information to assist information finding
Moon Ting Su, John G. Hosking, John C. Grundy, Ewan D. Tempero |
J. Syst. Softw. | 3 |
| 2016 | A systematic mapping study of mobile application testing techniques
Samer Zein, Norsaremah Salleh, John C. Grundy |
J. Syst. Softw. | 3 |
| 2016 | Ontology-based automated support for goal-use case model analysis
Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
Softw. Qual. J. | 2 |
| 2015 | Providing Fairer Resource Allocation for Multi-tenant Cloud-Based SystemsabstractA fundamental premise in cloud computing is trying to provide a more sophisticated computing resource sharing capability. In order to provide better allocation, the Dominant Resource Fairness (DRF) approach has been developed to address the "fair resource allocation problem" at the application layer for multi-tenant cloud applications. Nevertheless conventional DRF only considers the interplay of CPU and memory, which may result in over allocation of resources to one tenant's application to the detriment of others. In this paper, we propose an improved DRF algorithm with 3-dimensional demand vector to support disk resources as the third dominant shared resource, enhancing fairer resource sharing. Our technique is integrated with LINUX 'group' controls resource utilisation and realises data isolation to avoid undesirable interactions between co-located tasks. Our method ensures all tenants receive system resources fairly, which improves overall utilisation and throughput as well as reducing traffic in an over-crowded system. We evaluate the performance of different types of workload using different algorithms and compare ours to the default algorithm. Results show an increase of 15% resource utilisation and a reduction of 59% completion time on average, indicating that our DRF algorithm provides a better, smoother, fairer high-performance resource allocation scheme for both continuous workloads and batch jobs. Jia Ru, John C. Grundy, Yun Yang 0001, Jacky W. Keung |
CloudCom | 2 |
| 2015 | A Preliminary Study of Open Learner Model Representation Formats to Support Formative AssessmentabstractOpen learner models provide a way of showing teachers and students the learning progress of a student against expectations. Creating an effective interface to present a learner model is an important part in open learner modeling. Usefulness of the learner model relies on using a clear and effective representation format to facilitate users' understanding of the information presented. In this paper, we propose a range of open learner model representation formats to display students' learning task status and achievement in terms of learning outcomes. We investigate different types of representation formats and data useful for users to inspect the learner model. An interface design prototype has been built to provide potential users with an evaluation platform that enables investigation of these aspects. The results obtained will allow us to develop a more effective new open learner model visualisation tool. Check Yee Law, John C. Grundy, Andrew Cain, Rajesh Vasa |
COMPSAC | 2 |
| 2015 | A framework for convergence of cloud services and Internet of thingsabstractToday, Cloud Computing and the Internet of things are two “major forces” that drive the development of new Information Technology (IT) solutions. Many Internet of things (IoT) based large-scale applications rely on a cloud platform for data processing and storage. However, big data generated or collected by large-scale geo-distributed devices needs to be transferred to the cloud, often becoming a bottleneck for the system. In this paper, we propose a framework that integrates popular cloud services with a network of IoT devices. In the framework, novel methods have been designed for reliable and efficient data transportation. This framework provides a convergence of cloud services and devices that will ease the development of IoT based, cloud-enabled applications. We have implemented a prototype of the framework to demonstrate the convergence of popular cloud services and IoT technologies. Dong Yuan 0001, Jiong Jin, John C. Grundy, Yun Yang 0001 |
CSCWD | 3 |
| 2015 | Model-Driven Engineering for the Social EnterpriseabstractSummary form only given. Model-driven engineering has gained popularity in recent years offering a way to abstractly specify complex computational models and algorithms and generate both configurations and code to achieve their realisation. Often domain-specific languages are used as way to express these model structures enabling end users to better specify their target system needs. We have been applying MDE and Domain-Specific Visual Languages (DSVLs) to the domain of Big Data analytics systems to better support end users in realising solutions for the enterprise as well as individual needs. In this talk I discuss key requirements of Big Data social enterprise systems, including those for health, transport and finance domains. I discuss approaches to utilising MDE and DSVLs to achieve desired solutions, including interface and architectures. I report on our and others progress to date and outline ways increasing personal and social data from the emerging Internet of Things with further transform this space. John C. Grundy |
EDOC | 1 |
| 2015 | Improving Tenants' Trust in SaaS Applications Using Dynamic Security MonitorsabstractIt is almost impossible to prove that a given software system achieves an absolute security level. This becomes more complicated when addressing multi-tenant cloud-based SaaS applications. Developing practical security properties and metrics to monitor, verify, and assess the behavior of such software systems is a feasible alternative to such problem. However, existing efforts focus either on verifying security properties or security metrics but not both. Moreover, they are either hard to adopt, in terms of usability, or require design-time preparation to support monitoring of such security metrics and properties which is not feasible for SaaS applications. In this paper, we introduce, to the best of our knowledge, the first unified monitoring platform that enables SaaS application tenants to specify, at run-time, security metrics and properties without design-time preparation and hence increases tenants' trust of their cloud-assets security. The platform automatically converts security metrics and properties specifications into security probes and integrates them with the target SaaS application at run-time. Probes-generated measurements are fed into an analysis component that verifies the specified properties and calculates security metrics' values using aggregation functions. This is then reported to SaaS tenants and cloud platform security engineers. We evaluated our platform expressiveness and usability, soundness, and performance overhead. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 2 |
| 2015 | Bootstrapping Mobile App DevelopmentabstractModern IDEs provide limited support for developers when starting a new data-driven mobile app. App developers are currently required to write copious amounts of boilerplate code, scripts, organise complex directories, and author actual functionality. Although this scenario is ripe for automation, current tools are yet to address it adequately. In this paper we present RAPPT, a tool that generates the scaffolding of a mobile app based on a high level description specified in a Domain Specific Language (DSL). We demonstrate the feasibility of our approach by an example case study and feedback from a professional development team. Demo at: https://www.youtube.com/watch?v=ffquVgBYpLM. Scott Barnett, Rajesh Vasa, John C. Grundy |
ICSE (2) | 3 |
| 2015 | StressCloud: A Tool for Analysing Performance and Energy Consumption of Cloud ApplicationsabstractFinding the best deployment configuration that maximises energy efficiency while guaranteeing system performance of cloud applications is an extremely challenging task. It requires the evaluation of system performance and energy consumption under a wide variety of realistic workloads and deployment configurations. This paper demonstrates StressCloud, an automatic performance and energy consumption analysis tool for cloud applications in real-world cloud environments. StressCloud supports 1) the modelling of realistic cloud application workloads, 2) the automatic generation and running of load tests, and 3) the profiling of system performance and energy consumption. Feifei Chen 0001, John C. Grundy, Jean-Guy Schneider, Yun Yang 0001, Qiang He 0001 |
ICSE (2) | 2 |
| 2015 | Performance Analysis Using Subsuming Methods: An Industrial Case StudyabstractLarge-scale object-oriented applications consist of tens of thousands of methods and exhibit highly complex runtime behaviour that is difficult to analyse for performance. Typical performance analysis approaches that aggregate performance measures in a method-centric manner result in thinly distributed costs and few easily identifiable optimisation opportunities. Subsuming methods analysis is a new approach that aggregates performance costs across repeated patterns of method calls that occur in the application's runtime behaviour. This allows automatic identification of patterns that are expensive and represent practical optimisation opportunities. To evaluate the practicality of this analysis with a real world large-scale object-oriented application we completed a case study with the developers of letterboxd.com - a social network website for movie goers. Using the results of the analysis we were able to rapidly implement changes resulting in a 54.8% reduction in CPU load and an 49.6% reduction in average response time. David Maplesden, Karl von Randow, Ewan D. Tempero, John G. Hosking, John C. Grundy |
ICSE (2) | 5 |
| 2015 | Experience report: Anomaly detection of cloud application operations using log and cloud metric correlation analysisabstractFailure of application operations is one of the main causes of system-wide outages in cloud environments. This particularly applies to DevOps operations, such as backup, redeployment, upgrade, customized scaling, and migration that are exposed to frequent interference from other concurrent operations, configuration changes, and resources failure. However, current practices fail to provide a reliable assurance of correct execution of these kinds of operations. In this paper, we present an approach to address this problem that adopts a regression-based analysis technique to find the correlation between an operation's activity logs and the operation activity's effect on cloud resources. The correlation model is then used to derive assertion specifications, which can be used for runtime verification of running operations and their impact on resources. We evaluated our proposed approach on Amazon EC2 with 22 rounds of rolling upgrade operations while other types of operations were running and random faults were injected. Our experiment shows that our approach successfully managed to raise alarms for 115 random injected faults, with a precision of 92.3%. Mostafa Farshchi, Jean-Guy Schneider, Ingo Weber, John C. Grundy |
ISSRE | 4 |
| 2015 | Integrating goal-oriented and use case-based requirements engineering: The missing linkabstractCombining goal-oriented and use case modeling has been shown as an effective method of requirements engineering. To ensure the quality of such modeled artifacts, a conceptual foundation is needed to govern the process of determining what types of artifacts to be modeled, and how they should be specified and analyzed for 3Cs problems (completeness, consistency and correctness). However, such a foundation is missing in current goal-use case integration approaches. In this paper, we present GUIMeta, a meta-model, to address this problem. GUIMeta consists of three layers. The artifact layer defines the semantics and classification of artifacts and their relationships. The specification layer offers specification rules for each artifact class. The ontology layer allows semantics to be integrated into the entire model. Our promising evaluation shows the suitability of GUIMeta in modeling goals and use cases. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
MoDELS | 2 |
| 2015 | Automating Performance and Energy Consumption Analysis for Cloud ApplicationsabstractIn cloud environments, IT solutions are delivered to users via shared infrastructure, enabling cloud service providers to deploy applications as services according to user QoS (Quality of Service) requirements. One consequence of this cloud model is the huge amount of energy consumption and significant carbon footprints caused by large cloud infrastructures. A key and common objective of cloud service providers is thus to develop cloud application deployment and management solutions with minimum energy consumption while guaranteeing performance and other QoS specified in Service Level Agreements (SLAs). However, finding the best deployment configuration that maximises energy efficiency while guaranteeing system performance is an extremely challenging task, which requires the evaluation of system performance and energy consumption under various workloads and deployment configurations. In order to simplify this process we have developed Stress Cloud, an automatic performance and energy consumption analysis tool for cloud applications in real-world cloud environments. Stress Cloud supports the modelling of realistic cloud application workloads, the automatic generation of load tests, and the profiling of system performance and energy consumption. We demonstrate the utility of Stress Cloud by analysing the performance and energy consumption of a cloud application under a broad range of different deployment configurations. Feifei Chen 0001, John C. Grundy, Jean-Guy Schneider, Yun Yang 0001, Qiang He 0001 |
SERVICES | 2 |
