EDBT 2026 Demo / reviewers in the wild / expert
Clemente Izurieta
dblp:26/3781
· DBLP profile ↗
33ranked-venue papers
7as first author
13since 2021 · last 2026
0000-0002-1002-3906ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 28 · 6 first-author · 12 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 1 since 2021Theory of computation · 2Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Barriers to Use: Perspectives on Environmental Research Software
Yvette D. Hastings, Jeffrey C. Carver, Clemente Izurieta, Ann Marie Reinhold |
ICSOFT | 3 |
| 2024 | Deciphering Discrepancies: A Comparative Analysis of Docker Image SecurityabstractAs the use of microservices continues to grow and become a foundational approach to architecting software solutions, ensuring the security of microservices is paramount. Docker images have emerged as the predominant solution to containerize microservices-and thus, Docker images are becoming a large attack surface. Thus, reducing vulnerabilities in Docker images will reduce microservice cyberattacks. A common way to find vulnerabilities in Docker images employs static analysis tools like Trivy and Grype. However, these tools frequently generate disparate vulnerability reports when analyzing the same Docker image, thus causing uncertainty in tool selection. We collected 927 Docker images, analyzed them with Trivy and Grype, and compared the vulnerabilities reported in each image. Among the 865 images found to have vulnerabilities, Trivy and Grype disagreed on both the number of vulnerabilities and the vulnerability IDs found therein. Since both tools interface with external vulnerability databases, some discrepancies can be attributed to how the tools interface with these external resources. The external vulnerability databases partially overlap and frequently contradict one another, thereby creating challenges for static analysis tool developers and end users alike. This New Ideas and Emerging Results (NIER) study contains new and critical information that practitioners need for selecting and using static analysis tools-given that increases in the use of Docker technologies means increases in the size of the attack surfaces. Brittany Boles, Eric O'Donoghue, Assoumer Redempta Manzi Muneza, Garrett Perkins, Clemente Izurieta, Ann Marie Reinhold |
SCAM | 5 |
| 2024 | A study of behavioral decay in design patternsabstractAbstract Design patterns represent a means of communicating reusable solutions to common problems, provided they are implemented and maintained correctly. However, many design pattern instances erode as they age, sacrificing qualities they once provided. Identifying such instances of pattern decay is valuable because it allows for proactive attempts to extend the longevity and quality attributes of pattern components. Apart from structural decay, design patterns can exhibit symptoms of behavioral decay. We utilized a taxonomy that characterizes these negative behaviors and designed a case study wherein we measured structural and behavioral decay, hereafter referred to as pattern grime, as well as pattern quality and size, across pattern evolutions. We evaluated the relationships between structural and behavioral grime and found statistically significant cases of strong correlations between specific types of structural and behavioral grime. Furthermore, we extended the QATCH operational software quality model to incorporate design pattern evolution metrics and measured and correlated software quality to the presence of behavioral grime in software systems. Our results suggest a strong inverse relationship between software quality and behavioral grime. Derek Reimanis, Clemente Izurieta |
J. Softw. Evol. Process. | 2 |
| 2024 | A Comprehensive View on TD Prevention Practices and Reasons for Not Preventing ItabstractContext . Technical debt (TD) prevention allows software practitioners to apply practices to avoid potential TD items in their projects. Aims . To uncover and prioritize, from the point of view of software practitioners, the practices that could be used to avoid TD items, the relations between these practices and the causes of TD, and the practice avoidance reasons (PARs) that could explain the failure to prevent TD. Method . We analyze data collected from six replications of a global industrial family of surveys on TD, totaling 653 answers. We also conducted a follow up survey to understand the importance level of analyzed data. Results . Most practitioners indicated that TD could be prevented, revealing 89 prevention practices and 23 PARs for explaining the failure to prevent TD. The article identifies statistically