EDBT 2026 Demo / reviewers in the wild / expert
Sharmin Afrose
dblp:141/9285
· DBLP profile ↗
10ranked-venue papers
4as first author
4since 2021 · last 2025
0000-0003-1835-773XORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 5 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 2 · 1 first-author · 1 since 2021Systems, architecture and hardware · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
3 papers |
Program analysis · 60% Software testing · 40% | |
| Network and information security
3 papers |
Systems and software security · 88% Blockchain and cryptocurrency security · 12% |
Topics — the 4 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Systems and software security › software vulnerability
cryptographic API misuse |
1.4 | 3 | 2023 | Evaluation of Static Vulnerability Detection Tools With Java Cryptographic API Benchmarks · IEEE Trans. Software Eng. 2023 Poster: Deployment-quality and Accessible Solutions for Cryptography Code Development · CCS 2019 CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects · CCS 2019 |
Program analysis
static analysis |
0.8 | 2 | 2019 | Poster: Deployment-quality and Accessible Solutions for Cryptography Code Development · CCS 2019 CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects · CCS 2019 |
Program analysis › static analysis
program slicing |
0.2 | 2 | 2019 | Poster: Deployment-quality and Accessible Solutions for Cryptography Code Development · CCS 2019 CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java Projects · CCS 2019 |
Blockchain and cryptocurrency security › smart contract security
vulnerability detection |
0.2 | 1 | 2023 | Evaluation of Static Vulnerability Detection Tools With Java Cryptographic API Benchmarks · IEEE Trans. Software Eng. 2023 |
Methods — techniques the papers use, named apart from their topics
inter-procedural program slicing · 1.5static analysis · 1.3benchmark evaluation · 1.3flow-sensitive data flow analysis · 0.8data flow analysis · 0.8
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | A cross-platform execution engine for the quantum intermediate representationabstractHybrid languages like the quantum intermediate representation (QIR) are essential for programming systems that mix quantum and conventional computing models, while execution of these programs is often deferred to a system-specific implementation. Here, we develop the QIR Execution Engine (QIR-EE) for parsing, interpreting, and executing QIR across multiple hardware platforms. QIR-EE uses LLVM to execute hybrid instructions specifying quantum programs and, by design, presents extension points that support customized runtime and hardware environments. We demonstrate an implementation that uses the XACC quantum hardware-accelerator library to dispatch prototypical quantum programs on different commercial quantum platforms and numerical simulators, and we validate execution of QIR-EE on IonQ, Quantinuum, and IBM hardware. Our results highlight the efficiency of hybrid executable architectures for handling mixed instructions, managing mixed data, and integrating with quantum computing frameworks to realize cross-platform execution. Vicente Leyton-Ortega, Daniel Claudino, Seth R. Johnson, Austin J. Adams, Sharmin Afrose, Meenambika Gowrishankar, Anthony M. Cabrera, Travis S. Humble |
J. Supercomput. | 6 |
| 2023 | Evaluation of Static Vulnerability Detection Tools With Java Cryptographic API BenchmarksabstractSeveral studies showed that misuses of cryptographic APIs are common in real-world code (e.g., Apache projects and Android apps). There exist several open-sourced and commercial security tools that automatically screen Java programs to detect misuses. To compare their accuracy and security guarantees, we develop two comprehensive benchmarks named CryptoAPI-Bench and ApacheCryptoAPI-Bench. CryptoAPI-Bench consists of 181 unit test cases that cover basic cases, as well as complex cases, including interprocedural, field sensitive, multiple class test cases, and path sensitive data flow of misuse cases. The benchmark also includes correct cases for testing false-positive rates. The ApacheCryptoAPI-Bench consists of 121 cryptographic cases from 10 Apache projects. We evaluate four tools, namely, SpotBugs, CryptoGuard, CrySL, and another tool (anonymous) using both benchmarks. We present their performance and comparative analysis. The ApacheCryptoAPI-Bench also examines the scalability of the tools. Our benchmarks are useful for advancing state-of-the-art solutions in the space of misuse detection. Sharmin Afrose, Ya Xiao 0002, Sazzadur Rahaman, Barton P. Miller, Danfeng Yao |
IEEE Trans. Software Eng. | 1 |
