EDBT 2026 Demo / reviewers in the wild / expert
Manar H. Alalfi
dblp:49/2794
· DBLP profile ↗
29ranked-venue papers
7as first author
12since 2021 · last 2026
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 26 · 7 first-author · 10 since 2021Applied, interdisciplinary, general and emerging computing · 6 · 5 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-authorSecurity and privacy · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | GasZero: A Neuro-Symbolic Approach to Solidity Gas Optimization
Sourena Khanzadeh, Manar H. Alalfi |
COMPSAC | 2 |
| 2026 | An Agentic AI Framework for Conflict-Aware Smart Home Automation via Natural Language
Sayyada Aisha Mehvish, Manar H. Alalfi |
SANER | 2 |
| 2026 | AgentHAB: Automating OpenHAB Rule Generation with Multi-Agent Policy and Validation
Roxie Reginold, Manar H. Alalfi |
SANER | 2 |
| 2026 | Cracking IoT security: can LLMs outsmart static analysis tools?
Jason Quantrill, Noura Khajehnouri, Manar H. Alalfi |
Empir. Softw. Eng. | 4 |
| 2025 | SmartTinkerer: Bridging Smart Home Testing Gaps with LLM, Digital Twin & Reinforcement LearningabstractThere has been a significant rise in the use of Internet of Things (IoT) devices in recent years, but along with the increase in usage, there’s also a rise in security vulnerabilities in the IoT software. The security vulnerabilities are difficult to find, and even more difficult to exploit dynamically. The software technologies, particularly used in the Samsung SmartThings environment, have a huge gap in terms of deprecated language usage, having a good testing environment and a security vulnerability scanning. This paper introduces a new tool, SmartTinkerer , filling these gaps by employing LLMs to translate deprecated language to new APIs, creating a digital twin simulating a virtual smart home device system for a testing environment and using reinforcement learning on the digital simulation to better scan for vulnerabilities. Samad Alias Nyein Chan, Manar H. Alalfi |
COMPSAC | 2 |
| 2025 | KASTroid: A Static Taint Analysis Framework for Kotlin-Based Android ApplicationsabstractWe introduce KASTroid1, a static taint analysis framework designed to detect information leakage vulnerabilities in Kotlin-based Android applications, with a focus on insecure usage of broadcasts. As Kotlin increasingly replaces Java as the preferred language for Android development, ensuring the security of inter-component communication, particularly through broadcasts, is critical. KASTroid employs a novel static analysis approach to identify tainted flows arising from unsafe broadcast practices, such as the use of implicit broadcasts via sendBroadcast, which can expose sensitive user data to unauthorized applications. We evaluated KASTroid on a dataset of 1,716 Kotlin Android applications and found that over 70% of broadcasts are implicit, posing significant privacy risks. To demonstrate the framework’s effectiveness, we present a case study on a previous version of AndroidAPS, a medical application, where KASTroid identified unsafe broadcast usage that could leak sensitive information to other local applications. Our findings highlight the importance of secure broadcast practices and demonstrate KASTroid’s ability to assist developers in detecting and remedying such vulnerabilities. Bara' Nazzal, Manar H. Alalfi, James R. Cordy |
COMPSAC | 2 |
| 2025 | oHIT - A framework for openHAB Interaction Threats Identification in IoT SystemsabstractAs we increase our reliance upon Internet of Things (IoT) systems, we increase our convenience and efficiency, but we also expose ourselves to significant safety challenges, particularly in home automation platforms like openHAB. openHAB’s rule-based trigger-condition-action (TCA) paradigm allows for extensive flexibility in designing one’s home system, but increases the risk of unintended rule interactions, leading to unpredictable or unsafe behaviors. This paper presents oHIT, a novel framework for detecting Rule Interaction Threats in openHAB systems. oHIT systematically analyzes openHAB rules files, identifies foundational threat categories — including Action Contradiction, Trigger Cascade, and Condition Cascade — and differentiates between strong and weak variations of these threats. The framework leverages static analysis, transformation techniques, and symbolic reasoningto enable efficient threat detection. Evaluations show that oHIT achieves overall precision of 79% with a recall of 100% in detecting Rule Interaction threats on two real-world datasets, demonstrating oHIT’s effectiveness. This research addresses a critical gap in IoT safety analysis, paving the way for safer and more reliable automation in interconnected environments. Jason Quantrill, Noura Khajehnouri, Manar H. Alalfi |
COMPSAC | 3 |