| 2015 | Rule-based extraction of goal-use case models from textabstractGoal and use case modeling has been recognized as a key approach for understanding and analyzing requirements. However, in practice, goals and use cases are often buried among other content in requirements specifications documents and written in unstructured styles. It is thus a time-consuming and error-prone process to identify such goals and use cases. In addition, having them embedded in natural language documents greatly limits the possibility of formally analyzing the requirements for problems. To address these issues, we have developed a novel rule-based approach to automatically extract goal and use case models from natural language requirements documents. Our approach is able to automatically categorize goals and ensure they are properly specified. We also provide automated semantic parameterization of artifact textual specifications to promote further analysis on the extracted goal-use case models. Our approach achieves 85% precision and 82% recall rates on average for model extraction and 88% accuracy for the automated parameterization. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
ESEC/SIGSOFT FSE | 2 |
| 2015 | Mobile Application Testing in Industrial Contexts: An Exploratory Multiple Case-Study
Samer Zein, Norsaremah Salleh, John C. Grundy |
SoMeT | 3 |
| 2015 | A multi-view framework for generating mobile appsabstractThis paper demonstrates a multi-view framework for Rapid APPlication Tool (RAPPT). RAPPT enables rapid development of mobile applications. It employs a multilevel approach to mobile application development: a Domain Specific Visual Language to define the high level structure of mobile apps, a Domain Specific Textual Language to define behavioural concepts, and concrete source code for fine grained improvements. Scott Barnett, Iman Avazpour, Rajesh Vasa, John C. Grundy |
VL/HCC | 4 |
| 2015 | Subsuming Methods: Finding New Optimisation Opportunities in Object-Oriented SoftwareabstractThe majority of existing application profiling techniques aggregate and report performance costs by method or calling context. Modern large-scale object-oriented applications consist of thousands of methods with complex calling patterns. Consequently, when profiled, their performance costs tend to be thinly distributed across many thousands of locations with few easily identifiable optimisation opportunities. David Maplesden, Ewan D. Tempero, John G. Hosking, John C. Grundy |
ICPE | 4 |
| 2015 | Generating Reusable Visual Notations Using Model TransformationabstractVisual notations are a key aspect of visual languages. They provide a direct mapping between the intended information and set of graphical symbols. Visual notations are most often implemented using the low level syntax of programming languages which is time consuming, error prone, difficult to maintain and hardly human-centric. In this paper we describe an alternative approach to generating visual notations using by-example model transformations. In our new approach, a semantic mapping between model and view is implemented using model transformations. The notations resulting from this approach can be reused by mapping varieties of input data to their model and can be composed into different visualizations. Our approach is implemented in the CONVErT framework and has been applied to many visualization examples. Three case studies for visualizing statistical charts, visualization of traffic data, and reuse of a Minard's map visualization's components, are presented in this paper. A detailed user study of our approach for reusing notations and generating visualizations has been provided. 80% of the participants in this user study agreed that the novel approach to visualization was easy and 87% stated that they quickly learned to use the tool support. Iman Avazpour, John C. Grundy, Hai Le Vu 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2015 | Performance Analysis for Object-Oriented Software: A Systematic MappingabstractPerformance is a crucial attribute for most software, making performance analysis an important software engineering task. The difficulty is that modern applications are challenging to analyse for performance. Many profiling techniques used in real-world software development struggle to provide useful results when applied to large-scale object-oriented applications. There is a substantial body of research into software performance generally but currently there exists no survey of this research that would help identify approaches useful for object-oriented software. To provide such a review we performed a systematic mapping study of empirical performance analysis approaches that are applicable to object-oriented software. Using keyword searches against leading software engineering research databases and manual searches of relevant venues we identified over 5,000 related articles published since January 2000. From these we systematically selected 253 applicable articles and categorised them according to ten facets that capture the intent, implementation and evaluation of the approaches. Our mapping study results allow us to highlight the main contributions of the existing literature and identify areas where there are interesting opportunities. We also find that, despite the research including approaches specifically aimed at object-oriented software, there are significant challenges in providing actionable feedback on the performance of large-scale object-oriented applications. David Maplesden, Ewan D. Tempero, John G. Hosking, John C. Grundy |
IEEE Trans. Software Eng. | 4 |
| 2014 | GUITAR: An ontology-based automated requirements analysis toolabstractCombining goal-oriented and use case modeling has been proven to be an effective method in requirements elicitation and elaboration. However, current requirements engineering approaches generally lack reliable support for automated analysis of such modeled artifacts. To address this problem, we have developed GUITAR, a tool which delivers automated detection of incorrectness, incompleteness and inconsistency between artifacts. GUITAR is based on our goal-use case integration meta-model and ontologies of domain knowledge and semantics. GUITAR also provides comprehensive explanations for detected problems and can suggest resolution alternatives. Tuong Huan Nguyen, John C. Grundy, Mohamed Almorsy |
RE | 2 |
| 2014 | Automatic Acceptance Test Case Generation From Essential Use CasesabstractRequirements validation is a crucial process to determine whether client-stakeholders' needs and expectations of a product are sufficiently correct and complete. Various requirements validation techniques have been used to evaluate the correctness and quality of requirements, but most of these techniques are tedious, expensive and time consuming. Accordingly, most project members are reluctant to invest their time and efforts in the requirements validation process. Moreover, automated tool supports that promote effective collaboration between the client-stakeholders and the engineers are still lacking. In this paper, we describe a novel approach that combines prototyping and test-based requirements techniques to improve the requirements validation process and promote better communication and collaboration between requirements engineers and client-stakeholders. To justify the potential of this prototype tool, we also present three types of evaluation conducted on the prototpye tool, which are the usability survey, 3-tool comparison analysis and expert reviews. Massila Kamalrudin, M. Nor Aiza, John C. Grundy, John G. Hosking, Mark Robinson |
SoMeT | 3 |
| 2014 | MEReq: A Tool to Capture and Validate Multi-Lingual RequirementsabstractWithin the era of globalisation that acknowledges differences and diversity, multiple languages have been increasingly used to capture requirements. This practice is particularly prevalent in Malaysia, where both Malay and English languages are used as a media of communication. Nevertheless, capturing requirements in multiple languages is often error-prone due to natural language imprecision being compounded by language differences. Considering that two languages may be used to describe requirements for the same system in different ways, we were motivated to develop MEReq, a tool which uses Essential Use Case (EUC) models to support capturing and checking the inconsistency occurring in English and Malay multi-lingual requirements. MEReq is tablet compatible to minimise time for on-site capture and validation of multi-lingual requirements. This paper describes the MEReq approach and demonstrates its use to capture and validate English and Malay requirements. Massila Kamalrudin, Safiah Sidek, Noorrezam Yusop, John C. Grundy, John G. Hosking |
SoMeT | 4 |
| 2014 | Generating Reusable Visual Notations using Model TransformationabstractVisual notations are a key aspect of visual languages. They provide a direct mapping between the intended information and set of graphical symbols. Visual notations are most often implemented using the low level syntax of programming languages which is time consuming, error prone, difficult to maintain and hardly human-centric. In this paper we describe an alternative approach to generating visual notations using by-example model transformations. In our new approach, a semantic mapping between model and view is implemented using model transformations. The notations resulting from this approach can be reused by mapping varieties of input data to their model and can be composed into different visualisations. Our approach is implemented in the CONVErT framework and has been applied to many visualisation examples. Two case studies for visualising statistical charts and visualisation of traffic data are presented in this paper. A detailed user study of our approach for reusing notations and generating visualisations has been provided that shows good reusability and general acceptance of the novel approach. Iman Avazpour, John C. Grundy, Hai Le Vu 0001 |
VINCI | 2 |
| 2014 | HorusCML: Context-aware domain-specific visual languages designerabstractThe objective behind building domain-specific visual languages (DSVLs) is to provide users with the most appropriate concepts and notations that best fit with their domain and experience. However, the existing DSVL designers do not support integrating environment and user context information when modeling, editing or viewing DSVL models at different locations, permissions, devices, etc. In this paper, we introduce HorusCML, a context-aware DSVL designer, which supports DSVL experts in integrating necessary context details within their DSVLs. The resultant DSVLs can reflect different facets, layouts, and behaviours according to context it is used in. We show a case study on developing a context-aware data flow diagram DSVL tool using HorusCML. Mohamed Almorsy, John C. Grundy, Ulf Rüegg |
VL/HCC | 2 |
| 2014 | Convert meets KIELER: Integrating advanced layout algorithms into by-example visualisationsabstractThe CONcrete Visual assistEd Transformation (CONVErT) framework provides facilities to generate reusable notations and compose them to form a wide variety of visualisations. With an increased number of notations in large scale visualisations, it is crucial to use advanced layout algorithms to improve understandability of such complex visualisations. This showpiece paper demonstrates how advanced layout algorithms can be integrated into the notation specifications of CONVErT to generate layouts of complex visualisations. Iman Avazpour, Ulf Rüegg, John C. Grundy |
VL/HCC | 3 |
| 2014 | An empirical study to review and revise job responsibilities of software testersabstractThe broad domain of software testing includes different job responsibilities such as creating test plans, devising and running a variety of tests, documenting results, to liaising between different development teams. In this paper, we attempt to collate a list of software testing job responsibilities by applying three different social research methodologies to collect information from different sources. We found that “test” specific responsibilities are divided into several unit tasks including test suite generation, execution of test plans, and so on. We also found that along with test specific responsibilities, software testers must perform a number of other tasks common to other IT professionals in order to carry out their roles. Tanjila Kanij, Robert G. Merkel, John C. Grundy |
VL/HCC | 3 |
| 2014 | Automated analysis of performance and energy consumption for cloud applicationsabstractIn cloud environments, IT solutions are delivered to users via shared infrastructure. One consequence of this model is that large cloud data centres consume large amounts of energy and produce significant carbon footprints. A key objective of cloud providers is thus to develop resource provisioning and management solutions at minimum energy consumption while still guaranteeing Service Level Agreements (SLAs). However, a thorough understanding of both system performance and energy consumption patterns in complex cloud systems is imperative to achieve a balance of energy efficiency and acceptable performance. In this paper, we present StressCloud, a performance and energy consumption analysis tool for cloud systems. StressCloud can automatically generate load tests and profile system performance and energy consumption data. Using StressCloud, we have conducted extensive experiments to profile and analyse system performance and energy consumption with different types and mixes of runtime tasks. We collected fine-grained energy consumption and performance data with different resource allocation strategies, system configurations and workloads. The experimental results show the correlation coefficients of energy consumption, system resource allocation strategies and workload, as well as the performance of the cloud applications. Our results can be used to guide the design and deployment of cloud applications to balance energy and performance requirements. Feifei Chen 0001, John C. Grundy, Jean-Guy Schneider, Yun Yang 0001, Qiang He 0001 |
ICPE | 2 |
| 2014 | Adaptable, model-driven security engineering for SaaS cloud-based applications
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
Autom. Softw. Eng. | 2 |
| 2014 | Guest editorial: automated techniques for migrating to the Cloud (I)
Ching-Hsien Hsu, John C. Grundy |
Autom. Softw. Eng. | 2 |
| 2014 | Guest editorial: automated techniques for migrating to the cloud (II)
Ching-Hsien Hsu, John C. Grundy |
Autom. Softw. Eng. | 2 |
| 2014 | Investigating the effects of personality traits on pair programming in a higher education setting through a family of experiments
Norsaremah Salleh, Emilia Mendes, John C. Grundy |