| 2021 | Measurement of Local Differential Privacy Techniques for IoT-based Streaming DataabstractVarious Internet of Things (IoT) devices generate complex, dynamically changed, and infinite data streams. Adversaries can cause harm if they can access the user’s sensitive raw streaming data. For this reason, protecting the privacy of the data streams is crucial. In this paper, we explore local differential privacy techniques for streaming data. We compare the techniques and report the advantages and limitations. We also present the effect on component (e.g., smoother, perturber) variations of distribution-based local differential privacy. We find that combining distribution-based noise during perturbation provides more flexibility to the interested entity. Sharmin Afrose, Danfeng Yao, Olivera Kotevska |
PST | 1 |
| 2021 | Frequent Itemsets Mining with a Guaranteed Local Differential Privacy in Small DatasetsabstractIn this paper, we propose an iterative approach to estimate the frequent itemsets with high accuracy while satisfying the local differential privacy (LDP). The key component behind the improved accuracy of the estimated frequent itemsets by our approach is our novel two-level randomization technique for guaranteeing the LDP. Our randomization technique exploits the correlation of the presence of items in a user’s itemset, which has not been considered before. We present a mathematical proof that shows that our approach satisfies the LDP constraint. Extensive experiments are performed to validate the effectiveness and efficiency of our proposed algorithms using real datasets. Sharmin Afrose, Tanzima Hashem, Mohammed Eunus Ali |
SSDBM | 1 |
| 2020 | A Comprehensive Benchmark on Java Cryptographic API MisusesabstractMisuses of cryptographic APIs are prevalent in existing real-world Java code. Some open-sourced and commercial cryptographic vulnerability detection tools exist that capture misuses in Java program. To analyze their efficiency and coverage, we build a comprehensive benchmark named CryptoAPI-Bench that consists of 171 unit test cases. The test cases include basic cases and complex cases. We assess four tools i.e., SpotBugs, CryptoGuard, CrySL, and Coverity using CryptoAPI-Bench and show their relative performance. Sharmin Afrose, Sazzadur Rahaman, Danfeng Yao |
CODASPY | 1 |
| 2020 | Deployment-quality and Accessible Solutions for Cryptography Code DevelopmentabstractCryptographic API misuses seriously threatens software security. Automatic screening of cryptographic misuse vulnerabilities has been a popular and important line of research over the years. However, the vision of producing a scalable detection tool that developers can routinely use to screen millions of line of code has not been achieved yet. Our main technical goal is to attain a high precision and high throughput approach based on specialized program analysis. Specifically, we design inter-procedural program slicing on top of a new on-demand flow-, context- and field- sensitive data flow analysis. Our current prototype named CryptoGuard can detect a wide range of Java cryptographic API misuses with a precision of 98.61%, when evaluated on 46 complex Apache Software Foundation projects (including, Spark, Ranger, and Ofbiz). Our evaluation on 6,181 Android apps also generated many security insights. We created a comprehensive benchmark named CryptoApi-Bench with 40-unit basic cases and 131-unit advanced cases for in-depth comparison with leading solutions (e.g., SpotBugs, CrySL, Coverity). To make CryptoGuard widely accessible, we are in the process of integrating CryptoGuard with the Software Assurance Marketplace (SWAMP). SWAMP is a popular no-cost service for continuous software assurance and static code analysis. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Ke Tian, Miles Frantz, Na Meng 0001, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu, Danfeng Yao |
CODASPY | 3 |
| 2019 | CryptoGuard: High Precision Detection of Cryptographic Vulnerabilities in Massive-sized Java ProjectsabstractCryptographic API misuses, such as exposed secrets, predictable random numbers, and vulnerable certificate verification, seriously threaten software security. The vision of automatically screening cryptographic API calls in massive-sized (e.g., millions of LoC) programs is not new. However, hindered by the practical difficulty of reducing false positives without compromising analysis quality, this goal has not been accomplished. CryptoGuard is a set of detection algorithms that refine program slices by identifying language-specific irrelevant elements. The refinements reduce false alerts by 76% to 80% in our experiments. Running our tool, CryptoGuard, on 46 high-impact large-scale Apache projects and 6,181 Android apps generated many security insights. Our findings helped multiple popular Apache projects to harden their code, including Spark, Ranger, and Ofbiz. We also have made progress towards the science of analysis in this space, including manually analyzing 1,295 Apache alerts, confirming 1,277 true positives (98.61% precision), and in-depth comparison with leading solutions including CrySL, SpotBugs, and Coverity. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, Danfeng Yao |
