EDBT 2026 Demo / reviewers in the wild / expert
Rahul Mohanani
dblp:145/4101
· DBLP profile ↗
14ranked-venue papers
5as first author
9since 2021 · last 2026
0000-0001-7018-8836ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 14 · 5 first-author · 9 since 2021Applied, interdisciplinary, general and emerging computing · 2 · 1 first-author · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Managing security issues in software containers: From practitioners' perspectiveabstractSoftware development industries are increasingly adopting containers to enhance the scalability and flexibility of applications. Security in containerized projects is a critical challenge that can lead to data breaches and performance degradation, thereby directly affecting the reliability and operations of the container services. Despite the ongoing effort to manage the security issues in containerized projects in SE research, more investigations are needed to explore the human perspective of security management in containerized projects. This research aims to explore security management in containerized projects by exploring how SE practitioners manage the security issues in containerized projects. A clear understanding of security management in containerized projects will enable industries to develop robust security strategies that enhance software reliability and trust. To achieve this, we conducted two semi-structured interview studies to examine how practitioners approach security management. The first study focused on practitioners’ perceptions of security challenges in containerized environments, where we interviewed 15 participants between December 2022 and October 2023. The second study explored how to address security issues, with 20 participants interviewed between October 2024 and December 2024. Data analysis reveals how SE practitioners address the various security challenges in containerized projects. Our analysis also identified the technical and non-technical enablers that can be utilized to enhance security in containerized projects. Overall, we propose a conceptual model that visualizes how practitioners manage security issues in containerized projects. We argue that our proposed model will guide practitioners in making informed decisions to plan, develop, and deploy secure container systems. Maha Sroor, Rahul Mohanani, Ricardo Colomo-Palacios, Sandun Dasanayake, Tommi Mikkonen |
J. Syst. Softw. | 2 |
| 2025 | A Systematic Mapping Study on Risks and Vulnerabilities in Software ContainersabstractSoftware containers are widely adopted for developing and deploying software applications. Despite their popularity, major security concerns arise during container development and deployment. Software engineering (SE) research literature reveals a lack of reviewed, aggregated and organized knowledge of risks and vulnerabilities, security practices, and tools in container-based systems development and deployment. Therefore, we conducted a Systematic Mapping Study (SMS) based on 129 selected primary studies to explore and organize existing knowledge on security issues in software container systems. Data from the primary studies enabled us to identify critical risks and vulnerabilities across the container life-cycle and categorize them using a novel taxonomy. Additionally, the findings highlight the causes and implications and provide a list of mitigation techniques to overcome these risks and vulnerabilities. Furthermore, we provide an aggregation of security practices and tools that can help support and improve the overall security of container systems. This study offers critical insights into the current landscape of security issues within software container systems. Our analysis highlights the need for future SE research to focus on security enhancement practices that strengthen container systems and develop effective mitigation strategies to comprehensively address existing risks and vulnerabilities. Maha Sroor, Teerath Das, Rahul Mohanani, Tommi Mikkonen |
APSEC | 3 |
| 2025 | Systematic mapping study on requirements engineering for regulatory compliance of software systemsabstractContext: As the diversity and complexity of regulations affecting Software-Intensive Products and Services (SIPS) is increasing, software engineers need to address the growing regulatory scrutiny. We argue that, as with any other non-negotiable requirements, SIPS compliance should be addressed early in SIPS engineering—i.e., during requirements engineering (RE). Objectives: In the conditions of the expanding regulatory landscape, existing research offers scattered insights into regulatory compliance of SIPS. This study addresses the pressing need for a structured overview of the state of the art in software RE and its contribution to regulatory compliance of SIPS. Method: We conducted a systematic mapping study to provide an overview of the current state of research regarding challenges, principles, and practices for regulatory compliance of SIPS related to RE. We focused on the role of RE and its contribution to other SIPS lifecycle process areas. We retrieved 6914 studies published from 2017 (January 1) until 2023 (December 31) from four academic databases, which we filtered down to 280 relevant primary studies. Results: We identified and categorized the RE-related challenges in regulatory compliance of SIPS and their potential connection to six types of principles and practices addressing challenges. We found that about 13.6% of the primary studies considered the involvement of both software engineers and legal experts in developing principles and practices. About 20.7% of primary studies considered RE in connection to other process areas. Most primary studies focused on a few popular regulation fields (privacy, quality) and application domains (healthcare, software development, avionics). Our results suggest that there can be differences in terms of challenges and involvement of stakeholders across different fields of regulation. Conclusion: Our findings highlight the need for an in-depth investigation of stakeholders’ roles, relationships between process areas, and specific challenges for distinct regulatory fields to guide research and practice. Oleksandr Kosenkov, Parisa Elahidoost, Tony Gorschek, Jannik Fischbach, Daniel Méndez 0001, Michael Unterkalmsteiner, Davide Fucci, Rahul Mohanani |
Inf. Softw. Technol. | 8 |