Empir. Softw. Eng. | 3 |
| 2014 | Performance appraisal of software testers
Tanjila Kanij, John C. Grundy, Robert G. Merkel |
Inf. Softw. Technol. | 2 |
| 2014 | KBRE: a framework for knowledge-based requirements engineering
Tuong Huan Nguyen, Quoc Bao Vo, Markus Lumpe, John C. Grundy |
Softw. Qual. J. | 4 |
| 2013 | An empirical study of the effects of personality on software testingabstractThe effectiveness of testing is a major determinant of software quality. It is believed that individual testers vary in their effectiveness, but so far the factors contributing to this variation have not been well studied. In this study, we examined whether personality traits, as described by the five-factor model, affect performance on a software testing task. ICT students were given a small software testing task at which their effectiveness was assessed using several different criteria, including bug location rate, weighted fault density, and bug report quality. Their personality was assessed using the NEO PI-3 personality questionnaire. We then compared testing performance according to individual and aggregate measures against different five-factor personality traits. Several weak correlations between two of these personality traits, extraversion and conscientiousness, and testing effectiveness were found. Tanjila Kanij, Robert G. Merkel, John C. Grundy |
CSEE&T | 3 |
| 2013 | A Preliminary User Evaluation of an Infrastructure to Support Activity-Based Computing in Global Software Development (ABC4GSD)abstractGlobal Software Engineering (GSE) teams face challenges due to the need to replace traditional physical presence interactions and co-ordination with computer-mediated means. A vast majority of the available tool support for distributed collaboration is deep-seated in a desktop metaphor introduced in the `70s, and huge efforts are being devoted to overcome its known limitations. Over the last few years we have looked into the feasibility of providing an approach based on Activity-Based Computing (ABC) to address these issues in a novel way. We have developed a middleware and support tool, ABC4GSD, to enable collaborative distributed features in an application, while maintaining common interactions with the workstation that users are accustomed to. In this paper we present the results of a user evaluation we conducted on ABC4GSD using exemplar GSE scenarios. Participants' responses show positive and encouraging reception of the activity-based approach to supporting GSE. Paolo Tell, Muhammad Ali Babar 0001, John C. Grundy |
ICGSE | 3 |
| 2013 | Automated software architecture security risk analysis using formalized signaturesabstractReviewing software system architecture to pinpoint potential security flaws before proceeding with system development is a critical milestone in secure software development lifecycles. This includes identifying possible attacks or threat scenarios that target the system and may result in breaching of system security. Additionally we may also assess the strength of the system and its security architecture using well-known security metrics such as system attack surface, Compartmentalization, least-privilege, etc. However, existing efforts are limited to specific, predefined security properties or scenarios that are checked either manually or using limited toolsets. We introduce a new approach to support architecture security analysis using security scenarios and metrics. Our approach is based on formalizing attack scenarios and security metrics signature specification using the Object Constraint Language (OCL). Using formal signatures we analyse a target system to locate signature matches (for attack scenarios), or to take measurements (for security metrics). New scenarios and metrics can be incorporated and calculated provided that a formal signature can be specified. Our approach supports defining security metrics and scenarios at architecture, design, and code levels. We have developed a prototype software system architecture security analysis tool. To the best of our knowledge this is the first extensible architecture security risk analysis tool that supports both metric-based and scenario-based architecture security analysis. We have validated our approach by using it to capture and evaluate signatures from the NIST security principals and attack scenarios defined in the CAPEC database. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICSE | 2 |
| 2013 | Tool support for automatic model transformation specification using concrete visualisationsabstractComplex model transformation is crucial in several domains, including Model-Driven Engineering (MDE), information visualisation and data mapping. Most current approaches use meta-model-driven transformation specification via coding in textual scripting languages. This paper demonstrates a novel approach and tool support that instead provides for specification of correspondences between models using concrete visualisations of source and target models, and generates transformation scripts from these by-example model correspondence specifications. Iman Avazpour, John C. Grundy, Lars Grunske |
ASE | 2 |
| 2013 | A suite of domain-specific visual languages for scientific software application modellingabstractMany advances in science now require sophisticated scientific software applications that facilitate data and computationally intensive experiments. However, the effective utilization of existing computational power e.g., grid and cloud platforms depends on the capabilities of scientists to implement parallel, scalable code for such experiments. Currently, tools aimed at supporting scientists are either very limited to specific domains, or require significant development using low-level code. We describe our work towards a more end user-friendly scientific applications development process, notations and toolset. We introduce a scientific application designer intended for use primarily by scientists to enable them in describing workflow, processes, entities, formulae, computation and ultimately realization code for different computing platforms. This is achieved via a set of integrated, domain-specific visual and textual languages (DSVLs). A Web-based modeling tool supports definition of new DSVLs and modeling of these applications. We are currently extending our tool to support generation of multi-core and GPU implementations, and visualization of results. Mohamed Almorsy, John C. Grundy, Richard J. Sadus, Willem van Straten, David G. Barnes, Owen Kaluza |
VL/HCC | 2 |
| 2013 | Using concrete visual notations as first class citizens for model transformation specificationabstractModel transformations are an important part of Model Driven Engineering (MDE). To generate a transformation with current MDE approaches, users are required to specify (or provide) complex meta-models and then engage in quite low-level coding in textual transformation scripting languages. This paper introduces a new approach to visualising source and target models that allows specifiers of complex data transformations to use the resultant visual notations for specifying transformations by example using drag and drop. We demonstrate the applicability of our new approach by an example case study. Iman Avazpour, John C. Grundy |
VL/HCC | 2 |
| 2013 | Experimental analysis of task-based energy consumption in cloud computing systemsabstractCloud computing delivers IT solutions as a utility to users. One consequence of this model is that large cloud data centres consume large amounts of energy and produce significant carbon footprints. A common objective of cloud providers is to develop resource provisioning and management solutions that minimise energy consumption while guaranteeing Service Level Agreements (SLAs). In order to achieve this objective, a thorough understanding of energy consumption patterns in complex cloud systems is imperative. We have developed an energy consumption model for cloud computing systems. To operationalise this model, we have conducted extensive experiments to profile the energy consumption in cloud computing systems based on three types of tasks: computation-intensive, data-intensive and communication-intensive tasks. We collected fine-grained energy consumption and performance data with varying system configurations and workloads. Our experimental results show the correlation coefficients of energy consumption, system configuration and workload, as well as system performance in cloud systems. These results can be used for designing energy consumption monitors, and static or dynamic system-level energy consumption optimisation strategies for green cloud computing systems. Feifei Chen 0001, John C. Grundy, Yun Yang 0001, Jean-Guy Schneider, Qiang He 0001 |
ICPE | 2 |
| 2013 | Guest editors introduction: special issue on innovative automated software engineering tools
John C. Grundy, John G. Hosking |
Autom. Softw. Eng. | 1 |
| 2013 | Guest editors introduction: special issue on innovative automated software engineering tools - part #2
John C. Grundy, John G. Hosking |
Autom. Softw. Eng. | 1 |
| 2013 | A Taxonomy and Mapping of Computer-Based Critiquing ToolsabstractCritics have emerged in recent times as a specific tool feature to support users in computer-mediated tasks. These computer-supported critics provide proactive guidelines or suggestions for improvement to designs, code, and other digital artifacts. The concept of a critic has been adopted in various domains, including medical, programming, software engineering, design sketching, and others. Critics have been shown to be an effective mechanism for providing feedback to users. We propose a new critic taxonomy based on extensive review of the critic literature. The groups and elements of our critic taxonomy are presented and explained collectively with examples, including the mapping of 13 existing critic tools, predominantly for software engineering and programming education tasks to the taxonomy. We believe this critic taxonomy will assist others in identifying, categorizing, developing, and deploying computer-supported critics in a range of domains. Norhayati Mohd. Ali, John G. Hosking, John C. Grundy |
IEEE Trans. Software Eng. | 3 |
| 2013 | Generating Domain-Specific Visual Language Tools from Abstract Visual SpecificationsabstractDomain-specific visual languages support high-level modeling for a wide range of application domains. However, building tools to support such languages is very challenging. We describe a set of key conceptual requirements for such tools and our approach to addressing these requirements, a set of visual language-based metatools. These support definition of metamodels, visual notations, views, modeling behaviors, design critics, and model transformations and provide a platform to realize target visual modeling tools. Extensions support collaborative work, human-centric tool interaction, and multiplatform deployment. We illustrate application of the metatoolset on tools developed with our approach. We describe tool developer and cognitive evaluations of our platform and our exemplar tools, and summarize key future research directions. John C. Grundy, John G. Hosking, Karen Na-Liu Li, Norhayati Mohd. Ali, Jun Huh, Richard Lei Li |
IEEE Trans. Software Eng. | 1 |
| 2012 | TOSSMA: A Tenant-Oriented SaaS Security Management ArchitectureabstractMulti-tenancy helps service providers to save costs, improve resource utilization, and reduce service customization and maintenance time by sharing of resources and services. On the other hand, supporting multi-tenancy adds more complexity to the shared application's required capabilities. Security is a key requirement that must be addressed when engineering new SaaS applications or when re-engineering existing applications to support multi-tenancy. Traditional security (re)engineering approaches do not fit with the multi-tenancy application model where tenants and their security requirements emerge after the system was first developed. Enabling, runtime, adaptable and tenant-oriented application security customization on single service instance is a key challenging security goal in multi-tenant application engineering. In this paper we introduce TOSSMA, a Tenant-Oriented SaaS Security Management Architecture. TOSSMA allows service providers to enable their tenants in defining, customizing and enforcing their security requirements without having to go back to application developers for maintenance or security customizations. TOSSMA supports security management for both new and existing systems. Service providers are not required to write security integration code to use a specific security platform or mechanism. In this paper, we describe details of our approach and architecture, our prototype implementation of TOSSMA, give a usage example of securing a multi-tenant SaaS, and discuss our evaluation experiments of TOSSMA. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 2 |
| 2012 | QoS-Driven Service Selection for Multi-tenant SaaSabstractCloud-based software applications (Software as a Service - SaaS) for multi-tenant provisioning have become a major development paradigm in Web engineering. Instead of serving a single end-user, a multi-tenant SaaS provides multiple end-users with the same functionality but with potentially different quality-of-service (QoS) values. The service selection for such a SaaS is a complex decision-making process which involves a number of stakeholders with different QoS requirements. SaaS developers need to compose services with different QoS values to meet end-users' different multidimensional QoS constraints for the SaaS. Furthermore, they also need to satisfy SaaS providers' optimisation goals for the SaaS, such as least resource cost and best system performance. Existing QoS-aware service selection approaches are oriented at a single tenant. They do not consider the characteristics of multi-tenant SaaS and hence are ineffective and inefficient when applied to compose multi-tenant SaaS. In this paper, we introduce a novel QoS-driven approach for helping SaaS developers select the services for composing multi-tenant SaaS, which achieves SaaS providers' optimisation goals while fulfilling the end-users' different levels of QoS constraints. The proposed approach is evaluated using an example SaaS synthetically generated based on a dataset of real-world Web services. Experimental results show that our approach significantly outperforms existing approaches in terms of both effectiveness and performance. Qiang He 0001, Jun Han 0004, Yun Yang 0001, John C. Grundy, Hai Jin 0001 |