| 2025 | A Modeling and Static Analysis Approach for the Verification of Privacy and Safety Properties in Kotlin Android AppsabstractThe safety and privacy of medical devices is critical, as they directly affect the health of users and handle sensitive personal data. Ensuring that these devices meet safety and security standards is essential, especially with the rise of do-it-yourself solutions such as open-source artificial pancreas systems (APSs) for insulin delivery. In this work, we study AndroidAPS, an APS controller written in Kotlin, and propose an approach to detect safety and security issues. We develop a modeling and analysis framework for Kotlin applications that extracts a structural model and supports detecting logging vulnerabilities and ensuring the application of safety constraints. We conduct two experiments. The first examines logging behavior to check for privacy risks. Out of $\mathbf{3, 0 5 9 ~ l o g g i n g}$ instances, our tool identified 48 sinks that received 144 sensitive flows, with $68 \%$ precision due to coarse-grained flagging. The second experiment verifies that calculation-related values are validated against safety constraints before being set to the profile. We show that AndroidAPS generally adheres to its safety design properties, but it has one calculation-related value that is not explicitly validated at the plugin level and only partially validated earlier in the flow. Bara' Nazzal, Manar H. Alalfi, James R. Cordy |
PST | 2 |
| 2023 | Security and Safety Verification in IoT AppsabstractInnovative Internet of Things (IoT) technologies promise to automate users' routines, thereby improving their daily lives. With the rapid increase in IoT-connected devices, unexpected behaviors resulting from unplanned or unanticipated interactions between numerous IoT applications pose significant risks, particularly in critical domains like healthcare systems, automotive, manufacturing, and smart cities. This thesis proposes a Model-Driven Engineering (MDE) approach to support the verification of safety and security properties in interacting heterogeneous IoT applications. The proposed method intends to apply to both existing IoT applications and those under development, ensuring these apps operate safely and securely in their interactions. Lobna Abuserrieh, Manar H. Alalfi |
ICSME | 2 |
| 2023 | An empirical study on the complexity, security and maintainability of Ethereum-based decentralized applications (DApps)abstractThe Ethereum blockchain’s smart contract is a programmable transaction that performs general-purpose computations and can be executed automatically on the blockchain. Leveraging this component, blockchain technology (BT) has grown beyond the scope of cryptocurrencies and can now be applicable in various industries other than finance. In this paper, we investigated the current trends in Ethereum-based decentralized applications (DApps) to be able to categorize and analyze the DApps to measure the complexity of smart contracts behind them, their level of security and their correlation to the maintainability of the DApps. We leveraged the source code analysis, security analysis, and the developmental metadata of the DApps to infer this correlation. Based on our findings, we concluded that the maintainability of Ethereum DApps is proportional to the code size, number of functions, and, most importantly, the number of outgoing invocations and statements in the smart contracts. Noama Fatima Samreen, Manar H. Alalfi |
Blockchain Res. Appl. | 2 |
| 2022 | Predicting sensitive information leakage in IoT applications using flows-aware machine learning approach
Hajra Naeem, Manar H. Alalfi |
Empir. Softw. Eng. | 2 |
| 2022 | A mutation framework for evaluating security analysis tools in IoT applicationsabstractSummary With the growing and widespread use of Internet of Things (IoT) in our daily life, its security is becoming more crucial. To ensure information security, we require better security analysis tools for IoT applications. Hence, this paper presents an automated framework to evaluate taint‐flow analysis tools in the domain of IoT applications. First, we propose a set of mutational operators tailored to evaluate three types of sensitivity analysis, flow, path and context sensitivity. Then we developed mutators to automatically generate mutants for those types. We demonstrated the framework on a subset of mutational operators to evaluate three taint‐flow analysers, SaINT, Taint‐Things and FlowsMiner. Our framework and experiments ranked the taint analysis tools according to precision and recall as follows: Taint‐Things (99% recall, 100% precision), FlowsMiner (100% recall, 87.6% precision) and SaINT (100% recall, 56.8% precision). To the best of our knowledge, our framework is the first framework to address the need for evaluating taint‐flow analysis tools and specifically those developed for IoT SmartThings applications. Manar H. Alalfi, Sajeda Parveen, Bara' Nazzal |
Softw. Test. Verification Reliab. | 1 |
| 2020 | An Approach for the Identification of Information Leakage in Automotive Infotainment systemsabstractThe advancements in the digitization world has revolutionized the automotive industry. Today's modern cars are equipped with internet, computers that can provide autonomous driving functionalities as well as infotainment systems that can run mobile operating systems, like Android Auto and Apple CarPlay. Android Automotive is Google's android operating system tailored to run natively on vehicle's infotainment systems, it allows third party apps to be installed and run on vehicle's infotainment systems. Such apps may raise security concerns related to user's safety, security and privacy. This paper investigates security concerns of in-vehicle apps, specifically, those related to inter component communication (ICC) among these apps. ICC allows apps to share information via inter or intra apps components through a messaging object called intent. In case of insecure communication, Intent can be hijacked or spoofed by malicious apps and user's sensitive information can be leaked to hacker's database. We investigate the attack surface and vulnerabilities in these apps and provide a static analysis approach and a tool to find data leakage vulnerabilities. The approach can also provide hints to mitigate these leaks. We evaluate our approach by analyzing a set of Android Auto apps downloaded from Google Play store, and we report our validated results on vulnerabilities identified on those apps. Abdul Moiz, Manar H. Alalfi |
