Domenico Amalfitano

dblp:91/6656 · DBLP profile ↗
← Back
37ranked-venue papers
21as first author
21since 2021 · last 2026
0000-0002-4761-4443ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 32 · 20 first-author · 17 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 2 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSystems, architecture and hardware · 1 · 1 since 2021
YearPublicationVenuePosition
2026 CIAO - Code In Architecture Out - Automated Software Architecture Documentation with Large Language Models
abstract
Software architecture documentation is essential for system comprehension, yet it is often unavailable or incomplete. While recent LLM-based techniques can generate documentation from code, they typically address local artifacts rather than producing coherent, system-level architectural descriptions. This paper presents a structured process for automatically generating system-level architectural documentation directly from GitHub repositories using Large Language Models. The process, called CIAO (Code In Architecture Out), defines an LLM-based work-flow that takes a repository as input and produces system-level architectural documentation following a template derived from ISO/IEC/IEEE 42010, SEI Views & Beyond, and the C4 model. The resulting documentation can be directly added to the target repository. We evaluated the process through a study with 22 developers, each reviewing the documentation generated for a repository they had contributed to. The evaluation shows that developers generally perceive the produced documentation as valuable, comprehensible, and broadly accurate with respect to the source code, while also highlighting limitations in diagram quality, high-level context modeling, and deployment views. We also assessed the operational cost of the process, finding that generating a complete architectural document requires only a few minutes and is inexpensive to run. Overall, the results indicate that a structured, standards-oriented approach can effectively guide LLMs in producing system-level architectural documentation that is both usable and cost-effective.
Tiziano Santilli, Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione
ICSA3
2026 A decontextualized LLM-based safeguard technique for automated jailbreak mitigation
abstract
Context: Large Language Models (LLMs) are increasingly deployed in high-risk settings, where harmful or unethical outputs remain a risk. Adversarial prompting (“jailbreaks”) can circumvent default safeguards. Emerging regulation (e.g., the EU AI Act) demands proactive controls that verify outputs before delivery. Objectives: We present and evaluate D-SHIELD, a plugin-based safeguard that separates generation from validation via a stateless, decontextualized validator. Objectives are to assess alignment with expert judgments, evaluate end-to-end mitigation on publicly sourced jailbreaks, compare with representative plugin-based defenses, and examine a lightweight configuration optimized for cost without reducing protection. Methods: D-SHIELD routes candidate responses from the user-facing LLM to a secondary, decontextualized LLM operating in isolation (no prompt or conversation context) to classify each response based on indications of prohibited content derived from the EU AI Act, The General-Purpose AI Code of Practice, GDPR, and provider policies. This decontextualized design intentionally prevents prompt contamination, adversarial framing, and conversational drift from influencing the validation decision, addressing key weaknesses of context-aware validators. We create an expert-labeled dataset from designed jailbreaks for direct comparison with the decontextualized validator’s classification. We then embed the validator in a working prototype and evaluate on publicly sourced jailbreaks. Finally, we conduct a comparative study against baseline jailbreak-mitigation techniques and analyze a lightweight guard variant. Results: The decontextualized validator closely aligns with expert decisions, especially for explicit harms, while adopting a conservative stance on borderline cases. In prototype evaluation on publicly sourced jailbreaks, the safeguard blocked most harmful responses. Compared with baselines, D-SHIELD yields fewer successful attacks under a common benchmark. The lightweight variant delivers comparable protection at markedly lower cost. Conclusion: Decontextualized, output-level validation provides an effective, regulation-aligned solution for LLM safety. Restricting the validator to the generated text complements input-level defenses and supports practical deployment, particularly in a lightweight configuration.