IEEE CLOUD | 4 |
| 2012 | Supporting Virtualization-Aware Security Solutions Using a Systematic Approach to Overcome the Semantic GapabstractA prerequisite to implementing virtualization-aware security solutions is to solve the "semantic gap" problem. Current approaches require a deep knowledge of the kernel data to manually solve the semantic gap. However, kernel data is very complex; an Operating System (OS) kernel contains thousands of data structures that have direct and indirect (pointer) relations between each other with no explicit integrity constraints. This complexity makes it impractical to use manual methods. In this paper, we present a new solution to systematically and efficiently solve the semantic gap for any OS, without any prior knowledge of the OS. We present: (i) KDD, a tool that systematically builds a precise kernel data definition for any C-based OS such as Windows and Linux. KDD generates this definition by performing points-to analysis on the kernel's source code to disambiguate the pointer relations. (ii) SVA, a security appliance that solves the semantic gap based on the generated definition, to systematically and externally map the virtual machines' physical memory and extract the runtime dynamic objects. We have implemented prototypes for KDD and SVA, and have performed different experiments to prove their effectiveness. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
IEEE CLOUD | 3 |
| 2012 | SMURF: Supporting Multi-tenancy Using Re-aspects Framework
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ICECCS | 2 |
| 2012 | Supporting automated vulnerability analysis using formalized vulnerability signaturesabstractAdopting publicly accessible platforms such as cloud computing model to host IT systems has become a leading trend. Although this helps to minimize cost and increase availability and reachability of applications, it has serious implications on applications’ security. Hackers can easily exploit vulnerabilities in such publically accessible services. In addition to, 75% of the total reported application vulnerabilities are web application specific. Identifying such known vulnerabilities as well as newly discovered vulnerabilities is a key challenging security requirement. However, existing vulnerability analysis tools cover no more than 47% of the known vulnerabilities. We introduce a new solution that supports automated vulnerability analysis using formalized vulnerability signatures. Instead of depending on formal methods to locate vulnerability instances where analyzers have to be developed to locate specific vulnerabilities, our approach incorporates a formal vulnerability signature described using OCL. Using this formal signature, we perform program analysis of the target system to locate signature matches (i.e. signs of possible vulnerabilities). A newly–discovered vulnerability can be easily identified in a target program provided that a formal signature for it exists. We have developed a prototype static vulnerability analysis tool based on our formalized vulnerability signatures specification approach. We have validated our approach in capturing signatures of the OWSAP Top10 vulnerabilities and applied these signatures in analyzing a set of seven benchmark applications. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 2 |
| 2012 | Supporting automated software re-engineering using re-aspectsabstractSystem maintenance, including omitting an existing system feature e.g. buggy or vulnerable code, or modifying existing features, e.g. replacing them, is still very challenging. To address this problem we introduce the “re-aspect” (re-engineering aspect), inspired from traditional AOP. A re-aspect captures system modification details including signatures of entities to be updated; actions to apply including remove, modify, replace, or inject new code; and code to apply. Re-aspects locate entities to update, entities that will be impacted by the given update, and finally propagate changes on the system source code. We have applied our re-aspects technique to the security re-engineering problem and evaluated it on a set of open source .NET applications to demonstrate its usefulness. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
ASE | 2 |
| 2012 | Supporting operating system kernel data disambiguation using points-to analysisabstractGeneric pointers scattered around operating system (OS) kernels make the kernel data layout ambiguous. This limits current kernel integrity checking research to covering a small fraction of kernel data. Hence, there is a great need to obtain an accurate kernel data definition that resolves generic pointer ambiguities, in order to formulate a set of constraints between structures to support precise integrity checking. In this paper, we present KDD, a new tool for systematically generating a sound kernel data definition for any C-based OS e.g. Windows and Linux, without any prior knowledge of the kernel data layout. KDD performs static points-to analysis on the kernel’s source code to infer the appropriate candidate types for generic pointers. We implemented a prototype of KDD and evaluated it to prove its scalability and effectiveness. Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
ASE | 2 |
| 2012 | MaramaAI: tool support for capturing and managing consistency of multi-lingual requirementsabstractRequirements captured by Requirements Engineers are commonly inconsistent with their client’s intended requirements and are often error prone especially if the requirements are written in multiple languages. We demonstrate the use of our automated inconsistency-checking tool MaramaAI to capture and manage the consistency of multi-lingual requirements in both the English and Malay languages for requirements engineers and clients using a round-trip, rapid prototyping approach. Massila Kamalrudin, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2012 | REInDetector: a framework for knowledge-based requirements engineeringabstractRequirements engineering (RE) is a coordinated effort to allow clients, users, and software engineers to jointly formulate assumptions, constraints, and goals about a software solution. However, one of the most challenging aspects of RE is the detection of inconsistencies between requirements. To address this issue, we have developed REInDetector, a knowledge-based requirements engineering tool, supporting automatic detection of a range of inconsistencies. It provides facilities to elicit, structure, and manage requirements with distinguished capabilities for capturing the domain knowledge and the semantics of requirements. This permits an automatic analysis of both consistency and realizability of requirements. REInDetector finds implicit consequences of explicit requirements and offers all stakeholders an additional means to identify problems in a more timely fashion than existing RE tools. In this paper, we describe the Description Logic used to capture requirements, the REInDetector tool, its support for inconsistency detection, and its efficacy as applied to several RE examples. An important feature of REInDetector is also its ability to generate comprehensive explanations to provide more insights into the detected inconsistencies. Tuong Huan Nguyen, Quoc Bao Vo, Markus Lumpe, John C. Grundy |
ASE | 4 |
| 2012 | Operating System Kernel Data Disambiguation to Support Security Analysis
Amani S. Ibrahim, John C. Grundy, James H. Hamlyn-Harris, Mohamed Almorsy |
NSS | 2 |
| 2012 | Identifying OS Kernel Objects for Run-Time Security Analysis
Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 3 |
| 2012 | CONVErT: A framework for complex model visualisation and transformationabstractModel Driven Engineering (MDE) has become a commonly used approach in software engineering. It promotes using models as primary artefacts and proposes methods for transforming them to desired software products. However, the specification of models and their transformations in MDE with current techniques is not user-friendly, due to excessive use of high level abstract models and textual representation of transformation languages. This paper briefly describes CONVErT, an approach and tool developed for user-centric transformation generation using concrete model visualisations. Iman Avazpour, John C. Grundy |
VL/HCC | 2 |
| 2012 | Visualizing traceability links between source code and documentationabstractIt is well recognized that visualizing traceability links between software artifacts helps developers to recover, browse, and maintain these inter-relationships effectively and efficiently. However, it is a major challenge for researchers to efficiently visualize traceability links for big software systems because of scalability and visual clutter issues. In this paper we present a new approach that combines treemap and hierarchical tree visualization techniques to provide a global structure of traces and a detailed overview of each trace. These both reduce visual clutter while still being highly scalable and interactive. Our usability study shows that our approach can support comprehension, browsing, and maintenance of traceability links. John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2012 | Supporting requirements modelling in the Malay language using essential use casesabstractRequirements are typically modelled in natural language, leading to inconsistencies, incompleteness and incorrectness due to inherent natural language ambiguities and lack of precise modelling rules. In previous work, we developed a technique and toolset to support extraction of requirements from English text and supporting semi-formal modelling and roundtrip refinement using Essential use cases, helping to mitigate some of these problems. In this paper we describe new work applying this human-centric approach to requirements engineering to the Malay language. We describe an extension of our original Essential Use Cases toolset to support requirements modelling in the Malay language essential interaction modelling, and results of a preliminary experiment to gauge our tool's effectiveness in supporting Malay natural language extraction and round-trip requirements refinement. Massila Kamalrudin, John C. Grundy, John G. Hosking |
VL/HCC | 2 |
| 2012 | VAM-aaS: Online Cloud Services Security Vulnerability Analysis and Mitigation-as-a-Service
Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
WISE | 2 |
| 2011 | Collaboration-Based Cloud Computing Security Management FrameworkabstractAlthough the cloud computing model is considered to be a very promising internet-based computing platform, it results in a loss of security control over the cloud-hosted assets. This is due to the outsourcing of enterprise IT assets hosted on third-party cloud computing platforms. Moreover, the lack of security constraints in the Service Level Agreements between the cloud providers and consumers results in a loss of trust as well. Obtaining a security certificate such as ISO 27000 or NIST-FISMA would help cloud providers improve consumers trust in their cloud platforms' security. However, such standards are still far from covering the full complexity of the cloud computing model. We introduce a new cloud security management framework based on aligning the FISMA standard to fit with the cloud computing model, enabling cloud providers and consumers to be security certified. Our framework is based on improving collaboration between cloud providers, service providers and service consumers in managing the security of the cloud platform and the hosted services. It is built on top of a number of security standards that assist in automating the security management process. We have developed a proof of concept of our framework using. NET and deployed it on a test bed cloud platform. We evaluated the framework by managing the security of a multi-tenant SaaS application exemplar. Mohamed Almorsy, John C. Grundy, Amani S. Ibrahim |
IEEE CLOUD | 2 |
| 2011 | The effects of openness to experience on pair programming in a higher education contextabstractThis paper describes a formal experiment carried out to investigate the effect of the personality factor Openness to experience on the academic performance of students who practiced pair programming (PP) in higher education. The experiment was carried out at the University of Auckland, using as subjects undergraduate students attending an introductory software programming course. Our results showed that differences in Openness level could significantly affect academic performance of students who pair programmed. In addition, our results also showed that most students gained higher satisfaction from the PP experience and their confidence level in solving programming exercises was also high. Norsaremah Salleh, Emilia Mendes, John C. Grundy |
CSEE&T | 3 |
| 2011 | A Preliminary Study on Factors Affecting Software Testing Team PerformanceabstractWith the growth of the software testing industry, many in-house testing groups and outsourcing testing companies have been established. Underlying the success of these testing groups and companies are team(s) of testers. This research investigates the importance of different factors, diversity and experience on building a successful testing team. We collected the opinions of testing practitioners on these factors via a survey. The outcome strongly indicates the relative importance of different factors and that diversity is helpful for a testing team. The results also support the importance of suitable team experience. Tanjila Kanij, Robert G. Merkel, John C. Grundy |
ESEM | 3 |