significant relationships between preventive practices and certain causes of TD. Further, it prioritizes the list of practices, PARs, and relationships regarding their level of importance for TD prevention based on the opinion of software practitioners. Conclusion . This work organizes TD prevention practices and PARs in a conceptual map and the relationships between practices and causes of TD in a Sankey diagram to help the visualization of the body of knowledge reported in this study. Sávio Freire, Alexia Pacheco, Nicolli Rios, Boris Perez, Camilo Castellanos, Darío Correal, Robert Ramac, Vladimir Mandic, Nebojsa Tausan, Gustavo López 0001, Manoel G. Mendonça, Davide Falessi, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
ACM Trans. Softw. Eng. Methodol. | 13 |
| 2023 | Dictionary Learning on Graph Data with Weisfieler-Lehman Sub-Tree Kernel and KsvdabstractGraph representation has gained wide popularity as a data representation method in many applications. Graph embedding methods convert graphs to a vector representation and are an important part of a data processing pipeline. In this paper, we utilize sparse dictionary learning techniques as a graph embedding solution. Sparse representation has notable applications in signal image processing. Inspired by the Graph2Vec algorithm, we aim to modify the Doc2Vec model training portion of the Graph2Vec by incorporating unsupervised dictionary learning. We investigate the viability of using the sparse dictionary learning technique KSVD for graph data. We train the dictionary on Weisfeiler-Lehman graph sub-tree kernel features. Furthermore, we use graph-based labeled data sets to compare classification results with several existing graph embedding methods. Findings show that using the learned sparse coefficients as features for a supervised machine learning algorithm provides on-par classification results when compared to other graph embedding methods. L. K. G. Liyanage, Reese Pearsall, Clemente Izurieta, Bradley M. Whitaker |
ICASSP | 3 |
| 2023 | Assessing IDEA Diagrams for Supporting Analysis of Capabilities and Issues in Technical Debt Management
Sávio Freire, Verusca Rocha, Manoel G. Mendonça, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
PROFES (1) | 4 |
| 2023 | A Test Suite Minimization Technique for Testing Numerical ProgramsabstractMetamorphic testing is a technique that uses metamorphic relations (i.e., necessary properties of the software under test), to construct new test cases (i.e., follow-up test cases), from existing test cases (i.e., source test cases). Metamorphic testing allows for the verification of testing results without the need of test oracles (a mechanism to detect the correctness of the outcomes of a program), and it has been widely used in many application domains to detect real-world faults. Numerous investigations have been conducted to further improve the effectiveness of metamorphic testing. Recent studies have emerged suggesting a new research direction on the generation and selection of source test cases that are effective in fault detection. Herein, we present two important findings: i) a mutant reduction strategy that is applied to increase the testing efficiency of source test cases, and ii) a test suite minimization technique to help reduce the testing costs without trading off fault-finding effectiveness. To validate our results, an empirical study was conducted to demonstrate the increase in efficiency and fault-finding effectiveness of source test cases. The results from the experiment provide evidence to support our claims. Prashanta Saha, Clemente Izurieta, Upulee Kanewala |
SERA | 2 |
| 2023 | Software practitioners' point of view on technical debt payment
Sávio Freire, Nicolli Rios, Boris Perez, Camilo Castellanos, Darío Correal, Robert Ramac, Vladimir Mandic, Nebojsa Tausan, Gustavo López 0001, Alexia Pacheco, Manoel G. Mendonça, Davide Falessi, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
J. Syst. Softw. | 13 |
| 2022 | A Mapping Study of Security Vulnerability Detection Approaches for Web ApplicationsabstractFor the last few decades, the number of security vulnerabilities has been increasing with the development of web applications. The domain of Web Applications is evolving. As a result, many empirical studies have been carried out to address different security vulnerabilities. However, an analysis of existing studies is needed before developing new security vulnerability testing techniques. We perform a systematic mapping study documenting state-of-the-art empirical research in web application security vulnerability detection. The aim is to describe a roadmap for synthesizing the documented empirical research. Existing research and literature have been reviewed using a systematic mapping study. Our study reports on work dating from 2001 to 2021. The initial search retrieved 150 papers from the IEEE Xplore and ACM Digital Libraries, of which 76 were added to the study. A classification scheme is derived based on the primary studies. The study demonstrates that vulnerability detection in web applications is an ongoing field of research and that the number of publications is increasing. Our study helps illuminate research areas that need more consideration. Karishma Rahman, Clemente Izurieta |
