EDBT 2026 Demo / reviewers in the wild / expert
Wasja Brunotte
dblp:246/8236
· DBLP profile ↗
10ranked-venue papers
3as first author
6since 2021 · last 2026
0000-0003-4127-6508ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 9 · 3 first-author · 6 since 2021Artificial intelligence and machine learning · 3 · 1 first-author · 1 since 2021Security and privacy · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Too Many Issues: Automatically Prioritizing Analyzer Findings by Tracing Security ImportanceabstractCode-based analyzers often find too many potentially security-related issues to address them all. Therefore, issues likely to lead to vulnerabilities should be fixed first. Such prioritization requires project-specific knowledge, such as quality requirements, security-related decisions, and design, which is not accessible to code analyzers. We present TraceSEC, an automated technique for prioritizing issues according to their security-related importance to the project. Its core concept is to incorporate available design artifacts and trace links between them, thus considering the project context that the code lacks. We reduce the problem of issue prioritization to a maximum flow problem and quantify the importance of each issue by the flow from user-defined quality aspects to the issue, i.e., quantifying its impact on project-specific security preferences. Our evaluation shows that TraceSEC effectively provides automated prioritization and can be tailored to project-specific quality goals. Its prioritization correlates stronger with manual expert prioritization than SonarQube rule severities, which are commonly used in practice. In particular, TraceSEC has a higher similarity for identifying high-priority issues. TraceSEC scales reasonably well for codebases up to four million lines of code, and the initial setup overhead is likely to be recouped after the first automated prioritization. Sven Peldszus, Katharina Großer, Marco Konersmann, Wasja Brunotte, Maike Ahrens, Kurt Schneider, Jan Jürjens |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2023 | Context, Content, Consent - How to Design User-Centered Privacy Explanations (S)abstractIn the context of the ongoing digitalization of society, human values such as privacy, ethics and trust are becoming increasingly important.Digital systems are entering private and professional spaces, which in turn affects the privacy of their end users.Hence, there is a need for conveying privacy information in a transparent and understandable manner, with the user in the focus.Lawmakers introduced privacy policies as a means of communicating privacy information.However, those documents have proven to be practically useless for end users.Privacy policies are long, vague, ambiguous and use complex language, such as legal terms, which often require profound background knowledge.Explainability has shown potential as a means to increase transparency and foster trust in software systems.Based upon the foundation of explainability, we developed a layered concept for usercentered privacy explanations, which is implemented within a high-fidelity software prototype.Finally, we tested and evaluated our concept by conducting an interactive user study with 61 participants.The results of our study suggest that our layered design concept enabled participants to understand the privacy aspects they regarded as important.We conclude that our approach seems to be an appropriate way to communicate complex privacy information to end users. Wasja Brunotte, Jakob Droste, Kurt Schneider |
SEKE | 1 |
| 2023 | Privacy explanations - A means to end-user trust
Wasja Brunotte, Alexander Specht, Larissa Chazette, Kurt Schneider |
J. Syst. Softw. | 1 |
| 2022 | Quo Vadis, Explainability? - A Research Roadmap for Explainability Engineering
Wasja Brunotte, Larissa Chazette, Verena Klös, Timo Speith |
REFSQ | 1 |
| 2022 | Explainable software systems: from requirements analysis to system evaluationabstractAbstract The growing complexity of software systems and the influence of software-supported decisions in our society sparked the need for software that is transparent, accountable, and trustworthy. Explainability has been identified as a means to achieve these qualities. It is recognized as an emerging non-functional requirement (NFR) that has a significant impact on system quality. Accordingly, software engineers need means to assist them in incorporating this NFR into systems. This requires an early analysis of the benefits and possible design issues that arise from interrelationships between different quality aspects. However, explainability is currently under-researched in the domain of requirements engineering, and there is a lack of artifacts that support the requirements engineering process and system design. In this work, we remedy this deficit by proposing four artifacts: a definition of explainability, a conceptual model, a knowledge catalogue, and a reference model for explainable systems. These artifacts should support software and requirements engineers in understanding the definition of explainability and how it interacts with other quality aspects. Besides that, they may be considered a starting point to provide practical value in the refinement of explainability from high-level requirements to concrete design choices, as well as on the identification of methods and metrics for the evaluation of the implemented requirements. Larissa Chazette, Wasja Brunotte, Timo Speith |
Requir. Eng. | 2 |
