Zainab Aamir

dblp:336/4062 · DBLP profile ↗
← Back
2ranked-venue papers
0as first author
2since 2021 · last 2025
0009-0006-2000-6823ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Human-computer interaction and pervasive computing
1 paper
Immersive interaction · 44% Usability and user experience research · 44% Human-AI interaction · 13%
Network and information security
1 paper
Systems and software security · 87% Usable security · 13%
Computer graphics and multimedia
1 paper
Visualization and visual analytics · 100%
Software engineering, system software, and programming languages
1 paper
Program analysis · 100%

Topics — the 7 heaviest of 8, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Visualization and visual analytics › visual analytics
immersive analytics
0.912025
Explainable XR: Understanding User Behaviors of XR Environments Using LLM-Assisted Analytics Framework · IEEE Trans. Vis. Comput. Graph. 2025
Immersive interaction › extended reality
extended reality interaction
0.912025
Explainable XR: Understanding User Behaviors of XR Environments Using LLM-Assisted Analytics Framework · IEEE Trans. Vis. Comput. Graph. 2025
Usability and user experience research
user behavior analysis
0.912025
Explainable XR: Understanding User Behaviors of XR Environments Using LLM-Assisted Analytics Framework · IEEE Trans. Vis. Comput. Graph. 2025
Systems and software security › vulnerability discovery
regular expression denial of service
0.712023
Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies · SP 2023
Systems and software security
software vulnerability
0.712023
Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies · SP 2023
Program analysis › static analysis
vulnerability detection
0.712023
Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies · SP 2023
Human-AI interaction › large language model interaction
LLM-assisted visual analytics
0.312025
Explainable XR: Understanding User Behaviors of XR Environments Using LLM-Assisted Analytics Framework · IEEE Trans. Vis. Comput. Graph. 2025

Methods — techniques the papers use, named apart from their topics

visual analytics · 1.7user study · 1.7large language model · 1.7static analysis · 1.3fix strategies · 1.3anti-patterns · 1.3
YearPublicationVenuePosition
2025 Explainable XR: Understanding User Behaviors of XR Environments Using LLM-Assisted Analytics Framework
abstract
We present Explainable XR, an end-to-end framework for analyzing user behavior in diverse eXtended Reality (XR) environments by leveraging Large Language Models (LLMs) for data interpretation assistance. Existing XR user analytics frameworks face challenges in handling cross-virtuality - AR, VR, MR - transitions, multi-user collaborative application scenarios, and the complexity of multimodal data. Explainable XR addresses these challenges by providing a virtuality-agnostic solution for the collection, analysis, and visualization of immersive sessions. We propose three main components in our framework: (1) A novel user data recording schema, called User Action Descriptor (UAD), that can capture the users' multimodal actions, along with their intents and the contexts; (2) a platform-agnostic XR session recorder, and (3) a visual analytics interface that offers LLM-assisted insights tailored to the analysts' perspectives, facilitating the exploration and analysis of the recorded XR session data. We demonstrate the versatility of Explainable XR by demonstrating five use-case scenarios, in both individual and collaborative XR applications across virtualities. Our technical evaluation and user studies show that Explainable XR provides a highly usable analytics solution for understanding user actions and delivering multifaceted, actionable insights into user behaviors in immersive environments.
Yoonsang Kim, Zainab Aamir, Mithilesh Kumar Singh, Saeed Boorboor, Klaus Mueller 0001, Arie E. Kaufman
IEEE Trans. Vis. Comput. Graph.2
2023 Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies
abstract
Regular expressions are used for diverse purposes, including input validation and firewalls. Unfortunately, they can also lead to a security vulnerability called ReDoS (Regular Expression Denial of Service), caused by a super-linear worst-case execution time during regex matching. Due to the severity and prevalence of ReDoS, past work proposed automatic tools to detect and fix regexes. Although these tools were evaluated in automatic experiments, their usability has not yet been studied; usability has not been a focus of prior work. Our insight is that the usability of existing tools to detect and fix regexes will improve if we complement them with anti-patterns and fix strategies of vulnerable regexes.We developed novel anti-patterns for vulnerable regexes, and a collection of fix strategies to fix them. We derived our anti-patterns and fix strategies from a novel theory of regex infinite ambiguity — a necessary condition for regexes vulnerable to ReDoS. We proved the soundness and completeness of our theory. We evaluated the effectiveness of our anti-patterns, both in an automatic experiment and when applied manually. Then, we evaluated how much our anti-patterns and fix strategies improve developers’ understanding of the outcome of detection and fixing tools. Our evaluation found that our anti-patterns were effective over a large dataset of regexes (N=209,188): 100% precision and 99% recall, improving the state of the art 50% precision and 87% recall. Our anti-patterns were also more effective than the state of the art when applied manually (N=20): 100% developers applied them effectively vs. 50% for the state of the art. Finally, our anti-patterns and fix strategies increased developers’ understanding using automatic tools (N=9): from median "Very weakly" to median "Strongly" when detecting vulnerabilities, and from median "Very weakly" to median "Very strongly" when fixing them.
Sk Adnan Hassan, Zainab Aamir, James C. Davis 0001, Francisco Servant
SP2