SCAM | 2 |
| 2020 | Identifying Vulnerable IoT Applications using Deep LearningabstractThis paper presents an approach for the identification of vulnerable IoT applications using deep learning algorithms. The approach focuses on a category of vulnerabilities that leads to sensitive information leakage which can be identified using taint flow analysis. First, we analyze the source code of IoT apps in order to recover tokens along their frequencies and tainted flows. Second, we develop, Token2Vec, which transforms the source code tokens into vectors. We have also developed Flow2Vec, which transforms the identified tainted flows into vectors. Third, we use the recovered vectors to train a deep learning algorithm to build a model for the identification of tainted apps. We have evaluated the approach on two datasets and the experiments show that the proposed approach of combining tainted flows features with the base benchmark that uses token frequencies only, has improved the accuracy of the prediction models from 77.78% to 92.59% for Corpus1 and 61.11% to 87.03% for Corpus2. Hajra Naeem, Manar H. Alalfi |
SANER | 2 |
| 2020 | A Mutation Framework for Evaluating Security Analysis Tools in IoT ApplicationsabstractIn this paper, we present an automated framework to evaluate taint flow analysis tools in the domain of IoT (Internet of things) apps. First, we propose a set of mutational operators tailored to evaluate flow-sensitive analysis tools. Then we developed mutators to automatically generate mutants for this type of sensitivity analysis. We demonstrated the framework on flow- sensitivity mutational operators to evaluate two taint flow analyzers, SaINT and Taint-Things. To the best of our knowledge, our framework is the first framework to address the need for evaluating taint flow analysis tools specifically developed for IoT SmartThings apps. Sajeda Parveen, Manar H. Alalfi |
SANER | 2 |
| 2019 | Automated Identification of Over-Privileged SmartThings AppsabstractThe permission system in the SmartThings platform governs how apps access devices. The system was designed to protect devices from third-party apps, by forcing apps to access devices through their capabilities. Design flaws in the system result in apps being over-privileged with unauthorized capabilities. This vulnerability represents serious security challenges to this platform and its users. In this paper, we present an automated tool that can identify over-privilege vulnerability in SmartThings apps. We have identified common patterns, and we have used this knowledge to design our automated over-privilege detection tool. We have evaluated the effectiveness of our tool on 222 official and third-party apps, and we have found that approximately 5.5% of defined devices were misused with 76 identified instances of over-privilege. Atheer Abu Zaid, Manar H. Alalfi, Ali Miri |
ICSME | 2 |
| 2018 | Modeling AUTOSAR Implementations in Simulink
Manar H. Alalfi, Thomas R. Dean, S. Ramesh 0002 |
ECMFA | 2 |
| 2018 | An approach to clone detection in sequence diagrams and its application to security analysis
Manar H. Alalfi, Elizabeth P. Antony, James R. Cordy |
Softw. Syst. Model. | 1 |
| 2016 | Clone detection in MATLAB Stateflow models
Thomas R. Dean, Manar H. Alalfi |
Softw. Qual. J. | 3 |
| 2015 | SimNav: Simulink navigation of model clone classesabstractSimNav is a graphical user interface designed for displaying and navigating clone classes of Simulink models detected by the model clone detector Simone. As an embedded Simulink interface tool, SimNav allows model developers to explore detected clones directly in their own model development environment rather than a separate research tool interface. SimNav allows users to open selected models for side-by-side comparison, in order to visually explore clone classes and view the differences in the clone instances, as well as to explore the context in which the clones exist. This tool paper describes the motivation, implementation, and use cases for SimNav. Eric James Rapos, Andrew Stevenson, Manar H. Alalfi, James R. Cordy |
SCAM | 3 |
| 2015 | Detecting Android Malware Using Clone Detection
Manar H. Alalfi, Thomas R. Dean, Ying Zou 0001 |
J. Comput. Sci. Technol. | 2 |