Tiziano Santilli, Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione
Inf. Softw. Technol.3
2026 A material-aware, multi-modal synthetic dataset for smart city applications: Design and construction
abstract
Large-scale synthetic environments are essential for advancing smart cities research. However, existing urban benchmarks typically prioritize either visual photorealism or geometric fidelity, often neglecting the material-level semantics and physical attributes required for simulations. To address this gap, this paper introduces UR-MAT , a modular design framework and a multimodal synthetic dataset specifically built to bridge computer vision and physics-based modelling. We present a unified construction workflow that integrates georeferenced geometry, physically based rendering (PBR) materials, and domain-specific metadata (e.g., electromagnetic properties based on ITU-R standards) into a traceable data representation. The resulting dataset encompasses eight heterogeneous urban scenarios, providing spatially aligned RGB imagery, depth maps, semantic segmentation masks, and 3D point clouds. The utility of UR-MAT is validated through cross-domain experiments: (i) a quantitative baseline analysis on semantic material segmentation across fourteen material classes, where the best-performing model achieved 0.787 mIoU and 0.968 pixel accuracy, and (ii) electromagnetic ray-tracing simulations, which verify that the dataset’s material annotations yield physically consistent and deterministic radio propagation patterns. By enabling perception and simulation tasks within a single coherent framework, UR-MAT serves as a resource for developing perception-driven communication strategies and next-generation Digital Twins.
Debora Russo, Domenico Amalfitano, Gerardo Di Martino, Nicola Mazzocca, Valeria Vittorini
Inf. Sci.2
2026 AI in GUI-based testing: A survey of techniques, tools, and perceived advantages and limitations
Domenico Amalfitano, Riccardo Coppola, Damiano Distante, Filippo Ricca
J. Syst. Softw.1
2026 Statistical-based metric threshold setting method for software fault prediction in firmware projects: An industrial experience
abstract
Ensuring software quality in embedded firmware is critical, especially in safety-critical domains such as automotive systems, where compliance with functional safety standards like ISO 26262 requires strong guarantees of software reliability. While machine learning-based fault prediction models have demonstrated high accuracy, their lack of transparency and interpretability limits their adoption in industrial settings. Developers need actionable insights that can be directly employed in software quality assurance (SQA) processes and guide defect mitigation strategies. In this paper, we present a structured process for defining context-specific software metric thresholds suitable for integration into fault detection workflows in industrial settings. Our approach supports cross-project fault prediction by deriving thresholds from one set of projects and applying them to independently developed firmware, thereby enabling reuse across similar software systems without retraining or domain-specific tuning. We analyze three real-world C-embedded firmware projects provided by an industrial partner, using Coverity and Understand static analysis tools to extract software metrics. Through statistical analysis and hypothesis testing, we identify discriminative metrics and derived empirical threshold values capable of distinguishing faulty from non-faulty functions. The derived thresholds are then validated through an experimental evaluation, demonstrating their effectiveness in identifying fault-prone functions with high precision. The results confirm that statistically derived thresholds can serve as a practical and interpretable solution for fault prediction, aligning with industry standards and SQA practices. This approach provides a practical alternative to black-box AI models, allowing developers to systematically assess software quality, take preventive actions, and integrate metric-based fault prediction into industrial development workflows to mitigate software faults.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana
J. Syst. Softw.1
2026 TwinArch: A digital twin reference architecture
Alessandra Somma, Domenico Amalfitano, Alessandra De Benedictis, Patrizio Pelliccione
J. Syst. Softw.2
2025 Automated Software Architecture Design Recovery from Source Code Using LLMs
Domenico Amalfitano, Tiziano Santilli, Patrizio Pelliccione, Anna Rita Fasolino
ECSA1
2025 The Scent of Test Effectiveness: Can Scriptless Testing Reveal Code Smells?
abstract
This paper presents an industrial experience applying random scriptless GUI testing to the Yoho web application developed by Marviq. The study was motivated by several key challenges faced by the company, including the need to optimise testing resources, explore how random testing can complement manual testing, and investigate new coverage metrics, such as “code smell coverage”, to assess software quality and maintainability. We conducted an experiment to explore the impact of the number and length of random GUI test sequences on traditional adequacy metrics, the complementarity of random with manual testing, and the relationship between code smell coverage and traditional code coverage. Using Testar for scriptless testing and SonarQube code smell identification, results show that longer random test sequences yielded better test adequacy metrics and increased code smell coverage. In addition, random testing offers promising efficiency in test coverage and detects unique smells that m anual testing might overlook. Additionally, including code smell coverage provides valuable insights into long-term code maintainability, revealing gaps that traditional metrics may not capture. These findings highlight the benefits of combining functional testing with metrics assessing code quality, particularly in resource-constrained environments.