SEAA | 2 |
| 2022 | Introduction to the Special Issue on value and waste in software engineering
Michael Felderer, Matthias Galster, Clemente Izurieta, Carolyn B. Seaman |
Inf. Softw. Technol. | 3 |
| 2022 | Prevalence, common causes and effects of technical debt: Results from a family of surveys with the IT industry
Robert Ramac, Vladimir Mandic, Nebojsa Tausan, Nicolli Rios, Sávio Freire, Boris Perez, Camilo Castellanos, Darío Correal, Alexia Pacheco, Gustavo López 0001, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
J. Syst. Softw. | 11 |
| 2021 | How do Technical Debt Payment Practices Relate to the Effects of the Presence of Debt Items in Software Projects?abstractContext: Knowing the effects of technical debt (TD) can support software development teams in the prioritization of TD items to pay off. However, little is known about the relations between the effects of TD and TD payment practices. Having this knowledge can provide valuable information for decision making about which payment practice can be applied given the presence of specific effects of TD. Aims: To investigate, from the point of view of software practitioners, (i) which TD payment practices have been used when certain effects of the presence of debt are felt in software projects and (ii) the reasons for not paying debt items despite the effects they are causing to the project. Method: We analyze quantitatively and qualitatively data collected from a survey with 432 practitioners across four countries. Results: Among the identified relations, the practice "code refactoring" is commonly used to pay debt items off when the effects "delivery delay" and "rework" are felt in software projects. On the other hand, when practitioners face the TD effects "low external quality" and "delivery delay", ,they commonly justify the non- payment of the debt items indicating the need of "focusing on short term goals". Conclusion: We organize the relationship between TD effects, and payment practices and reasons for not eliminating debt items. All this information is structured in an alluvial diagram, which can facilitate the visualization of the identified relations. Sávio Freire, Nicolli Rios, Boris Perez, Darío Torres, Manoel G. Mendonça, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
SANER | 6 |
| 2021 | Technical debt payment and prevention through the lenses of software architects
Boris Perez, Camilo Castellanos, Darío Correal, Nicolli Rios, Sávio Freire, Rodrigo O. Spínola, Carolyn B. Seaman, Clemente Izurieta |
Inf. Softw. Technol. | 8 |
| 2020 | Surveying Software Practitioners on Technical Debt Payment Practices and Reasons for not Paying off Debt ItemsabstractBackground: Little is known about the practices used for technical debt (TD) payment. The study of payment practices, as well as the reasons for not applying them, can help practitioners to control and manage TD items. Aims: To investigate, from the point of view of software practitioners, if TD items have been paid off in software projects, the practices that have been used to pay off TD and the reasons that hamper the implementation of these practices. Method: We analyzed - both quantitatively and qualitatively - a corpus of responses from a survey of 432 practitioners, from four countries, about the possibility of TD payment. Results: We found that, for most of the cases, TD items have not been eliminated from software projects. The main reasons for not paying off TD are lack of organizational interest, low priority on the debt, focus on short-term goals, cost, and lack of time. On the other hand, we identified that code refactoring, design refactoring, and update system documentation are the most used practices for TD payment. Practitioners also cited practices related to the prevention, prioritization, and creation of a favorable setting as part of TD payment initiatives. Conclusion: This paper summarizes the identified practices and reasons for not paying off debt items in a map. Our map reveals that the majority of payment practices are of a technical nature while the majority of reasons for not paying off debts are associated with non-technical issues. Sávio Freire, Nicolli Rios, Boris Gutierrez, Darío Torres, Manoel G. Mendonça, Clemente Izurieta, Carolyn B. Seaman, Rodrigo O. Spínola |
