EDBT 2026 Demo / reviewers in the wild / expert
Alfusainey Jallow
dblp:385/6372
· DBLP profile ↗
2ranked-venue papers
2as first author
2since 2021 · last 2025
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 2 first-author · 2 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Software engineering, system software, and programming languages
2 papers |
Software maintenance and evolution · 60% Empirical software engineering · 40% | |
| Network and information security
2 papers |
Systems and software security · 100% |
Topics — the 5 heaviest of 5, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Empirical software engineering
mining software repositories |
1.1 | 2 | 2025 | Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025 Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024 |
Software maintenance and evolution › code reuse
code snippet reuse |
0.9 | 1 | 2025 | Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025 |
Systems and software security › software supply chain security
vulnerability propagation |
0.8 | 1 | 2024 | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024 |
Software maintenance and evolution
code reuse |
0.8 | 1 | 2024 | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software Security · SP 2024 |
Systems and software security
vulnerability analysis |
0.3 | 1 | 2025 | Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets · USENIX Security Symposium 2025 |
Methods — techniques the papers use, named apart from their topics
empirical study · 1.5code clone detection · 1.5
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Stack Overflow Meets Replication: Security Research Amid Evolving Code Snippets
Alfusainey Jallow, Sven Bugiel |
USENIX Security Symposium | 1 |
| 2024 | Measuring the Effects of Stack Overflow Code Snippet Evolution on Open-Source Software SecurityabstractThis paper assesses the effects of Stack Overflow code snippet evolution on the security of open-source projects. Users on Stack Overflow actively revise posted code snippets, sometimes addressing bugs and vulnerabilities. Accordingly, developers that reuse code from Stack Overflow should treat it like any other evolving code dependency and be vigilant about updates. It is unclear whether developers are doing so, to what extent outdated code snippets from Stack Overflow are present in GitHub projects, and whether developers miss security-relevant updates to reused snippets.To shed light on those questions, we devised a method to 1) detect outdated code snippets versions from 1.5M Stack Overflow snippets in 11,479 popular GitHub projects and 2) detect security-relevant updates to those Stack Overflow code snippets not reflected in those GitHub projects. Our results show that developers did not update dependent code snippets when those evolved on Stack Overflow. We found that 2,405 code snippet versions reused in 2,109 GitHub projects were outdated, with 43 projects missing fixes to bugs and vulnerabilities on Stack Overflow. Those 43 projects containing outdated, insecure snippets were forked on average 1,085 times (max. 16,121), indicating that our results are likely a lower bound for affected code bases. An important insight from our work is that treating Stack Overflow code as purely static code impedes holistic solutions to the problem of copying insecure code from Stack Overflow. Instead, our results suggest that developers need tools that continuously monitor Stack Overflow for security warnings and code fixes for reused code snippets and not only warn during copy-pasting. Alfusainey Jallow, Michael Schilling 0001, Michael Backes 0001, Sven Bugiel |
SP | 1 |