| 2021 | Exploring Explainability: A Definition, a Model, and a Knowledge CatalogueabstractThe growing complexity of software systems and the influence of software-supported decisions in our society awoke the need for software that is transparent, accountable, and trust-worthy. Explainability has been identified as a means to achieve these qualities. It is recognized as an emerging non-functional requirement (NFR) that has a significant impact on system quality. However, in order to incorporate this NFR into systems, we need to understand what explainability means from a software engineering perspective and how it impacts other quality aspects in a system. This allows for an early analysis of the benefits and possible design issues that arise from interrelationships between different quality aspects. Nevertheless, explainability is currently under-researched in the domain of requirements engineering and there is a lack of conceptual models and knowledge catalogues that support the requirements engineering process and system design. In this work, we bridge this gap by proposing a definition, a model, and a catalogue for explainability. They illustrate how explainability interacts with other quality aspects and how it may impact various quality dimensions of a system. To this end, we conducted an interdisciplinary Systematic Literature Review and validated our findings with experts in workshops. Larissa Chazette, Wasja Brunotte, Timo Speith |
RE | 2 |
| 2020 | Community Knowledge About Security: - Identification and Classification of User Contributions
Fabien Patrick Viertel, Wasja Brunotte, Yannick Evers, Kurt Schneider |
CRiSIS | 2 |
| 2020 | Which Information Help agile Teams the Most? An Experience Report on the Problems and NeedsabstractFast feedback promotes agile teams to improve their work during the software process, making it crucial for team success. Information systems accelerate the availability of information that result in compact knowledge sources. In practice, feedback in Sprints is often limited to sole progress and performance measures, e.g., burndown charts or velocity diagrams. Sprint insights related to team dynamics are rarely considered, even though they frequently cause project failures, e.g., lack of social interaction. In this paper, we describe a survey study conducted with international members of the software engineering community to reveal which information helps agile teams the most and provides practical support in Sprints. We describe results in an experience report highlighting the frequent information problems and needs of agile teams, considering the perspective of 90 researchers and practitioners. The responses were quantitatively interpreted. The report promotes understanding about how or what kind of information would be useful for agile development teams. Moreover, it reveals what information problems were perceived as crucial for project success and avoidable, considering proper team feedback. The study endorses practical needs for system-aided feedback that supplies knowledge on the human factors in Sprints. The findings are relevant for practitioners and researchers that struggle on improving team feedback based on information needs. Fabian Kortum, Jil Klünder, Oliver Karras, Wasja Brunotte, Kurt Schneider |
SEAA | 4 |
| 2019 | Sprint Performance Forecasts in Agile Software Development - The Effect of Futurespectives on Team-Driven DynamicsabstractIn agile software development, the sprint performances and dynamics of teams often imply tendencies for the success of a project.Post mortem strategies, e.g., retrospectives help the team to report and share individually gained experiences (positives and negatives) from previous sprints, and enable them to use these experiences for future sprint planning.The interpretation of effects on sprint performance is often subjective, especially with concern to social-driven factors in teams.Involving strategies from predictive analytics in sprint retrospectives could reduce potential interpretation gaps of dynamics, and enhance the pre-knowledge, also awareness situation when preparing for the next sprint.In a case study involving 15 software projects with a total of 130 involved undergraduate students, we investigated the post-effects on team performances and behavioral-driven factors when providing predictive analytics in retrospectives.Besides measures for productivity, we consider human factors, e.g., team structures, communication, meetings and mood affects in teams as well as project success metrics.We developed a unique JIRA plugin called ProDynamics that collects performance information from projects and derives trend-insights for next sprints.The ProDynamics plugin enables the use of a times series and neural network model within a JIRA system to interpret factorial dependencies and behavioral pattern, thus to show the next sprint course of a team. Fabian Kortum, Jil Klünder, Wasja Brunotte, Kurt Schneider |
SEKE | 3 |
| 2019 | Detecting Security Vulnerabilities using Clone Detection and Community KnowledgeabstractFaced with the severe financial and reputation implications associated with data breaches, enterprises now recognize security as a top concern for software analysis tools.While software engineers are typically not equipped with the required expertise to identify vulnerabilities in code, community knowledge in the form of publicly available vulnerability databases could come to their rescue.For example, the Common Vulnerabilities and Exposures Database (CVE) contains data about already reported weaknesses.However, the support with available examples in these databases is scarce.CVE entries usually do not contain example code for a vulnerability, its exploit or patch.They just link to reports or repositories that provide this information.Manually searching these sources for relevant information is time-consuming and error-prone.In this paper, we propose a vulnerability detection approach based on community knowledge and clone detection.The key idea is to harness available example source code of software weaknesses, from a large-scale vulnerability database, which are matched to code fragments using clone detection.We leverage a clone detection technique from the literature, which we adapted to make it applicable to vulnerability databases.In an evaluation based on 20 reports and affected projects, our approach showed good precision and recall. Fabien Patrick Viertel, Wasja Brunotte, Daniel Strüber 0001, Kurt Schneider |
SEKE | 2 |