Olivia Rodríguez-Valdés, Domenico Amalfitano, Otto Sybrandi, Beatriz Marín, Tanja E. J. Vos
ENASE2
2025 Material-Aware Synthetic Data Generation for Smart City Applications
abstract
The development of smart city applications increasingly relies on datasets that capture not only urban geometry but also the material properties that influence real-world interactions. However, most existing datasets lack detailed semantic labels and physical attributes, limiting their applicability to tasks such as signal propagation modeling and material-aware analysis. In this paper, we propose a structured process and a tool pipeline for generating material-aware synthetic datasets from custom 3D urban scenes. Our approach integrates 3D modeling, physically-based rendering, and automated data capture to produce multimodal outputs, including RGB images, depth maps, segmentation masks, structured metadata, and annotated 3D meshes. We demonstrate the process and pipeline instantiation using the Louvre Museum district as a running scenario, capturing the site's complex architecture and material diversity. A preliminary ray-tracing simulation in MATLAB further demonstrates how the generated data can support material-aware applications. By bridging geometry, appearance, and physical information, the proposed solution can contribute to advancing simulation-ready datasets for smart city research.
Debora Russo, Domenico Amalfitano, Gerardo Di Martino, Nicola Mazzocca, Valeria Vittorini
HPCC2
2025 A Web Crawling-Based Process and a Graph-Based Database for Mobile Vulnerability Analysis
Domenico Amalfitano, Andrea Abbate, Damiano Distante, Antonio Maria Rinaldi, Cristiano Russo, Cristian Tommasino
ICWE1
2025 Enhancing Software Maintainability Through LLM-Assisted Code Refactoring
Tommaso Fulcini, Riccardo Coppola, Flavio Giobergia, Amirali Changizi, Meelad Dashti, Kimia Dorrani, Domenico Amalfitano, Damiano Distante, Filippo Ricca
PROFES7
2025 A model-driven approach for engineering Mobility Digital Twins: The Bologna case study
abstract
As cities grapple with increasing congestion, sustainability concerns, and the need for efficient mobility systems, Mobility Digital Twins (MoDTs) have emerged as promising technology for improving urban transportation. However, the development of MoDTs remains hindered by challenges such as structural complexity, data heterogeneity, lack of interoperability, and limited support for scalability, maintainability, and adaptability. This work aims to address these barriers by introducing a structured and systematic engineering framework that supports the design development of MoDT, reducing technical debt, development costs and human errors, while promoting long-term evolution. We propose a Model-Driven Engineering (MDE) approach that organizes the development of MoDTs through models at different levels of abstraction and adopts automated transformations from high-level specifications to executable code artifacts, supporting MoDT life-cycle. The proposed approach is validated through its application in developing a MoDT for the city of Bologna, Italy. To support this, we introduce the M2DT tool, which automates the workflow from high-level models to software code artifacts. The resulting BoMoDT platform is built using open-source technologies and real mobility data. This case study demonstrates the feasibility and effectiveness of our approach, which, to our knowledge, is the first to apply a model-driven strategy for the entire MoDT development. A qualitative evaluation confirms that our framework addresses key challenges in MoDT development. Quantitative experiments further validate BoMoDT’s ability to accurately reproduce and monitor real urban mobility conditions. The proposed approach offers a solid foundation for addressing MoDT development challenges. By combining automation with structured abstraction, it improves adaptability and maintainability while enabling scalable integration, helping make MoDTs more accessible for future urban system design. • Six challenges in Mobility Digital Twins are identified from literature analysis. • A model-driven approach is introduced to structure their development. • The approach is applied to real world urban mobility case study. • BoMoDT is presented as DT platform for simulation and monitoring of Bologna mobility. • Fidelity and responsiveness are quantitatively evaluated.