| 2024 | Practitioners' Perceptions of Security Issues in Software Containers: A Qualitative StudyabstractSoftware containers have emerged as solutions for developing and deploying software applications. Despite the popularity and portability of containers, there is significant concern about container security, which hinders their adoption. Recent research has made efforts to investigate container security theoretically and experimentally. Meanwhile, software practitioners have also developed practices to improve and maintain container security based on their work experience. However, a notable gap exists in expressing practitioners' viewpoints on container security. Consequently, this study aims to understand practitioners' perceptions of container security and their man-agement strategies in real-world projects. We conducted semi-structured interviews with practitioners across various domains to explore their opinions on container security issues, causes, implications, tools, and practices. Our data analysis reveals emergent patterns in handling container security in real projects. These patterns are presented as a model that highlights the relationships between the major themes and how they affect each other. Our findings reveal that containers offer many advantages to software systems but face challenges in maintaining security. Finally, this research attempts to bridge the knowledge gap between academia and industry by providing a comprehensive understanding of container security issues as perceived by the practitioners and their interrelationships. Maha Sroor, Rahul Mohanani, Teerath Das, Tommi Mikkonen, Sandun Dasanayake |
SEAA | 2 |
| 2023 | Implementing AI Ethics: Making Sense of the Ethical RequirementsabstractSociety’s increasing dependence on Artificial Intelligence (AI) and AI-enabled systems require a more practical approach from software engineering (SE) executives in middle and higher-level management to improve their involvement in implementing AI ethics by making ethical requirements part of their management practices. However, research indicates that most work on implementing ethical requirements in SE management primarily focuses on technical development, with scarce findings for middle and higher-level management. We investigate this by interviewing ten Finnish SE executives in middle and higher-level management to examine how they consider and implement ethical requirements. We use ethical requirements from the European Union (EU) Trustworthy Ethics guidelines for Trustworthy AI as our reference for ethical requirements and an Agile portfolio management framework to analyze implementation. Our findings reveal a general consideration of privacy and data governance ethical requirements as legal requirements with no other consideration for ethical requirements identified. The findings also show practicable consideration of ethical requirements as technical robustness and safety for implementation as risk requirements and societal and environmental well-being for implementation as sustainability requirements. We examine a practical approach to implementing ethical requirements using the ethical risk requirements stack employing the Agile portfolio management framework. Mamia Agbese, Rahul Mohanani, Arif Ali Khan, Pekka Abrahamsson |
EASE | 2 |
| 2023 | Ethical Requirements Stack: A framework for implementing ethical requirements of AI in software engineering practicesabstractNon peer reviewed Mamia Agbese, Rahul Mohanani, Arif Ali Khan, Pekka Abrahamsson |
EASE | 2 |
| 2023 | Anomaly Detection Through Container Testing: A Survey of Company Practices
Salla Timonen, Maha Sroor, Rahul Mohanani, Tommi Mikkonen |
PROFES (1) | 3 |
| 2022 | How Templated Requirements Specifications Inhibit Creativity in Software EngineeringabstractDesiderata is a general term for stakeholder needs, desires or preferences. Recent experiments demonstrate that presenting desiderata as templated requirements specifications leads to less creative solutions. However, these experiments do not establish how the presentation of desiderata affects design creativity. This study, therefore, aims to explore the cognitive mechanisms by which presenting desiderata as templated requirements specifications reduces creativity during software design. Forty-two software designers, organized into 21 pairs, participated in a dialog-based protocol study. Their interactions were transcribed and the transcripts were analyzed in two ways: (1) using inductive process coding and (2) using an a-priori coding scheme focusing on fixation and critical thinking. Process coding shows that participants exhibited seven categories of behavior: making design moves, uncritically accepting, rejecting, grouping, questioning, assuming and considering quality criteria. Closed coding shows that participants tend to accept given requirements and priority levels while rejecting newer, more innovative design ideas. Overall, the results suggest that designers fixate on desiderata presented as templated requirements specifications, hindering critical thinking. More precisely, requirements fixation mediates the negative relationship between specification formality and creativity. Rahul Mohanani, Paul Ralph, Burak Turhan, Vladimir Mandic |
IEEE Trans. Software Eng. | 1 |
| 2021 | Requirements Framing Affects Design CreativityabstractDesign creativity, the originality and practicality of a solution concept, is critical for the success of many software projects. However, little research has investigated the relationship between the way desiderata are presented and design creativity. This study therefore investigates the impact of presenting desiderata as ideas, requirements or prioritized requirements on design creativity. Two between-subjects randomized controlled experiments were conducted with 42 and 34 participants. Participants were asked to create design concepts from a list of desiderata. Participants who received desiderata framed as requirements or prioritized requirements created designs that are, on average, less original but more practical than the designs created by participants who received desiderata framed as ideas. This suggests that more formal, structured presentations of desiderata are less appropriate where more innovative solutions are desired. The results also show that design performance is highly susceptible to minor changes in the vernacular used to communicate desiderata. Rahul Mohanani, Burak Turhan, Paul Ralph |
IEEE Trans. Software Eng. | 1 |