CCS | 3 |
| 2019 | Poster: Deployment-quality and Accessible Solutions for Cryptography Code DevelopmentabstractCryptographic API misuses seriously threaten software security. Automatic screening of cryptographic misuse vulnerabilities has been a popular and important line of research over the years. However, the vision of producing a scalable detection tool that developers can routinely use to screen millions of line of code has not been achieved yet. Our main technical goal is to attain a high precision and high throughput approach based on specialized program analysis. Specifically, we design inter-procedural program slicing on top of a new on-demand flow-, context- and field- sensitive data flow analysis. Our current prototype named CryptoGuard can detect a wide range of Java cryptographic API misuses with a precision of 98.61%,, when evaluated on 46 complex Apache Software Foundation projects (including, Spark, Ranger, and Ofbiz). Our evaluation on 6,181 Android apps also generated many security insights. We created a comprehensive benchmark named CryptoAPI-Bench with 40-unit basic cases and 131-unit advanced cases for in-depth comparison with leading solutions (e.g., SpotBugs, CrySL, Coverity). To make CryptoGuard widely accessible, we are in the process of integrating CryptoGuard with the Software Assurance Marketplace (SWAMP). SWAMP is a popular no-cost service for continuous software assurance and static code analysis. Sazzadur Rahaman, Ya Xiao 0002, Sharmin Afrose, Ke Tian, Miles Frantz, Na Meng 0001, Barton P. Miller, Fahad Shaon, Murat Kantarcioglu, Danfeng Yao |
CCS | 3 |
| 2018 | A Novel Secret Sharing Approach for Privacy-Preserving Authenticated Disease Risk Queries in Genomic DatabasesabstractRecent improvement in genomic research is paving the way towards significant progress in diagnosis and treatment of diseases. A disease risk query returns the probability of a patient to develop a particular disease based on her genomic and clinical data. Despite various innovative prospects, frequent and ubiquitous usage of genomic data in medical tests and personalized medicine may cause various privacy threats like genetic discrimination, exposure of susceptibility to diseases, and revelation of genomic data of relatives. Another major concern is on ensuring the reliability of the genome data and the correctness of the computed disease risk, which is known as authentication. We develop a novel secret sharing approach to protect privacy of sensitive genomic and clinical data, disease markers, disease name, and the query answer while ensuring authenticated result of the disease risk query. Experiments with real datasets show that our approach for authenticated disease risk queries achieves a high level of privacy with reduced processing and storage overhead. Maitraye Das, Nusrat Jahan Mozumder, Sharmin Afrose, Khandakar Ashrafi Akbar, Tanzima Hashem |
COMPSAC (1) | 3 |
| 2018 | Poster: Semantic Clustering in Credible Human Sensed Event DetectionabstractTwitter is one of the most popular social media platforms, and a widely used data channel for the propagation of information. Since too many open end users access and use the powerful channel for information propagation, it is becoming increasingly difficult to separate reliable information from the overwhelming pool of information. With the advent of social media generated "fake news" and with their growing influence on the society, the issue of detecting authentic information gains utmost importance. The purpose of our work is to measure the reliability or correctness of the information that is being propagated using Twitter. However, to measure the reliability it is important to preprocess the tweets and to find the similar events. For doing this, an effective clustering method is required which will measure the similarity between the tweets using both semantic and syntactic similarity. We also propose an efficient way to compute the credibility of the sources and how information propagates around the network. Sikder Tahsin Al-Amin, Suraiya Tairin, Sharmin Afrose, Walid Mohammad, Mahmuda Naznin |
DCOSS | 3 |