| 2011 | A combination approach for enhancing automated traceabilityabstractTracking a variety of traceability links between artifacts assists software developers in comprehension, efficient development, and effective management of a system. Traceability systems to date based on various Information Retrieval (IR) techniques have been faced with a major open research challenge: how to extract these links with both high precision and high recall. In this paper we describe an experimental approach that combines Regular Expression, Key Phrases, and Clustering with IR techniques to enhance the performance of IR for traceability link recovery between documents and source code. Our preliminary experimental results show that our combination technique improves the performance of IR, increases the precision of retrieved links, and recovers more true links than IR alone. John G. Hosking, John C. Grundy |
ICSE | 3 |
| 2011 | Improving requirements quality using essential use case interaction patternsabstractRequirements specifications need to be checked against the 3C's - Consistency, Completeness and Correctness - in order to achieve high quality. This is especially difficult when working with both natural language requirements and associated semi-formal modelling representations. We describe a technique and support tool that allows us to perform semi-automated checking of natural language and semi-formal requirements models, supporting both consistency management between representations but also correctness and completeness analysis. We use a concept of essential use case interaction patterns to perform the correctness and completeness analysis on the semi-formal representation. We highlight potential inconsistencies, incompleteness and incorrectness using visual differencing in our support tool. We have evaluated our approach via an end user study which focused on the tool's usefulness, ease of use, ease of learning and user satisfaction and provided data for cognitive dimensions of notations analysis of the tool. Massila Kamalrudin, John G. Hosking, John C. Grundy |
ICSE | 3 |
| 2011 | Workshop on flexible modeling tools: (FlexiTools 2011)abstractModeling tools are often not used for tasks during the software lifecycle for which they should be more helpful; instead free-from approaches, such as office tools and white boards, are frequently used. Prior workshops explored why this is the case and what might be done about it. The goal of this workshop is to continue those discussions and also to form an initial set of challenge problems and research challenges that researchers and developers of flexible modeling tools should address. Harold Ossher, André van der Hoek, Margaret-Anne D. Storey, John C. Grundy, Rachel K. E. Bellamy, Marian Petre |
ICSE | 4 |
| 2011 | Improving automated documentation to code traceability by combining retrieval techniquesabstractDocumentation written in natural language and source code are two of the major artifacts of a software system. Tracking a variety of traceability links between software documentation and source code assists software developers in comprehension, efficient development, and effective management of a system. Automated traceability systems to date have been faced with a major open research challenge: how to extract these links with both high precision and high recall. In this paper we introduce an approach that combines three supporting techniques, Regular Expression, Key Phrases, and Clustering, with a Vector Space Model (VSM) to improve the performance of automated traceability between documents and source code. This combination approach takes advantage of strengths of the three techniques to ameliorate limitations of VSM. Four case studies have been used to evaluate our combined technique approach. Experimental results indicate that our approach improves the performance of VSM, increases the precision of retrieved links, and recovers more true links than VSM alone. John C. Grundy |
ASE | 2 |
| 2011 | Generating essential user interface prototypes to validate requirementsabstractRequirements need to be validated at an early stage of analysis to address inconsistency and incompleteness issues. Capturing requirements usually involves natural language analysis, which is often imprecise and error prone, or translation into formal models, which are difficult for non-technical stakeholders to understand and use. Users often best understand proposed software systems from the likely user interface they will present. To this end we describe novel automated tool support for capturing requirements as Essential Use Cases and translating these into “Essential User Interface” low-fidelity rapid prototypes. We describe our automated tool supporting requirements capture, lo-fi user interface prototype generation and consistency management. Massila Kamalrudin, John C. Grundy |
ASE | 2 |
| 2011 | CloudSec: A security monitoring appliance for Virtual Machines in the IaaS cloud modelabstractThe Infrastructure-as-a-Service (IaaS) cloud computing model has become a compelling computing solution with a proven ability to reduce costs and improve resource efficiency. Virtualization has a key role in supporting the IaaS model. However, virtualization also makes it a target for potent rootkits because of the loss of control problem over the hosted Virtual Machines (VMs). This makes traditional in-guest security solutions, relying on operating system kernel trustworthiness, no longer an effective solution to secure the virtual infrastructure of the IaaS model. In this paper, we explore briefly the security problem of the IaaS cloud computing model, and present CloudSec, a new virtualization-aware monitoring appliance that provides active, transparent and real-time security monitoring for hosted VMs in the IaaS model. CloudSec utilizes virtual machine introspection techniques to provide fine-grained inspection of VM's physical memory without installing any monitoring code inside the VM. It actively reconstructs and monitors the dynamically changing kernel data structures instances, as a prior step to enable providing protection for kernel data structures. We have implemented a proof-of-concept prototype using VMsafe libraries on a VMware ESX platform. We have evaluated the system monitoring accuracy and the performance overhead of CloudSec. Amani S. Ibrahim, James H. Hamlyn-Harris, John C. Grundy, Mohamed Almorsy |
NSS | 3 |
| 2011 | Automatic diagram layout support for the Marama meta-toolsetabstractAutomatic layout can be a crucial support feature for complex diagramming tools. Adding suitable layout algorithms to diagramming tools is a complex task and meta-tools should incorporate these for reuse. We present MaramaALM, a generalised set of automatic layout mechanisms. This has been incorporated in the Eclipse-based Marama meta-toolset to support automatic layout in Marama diagrams. It provides an easy-to-use mechanism for tool developers to add such layouts to their generated tools. We describe our motivation for MaramaALM, our approach to its implementation and an example case study of using these tool extensions. Pei Shan Yap, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2011 | Capturing Architecture Documentation Navigation Trails for Content Chunking and SharingabstractNavigating and understanding complex software architecture documentation is often challenging. To support finding relevant information in architecture documents (ADs), we propose a semi-automated approach based on the actual usage of ADs by previous users, i.e. by capturing users' exploration paths through ADs and making these paths available for future retracing and analysis. To do this, we have built a prototype tool (KaitoroCap) that captures users' AD exploration paths and saves them with contextual metadata. KaitoroCap displays the exploration paths in hierarchical tree views and these exploration paths can be searched. This is helpful for recalling previous navigations and to follow others' useful paths in finding relevant information in AD. Our approach also enables dynamic restructuring of ADs and incorporates user rating, tagging and commenting of the content of ADs. Initial user evaluation shows promising results. Moon Ting Su, John G. Hosking, John C. Grundy |
WICSA | 3 |
| 2011 | KaitoroCap: A Document Navigation Capture and Visualisation ToolabstractTo facilitate the usage of software architecture documents (ADs), we claim the architectural information in the ADs needs to be structured into or presented as chunks. A chunk allows related information to be retrieved collectively as a unit and simplifies information location tasks. We propose a new semi-automated approach based on the actual usage of ADs by previous users, i.e. by capturing users' exploration paths through ADs while engaging in information seeking tasks and making these paths available for future retracing and analysis. As part of our work, we developed KaitoroCap, a document navigation capture and visualisation tool. Its main features are exploration paths capture, retrieval, analysis, hierarchical tree-view visualization of paths, path searching, section rating, tagging, commenting, expanding/collapsing and page model generation to enable dynamic restructuring of ADs. This paper describes the design, implementation and usage examples of KaitoroCap. Moon Ting Su, John G. Hosking, John C. Grundy |
WICSA | 3 |
| 2011 | Using data mining for digital ink recognition: Dividing text and shapes in sketched diagrams
Rachel Blagojevic, Beryl Plimmer, John C. Grundy, Yong Wang 0049 |
Comput. Graph. | 3 |
| 2011 | Empirical Studies of Pair Programming for CS/SE Teaching in Higher Education: A Systematic Literature ReviewabstractThe objective of this paper is to present the current evidence relative to the effectiveness of pair programming (PP) as a pedagogical tool in higher education CS/SE courses. We performed a systematic literature review (SLR) of empirical studies that investigated factors affecting the effectiveness of PP for CS/SE students and studies that measured the effectiveness of PP for CS/SE students. Seventy-four papers were used in our synthesis of evidence, and 14 compatibility factors that can potentially affect PP's effectiveness as a pedagogical tool were identified. Results showed that students' skill level was the factor that affected PP's effectiveness the most. The most common measure used to gauge PP's effectiveness was time spent on programming. In addition, students' satisfaction when using PP was overall higher than when working solo. Our meta-analyses showed that PP was effective in improving students' grades on assignments. Finally, in the studies that used quality as a measure of effectiveness, the number of test cases succeeded, academic performance, and expert opinion were the quality measures mostly applied. The results of this SLR show two clear gaps in this research field: 1) a lack of studies focusing on pair compatibility factors aimed at making PP an effective pedagogical tool and 2) a lack of studies investigating PP for software design/modeling tasks in conjunction with programming tasks. Norsaremah Salleh, Emilia Mendes, John C. Grundy |
IEEE Trans. Software Eng. | 3 |
| 2010 | Managing Consistency between Textual Requirements, Abstract Interactions and Essential Use CasesabstractConsistency checking needs to be done from the earliest phase of requirements capture as requirements captured by requirement engineers are often vague, error-prone and inconsistent with users' needs. To improve such consistency checking we have applied a traceability approach with visualization capability. We have embedded this into a light-weight automated tracing tool in order to allow users to capture their requirements and generate Essential Use Case models of these requirements automatically. Our tool supports inconsistency checking between textual requirements, abstract interactions that derive from the text and Essential Use Case models. A preliminary evaluation has been conducted with target end users and the tool usefulness and ease of use are evaluated. We describe our motivation for this research, our prototype tool and results of our evaluation. Massila Kamalrudin, John C. Grundy, John G. Hosking |
COMPSAC | 2 |
| 2010 | The effects of neuroticism on pair programming: an empirical study in the higher education contextabstractThis paper reports on an empirical study that investigates the effects of the personality trait of neuroticism on the academic performance of students who practiced pair programming during one academic semester. The experiment was conducted at The University of Auckland involving 270 first year undergraduate students enrolled in an introductory programming course. In this study, we hypothesized that neuroticism or lack of 'emotional stability' potentially affects pair students' academic performance. However, from the analysis of our results we found lack of evidence to support this. A correlation analysis showed significant positive associations between the conscientiousness personality trait and almost all performance criteria, thus corroborating evidence reported in the educational psychology literature. Norsaremah Salleh, Emilia Mendes, John C. Grundy, Giles St. J. Burch |
ESEM | 3 |
| 2010 | Flexible Modeling Tools (FlexiTools2010)abstractModeling tools are often not used for tasks during the software lifecycle for which they should be helpful; more free-from approaches, such as office tools and white boards, are frequently used instead. Why is this? What might be done to make modeling tools more suitable? What key research challenges must be overcome to achieve this? The goal of this workshop is to bring together people who understand the activities and needs of developers and other stakeholders throughout the software lifecycle, user interface design and tool infrastructure to explore these questions. Harold Ossher, André van der Hoek, Margaret-Anne D. Storey, John C. Grundy, Rachel K. E. Bellamy |
ICSE (2) | 4 |
| 2010 | An empirical study of the effects of conscientiousness in pair programming using the five-factor personality modelabstractThis paper describes a formal experiment carried out to investigate the effect of the Personality factor conscientiousness on the effectiveness of Pair Programming as a pedagogical tool in higher Education. This experiment took place at the University of Auckland, using as subjects undergraduate students attending an introductory programming course. Conscientiousness was chosen because it has been shown to be the most consistent predictor of academic achievement. Our findings showed that differences in conscientiousness level did not significantly affect the academic performance of students who pair programmed, which could have been due to the short duration of the tasks used throughout the experiment. However, results revealed that another Personality factor - Openness to experience - presented a significant correlation with paired students' academic performance. Norsaremah Salleh, Emilia Mendes, John C. Grundy, Giles St. J. Burch |