Alessandra Somma, Domenico Amalfitano, Alessio Bucaioni, Alessandra De Benedictis
Inf. Softw. Technol.2
2025 A systematic mapping study of semantic technologies in multi-omics data integration
abstract
OBJECTIVE: The integration of multi-omics data is essential for understanding complex biological systems, providing insights beyond single-omics approaches. However, challenges related to data heterogeneity, standardization, and computational scalability persist. This study explores the interdisciplinary application of semantic technologies to enhance data integration, standardization, and analysis in multi-omics research. METHODS: We performed a systematic mapping study assessing literature from 2014 to 2024, focusing on the utilization of ontologies, knowledge graphs, and graph-based methods for multi-omics integration. RESULTS: Our findings indicate a growing number of publications in this field, predominantly appearing in high-impact journals. The deployment of semantic technologies has notably improved data visualization, querying, and management, thus enhancing gene and pathway discovery, and providing deeper disease insights and more accurate predictive modeling. CONCLUSION: The study underscores the significance of semantic technologies in overcoming multi-omics integration challenges. Future research should focus on integrating diverse data types, developing advanced computational tools, and incorporating AI and machine learning to foster personalized medicine applications.
Giovanni Maria De Filippis, Domenico Amalfitano, Cristiano Russo, Cristian Tommasino, Antonio Maria Rinaldi
J. Biomed. Informatics2
2025 A GUI-based Metamorphic Testing Technique for Detecting Authentication Vulnerabilities in Android Mobile Apps
abstract
The increasing use of mobile apps in daily life involves managing and sharing sensitive user information. New vulnerabilities are frequently reported in bug tracking systems, highlighting the need for effective security testing processes for these applications. This study introduces a GUI-based Metamorphic Testing technique designed to detect five common real-world vulnerabilities related to username and password authentication methods in Android applications, as identified by OWASP. We developed five Metamorphic Relationships to test for these vulnerabilities and implemented a Metamorphic Vulnerability Testing Environment to automate the technique. This environment facilitates the generation of Source test case and the automatic creation and execution of Follow-up test case . The technique was applied to 163 real-world Android applications, uncovering 159 vulnerabilities. Out of these, 108 apps exhibited at least one vulnerability. The vulnerabilities were validated through expert analysis conducted by three security professionals, who confirmed the issues by interacting directly with the app’s graphical user interfaces (GUIs). Additionally, to assess the practical relevance of our approach, we engaged with 37 companies whose applications were identified as vulnerable. Nine companies confirmed the vulnerabilities, and 26 updated their apps to address the reported issues. Our findings also indicate a weak inverse correlation between user-perceived quality and vulnerabilities; even highly rated apps can harbor significant security flaws.
Domenico Amalfitano, Misael Costa Júnior, Anna Rita Fasolino, Márcio Eduardo Delamaro
J. Syst. Softw.1
2025 Testing Context-Aware Software Systems From the Voices of the Automotive Industry
abstract
As automotive software systems evolve toward high and full driving automation, evaluating their quality becomes increasingly challenging, especially concerning emerging behaviors. Context awareness is the capability to sense the environment and adapt behavior. Automotive software systems are context-aware software systems (CASS). Previous secondary studies in technical literature indicate a need for testing techniques for CASS. However, these studies should have investigated the information provided by the industry. Therefore, this article undertakes a gray literature study to uncover evidence of CASS testing using 20 reports from 16 automotive companies as primary sources. Our findings show that industry practices exhibit quality assurance best practices, but CASS abstraction adoption still needs to be completed. Industry reports emphasize testing challenges but lack technical resolutions, relying on amassing diverse datasets for testing. This article has the potential to impact the quality assurance of automotive software systems significantly and lead industry professionals to enhance their testing process.
Santiago Matalonga, Domenico Amalfitano, Martín Solari, Jean C. R. Hauck, Guilherme Horta Travassos
IEEE Trans. Ind. Informatics2
2024 Automated Architecture Recovery for Embedded Software Systems: An Industrial Case Study
Domenico Amalfitano, Domenico Francesco De Angelis, Anna Rita Fasolino
ECSA1
2024 Characterizing Software Architectural Metrics for Continuous Compliance in the Automotive Domain
abstract
The software of critical systems, such as automotive, is increasingly required to change and evolve after production. In the automotive domain, this is a consequence of self-driving and connected cars, which continuously collect data from the field that is then exploited to produce safer and more advanced and reliable versions of the used algorithms or AI modules. Consequently, there exists a need for techniques and tools to facilitate incremental and Continuous Compliance with safety and security standards. This paper focuses on software architectural metrics that can be used for Continuous Compliance in the automotive domain. Our initial stride involved a literature review to find metrics capable of assessing software architectures. Subsequently, in collaboration with architecture, safety, and security experts in the automotive domain, we proposed a framework defining the characteristics these metrics must possess for continuous evaluation of software architectural compliance. The framework was used to characterize 48 metrics gathered from the literature review and to associate them with a score expressing their suitability to be used in software architecture Continuous Compliance processes.