EASE | 6 |
| 2020 | Hearing the Voice of Software Practitioners on Causes, Effects, and Practices to Deal with Documentation Debt
Nicolli Rios, Leonardo Mendes, Cristina Cerdeiral, Ana Patrícia F. M. Mascarenhas, Boris Perez, Darío Correal, Hernán Astudillo, Carolyn B. Seaman, Clemente Izurieta, Gleison Santos, Rodrigo O. Spínola |
REFSQ | 9 |
| 2019 | Leveraging secdevops to tackle the technical debt associated with cybersecurity attack tacticsabstractContext: Managing technical debt (TD) associated with external cybersecurity attacks on an organization can significantly improve decisions made when prioritizing which security weaknesses require attention. Whilst source code vulnerabilities can be found using static analysis techniques, malicious external attacks expose the vulnerabilities of a system at runtime and can sometimes remain hidden for long periods of time. By mapping malicious attack tactics to the consequences of weaknesses (i.e. exploitable source code vulnerabilities) we can begin to understand and prioritize the refactoring of the source code vulnerabilities that cause the greatest amount of technical debt on a system. Goal: To establish an approach that maps common external attack tactics to system weaknesses. The consequences of a weakness associated with a specific attack technique can then be used to determine the technical debt principal of said violation; which can be measured in terms of loss of business rather than source code maintenance. Method: We present a position study that uses Jaccard similarity scoring to examine how 11 malicious attack tactics can relate to Common Weakness Enumerations (CWEs). Results: We conduct a study to simulate attacks, and generate dependency graphs between external attacks and the technical consequences associated with CWEs. Conclusion: The mapping of cyber security attacks to weaknesses allows operational staff (SecDevOps) to focus on deploying appropriate countermeasures and allows developers to focus on refactoring the vulnerabilities with the greatest potential for technical debt. Clemente Izurieta, Mary Prouty |
TechDebt@ICSE | 1 |
| 2019 | Behavioral Evolution of Design Patterns: Understanding Software Reuse Through the Evolution of Pattern Behavior
Derek Reimanis, Clemente Izurieta |
ICSR | 2 |
| 2018 | A position study to investigate technical debt associated with security weaknessesabstractContext: Managing technical debt (TD) associated with potential security breaches found during design can lead to catching vulnerabilities (i.e., exploitable weaknesses) earlier in the software lifecycle; thus, anticipating TD principal and interest that can have decidedly negative impacts on businesses. Goal: To establish an approach to help assess TD associated with security weaknesses by leveraging the Common Weakness Enumeration (CWE) and its scoring mechanism, the Common Weakness Scoring System (CWSS). Method: We present a position study with a five-step approach employing the Quamoco quality model to operationalize the scoring of architectural CWEs. Results: We use static analysis to detect design level CWEs, calculate their CWSS scores, and provide a relative ranking of weaknesses that help practitioners identify the highest risks in an organization with a potential to impact TD. Conclusion: CWSS is a community agreed upon method that should be leveraged to help inform the ranking of security related TD items. Clemente Izurieta, David Rice, Kali Kimball, Tessa Valentien |
TechDebt@ICSE | 1 |
| 2017 | An Industry Perspective to Comparing the SQALE and Quamoco Software Quality ModelsabstractContext: We investigate the different perceptions of quality provided by leading operational quality models when used to evaluate software systems from an industry perspective. Goal: To compare and evaluate the quality assessments of two competing quality models and to develop an extensible solution to meet the quality assurance measurement needs of an industry stakeholder -The Construction Engineering Research Laboratory (CERL). Method: In cooperation with our industry partner TechLink, we operationalize the Quamoco quality model and employ a multiple case study design comparing the results of Quamoco and SQALE, two implementations of well known quality models. The study is conducted across current versions of several open source software