| 2014 | Semi-automatic Identification and Representation of Subsystem Variability in Simulink ModelsabstractThis paper presents a semi-automated framework for identifying and representing different kinds of variability in Simulink models. Based on the observed variants found in similar subsystem patterns inferred using Simone, a text-based model clone detection tool, we propose a set of variability operators for Simulink models. By applying these operators to six example systems, we are able to represent the variability in their similar subsystem patterns as a single subsystem template directly in the Simulink environment. The product of our framework is a single consolidated subsystem model capable of expressing the observed variability across all instances of each inferred pattern. The process of pattern inference and variability analysis is largely automated and can be easily applied to other collections of Simulink models. The framework is aimed at providing assistance to engineers to identify, understand, and visualize patterns of subsystems in a large model set. This understanding may help in reducing maintenance effort and bug identification at an early stage of the software development. Manar H. Alalfi, Eric James Rapos, Andrew Stevenson, Matthew Stephan, Thomas R. Dean, James R. Cordy |
ICSME | 1 |
| 2013 | Using mutation analysis for a model-clone detector comparison frameworkabstractModel-clone detection is a relatively new area and there are a number of different approaches in the literature. As the area continues to mature, it becomes necessary to evaluate and compare these approaches and validate new ones that are introduced. We present a mutation-analysis based model-clone detection framework that attempts to automate and standardize the process of comparing multiple Simulink model-clone detection tools or variations of the same tool. By having such a framework, new research directions in the area of model-clone detection can be facilitated as the framework can be used to validate new techniques as they arise. We begin by presenting challenges unique to model-clone tool comparison including recall calculation, the nature of the clones, and the clone report representation. We propose our framework, which we believe addresses these challenges. This is followed by a presentation of the mutation operators that we plan to inject into our Simulink models that will introduce variations of all the different model clone types that can then be searched for by each respective model-clone detector. Matthew Stephan, Manar H. Alalfi, Andrew Stevenson, James R. Cordy |
ICSE | 2 |
| 2013 | A Framework for Migrating Web Applications to Web Services
Asil A. Almonaies, Manar H. Alalfi, James R. Cordy, Thomas R. Dean |
ICWE | 2 |
| 2012 | Models are code too: Near-miss clone detection for Simulink modelsabstractWhile graph-based techniques show good results in finding exactly similar subgraphs in graphical models, they have great difficulty in finding near-miss matches. Text-based clone detectors, on the other hand, do very well with near-miss matching in source code. In this paper we introduce SIMONE, an adaptation of the mature text-based code clone detector NICAD to the efficient identification of structurally meaningful near-miss subsystem clones in graphical models. By transforming graph-based models to normalized text form, SIMONE extends NICAD to identify near-miss subsystem clones in Simulink models, uncovering important model similarities that are difficult to find in any other way. Manar H. Alalfi, James R. Cordy, Thomas R. Dean, Matthew Stephan, Andrew Stevenson |
ICSM | 1 |
| 2012 | Recovering Role-Based Access Control Security Models from Dynamic Web Applications
Manar H. Alalfi, James R. Cordy, Thomas R. Dean |
ICWE | 1 |
| 2010 | Analyzing natural-language artifacts of the software processabstractSoftware teams, as they communicate throughout the life-cycle of their projects, generate a substantial stream of textual data. Through emails and chats, developers discuss the requirements of their software system, they negotiate the distribution of tasks among them, and they make decisions about the system design, and the internal structure and functionalities of its code modules. The software research community has long recognized the importance and potential usefulness of such textual information. In this paper, we discuss our recent work on systematically analyzing several textual streams collected through our WikiDev2.0 tool. We use two different text-analysis methods to examine five different sources of textual data. We report on our experience using our method on analyzing the communications of a nine-member team over four months. Maryam Hasan, Eleni Stroulia, Denilson Barbosa 0001, Manar H. Alalfi |
ICSM | 4 |
| 2009 | Modelling methods for web application verification and testing: state of the artabstractAbstract Models are considered an essential step in capturing different system behaviours and simplifying the analysis required to check or improve the quality of software. Verification and testing of web software requires effective modelling techniques that address the specific challenges of web applications. In this study we survey 24 different modelling methods used in web site verification and testing. Based on a short catalogue of desirable properties of web applications that require analysis, two different views of the methods are presented: a general categorization by modelling level, and a detailed comparison based on property coverage. Copyright © 2008 John Wiley & Sons, Ltd. Manar H. Alalfi, James R. Cordy, Thomas R. Dean |
Softw. Test. Verification Reliab. | 1 |
| 2007 | A Survey of Analysis Models and Methods in Website Verification and Testing
Manar H. Alalfi, James R. Cordy, Thomas R. Dean |
ICWE | 1 |