ICSE (1) | 3 |
| 2010 | Building Digital Ink Recognizers Using Data Mining: Distinguishing between Text and Shapes in Hand Drawn Diagrams
Rachel Blagojevic, Beryl Plimmer, John C. Grundy, Yong Wang 0049 |
IEA/AIE (1) | 3 |
| 2010 | End-user oriented critic specification for domain-specific visual language toolsabstractThis paper presents a new approach to specifying critics for domain-specific visual language tools using a visual and template-based approach. In this paper we describe our approach for specifying critics for domain-specific visual language tools. This allows target end-user tool developers to design and implement critics efficiently in a natural manner. We describe a survey that we conducted to evaluate our new approach and the Cognitive Dimensions approach that was applied in the survey questionnaire design. Survey results are briefly discussed along with the issues raised by some respondents to improve our approach. Norhayati Mohd. Ali, John G. Hosking, John C. Grundy, Jun Huh |
ASE | 3 |
| 2010 | VikiBuilder: end-user specification and generation of visual wikisabstractWith the need to make sense out of large and constantly growing information spaces, tools to support information management are becoming increasingly valuable. In prior work we proposed the "Visual Wiki" concept to describe and implement web-based information management applications. By focusing on the integration of two promising approaches, visualizations and collaboration tools, our Visual Wiki work explored synergies and demonstrated the value of the concept. Building on this, we introduce "VikiBuilder", a Visual Wiki meta-tool, which provides end-user supported modeling and automatic generation of Visual Wiki instances. We describe the design and implementation of the VikiBuilder including its architecture, a domain specific visual language for modeling Visual Wikis, and automatic generation of those. To demonstrate the utility of the tool, we have used it to construct a variety of different Visual Wikis. We describe the construction of Visual Wikis and discuss the strengths and weaknesses of our meta-tool approach. Christian Hirsch, John G. Hosking, John C. Grundy |
ASE | 3 |
| 2010 | Tool support for essential use cases to better capture software requirementsabstractCapturing software requirements from clients often leads to error prone and vague requirements documents. To surmount this issue, requirements engineers often choose to use UML models to capture their requirements. In this paper we discuss the use of Essential Use Cases (EUCs) as an alternative, user-centric representation which was developed to ease the process of capturing and describing requirements. However, EUCs are not commonly used in practice because, to our knowledge, no suitable tool support has been developed. In addition, requirements engineers face difficulties in finding the correct 'essential' requirements (abstract interactions) in a time efficient manner. In order to overcome these problems, we have developed a prototype tool for automated tracing of abstract interactions. We describe the tool and compare the performance and correctness of the results provided by it to that of manual essential use case extraction efforts by a group of requirements engineers. The results of an end user study of the tool's usefulness and ease of use are also discussed. Massila Kamalrudin, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2010 | MaramaAI: Automated and Visual Approach for Inconsistency Checking of RequirementsabstractRequirements are commonly vague and ambiguous. In this paper, we describe an automated Inconsistency Checker called MaramaAI for checking for high-level inconsistency between textual requirements, abstract interactions and Essential Use Cases. We use concepts of phrase extraction and essential interaction patterns to carry out these checks. We provide further support for checking of requirements quality attributes such as completeness and correctness using visual differencing. Massila Kamalrudin, John G. Hosking, John C. Grundy |
RE | 3 |
| 2010 | Design of a Suite of Visual Languages for Supply Chain SpecificationabstractSupply chain modelling and simulation by SMEs (Small-to-Medium Enterprises) is a challenging problem. This is due both to complexity of the supply chain models required and the lack of required expertise among the SMEs. The problem is important since SMEs need to represent and modify their evolving skills and processes to be visible in electronic marketplaces and supply chain design platforms. We demonstrate how this problem can be addressed by developing a suite of novel domain-specific visual languages and a support tool. The challenging setup of our research context motivated us to trial a new approach for the design of our visual languages and to employ a collaborative development process across our distributed research team. Rick Zhang, John G. Hosking, John C. Grundy, Nikolay Mehandjiev, Martin Carpenter |
VL/HCC | 3 |
| 2009 | An empirical study of the effects of personality in pair programming using the five-factor modelabstractPair Programming (PP) has been long researched in industry and academia. Although research evidence about its usefulness is somewhat inconclusive, previous studies showed that its use in an academic environment can benefit students in programming and design courses. In our study, we investigated the ldquohumanrdquo aspect of PP; in particular the effects that personality attributes may have on PP's effectiveness as a pedagogical tool. We conducted a formal experiment at the University of Auckland to investigate the influence of personality differences among paired students using the five-factor model as a personality measurement framework. The aim of our study was to improve the implementation of PP as a pedagogical tool through understanding the impact the variation in the personality profile of paired students has towards their academic performance. Our findings showed that differences in personality traits did not significantly affect the academic performance of students who pair programmed. Norsaremah Salleh, Emilia Mendes, John C. Grundy, Giles St. J. Burch |
ESEM | 3 |
| 2009 | A domain-specific visual language for report writing using Microsoft DSL toolsabstractMany domain specific textual languages have been developed for generating complex reports. These are challenging for novice users to learn, understand and use. We describe our work developing the prototype of a new visual language tool for a company to augment their textual report writing language. We describe key motivations for our visual language tool solution, its architecture, design and development using Microsoft DSL tools, and its evaluation by end-users. Ruskin Dantra, John C. Grundy, John G. Hosking |
VL/HCC | 2 |
| 2009 | Template-based critic authoring for domain-specific visual language toolsabstractIn recent years, there has been an increasing interest in using computer-based ldquocritic toolsrdquo for supporting the end-users or tool designers in analyzing and proactively improving their design artifacts. Several approaches have been applied to designing and realizing such critics, for example rule-based, pattern-matching and knowledge-based approaches. While many studies have found evidence that critic tools are an efficient feedback-providing mechanism, there is still insufficient knowledge about how to provide an effective critic authoring environment. In this paper we apply a business rule template approach as a mechanism to specify and realize critics for Marama-based domain-specific visual language tools. We describe a visual design critic authoring template approach that supports end-users or tool designers in the construction of critics for any Marama-based tools. Norhayati Mohd. Ali, John G. Hosking, Jun Huh, John C. Grundy |
VL/HCC | 4 |
| 2008 | Marama: an eclipse meta-toolset for generating multi-view environmentsabstractWe describe the Marama suite of meta-tools. This Eclipse-based toolset permits rapid specification of notational elements, meta-models, view editors and view-model mappings. It has a novel set of behavioural specification tools for both visual and model level behaviours. An integrated mapping tool provides model transformation and code generation support. The toolset has been applied to several significant application development tasks and has undergone a variety of evaluations. John C. Grundy, John G. Hosking, Jun Huh, Karen Na-Liu Li |
ICSE | 1 |
| 2008 | Model-Driven Development of Mobile Personal Health Care ApplicationsabstractPersonal health care applications on mobile devices allow patients to enhance their health via reminders, monitoring and feedback to health care providers. Engineering such applications is challenging with a need for health care plan meta-models, per-patient instantiation of care plans, and development and deployment of supporting Web and mobile device applications. We describe a novel prototype environment for visually modelling health care plans and automated plan and mobile device application code generation. Abizer Khambati, John C. Grundy, James R. Warren, John G. Hosking |
ASE | 2 |
| 2008 | MaramaEML: An Integrated Multi-View Business Process Modelling Environment with Tree-Overlays, Zoomable Interfaces and Code GenerationabstractMaramaEML is an integrated support tool for the enterprise modelling language (EML) built using the Eclipse based Marama framework. It provides support for multiple visual notations including: the business process modelling notation (BPMN); the EML tree- based, multi-layer hierarchical service representation; fisheye zooming capabilities; automatic BPEL code generation; and inter-notation mapping. Richard Lei Li, John G. Hosking, John C. Grundy |
ASE | 3 |
| 2008 | Development of techniques for sketched diagram recognitionabstractThe focus of this research is to develop general diagram recognition techniques based on quantitative experiments using machine learning to determine the most significant ink features and effective algorithms for use throughout the recognition process. This should improve on existing recognition success rates. Rachel Blagojevic, Beryl Plimmer, John C. Grundy, Yong Wang 0049 |
VL/HCC | 3 |
| 2008 | A domain specific visual language for design and coordination of supply networksabstractWe have developed a domain specific visual language (DSVL) and environment to support the modeling of small business-based dynamic supply networks. We describe our approach to the design of the DSVL, challenges faced, the implementation of a prototype environment, and preliminary evaluation. John G. Hosking, Nikolay Mehandjiev, John C. Grundy |
VL/HCC | 3 |
| 2008 | Introduction to the Special Issue
John C. Grundy, Jun Han 0004 |
J. Syst. Softw. | 1 |
| 2008 | SUMLOW: early design-stage sketching of UML diagrams on an E-whiteboardabstractAbstract Most visual diagramming tools provide point‐and‐click construction of computer‐drawn diagram elements using a conventional desktop computer and mouse. SUMLOW is a unified modelling language (UML) diagramming tool that uses an electronic whiteboard (E‐whiteboard) and sketching‐based user interface to support collaborative software design. SUMLOW allows designers to sketch UML constructs, mixing different UML diagram elements, diagram annotations, and hand‐drawn text. A key novelty of the tool is the preservation of hand‐drawn diagrams and support for manipulation of these sketches using pen‐based actions. Sketched diagrams can be automatically ‘formalized’ into computer‐recognized and ‐drawn UML diagrams and then exported to a third party CASE tool for further extension and use. We describe the motivation for SUMLOW, illustrate the use of the tool to sketch various UML diagram types, describe its key architecture abstractions and implementation approaches, and report on two evaluations of the toolset. We hope that our experiences will be useful for others developing sketching‐based design tools or those looking to leverage pen‐based interfaces in software applications. Copyright © 2007 John Wiley & Sons, Ltd. John C. Grundy, John G. Hosking |
Softw. Pract. Exp. | 2 |
| 2007 | Supporting Generic Sketching-Based Input of Diagrams in a Domain-Specific Visual Language Meta-ToolabstractSoftware engineers often use hand-drawn diagrams as preliminary design artefacts and as annotations during reviews. We describe the addition of sketching support to a domain-specific visual language meta-tool enabling a wide range of diagram-based design tools to leverage this human-centric interaction support. Our approach allows visual design tools generated from high-level specifications to incorporate a range of sketching-based functionality including both eager and lazy recognition, moving from sketch to formalized content and back and using sketches for secondary annotation and collaborative design review. We illustrate the use of our sketching extension for an example domain-specific visual design tool and describe the architecture and implementation of the extension as a plug-in for our Eclipse-based meta-tool. John C. Grundy, John G. Hosking |
ICSE | 1 |
