EDBT 2026 Demo / reviewers in the wild / expert
Tanzirul Azim
dblp:129/8213 · also Md Tanzirul Azim
· DBLP profile ↗
8ranked-venue papers
4as first author
0since 2021 · last 2019
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 3 first-authorComputer networks · 1 · 1 first-authorSecurity and privacy · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
7 papers |
Debugging and program repair · 33% Software testing · 30% Program analysis · 28% | |
| Network and information security
2 papers |
Web and mobile security · 62% Systems and software security · 38% |
Topics — the 17 heaviest of 20, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Debugging and program repair
fault localization |
0.8 | 3 | 2019 | Dynamic slicing for Android · ICSE 2019 Finding resume and restart errors in Android applications · OOPSLA 2016 Towards self-healing smartphone software via automated patching · ASE 2014 |
Software testing
mobile application testing |
0.4 | 3 | 2015 | Versatile yet lightweight record-and-replay for Android · OOPSLA 2015 Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013 RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013 |
Debugging and program repair
record and replay |
0.4 | 2 | 2015 | Versatile yet lightweight record-and-replay for Android · OOPSLA 2015 RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013 |
Program analysis
dynamic analysis |
0.4 | 1 | 2019 | Dynamic slicing for Android · ICSE 2019 |
Program analysis › dynamic analysis
dynamic slicing |
0.4 | 1 | 2019 | Dynamic slicing for Android · ICSE 2019 |
Program analysis
static analysis |
0.3 | 2 | 2016 | Finding resume and restart errors in Android applications · OOPSLA 2016 Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013 |
Software testing
test generation |
0.2 | 1 | 2016 | Finding resume and restart errors in Android applications · OOPSLA 2016 |
Debugging and program repair › automated program repair
automated patch generation |
0.2 | 1 | 2014 | Towards self-healing smartphone software via automated patching · ASE 2014 |
Software testing › fault detection
crash detection |
0.2 | 1 | 2014 | Towards self-healing smartphone software via automated patching · ASE 2014 |
Software testing
GUI testing |
0.2 | 1 | 2013 | RERAN: timing- and touch-sensitive record and replay for Android · ICSE 2013 |
Software testing
regression testing |
0.1 | 1 | 2019 | Dynamic slicing for Android · ICSE 2019 |
Software testing › regression testing
test suite reduction |
0.1 | 1 | 2019 | Dynamic slicing for Android · ICSE 2019 |
Operating systems › mobile systems
mobile platform |
0.1 | 1 | 2015 | Versatile yet lightweight record-and-replay for Android · OOPSLA 2015 |
Web and mobile security › mobile security
android security |
0.1 | 1 | 2014 | Brahmastra: Driving Apps to Test the Security of Third-Party Components · USENIX Security Symposium 2014 |
Operating systems › mobile systems
mobile operating systems |
0.1 | 1 | 2014 | Towards self-healing smartphone software via automated patching · ASE 2014 |
Program analysis
data flow analysis |
0.0 | 1 | 2013 | Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013 |
Program analysis › static analysis
taint analysis |
0.0 | 1 | 2013 | Targeted and depth-first exploration for systematic testing of android apps · OOPSLA 2013 |
Methods — techniques the papers use, named apart from their topics
static analysis · 0.8dynamic analysis · 0.7instrumentation · 0.4asynchronous slicing · 0.4input generation · 0.2stream-oriented record-and-replay · 0.2bytecode rewriting · 0.2static taint-style dataflow analysis · 0.2event stream capture · 0.2control flow graph construction · 0.2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2019 | Dynamic slicing for AndroidabstractDynamic program slicing is useful for a variety of tasks, from testing to debugging to security. Prior slicing approaches have targeted traditional desktop/server platforms, rather than mobile platforms such as Android. Slicing mobile, event-based systems is challenging due to their asynchronous callback construction and the IPC (interprocess communication)- heavy, sensor-driven, timing-sensitive nature of the platform. To address these problems, we introduce AndroidSlicer1, the first slicing approach for Android. AndroidSlicer combines a novel asynchronous slicing approach for modeling data and control dependences in the presence of callbacks with lightweight and precise instrumentation; this allows slicing for apps running on actual phones, and without requiring the app's source code. Our slicer is capable of handling a wide array of inputs that Android supports without adding any noticeable overhead. Experiments on 60 apps from Google Play show that AndroidSlicer is effective (reducing the number of instructions to be examined to 0.3% of executed instructions) and efficient (app instrumentation and post-processing combined takes 31 seconds); all while imposing a runtime overhead of just 4%. We present three applications of AndroidSlicer that are particularly relevant in the mobile domain: (1) finding and tracking input parts responsible for an error/crash, (2) fault localization, i.e., finding the instructions responsible for an error/crash, and (3) reducing the regression test suite. Experiments with these applications on an additional set of 18 popular apps indicate that AndroidSlicer is effective for Android testing and debugging. Tanzirul Azim, Arash Alavi 0001, Iulian Neamtiu, Rajiv Gupta 0001 |