| 2020 | Cognitive Biases in Software Engineering: A Systematic Mapping StudyabstractOne source of software project challenges and failures is the systematic errors introduced by human cognitive biases. Although extensively explored in cognitive psychology, investigations concerning cognitive biases have only recently gained popularity in software engineering research. This paper therefore systematically maps, aggregates and synthesizes the literature on cognitive biases in software engineering to generate a comprehensive body of knowledge, understand state-of-the-art research and provide guidelines for future research and practise. Focusing on bias antecedents, effects and mitigation techniques, we identified 65 articles (published between 1990 and 2016), which investigate 37 cognitive biases. Despite strong and increasing interest, the results reveal a scarcity of research on mitigation techniques and poor theoretical foundations in understanding and interpreting cognitive biases. Although bias-related research has generated many new insights in the software engineering community, specific bias mitigation techniques are still needed for software professionals to overcome the deleterious effects of cognitive biases on their work. Rahul Mohanani, Iflaah Salman, Burak Turhan, Pilar Rodríguez 0002, Paul Ralph |
IEEE Trans. Software Eng. | 1 |
| 2019 | Temporal Discounting in Software Engineering: A Replication StudyabstractBackground: Many decisions made in Software Engineering practices are intertemporal choices: trade-offs in time between closer options with potential short-term benefit and future options with potential long-term benefit. However, how software professionals make intertemporal decisions is not well understood. Aim: This paper investigates how shifting time frames influence preferences in software projects in relation to purposefully selected background factors. Method: We investigate temporal discounting by replicating a questionnaire-based observational study. The replication uses a changed-population and -experimenter design to increase the internal and external validity of the original results. Results: The results of this study confirm the occurrence of temporal discounting in samples of both professional and student participants from different countries and demonstrate strong variance in discounting between study participants. We found that professional experience influenced discounting. Participants with broader professional experience exhibited less discounting than those with narrower experience. Conclusions: The results provide strong empirical support for the relevance and importance of temporal discounting in SE and the urgency of targeted interdisciplinary research to explore the underlying mechanisms and their theoretical and practical implications. The results suggest that technical debt management could be improved by increasing the breadth of experience available for critical decisions with long-term impact. In addition, the present study provides a methodological basis for replicating temporal discounting studies in software engineering. Fabian Fagerholm, Christoph Becker 0001, Alexander Chatzigeorgiou, Stefanie Betz, Leticia Duboc, Birgit Penzenstadler, Rahul Mohanani, Colin C. Venters |
ESEM | 7 |
| 2019 | Temporal discounting in technical debt: how do software practitioners discount the future?abstractTechnical Debt management decisions always imply a trade-off among outcomes at different points in time. In such intertemporal choices, distant outcomes are often valued lower than close ones, a phenomenon known as temporal discounting. Technical Debt research largely develops prescriptive approaches for how software engineers should make such decisions. Few have studied how they actually make them. This leaves open central questions about how software practitioners make decisions. This paper investigates how software practitioners discount uncertain future outcomes and whether they exhibit temporal discounting. We adopt experimental methods from intertemporal choice, an active area of research. We administered an online questionnaire to 33 developers from two companies in which we presented choices between developing a feature and making a longer-term investment in architecture. The results show wide-spread temporal discounting with notable differences in individual behavior. The results are consistent with similar studies in consumer behavior and raise a number of questions about the causal factors that influence temporal discounting in software engineering. As the first empirical study on intertemporal choice in SE, the paper establishes an empirical basis for understanding how software developers approach intertemporal choice and provides a blueprint for future studies. Christoph Becker 0001, Fabian Fagerholm, Rahul Mohanani, Alexander Chatzigeorgiou |
TechDebt@ICSE | 3 |
| 2017 | Perceptions of Creativity in Software Engineering Research and PracticeabstractSoftware engineering, especially design and requirements engineering, is intensely creative. However, practitioners and researchers appear to perceive creativity differently, hindering knowledge transfer. To explore and understand these perceptual differences, this paper combines a systematic mapping study of SE research literature with an interview study of practitioners. The subsequent analysis of 84 primary studies and 17 semi-structured interviews reveal some agreement (e.g. creativity is a process that produces novel and useful ideas). However, it also reveals important differences in the way creativity is conceptualized, measured and improved. These differences undermine evidence-based techniques to enhance and measure creativity in SE research and practice. Rahul Mohanani, Prabhat Ram, Ahmed Lasisi, Paul Ralph, Burak Turhan |
SEAA | 1 |
| 2014 | Requirements fixationabstractThere is a broad consensus that understanding system desiderata (requirements) and design creativity are both important for software engineering success. However, little research has addressed the relationship between design creativity and the way requirements are framed or presented. This paper therefore aims to investigate the possibility that the way desiderata are framed or presented can affect design creativity. Forty two participants took part in a randomized control trial where one group received desiderata framed as “requirements” while the other received desiderata framed as “ideas”. Participants produced design concepts which were judged for originality. Participants who received requirements framing produced significantly less original designs than participants who received ideas framing (Mann-Whitney U=116.5, p=0.004). We conclude that framing desiderata as “requirements” may cause requirements fixation where designers’ preoccupation with satisfying explicit requirements inhibits their creativity. Rahul Mohanani, Paul Ralph, Ben Shreeve |
ICSE | 1 |