Domenico Amalfitano, Anna Rita Fasolino, Patrizio Pelliccione, Tiziano Santilli
ICSA1
2024 State of the Practice in Software Testing Teaching in Four European Countries
abstract
Software testing is an indispensable component of software development, yet it often receives insufficient attention. The lack of a robust testing culture within computer science and informatics curricula contributes to a shortage of testing expertise in the software industry. Addressing this problem at its root -education- is paramount. In this paper, we conduct a comprehensive mapping review of software testing courses, elucidating their core attributes and shedding light on prevalent subjects and instructional methodologies. We mapped 117 courses offered by Computer Science (and related) degrees in 49 academic institutions from four Western European countries, namely Belgium, Italy, Portugal and Spain. The testing subjects were mapped against the conceptual framework provided by the ISO/IEC/IEEE 29119 standard on software testing. Among the results, the study showed that dedicated software testing courses are offered by only 39% of the analysed universities, whereas the basics of software testing are taught in at least one course at every university. The analysis of the software testing topics highlights the gaps that need to be filled in order to better align the current academic offerings with the real industry needs.
Porfirio Tramontana, Beatriz Marín, Ana C. R. Paiva, Alexandra Mendes, Tanja E. J. Vos, Domenico Amalfitano, Felix Cammaerts, Monique Snoeck, Anna Rita Fasolino
ICST6
2024 FRAFOL: FRAmework FOr Learning mutation testing
abstract
Mutation testing has evolved beyond academic research, is deployed in industrial and open-source settings, and is increasingly part of universities' software engineering curricula. While many mutation testing tools exist, each with different strengths and weaknesses, integrating them into educational activities and exercises remains challenging due to the tools' complexity and the need to integrate them into a development environment. Additionally, it may be desirable to use different tools so that students can explore differences, e.g., in the types or numbers of generated mutants. Asking students to install and learn multiple tools would only compound technical complexity and likely result in unwanted differences in how and what students learn. This paper presents FRAFOL, a framework for learning mutation testing. FRAFOL provides a common environment for using different mutation testing tools in an educational setting.
Pedro Tavares, Ana C. R. Paiva, Domenico Amalfitano, René Just
ISSTA3
2022 Alternatives for testing of context-aware software systems in non-academic settings: results from a Rapid Review
abstract
Context: Context-awareness challenges the engineering of contemporary software systems and jeopardizes their testing. The variation of context represents a relevant behavior that deepens the limitations of available software testing practices and technologies. However, such software systems are mainstream. Therefore, researchers in non-academic settings also face challenges when developing and testing contemporary soft-ware systems. Objective: To understand how researchers deal with the variation of context when testing context-aware software systems developed in non-academic settings. Method: To undertake a secondary study (Rapid Review) to uncover the necessary evidence from primary sources describing the testing of context-aware software systems outside academia. Results: The current testing initiatives in non-academic settings aim to generate or improve test suites that can deal with the context variation and the sheer volume of test input possibilities. They mostly rely on modeling the systems' dynamic behavior and increasing computing resources to generate test inputs to achieve this. We found no evidence of test results aiming at managing context variation through the testing lifecycle process. Conclusions: So far, the identified testing initiatives and strategies are not ready for mainstream adoption. They are all domain-specific, and while the ideas and approaches can be reproduced in distinct settings, the technologies are to be re-engineered and tailored to the context-awareness of contemporary software systems in different problem domains. Further and joint investigations in academia and experiences in non-academic settings can evolve the body of knowledge regarding the testing of contemporary soft-ware systems in the field.
