Ahmad A. Saifan

dblp:04/5379 · DBLP profile ↗
← Back
8ranked-venue papers
4as first author
5since 2021 · last 2025
0000-0002-4974-8939ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 3 · 2 first-author · 1 since 2021Artificial intelligence and machine learning · 2 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021Systems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2025 A self-supervised transformer framework for cross-domain fraudulent review detection (CROSS-FRD)
Ali Al-Yousef, Rami Mohawesh, Ahmad A. Saifan, Moy'awiah A. Al-Shannaq
J. Supercomput.3
2021 Generating Optimal Attack Paths in Generative Adversarial Phishing
abstract
Phishing attacks have witnessed a rapid increase thanks to the matured social engineering techniques, COVID-19 pandemic, and recently adversarial deep learning techniques. Even though adversarial phishing attacks are recent, attackers are crafting such attacks by considering context, testing different attack paths, then selecting paths that can evade machine learning phishing detectors. This research proposes an approach that generates adversarial phishing attacks by finding optimal subsets of features that lead to higher evasion rate. We used feature engineering techniques such as Recursive Feature Elimination, Lasso, and Cancel Out to generate then test attack vectors that have higher potential to evade phishing detectors. We tested the evasion performance of each technique then classified different evasion tests as passed or failed depending on their evasion rate. Our findings showed that our threat model has better evasion capability compared to the original Generative Adversarial Deep Neural Network (GAN) which perturbs features in a random manner.
Rayah Al-Qurashi, Ahmed Aleroud, Ahmad A. Saifan, Mohammad Alsmadi, Izzat Alsmadi
ISI3
2021 Privacy preserving defect prediction using generalization and entropy-based data reduction
abstract
The software engineering community produces data that can be analyzed to enhance the quality of future software products, and data regarding software defects can be used by data scientists to create defect predictors. However, sharing such data raises privacy concerns, since sensitive software features are usually considered as business assets that should be protected in accordance with the law. Early research efforts on protecting the privacy of software data found that applying conventional data anonymization to mask sensitive attributes of software features degrades the quality of the shared data. In addition, data produced by such approaches is not immune to attacks such as inference and background knowledge attacks. This research proposes a new approach to share protected release of software defects data that can still be used in data science algorithms. We created a generalization (clustering)-based approach to anonymize sensitive software attributes. Tomek link and AllNN data reduction approaches were used to discard noisy records that may affect the usefulness of the shared data. The proposed approach considers diversity of sensitive attributes as an important factor to avoid inference and background knowledge attacks on the anonymized data, therefore data discarded is removed from both defective and non-defective records. We conducted experiments conducted on several benchmark software defect datasets, using both data quality and privacy measures to evaluate the proposed approach. Our findings showed that the proposed approach outperforms existing well-known techniques using accuracy and privacy measures.
Ahmad A. Saifan, Zainab Lataifeh
Intell. Data Anal.1
2021 Fault-based testing for discovering SQL injection vulnerabilities in web applications
abstract
In this paper we proposed a model to investigate the behaviour of websites when dealing with invalid inputs. Many vulnerabilities rise from invalid inputs. An invalid input is considered as a form of a successful attack if it is processed by the website code or back-end database. Based on this assumption, we proposed a list of indicators that tested and processed invalid inputs. A tool is developed to implement this model. We tested the model through evaluating several websites selected randomly. Our tool has no special credentials or access to any of the tested websites. We found many SQL injection vulnerabilities based on our proposed model. Upon the manual investigation of the web pages that showed such vulnerabilities, we found few instances of false positives. We believe that this can provide a systematic and automated approach to test websites for vulnerabilities related to improper input validation.
Izzat Alsmadi, Ahmed Aleroud, Ahmad A. Saifan
Int. J. Inf. Comput. Secur.3
2021 Feature location enhancement based on source code augmentation with synonyms of terms
abstract
Summary In software maintenance the developers may add new feature to program, improve existing function, and remove bugs. In this case the developer should identify the location in the source code that corresponds to a specific functionality; this is known as feature location. This presents a new approach for enhancing the process of feature location using Information Retrieval (IR) and Natural Language Processing. The approach presented augments the source code with additional semantic information that was extracted and derived from the synonyms of source code terms. This approach works in a pipeline structure, starting by augmenting the source code corpus with synonyms of the original terms and ending by inferring the source code with a particular user query. More specifically, the WordNet platform is used for extracting the synonyms of terms. Moreover, the approach uses an advanced IR technique, namely the Latent Semantic Indexing, for searching and inferring the source code. The used approach was tested and evaluated on two open source systems, namely the Qt and Hippodraw. Four experiments were conducted on each system using 21 features and the results showed that enriching the source code with synonyms of terms clearly and significantly improved the process of feature location efficiently. The experimental results showed that the approach presented obtained higher levels of Recall and Precision. For that reason, it has been shown to improve the state‐of‐the‐art techniques for feature location process.
Ahmad A. Saifan, Lana Obeidat
Softw. Pract. Exp.1
2019 Source code-based defect prediction using deep learning and transfer learning
abstract
Ensuring the quality of software products is important for them to be successful. Discovering errors and fixing defective software modules early in the project lifecycle (e.g. in the testing phase) can save resources and enhance software quality. Developers should prioritize testing procedures and continuously maintain their software projects; however, when there are few instances of a new project, it is hard to build an accurate defect prediction model. Different information about software projects is available and can be utilized through open repositories. Developers can leverage the labeled defect information to build a defect prediction model. The abundance of historical software information in similar domains can assist in transferring the knowledge gained from training this information to other domains for cross-project defect prediction models. Deep learning is a promising machine learner. Deep Belief network (DBN) is a deep learning algorithm that can discover latent relationships between input features by training them through multi-hidden layers; however, it is difficult to build a good prediction model from a dataset with few modules or instances. In this research, we utilized auxiliary datasets to initialize a DBN model and transfer the obtained knowledge to train the DBN model using a source project in a cross-project combination. The expressive features generated from the DBN model are used to build a classical classifier from the source class label and test it on other target project instances. Our evaluation of 13 open Java projects from the PROMISE repository shows that our proposed model achieves improvements based on F-measures (3.6%, 4.9%, and 5.1%) for the three settings of the DBN model measured against the best used benchmark model of TCA/ TCA+ techniques. Moreover, T_DBN and DBN_Only models achieve improvement in terms of F-measure by (11.1% and 6.2%) against the best used benchmark model of TCA/TCA+ on Relink validation dataset.
Ahmad A. Saifan, Nawzat Al Smadi
Intell. Data Anal.1
2019 Mining software repositories for adaptive change commits using machine learning techniques
Omar Meqdadi, Nouh Alhindawi, Jamal Alsakran, Ahmad A. Saifan, Hatim Migdadi
Inf. Softw. Technol.4
2011 Implementing and Evaluating a Runtime Conformance Checker for Mobile Agent Systems
abstract
A Mobile Agent System (MAS) is a special kind of distributed system in which the agent software can move from one physical host to another. This paper describes a new approach, together with its implementation and evaluation, for checking the conformance of a MAS with respect to an executable model. In order to check the effectiveness of our conformance check, we have built a mutation-based evaluation framework. Part of the framework is a set of 29 new mutation operators for mobile agent systems. Our conformance checking approach is used to compare the mutated agents with the executable model and determine nonconformance. Our experimental results suggest that our approach holds promise for the generation and detection of non-equivalent mutants.
Ahmad A. Saifan, Jürgen Dingel, Jeremy S. Bradbury, Ernesto Posse
ICST1