ICSE | 1 |
| 2016 | uLink: Enabling User-Defined Deep Linking to App ContentabstractWeb deep links are instrumental to many fundamental user experiences such as navigating to one web page from another, bookmarking a page, or sharing it with others. Such experiences are not possible with individual pages inside mobile apps, since historically mobile apps did not have links equivalent to web deep links. Mobile deep links, introduced in recent years, still lack many important properties of web deep links. Unlike web links, mobile deep links need significant developer effort, cover a small number of predefined pages, and are defined statically to navigate to a page for a given link, but not to dynamically generate a link for a given page. We propose uLink, a novel deep linking mechanism that addresses these problems. uLink is implemented as an application library, which transparently tracks data- and UI-event-dependencies of app pages, and encodes the information in links to the pages; when a link is invoked, the information is utilized to recreate the target page quickly and accurately. uLink also employs techniques, based on static and dynamic analysis of the app, that can provide feedback to users about whether a link may break in the future due to, e.g., modifications of external resources such as a file the link depends on. We have implemented uLink on Android. Our evaluation with 34 (of 1000 most downloaded) Android apps shows that compared to existing mobile deep links, uLink requires minimal developer effort, achieves significantly higher coverage, and can provide accurate user feedback on a broken link. Tanzirul Azim, Oriana Riva, Suman Nath |
MobiSys | 1 |
| 2016 | Finding resume and restart errors in Android applicationsabstractSmartphone apps create and handle a large variety of ``instance'' data that has to persist across runs, such as the current navigation route, workout results, antivirus settings, or game state. Due to the nature of the smartphone platform, an app can be paused, sent into background, or killed at any time. If the instance data is not saved and restored between runs, in addition to data loss, partially-saved or corrupted data can crash the app upon resume or restart. While smartphone platforms offer API support for data-saving and data-retrieving operations, the use of this API is ad-hoc: left to the programmer, rather than enforced by the compiler. We have observed that several categories of bugs---including data loss, failure to resume/restart or resuming/restarting in the wrong state---are due to incorrect handling of instance data and are easily triggered by just pressing the `Home' or `Back' buttons. To help address this problem, we have constructed a tool chain for Android (the KREfinder static analysis and the KREreproducer input generator) that helps find and reproduce such incorrect handling. We have evaluated our approach by running the static analysis on 324 apps, of which 49 were further analyzed manually. Results indicate that our approach is (i) effective, as it has discovered 49 bugs, including in popular Android apps, and (ii) efficient, completing on average in 61 seconds per app. More generally, our approach helps determine whether an app saves too much or too little state. Zhiyong Shan, Tanzirul Azim, Iulian Neamtiu |
OOPSLA | 2 |
| 2015 | Versatile yet lightweight record-and-replay for AndroidabstractRecording and replaying the execution of smartphone apps is useful in a variety of contexts, from reproducing bugs to profiling and testing. Achieving effective record-and-replay is a balancing act between accuracy and overhead. On smartphones, the act is particularly complicated, because smartphone apps receive a high-bandwidth stream of input (e.g., network, GPS, camera, microphone, touchscreen) and concurrency events, but the stream has to be recorded and replayed with minimal overhead, to avoid interfering with app execution. Prior record-and-replay approaches have focused on replaying machine instructions or system calls, which is not a good fit on smartphones. We propose a novel, stream-oriented record-and-replay approach which achieves high-accuracy and low-overhead by aiming at a sweet spot: recording and replaying sensor and network input, event schedules, and inter-app communication via intents. To demonstrate the versatility of our approach, we have constructed a tool named VALERA that supports record-and-replay on the Android platform. VALERA works with apps running directly on the phone, and does not require access to the app source code. Through an evaluation on 50 popular Android apps, we show that: VALERA's replay fidelity far exceeds current record-and-replay approaches for Android; VALERA's precise timing control and low overhead (about 1% for either record or replay) allows it to replay high-throughput, timing-sensitive apps such as video/audio capture and recognition; and VALERA's support for event schedule replay enables the construction of useful analyses, such as reproducing event-driven race bugs. Yongjian Hu, Tanzirul Azim, Iulian Neamtiu |