Santiago Matalonga, Domenico Amalfitano, Andréa Cristina de Souza Doreste, Anna Rita Fasolino, Guilherme Horta Travassos
Inf. Softw. Technol.2
2021 Introduction to the special issue on engineering context-aware software systems
Domenico Amalfitano, Santiago Matalonga, Guilherme Horta Travassos
Inf. Softw. Technol.1
2020 A model-driven engineering approach for supporting questionnaire-based gap analysis processes through application lifecycle management systems
Domenico Amalfitano, Vincenzo De Simone, Stefano Scala, Anna Rita Fasolino
Softw. Qual. J.1
2019 Combining Automated GUI Exploration of Android apps with Capture and Replay through Machine Learning
Domenico Amalfitano, Vincenzo Riccio, Nicola Amatucci, Vincenzo De Simone, Anna Rita Fasolino
Inf. Softw. Technol.1
2019 Using tool integration for improving traceability management testing processes: An automotive industrial experience
abstract
Abstract Despite the high relevance of traceability in software processes, the activities of traceability creation and management are not always adequately supported in practice. The lack of integration between the tools adopted in the development processes is one of the main causes of such an ineffective management, where traceability relationships are still manually generated and maintained. In this paper we present an industrial experience we performed for improving the traceability management in a testing process performed in the Fiat Chrysler Automobiles company. In this context, we carried out a process for analyzing and identifying the main issues due to the ineffective traceability management and proposed a solution for addressing them. We designed and implemented a software architecture for integrating the existing application lifecycle management platform with the tools used in the process with the aim of automating the process execution and the traceability links management. The new architecture was validated by a case study that showed how the integration solution produced beneficial effects on quality attributes of the testing process.
Domenico Amalfitano, Vincenzo De Simone, Raffaele Rodolfo Maietta, Stefano Scala, Anna Rita Fasolino
J. Softw. Evol. Process.1
2019 Automated functional testing of mobile applications: a systematic mapping study
Porfirio Tramontana, Domenico Amalfitano, Nicola Amatucci, Anna Rita Fasolino
Softw. Qual. J.2
2019 Developing and Evaluating Objective Termination Criteria for Random Testing
abstract
Random testing is a software testing technique through which programs are tested by generating and executing random inputs. Because of its unstructured nature, it is difficult to determine when to stop a random testing process. Faults may be missed if the process is stopped prematurely, and resources may be wasted if the process is run too long. In this article, we propose two promising termination criteria, “All Equivalent” (AEQ) and “All Included in One” (AIO), applicable to random testing. These criteria stop random testing once the process has reached a code-coverage-based saturation point after which additional testing effort is unlikely to provide additional effectiveness. We model and implement them in the context of a general random testing process composed of independent random testing sessions. Thirty-six experiments involving GUI testing and unit testing of Java applications have demonstrated that the AEQ criteria is generally able to stop the process when a code coverage equal or very near to the saturation level is reached, while AIO is able to stop the process earlier in cases it reaches the saturation level of coverage. In addition, the performance of the two criteria has been compared against other termination criteria adopted in the literature.
Porfirio Tramontana, Domenico Amalfitano, Nicola Amatucci, Atif M. Memon, Anna Rita Fasolino
ACM Trans. Softw. Eng. Methodol.2
2018 Exploiting ALM and MDE for Supporting Questionnaire-Based Gap Analysis Processes
abstract
Gap Analysis is a common approach in industry to evaluate the gaps between the implemented software processes and the requirements suggested by both Process Quality Frameworks and Standards. Gap Analysis processes are usually executed by approaches based on questionnaires that need to be crafted ad-hoc according to specific appraisal goals and submitted to the industrial personnel. The approaches used for developing, compiling and evaluating the answers given to these questionnaires do not follow well-defined methodologies or processes, and lack of adequate tool support. In this paper we aim at understanding the main issues affecting Questionnaire-based Gap Analysis processes in industrial practices. Moreover, we evaluate the feasibility of adopting state-of-the-art software engineering technologies for executing such processes. We propose a novel approach based on Application Lifecycle Management for configuring and enacting Questionnaire-based Gap Analysis processes. The approach exploits Model Driven Engineering for configuring and implementing the Application Lifecycle Management system. This configuration activity is aided by a tool, named GADGET, we developed for modeling the process and automatically transforming it towards the Application Lifecycle Management technology.