projects sampled from GitHub and commercial software for sustainment management systems implemented in the C# language from our industry partner. Each project represents a separate embedded unit of study in a given context -open source or commercial. We employ inter-rater agreement and correlation analysis to compare the results of both models, focusing on Maintainability, Reliability, and Security assessments. Results: Our observations suggest that there is a significant disconnect between the assessments of quality under both quality models. Conclusion: In order to support industry adoption, additional work is required to bring competing implementations of quality models into alignment. This exploratory case study helps us shed light into this problem. Clemente Izurieta, Isaac Griffith, Chris Huvaere |
ESEM | 1 |
| 2015 | A Mapping Study of Software Causal Factors for Improving MaintenanceabstractContext: Software maintenance is important to keep existing software systems functional for organizations or users that depend on that software. Goal: We aim to identify the factors, i.e., software characteristics such as code complexity, leading to maintenance problems. Method: We present a Mapping Study (MS) on controlled experiments that investigated software characteristics related to defects during maintenance. Results: The search strategy identified 78 papers, of which 9 have been included in our study, dated from 1985 to 2013, after applying our inclusion and exclusion criteria. We extracted data from these papers to identify the research methods, and the independent, dependent, blocked, and measured variables. Conclusions: Our MS results point to a weak evidence on software factors causing defects during maintenance. Stronger evidence can be developed via more controlled experiments that address multiple independent variables and hold the software objects constant. Carson Carroll, Davide Falessi, Vanessa Forney, Alexa Frances, Clemente Izurieta, Carolyn B. Seaman |
ESEM | 5 |
| 2014 | Impacts of design pattern decay on system qualityabstractContext Software systems need to be of high enough quality to enable growth and stability. Melissa R. Dale, Clemente Izurieta |
ESEM | 2 |
| 2014 | Design pattern decay: the case for class grimeabstractContext: We investigate class grime, a form of design pattern decay, wherein classes of the pattern realization have extraneous attributes or methods, which obfuscate the intended design of a pattern. Goal: To expand the taxonomy of class grime using properties of class cohesion. Using this expanded taxonomy we explore the effect that forms of class grime have on pattern realization understandability. Method: A pilot study utilizing a formal experiment to explore the effects of class grime on design pattern understandability. The experiments used simulated injection of 8 types of class grime into design pattern realizations randomly selected from 16 design pattern types from a set of 6541 realizations from 520 distinct software systems. Results: We found that for each of the 8 identified class grime forms, understandability was negatively affected. Conclusion: This work serves as early communication of research for the validation of the extended taxonomy as well as the method of grime injection used in the experiment. Isaac Griffith, Clemente Izurieta |
ESEM | 2 |
| 2014 | A replication case study to measure the architectural quality of a commercial systemabstractContext: Long-term software management decisions are directly impacted by the quality of the software's architecture. Goal: Herein, we present a replication case study where structural information about a commercial software system is used in conjunction with bug-related change frequencies to measure and predict architecture quality. Method: Metrics describing history and structure were gathered and then correlated with future bug-related issues; the worst of which were visualized and presented to developers. Results: We identified dependencies between components that change together even though they belong to different architectural modules, and as a consequence are more prone to bugs. We validated these dependencies by presenting our results back to the developers. The developers did not identify any of these dependencies as unexpected, but rather architectural necessities. Conclusions: This replication study adds to the knowledge base of CLIO (a tool that detects architectural degradations) by incorporating a new programming language (C++) and by externally replicating a previous case study on a separate commercial code base. Additionally, we provide lessons learned and suggestions for future applications of CLIO. Derek Reimanis, Clemente Izurieta, Rachael Luhr, Lu Xiao 0001, Yuanfang Cai, Gabe Rudy |