| 2007 | Synthesizing client load models for performance engineering via web crawlingabstractAccurate web application performance testing relies on the use of loading tests based on a realistic client behaviour load model. Unfortunately developing such load models and associated test plans and scripts is tedious and error-prone with most existing web performance testing tools providing limited client load modelling capabilities. We describe a new approach and toolset that we have developed, MaramaMTE+, which improves the ability to model realistic web client load behaviour, automatically generates complex web application testing plans and scripts, and integrates load behaviour modelling with a generic performance engineering tool. MaramaMTE+ uses a stochastic form chart as its client loading model. A 3rd party web crawler application extracts structural information from a target web site, aggregating the collected data into a crawler database that is then used for form chart model generation. The performance engineer then augments this synthesized form chart with client loading probabilities. Realistic web loading tests for a 3rd party web load testing tool are then automatically generated from this resultant stochastic form chart client load model. We describe the development of our MaramaMTE+ environment, example usage of the tool, and compare and contrast the results obtained from our generated performance load tests against hand-built 3rd party tool load tests Yuhong Cai, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2007 | Meta tools for implementing domain specific visual languagesabstractIn this tutorial we present an overview of Domain-specific visual languages (DSVLs), DSVL-based software engineering tools and meta-tools for constructing DSVL-based tools. We present a motivation for DSVL usage in software engineering; examine several DSVL exemplar tools; illustrate the design of DSVLs including meta-model, notation and view type design; and compare and contrast several tools to realizing DSVLs. Included are three short group exercises in DSVL design. John G. Hosking, John C. Grundy |
ASE | 2 |
| 2007 | Visual Modelling of Complex Business Processes with Trees, Overlays and Distortion-based DisplaysabstractCurrent approaches to modelling complex business processes fail to scale to large organizations. Key issues are cobweb and labyrinth problems exhibited by conventional box and line metaphors and large numbers of hidden dependencies introduced by compartment-based modularity. We have been developing a new approach, Enterprise Modelling Language, based on trees, overlays and fish-eye viewers to overcome these shortcomings of existing workflow notations. EML utilizes several visual metaphors to enhance the representation, navigation and management of large organizational hierarchies and process flows. We describe a prototype support tool, MaramaEML, that provides support for multiple visual notations including the business process modelling notation (BPMN), the EML tree-based, multi-layer hierarchical representation, fisheye zooming capabilities, automatic BPEL code generation, and inter-notation mapping. We describe our experiences using EML to model large business processes and initial evaluation results. Richard Lei Li, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2007 | MaramaTatau: Extending a Domain Specific Visual Language Meta Tool with a Declarative Constraint MechanismabstractIt is increasingly common to use metatools to specify and generate domain specific visual language tools. A common problem for such metatools is specification of model level behaviours, such as constraints and dependencies. These often need to be specified using conventional code in the form of event handlers or the like. We report our experience in integrating a declarative constraint/dependency specification mechanism into a domain specific visual language metatool, focussing on the tradeoffs we have made in the notational design and environmental support used. The expressive power of the mechanism developed is illustrated by a substantial case study where we have redeveloped a complex visual tool for architectural modelling, eliminating conventional event handlers. Na Liu 0001, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2007 | Pounamu: A meta-tool for exploratory domain-specific visual language tool development
Nianping Zhu, John C. Grundy, John G. Hosking, Na Liu 0001, Shuping Cao, Akhil Mehra |
J. Syst. Softw. | 2 |
| 2007 | Experiences developing architectures for realizing thin-client diagram editing toolsabstractAbstract Diagram‐centric applications such as software design tools, project planning tools and business process modelling tools are usually ‘thick‐client’ applications running as stand‐alone desktop applications. There are several advantages to providing such design tools as Web‐based or even PDA‐ and mobile‐phone‐based applications. These include ease of access and upgrade, provision of collaborative work support and Web‐based integration with other applications. However, building such thin‐client diagram editing tools is very challenging. We have developed several thin‐client diagram editing applications realized as a set of plug‐in extensions to a meta‐tool for visual design environment development. In this paper, we discuss key user interaction and software architecture issues, illustrate examples of interacting with our thin‐client diagram editing tools, describe our design and implementation approaches, and present the results of several different evaluations of the resultant applications. Our experiences will be useful for those interested in developing their own thin‐client diagram editing architectures and applications. Copyright © 2007 John Wiley & Sons, Ltd. John C. Grundy, John G. Hosking, Shuping Cao, Dejin Zhao, Nianping Zhu, Ewan D. Tempero, Hermann Stoeckle |
Softw. Pract. Exp. | 1 |
| 2006 | Generating Domain-Specific Visual Language Editors from High-level Tool SpecificationsabstractDomain-specific visual language editors are useful in many areas of software engineering but developing such editors is challenging and time-consuming. We describe an approach to generating a wide range of these graphical editors for use as plug-ins to the Eclipse environment. Tool specifications from an existing meta-tool, Pounamu, are interpreted to produce dynamic, multi-view, multiuser Eclipse graphical editors. We describe the architecture and implementation of our approach, examples of its use realizing domain-specific modelling tools, and strengths and limitations of the approach John C. Grundy, John G. Hosking, Nianping Zhu, Na Liu 0001 |
ASE | 1 |
| 2006 | Off-Line Micro-Payment Protocol for Multiple Vendors in Mobile CommerceabstractMicro-payment systems have the potential to provide non-intrusive, high-volume and low-cost pay as-you-use services for a wide variety of Web-based applications. Previously we have developed NetPay, at off-line micro-payment protocol for e-commerce. In this paper, we describe a set of extensions, mobile NetPay, optimised for mobile e-commerce. Mobile NetPay provides high performance and security using one-way hashing functions for e-coin encryption. Each mobile user's transaction does not involve any broke, and double spending is detected during the redeeming transaction. We describe the motivation for mobile NetPay and describe three transactions of the mobile NetPay protocol in detail to illustrate the approach. We then discuss future research on this protocol Xiaoling Dai, Oluwatomi Ayoade, John C. Grundy |
PDCAT | 3 |
| 2006 | Inking in the IDE: Experiences with Pen-based Design and AnnotatioabstractHand-drawn designs and annotations are a common, human-centric approach frequently used during software design and code inspection. We describe our research experiences of adding support for hand-drawn design and annotation to three Integrated Development Environments (IDEs): a software design tool; a user interface design tool; and a programming tool. The aim of this work is to provide users with more natural interaction techniques seamlessly integrated into their IDEs through the use of hand-drawn diagrams, layouts and code mark-ups. Beryl Plimmer, John C. Grundy, John G. Hosking, Richard Priest |
VL/HCC | 2 |
| 2006 | Guest Editors' Introduction
John Penix, John C. Grundy |
Autom. Softw. Eng. | 2 |
| 2005 | Improving Agile Software Development using eXtreme AOCE and Aspect-Oriented CVSabstractCurrently there are no concurrent versioning systems (CVS) designed to properly support agile software development. The existing CVS lacks user friendliness and it requires users to be fully experienced with the system before they can adequately use it. Also its asynchronous style of merging often leads to code loss. In this paper, we describe a novel CVS system, called the aspect-oriented CVS (AOCVS) and our newly derived agile software development methodology, extreme aspect-oriented component engineering (extreme AOCE). Unlike the general CVS which is used for a vast variety of projects, AOCVS was designed and developed specifically for extreme AOCE. Our CVS tool merges the changes in a synchronous/real time fashion; this in turn removes the hassle for the developers on having to resolve merging conflicts. We also describe how our implemented AOCVS can be used to provide functionalities that can assist developers to produce and distribute reusable code and to communicate and manage aspect-oriented agile projects more efficiently and effectively. Our novel agile approach and tool allows software developers to use the rich cross-cutting systemic concerns, their behaviour and properties in aspect-oriented components to refactor, maintain, add functionalities and test complex software systems more easily, rapidly and accurately. Santokh Singh, Hsiao-Cheng Chen, Oliver Hunter, John C. Grundy, John G. Hosking |
APSEC | 4 |
| 2005 | A visual language and environment for composing web servicesabstractImplementing complex web service-based systems requires tools to effectively describe and co-ordinate the composition of web service components. We have developed a new domain-specific visual language called ViTABaL-WS and built a prototype design tool to support modelling complex interactions between web service components. ViTABaL-WS uses a "Tool Abstraction" metaphor for describing relationships between service definitions, and multiple-views of data-flow, control-flow and event propagation in a modelled process. The tool supports the generation of Business Process Execution Language (BPEL) definitions from a model, directly deploys a generated model to a workflow engine, and supports dynamic visualisation of a running BPEL process. Na Liu 0001, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2005 | A generic approach to supporting diagram differencing and merging for collaborative designabstractDifferentiation tools enable team members to compare two or more text files, e.g. code or documentation, after change. Although a number of general-purpose differentiation tools exist for comparing text documents very few tools exist for comparing diagrams. We describe a new approach for realising visual differentiation in CASE tools via a set of plug-in components. We have added diagram version control, visual differentiation and merging support as component-based plug-ins to the Pounamu meta-CASE tool. The approach is generic across a wide variety of diagram types and has also been deployed with an Eclipse diagramming plug-in. We describe our approach's architecture, key design and implementation issues, illustrate feasibility of our approach via implementation of it as plug-in components and evaluate its effectiveness. Akhil Mehra, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2005 | Deploying Multi-Agents for Intelligent Aspect-Oriented Web Services
Santokh Singh, John G. Hosking, John C. Grundy |
PRIMA | 3 |
| 2005 | A Suite of Visual Languages for Statistical Survey SpecificationabstractWe describe SDL, an integrated suite of visual languages aimed at supporting the process of designing statistical surveys. SDL comprises four diagrammatic notations: survey diagrams, survey data diagrams, survey analysis diagrams and survey process diagrams. A proof of concept environment supporting SDL is also presented, together with a cognitive dimensions evaluation of that environment and a cognitive walkthrough evaluation with a target end user - a professional statistician. These demonstrate the utility of SDL and lead us to propose development of a more comprehensive environment supporting the entire statistical survey process. Chul Hwee Kim, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2005 | A Visual Language and Environment for Specifying Design Tool Event HandlingabstractWe describe a new visual language for event handling specification and its incorporation into Pounamu, a meta-tool for building diverse visual design environments. Our visual language provides end users ways to express event handling mechanisms via visual specifications. Na Liu 0001, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2005 | SoftArch/MTE: Generating Distributed System Test-Beds from High-Level Software Architecture Descriptions
John C. Grundy, Yuhong Cai, Anna Liu |
Autom. Softw. Eng. | 1 |
| 2005 | Deployed software component testing using dynamic validation agents
John C. Grundy, Guoliang Ding, John G. Hosking |
J. Syst. Softw. | 1 |
| 2004 | Workshop on Directions in Software Engineering Environments (WoDiSEE)
John C. Grundy, Ray Welland, Hermann Stoeckle |
ICSE | 1 |
| 2004 | Automated Data Mapping Specification via Schema Heuristics and User Interaction
Sebastian Bossung, Hermann Stoeckle, John C. Grundy, Robert Amor, John G. Hosking |
ASE | 3 |
| 2004 | Experiences Integrating and Scaling a Performance Test Bed Generator with an Open Source CASE Tool
Yuhong Cai, John C. Grundy, John G. Hosking |
ASE | 2 |
| 2004 | An Architecture for Generating Web-Based, Thin-Client Diagramming Tools
Shuping Cao, John C. Grundy, John G. Hosking, Hermann Stoeckle, Ewan D. Tempero |
ASE | 2 |
| 2004 | Software Architecture Modelling and Performance Analysis with Argo/MTE
Yuhong Cai, John C. Grundy, John G. Hosking, Xiaoling Dai |
SEKE | 2 |
| 2004 | Integrating a Zoomable User Interfaces Concept into a Visual Language Meta-Tool EnvironmentabstractWe have introduced zoomable user interfaces into Pounamu, a visual language meta-tool, providing enhanced view navigation and management features. The zoomable user interfaces provide the user with support for flexible and dynamic design overviews and view element focus, and help address problems of lack of screen space and display capability in complex views Na Liu 0001, John G. Hosking, John C. Grundy |
VL/HCC | 3 |
| 2004 | Pounamu: A Meta-Yool for Multi-View Visual Language Environment ConstructionabstractWe describe a meta tool for specification and generation of multiple view visual tools. The tool permits rapid specification of visual notational elements, the tool information model, visual editors, the relationship between notational and model elements, and behaviour. Tools are generated on the fly and can be used for modelling immediately. Changes to the meta tool specification are immediately reflected in tool instances. Nianping Zhu, John C. Grundy, John G. Hosking |