Vincenzo De Simone, Domenico Amalfitano, Anna Rita Fasolino
SEAA2
2018 Why does the orientation change mess up my Android application? From GUI failures to code faults
abstract
Summary This paper investigates the failures exposed in mobile apps by the mobile‐specific event of changing the screen orientation. We focus on GUI failures resulting in unexpected GUI states that should be avoided to improve the apps quality and to ensure better user experience. We propose a classification framework that distinguishes 3 main classes of GUI failures due to orientation changes and exploit it in 2 studies that investigate the impact of such failures in Android apps. The studies involved both open‐source and apps from Google Play that were specifically tested exposing them to orientation change events. The results showed that more than 88% of these apps were affected by GUI failures, some classes of GUI failures were more common than others, and some GUI objects were more frequently involved. The app source code analysis allowed us to identify 6 classes of common faults causing specific GUI failures.
Domenico Amalfitano, Vincenzo Riccio, Ana C. R. Paiva, Anna Rita Fasolino
Softw. Test. Verification Reliab.1
2017 Improving traceability management through tool integration: an experience in the automotive domain
abstract
Despite the relevance of traceability in software processes is well-known, the activities of traceability creation and management are not always adequately supported in real software projects. The lack of integration between the tools adopted in the development processes is one of the main causes of such an ineffective management, where traceability relationships are still manually generated and maintained. In this paper we present an industrial experience we performed for improving the traceability management in a software development process performed in Fiat Chrysler Automobiles FCA company. We designed a software architecture for integrating the existing Application Lifecycle Management (ALM) platform with the tools used in the testing process. The architecture aimed at fully automating the execution of the testing process and at automatically generating the appropriate traceability links when they are established. It was implemented using a Continuous Integration Engine that allowed us to develop a modular, evolvable and reconfigurable integration architecture. The new architecture was validated by an experiment that showed its capability in correctly and completely generating and handling traceability links between artifacts involved in the testing process. The experiment demonstrated that the integration solution produced also beneficial effects on other quality attributes of the process.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Stefano Scala
ICSSP1
2017 A general framework for comparing automatic testing techniques of Android mobile apps
Domenico Amalfitano, Nicola Amatucci, Atif M. Memon, Porfirio Tramontana, Anna Rita Fasolino
J. Syst. Softw.1
2016 Introducing Software Product Lines in Model-Based Design Processes: An Industrial Experience
abstract
Software has gained a critical role in the automotive domain that is becoming more and more complex. The ever-growing complexity in automotive software development is due to its high variability. In this scenario, automotive companies need to adopt cost-effective development processes in order to manage the variability of the produced software. A well-known solution for dealing with this problem is the adoption of Software Product Lines (SPL). In this paper we report an experience we performed in collaboration with the Fiat Chrysler Automobiles (FCA) company for the application of the SPL in one of its Model-Based Design (MBD) processes. SPL were supported by AutoMative, a software infrastructure we implemented for the semi-automatic generation of Product Architectures from specification documents.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Mario Lubrano, Stefano Scala
WICSA1
2016 EXACT: A tool for comprehending VBA-based Excel spreadsheet applications
abstract
Spreadsheet applications are widely adopted by millions of end users from several application domains and provide strategic support to many business, scientific, industrial, and organizational processes. These applications are usually developed by rapid application development processes, exploiting host scripting languages allowing the basic spreadsheets to provide complex functionality, business rules, and user interfaces. Several factors complicate the comprehension of these applications because they are usually developed and maintained by end users without specific software engineering skills, grow over time, are not adequately documented, and do not present explicit separation between data, business logic, and user interface layers. This paper presents a reverse engineering tool intended to support the comprehension of Excel spreadsheet applications developed using the Visual Basic for Application programming language. The tool has been implemented as an add-in that extends the Excel working environment by providing analysis and visualization features. It is able to extract information about the elements composing the analyzed Excel spreadsheet application, the functionality it exposes through its user interface, and the dependencies among its cells. This information is provided by means of interactive views. The validity of the tool has been assessed by a qualitative case study performed with professional end users from an automotive industrial domain. Copyright © 2016 John Wiley & Sons, Ltd.