ESEM | 2 |
| 2014 | Comparing four approaches for technical debt identification
Nico Zazworka, Antonio Vetrò, Clemente Izurieta, Sunny Wong 0001, Yuanfang Cai, Carolyn B. Seaman, Forrest Shull |
Softw. Qual. J. | 3 |
| 2013 | A multiple case study of design pattern decay, grime, and rot in evolving software systems
Clemente Izurieta, James M. Bieman |
Softw. Qual. J. | 1 |
| 2010 | Effects of the number of developers on code quality in open source software: a case studyabstractEleven open source software projects were analyzed to determine if the number of committing developers impacts code quality. We use cyclomatic complexity, lines of code per function, comment density, and maximum nesting as surrogate measures of code quality. We find no significant evidence to suggest that the number of committing developers affects the quality of software. Brandon Norick, Justin Krohn, Eben Howard, Ben Welna, Clemente Izurieta |
ESEM | 5 |
| 2010 | Object oriented design pattern decay: a taxonomyabstractSoftware designs decay over time. While most studies focus on decay at the system level, this research studies design decay on well understood micro architectures, design patterns. Formal definitions of design patterns provide a homogeneous foundation that can be used to measure deviations as pattern realizations evolve. Empirical studies have shown modular grime to be a significant contributor to design pattern decay. Modular grime is observed when increases in the coupling of design pattern classes occur in ways unintended by the original designer. Further research is necessary to formally categorize distinct forms of modular grime. We identify three properties of coupling relationships that are used to classify subsets of modular grime. A taxonomy is presented which uses these properties to group modular grime into six disjoint categories. Illustrative examples of grime build-up are provided to demonstrate the taxonomy. A pilot study is used to validate the taxonomy and provide initial empirical evidence of the proposed classification. Travis Schanz, Clemente Izurieta |
ESEM | 2 |
| 2010 | An implicit representation of chordal comparability graphs in linear time
Andrew R. Curtis, Clemente Izurieta, Benson L. Joeris, Scott M. Lundberg, Ross M. McConnell |
Discret. Appl. Math. | 2 |
| 2009 | Comparison of JSON and XML Data Interchange Formats: A Case Study
Nurzhan Nurseitov, Michael Paulson, Randall Reynolds, Clemente Izurieta |
CAINE | 4 |
| 2008 | Testing Consequences of Grime Buildup in Object Oriented Design PatternsabstractEvidence suggests that as software ages the original realizations of design patterns remain in place, and participants in design pattern realizations accumulate "grime" - non-pattern-related code. This research examines the consequences that grime buildup has on the testability of general purpose design patterns. Test cases put in place during the design phase and initial implementation of a project can become ineffective as the system matures. The evolution of a design due to added functionality or defect fixing increases the coupling and dependencies between many classes that must be tested. We show that as systems age, the growth of grime and the appearance of anti-patterns increase testing requirements. Early recognition and removal of grime and anti-patterns can potentially improve system testability. Clemente Izurieta, James M. Bieman |
ICST | 1 |
| 2007 | How Software Designs Decay: A Pilot Study of Pattern EvolutionabstractA common belief is that software designs decay as systems evolve. This research examines the extent to which software designs actually decay by studying the aging of design patterns in successful object oriented systems. Aging of design patterns is measured using various types of decay indices developed for this research. Decay indices track the internal structural changes of a design pattern realization and the code that surrounds the realization. Hypotheses for each kind of decay are tested. We found that the original design pattern functionality remains, and pattern decay is due to the "grime ", non-pattern code, that grows around the pattern realization. Clemente Izurieta, James M. Bieman |
ESEM | 1 |
| 2006 | An Implicit Representation of Chordal Comparabilty Graphs in Linear-Time
Andrew R. Curtis, Clemente Izurieta, Benson L. Joeris, Scott M. Lundberg, Ross M. McConnell |
WG | 2 |
| 2003 | Semi Greedy Algorithm for Finding Connectivity in Microchip Physical Layouts
Clemente Izurieta |
CAINE | 1 |