VL/HCC | 2 |
| 2004 | Three Kinds of E-wallets for a NetPay Micro-Payment System
Xiaoling Dai, John C. Grundy |
WISE | 2 |
| 2003 | Architecture for a Component-Based, Plug-In Micro-payment System
Xiaoling Dai, John C. Grundy |
APWeb | 2 |
| 2003 | Experiences Developing a Collaborative Travel Planning Application with .NET Web Services
Philip White, John C. Grundy |
ICWS | 2 |
| 2003 | A 3D Metaphor for Software Production VisualizationabstractSoftware development is difficult because software is complex, the software production process is complex and understanding of software systems is a challenge. We propose a 3D visual approach to depict software production cost related program information to support software maintenance. The information helps us to reduce software maintenance costs, to plan the use of personnel wisely, to appoint experts efficiently and to detect system problems early. Thomas Panas, Rebecca Berrigan, John C. Grundy |
IV | 3 |
| 2003 | Desert Island
John C. Grundy |
Autom. Softw. Eng. | 1 |
| 2003 | Softarch: Tool Support for Integrated Software Architecture DevelopmentabstractA good software architecture design is crucial in successfully realising an object-oriented analysis (OOA) specification with an object-oriented design (OOD) model that meets the specification's functional and non-functional requirements. Most CASE tools and software architecture design notations do not adequately support software architecture modelling and analysis, integration with OOA and OOD methods and tools, and high-level, dynamic architectural visualisations of running systems. We describe SoftArch, an environment that provides flexible software architecture modelling using a concept of successive refinement and an extensible architecture meta-model. SoftArch provides extensible analysis tools enabling developers to analyse their architecture model properties. Run-time visualisation of systems uses dynamic annotation and animation of high-level architectural modelling views. SoftArch is integrated with a component-based CASE tool and run-time monitoring tool, and has facilities for 3rd party tool integration through a common exchange format. This paper discusses the motivation for SoftArch, its modelling, analysis and dynamic visualisation capabilities, and its integration with various analysis, design and implementation tools. John C. Grundy, John G. Hosking |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2002 | An Architecture for Building Multi-device Thin-Client Web User Interfaces
John C. Grundy, Wenjing Zou |
CAiSE | 1 |
| 2002 | Automatic Validation of Deployed J2EE Components Using AspectsabstractValidating that software components meet their requirements under a particular deployment scenario is very challenging. We describe a new approach that uses component aspects, describing functional and nonfunctional cross-cutting concerns impacting components, to perform automated deployed component validation. Aspect information associated with J2EE component implementations is inspected after component deployment by validation agents. These agents run automated tests to determine if the deployed components meet their aspect-described requirements. We describe the way component aspects are encoded, the automated agent-based testing process we employ, and our validation agent architecture and implementation. John C. Grundy, Guoliang Ding |
ASE | 1 |
| 2002 | Developing adaptable user interfaces for component-based systemsabstractSoftware components are becoming increasingly popular design and implementation technologies that can be plugged and played to provide user-enhanceable software. However, developing software components with user interfaces that can be adapted to diverse reuse situations is challenging. Examples of such adaptations include extending, composing and reconfiguring multiple component user interfaces, and adapting component user interfaces to particular user preferences, roles and subtasks. We describe our recent work in facilitating such adaptation via the concept of user interface aspects, which support effective component user interface design and realisation using an extended, component-based software architecture. John C. Grundy, John G. Hosking |
Interact. Comput. | 1 |
| 2002 | Engineering plug-in software components to support collaborative workabstractAbstract Many software applications require co‐operative work support, including collaborative editing, group awareness, versioning, messaging and automated notification and co‐ordination agents. Most approaches hard‐code such facilities into applications, with fixed functionality and limited ability to reuse groupware implementations. We describe our recent work in seamlessly adding such capabilities to component‐based applications via a set of collaborative work‐supporting plug‐in software components. We describe a variety of applications of this technique, along with descriptions of the novel architecture, user interface adaptation and implementation techniques for the collaborative work‐supporting components that we have developed. We report on our experiences to date with this method of supporting collaborative work enhancement of component‐based systems, and discuss the advantages of our approach over conventional techniques. Copyright © 2002 John Wiley & Sons, Ltd. John C. Grundy, John G. Hosking |
Softw. Pract. Exp. | 1 |
| 2001 | Generation of Distributed System Test-Beds from High-Level Software Architecture DescriptionsabstractMost distributed system specifications have performance benchmark requirements. However, determining the likely performance of complex distributed system architectures during development is very challenging. We describe a system where software architects sketch an outline of their proposed system architecture at a high level of abstraction, including indicating client requests, server services, and choosing particular kinds of middleware and database technologies. A fully working implementation of this system is then automatically generated, allowing multiple clients and servers to be run. Performance tests are then automatically run for this generated code and results are displayed back in the original high-level architectural diagrams. Architects may change performance parameters and architecture characteristics, comparing multiple test run results to determine the most suitable abstractions to refine to detailed designs for actual system implementation. We demonstrate the utility of this approach and the accuracy of our generated performance test-beds for validating architectural choices during early system development. John C. Grundy, Yuhong Cai, Anna Liu |
ASE | 1 |
| 2001 | Generating EDI Message Translations from Visual SpecificationsabstractElectronic data interchange (EDI) systems are used in many domains to support inter-organisational information exchange. To get systems using different EDI message formats to communicate, complex message translations (where data must be transformed from one EDI message format into another), are required. We describe a visual language and support environment which greatly simplify the task of the systems integrator by using a domain-specific visual language to express data formats and format translations. Complex message translations are automated by an underlying transformation engine. We describe the motivation for this system, its key visual language and transformation engine features, a prototype environment, and experience translating it into a commercial product. John C. Grundy, Rick Mugridge, John G. Hosking, Paul Kendall |
ASE | 1 |
| 2000 | Multi-Perspective Specification, Design and Implementation of Software Components Using AspectsabstractCurrent approaches to component-based systems engineering tend to focus on low-level software component interface design and implementation. This often leads to the development of components whose services are hard to understand and combine, make too many assumptions about other components they can be composed with and component documentation that is too low-level. Aspect-oriented component engineering is a new methodology that uses a concept of different system capabilities ("aspects") to categorise and reason about inter-component provided and required services. It supports the identification, description and reasoning about high-level component functional and non-functional requirements grouped by different systemic aspects, and the refinement of these requirements into design-level software component service implementation aspects. Aspect information is used to help implement better component interfaces and to encode knowledge of a component's capabilities for other components, developers and end users to access. We describe and illustrate the use of aspect-oriented component engineering techniques and notations to specify, design and implement software components, report on some basic tool support, and our experiences using the approach to build some complex, component-based software systems. John C. Grundy |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2000 | Constructing component-based software engineering environments: issues and experiences
John C. Grundy, Warwick B. Mugridge, John G. Hosking |
Inf. Softw. Technol. | 1 |
| 1999 | Aspect-Oriented Requirements Engineering for Component-Based Software SystemsabstractDeveloping requirements for software components, and ensuring these requirements are met by component designs, is very challenging, as very often application domain and stakeholders are not fully known during component development. The author introduces a new methodology, aspect-oriented component engineering, that addresses some difficult issues of component requirements engineering by analysing and characterising components based on different aspects of the overall application a component addresses. He gives an overview of the aspect-oriented component requirements engineering process, focus on component requirements analysis specification and reasoning, and briefly discuss tool support. John C. Grundy |
RE | 1 |
| 1999 | Visual Specification and Monitoring of Software Agents in Decentralized Process-Centred EnvironmentsabstractDistributed, cooperating software agents are useful in many problem domains, such as task automation and work coordination in process-centered environments. We describe a visual language for specifying such software agents, which uses the composition of event-based software components. These specifications may contain interfaces to remotely executing agents, and agents may be run locally or on distributed machines using a decentralized software architecture. As facilities to configure and monitor the state and activities of such distributed, cooperating software agents is essential, we provide primarily visual capabilities to achieve this. Our static and dynamic software agent visualization techniques have been used on several projects where distributed information processing, system interfacing, work coordination and task automation are required. We illustrate our visualization techniques with examples from these domains. John C. Grundy |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 1998 | Serendipity: Integrated Environment Support for Process Modelling, Enactment and Work Coordination
John C. Grundy, John G. Hosking |
Autom. Softw. Eng. | 1 |
| 1998 | Inconsistency Management for Multiple-View Software Development EnvironmentsabstractDevelopers need tool support to help manage the wide range of inconsistencies that occur during software development. Such tools need to provide developers with ways to define, detect, record, present, interact with, monitor and resolve complex inconsistencies between different views of software artifacts, different developers and different phases of software development. This paper describes our experience with building complex multiple-view software development tools that support diverse inconsistency management facilities. We describe software architectures that we have developed and user interface techniques that are used in our multiple-view development tools, and we discuss the effectiveness of our approaches compared to other architectural and HCI techniques. John C. Grundy, John G. Hosking, Warwick B. Mugridge |
IEEE Trans. Software Eng. | 1 |
| 1997 | Summary of the INTERACT97 Workshop on the Next Generation of CSCW Systems
John C. Grundy |
INTERACT | 1 |
| 1996 | Supporting Flexible Consistency Management via Discrete ChangeabstractA new software architecture for supporting inter-object consistency management is described. Objects with interdependent data values are kept consistent by propagating descriptions of object state changes along inter-object relationships. Response to and storage of these change descriptions supports the implementation of consistency management techniques in a more homogeneous way than existing models. Such techniques include efficient attribute recalculation and constraint schemes, multiple view consistency, and undo-redo, versioning and cooperative work facilities. Applications of the new architecture to user interface, graphical editor and programming environment construction are described. John C. Grundy, John G. Hosking, Warwick B. Mugridge |
Softw. Pract. Exp. | 1 |
| 1995 | Software Environment Support for Integrated Formal Program Specification and DevelopmentabstractFormal program development has gained widespread academic interest as a rigorous software engineering technique. One of the main hurdles for the wider IT industry in adopting these formal techniques is a lack of tools to support their use in combination with more traditional development techniques. This paper describes an integrated environment for object-oriented software development which incorporates formal Object-Z specifications for classes. These formal specification views are kept consistent with more traditional design and implementation views, allowing software developers to design, refine, implement and document their software utilising integrated formal techniques. John C. Grundy, John G. Hosking |
APSEC | 1 |