Domenico Amalfitano, Vincenzo De Simone, Anna Rita Fasolino, Porfirio Tramontana
J. Softw. Evol. Process.1
2014 Information Extraction from Legacy Spreadsheet-based Information System - An Experience in the Automotive Context
abstract
Nevertheless spreadsheets were originally designed for computing purposes and for commercial applications, they are often used in industry to implement Information Systems, thanks to the functionalities offered by integrated scripting languages and ad-hoc frameworks (e.g., Visual Basic for Applications). This technological solution allows the adoption of Rapid Application Development processes for the quickly development of Spreadsheets-based Information Systems, but the resulting systems are quite difficult to be maintained and very difficult to be migrated to other architectures such as Database-oriented Informative Systems or Web applications. In this paper we present an approach for reverse engineering the data model from an Excel spreadsheet-based system in the context of a process of migration to a Web based application based on a MVC architecture. The proposed approach was successfully applied in a real context of a company operating in the automotive industry. The main contribution of this paper is represented by the Data Model Reverse Engineering activity that is the basis of the Migration process.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Vincenzo De Simone, Giancarlo Di Mare, Stefano Scala
DATA1
2012 A toolset for GUI testing of Android applications
abstract
This paper presents a toolset for GUI testing of Android applications. The toolset is centered on a GUI ripper that systematically explores the GUI structure of an application under test with the aim of firing sequences of user events and exposing failures of the application. The toolset supports the execution of a testing procedure that automatically performs crash testing of subject applications and provides test results made of several artifacts. The paper illustrates some examples of using the toolset for testing real Android applications.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Salvatore De Carmine, Gennaro Imparato
ICSM1
2012 Using GUI ripping for automated testing of Android applications
abstract
We present AndroidRipper, an automated technique that tests Android apps via their Graphical User Interface (GUI). AndroidRipper is based on a user-interface driven ripper that automatically explores the app’s GUI with the aim of exercising the application in a structured manner. We evaluate AndroidRipper on an open-source Android app. Our results show that our GUI-based test cases are able to detect severe, previously unknown, faults in the underlying code, and the structured exploration outperforms a random approach.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana, Salvatore De Carmine, Atif M. Memon
ASE1
2010 DynaRIA: A Tool for Ajax Web Application Comprehension
abstract
Thanks to Rich Internet Applications (RIAs) with their enhanced interactivity, responsiveness and dynamicity, the user experience in the Web 2.0 is becoming more and more appealing and user-friendly. At the same time, the dynamic nature of RIAs, and the heterogeneous technologies, frameworks, communication models used for implementing them negatively affect their analyzability and understandability, so that specific software techniques and tools are needed for supporting their comprehension. This paper presents DynaRIA, a tool for the comprehension of RIAs implemented in Ajax that is based on dynamic analysis and provides functionalities for recording and analyzing user sessions from several perspectives, and producing various types of abstractions and visualizations about the run-time behaviour of the application.
Domenico Amalfitano, Anna Rita Fasolino, Armando Polcaro, Porfirio Tramontana
ICPC1
2009 Experimenting a reverse engineering technique for modelling the behaviour of rich internet applications
abstract
While the rapid and growing diffusion of rich Internet applications (RIAs) with their enhanced interactive, responsive and dynamic behaviour is sharpening the distance between Web applications and desktop applications, at the same time, the maintenance community is experiencing the need for effective analysis approaches for understanding and modelling this behaviour adequately. This paper presents a reverse engineering technique based on dynamic analysis and supported by a tool that reconstructs a model of the RIA behaviour based on finite state machines. The technique is based on the analysis of the RIA user interface evolution shown in user sessions, and exploits user interface equivalence criteria for abstracting relevant states and state transitions to be included in the model. For assessing the effectiveness and the cost of this technique, an experiment involving four distinct RIAs implemented with AJAX technique was carried out.
Domenico Amalfitano, Anna Rita Fasolino, Porfirio Tramontana
ICSM1