OOPSLA | 2 |
| 2014 | Towards self-healing smartphone software via automated patchingabstractFrequent app bugs and low tolerance for loss of functionality create an impetus for self-healing smartphone software. We take a step towards this via on-the-fly error detection and automated patching. Specifically, we add failure detection and recovery to Android by detecting crashes and ``sealing off'' the crashing part of the app to avoid future crashes. In the detection stage, our system dynamically analyzes app execution to detect certain exceptional situations. In the recovery stage, we use bytecode rewriting to alter app behavior as to avoid such situations in the future. When using our implementation, apps can resume operation (albeit with limited functionality) instead of repeatedly crashing. Our approach does not require access to app source code or any system (e.g., kernel-level) modification. Experiments on several real-world, popular Android apps and bugs show that our approach manages to recover the apps from crashes effectively, timely, and without introducing overhead. Tanzirul Azim, Iulian Neamtiu, Lisa M. Marvel |
ASE | 1 |
| 2014 | Brahmastra: Driving Apps to Test the Security of Third-Party Components
Ravi Bhoraskar, Seungyeop Han, Jinseong Jeon, Tanzirul Azim, Shuo Chen 0001, Jaeyeon Jung, Suman Nath, Rui Wang 0010, David Wetherall |
USENIX Security Symposium | 4 |
| 2013 | RERAN: timing- and touch-sensitive record and replay for AndroidabstractTouchscreen-based devices such as smartphones and tablets are gaining popularity, but their rich input capabilities pose new development and testing complications. To alleviate this problem, we present an approach and tool named Reran that permits record-and-replay for the Android smartphone platform. Existing GUI-level record-and-replay approaches are inadequate due to the expressiveness of the smartphone domain, in which applications support sophisticated GUI gestures, depend on inputs from a variety of sensors on the device, and have precise timing requirements among the various input events. We address these challenges by directly capturing the low-level event stream on the phone, which includes both GUI events and sensor events, and replaying it with microsecond accuracy. Moreover, Reran does not require access to app source code, perform any app rewriting, or perform any modifications to the virtual machine or Android platform. We demonstrate RERAN's applicability in a variety of scenarios, including (a) replaying 86 out of the Top-100 Android apps on Google Play; (b) reproducing bugs in popular apps, e.g., Firefox, Facebook, Quickoffice; and (c) fast-forwarding executions. We believe that our versatile approach can help both Android developers and researchers. Lorenzo Gomez, Iulian Neamtiu, Tanzirul Azim, Todd D. Millstein |
ICSE | 3 |
| 2013 | Targeted and depth-first exploration for systematic testing of android appsabstractSystematic exploration of Android apps is an enabler for a variety of app analysis and testing tasks. Performing the exploration while apps run on actual phones is essential for exploring the full range of app capabilities. However, exploring real-world apps on real phones is challenging due to non-determinism, non-standard control flow, scalability and overhead constraints. Relying on end-users to conduct the exploration might not be very effective: we performed a 7-use study on popular Android apps, and found that the combined 7-use coverage was 30.08% of the app screens and 6.46% of the app methods. Prior approaches for automated exploration of Android apps have run apps in an emulator or focused on small apps whose source code was available. To address these problems, we present A3E, an approach and tool that allows substantial Android apps to be explored systematically while running on actual phones, yet without requiring access to the app's source code. The key insight of our approach is to use a static, taint-style, dataflow analysis on the app bytecode in a novel way, to construct a high-level control flow graph that captures legal transitions among activities (app screens). We then use this graph to develop an exploration strategy named Targeted Exploration that permits fast, direct exploration of activities, including activities that would be difficult to reach during normal use. We also developed a strategy named Depth-first Exploration that mimics user actions for exploring activities and their constituents in a slower, but more systematic way. To measure the effectiveness of our techniques, we use two metrics: activity coverage (number of screens explored) and method coverage. Experiments with using our approach on 25 popular Android apps including BBC News, Gas Buddy, Amazon Mobile, YouTube, Shazam Encore, and CNN, show that our exploration techniques achieve 59.39--64.11% activity coverage and 29.53--36.46% method coverage. Tanzirul Azim, Iulian Neamtiu |
OOPSLA | 1 |