EDBT 2026 Demo / reviewers in the wild / expert
Bixin Li
dblp:l/BixinLi
· DBLP profile ↗
138ranked-venue papers
21as first author
46since 2021 · last 2026
0000-0001-9916-4790ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 109 · 14 first-author · 29 since 2021Applied, interdisciplinary, general and emerging computing · 28 · 4 first-author · 10 since 2021Artificial intelligence and machine learning · 24 · 3 first-author · 2 since 2021Computer networks · 5 · 2 first-author · 3 since 2021Systems, architecture and hardware · 2 · 2 since 2021Security and privacy · 2 · 2 since 2021Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Beyond Lexical: Functional Semantics and Fusion for Precise Architecture Recovery
Bixin Li, Yan Xiao 0002 |
SANER | 2 |
| 2026 | SVNT-DKB: A Data-Knowledge-Bayesian Integrated Safety Evaluation Framework for Autonomous Driving SystemsabstractThe autonomous driving system (ADS) faces significant challenges in safety verification: due to the high cost and inherent risks of large-scale real-world environment testing, safety-critical data in the real world is still scarce. This makes traditional data-based methods ineffective. To address this gap, this paper proposes the novel safety evaluation framework SVNT-DKB, which integrates data-based learning, knowledge-guided modeling and Bayesian probability reasoning structurally, resolving the contradiction between small sample limitations and cross-layer risk modeling. The core innovations of this framework include: (1) a four-dimensional hierarchical SVNT model (system-vehicle-network-traffic) based on system safety principles, capable of capturing causal risk propagation between the technical and environmental layers; (2) the DKB fusion strategy using Dempster–Shafer (DS) evidence theory, integrating multiple expert knowledge and reducing small sample bias; (3) an improved NewBIC scoring function with an adaptive scaling factor, capable of dynamically balancing expert knowledge and data reliability. Comprehensive experimental verification shows that SVNT-DKB has significant advantages in three aspects: (1) small sample robustness: with only 30 training samples, its overall accuracy reaches 86.7%, which is 33.4% higher than BPNN and 13.4% higher than SVM and the accuracy in high-risk scenarios is 86.3%; (2) industrial feasibility: compared with ANSYS Medini Analyze, it reduces data preprocessing time by 66.7% (10 ± 2[Formula: see text]ms versus 30 ± 5[Formula: see text]ms), increases system-level risk path coverage by 27% (92% versus 65%) and keeps diagnostic delay at 95 ± 3[Formula: see text]ms, meeting the real-time requirements of ISO 26262; (3) scenario generalization: it maintains reliable performance in urban intersections, highways and rainy conditions and the risk distribution is consistent with the accident statistics in the real world. These findings confirm the excellent performance of SVNT-DKB in small sample robustness, interpretability and real-time performance, effectively bridging the gap between limited data and the comprehensive safety guarantee requirements of ADSs. Bixin Li |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2026 | SDG-GNN based software design patterns detection
Facundo Chen, Lulu Wang 0001, Bixin Li |
Inf. Softw. Technol. | 3 |
| 2026 | A Survey of Blockchain Privacy Protection in Intra-Chain and Cross-Chain Scenarios: State-of-the-Art, Challenges, and Future WorkabstractThe rapid development of blockchain has spurred the emergence of programmable currency, finance, and society. However, blockchains are subject to severe privacy issues such as deanonymization, transaction linkability, and malicious contracts. Numerous studies in academia and industry have been dedicated to blockchain privacy protection. However, existing surveys tend to be limited in scope, often addressing only intra-chain privacy while neglecting cross-chain concerns and providing incomplete coverage of privacy protection methods. To facilitate interested researchers to comprehend the research field better, this paper presents a comprehensive survey about blockchain privacy protection utilizing a mapping study. We provide a detailed analysis of three types of privacy information, their corresponding privacy threats, four categories of privacy-preserving methods, and validation methods in intra-chain and cross-chain scenarios. We also summarize some typical applications of blockchain where privacy protection is crucial. Moreover, we highlight some deficiencies of the current study, and discuss challenges and future research directions in this field. Dongyu Cao, Bixin Li, Lulu Wang 0001 |
IEEE Trans. Big Data | 2 |
| 2026 | TRAGIC: Test Oracle Generation for ISA Compliance Testing via Large Language ModelabstractRISC-V is one of the latest Instruction Set Architectures (ISAs). It features an extremely modular and extensible design that makes it suitable for a variety of applications, from embedded systems to large computing systems. However, its inherent customizability and open nature also present challenges in terms of compliance and standardization. Traditionally, the validation relies on Spike as the reference simulator to generate compliance test oracles. Nevertheless, research has demonstrated that Spike may contain bugs, which may compromise the reliability of the generated test oracles. Therefore, developing new cross-validation methods has become increasingly important. To address this challenge, we propose TRAGIC, a method for generating compliance test oracles for RISC-V compliance testing based on Large Language Models (LLMs). Different from traditional software testing, ISA compliance testing demands a finer-grained multidimensional test oracle, including not only the program outputs but also the detailed program states, such as key registers and memory addresses. Furthermore, long instruction sequences frequently exceed the context limitations of LLMs, and direct reasoning under such conditions leads to a notable degradation in accuracy. Therefore, TRAGIC employs a hierarchical strategy with two key components. First, the Block Segmentation Component (BSC) decomposes complex test cases into manageable sub-tasks by analyzing the control flow and applying block slicing techniques. The segmentation both preserves the original program semantics and reduces the reasoning context, thereby enhancing inference accuracy. Second, the Graph of Inference Component (GIC) performs structured reasoning on these sub-tasks using explicitly designed Chain-of-Thought prompts. We utilize LLM to dynamically infer the output of each subtask and determine the next block to execute, continuing this iterative process until the entire task is completed. Meanwhile, key register and memory address tables are maintained and integrated into the final test oracle. By combining the BSC and the GIC, TRAGIC effectively mitigates the accuracy loss associated with long context information and enhances the accuracy of test oracle generation. TRAGIC passes evaluation on the official RISC-V compliance test suite with manually-written test cases. Furthermore, we also show that when integrated with automated test generation tools, our method found 6 bugs, 2 of which were previously unknown. Bixin Li, Xiaoning Du 0001, Lulu Wang 0001 |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 2 |
| 2026 | ZKVeil: A Privacy-Preserving Compliance Verification Scheme for Blockchain-Enabled Supply Chain TransactionsabstractBlockchain technology improves supply chain management by ensuring the immutability of transaction records and facilitating process tracking. However, the transparency of blockchain raises significant privacy concerns, as sensitive information such as buyer and supplier qualifications, product specifications, and transaction amounts is often exposed. Compliance verification, which needs access to specific sensitive data for compliance checks, becomes challenging in blockchain-based privacy-preserving supply chains. This paper introduces ZKVeil, an innovative scheme utilizing zero-knowledge proof technology to maintain the confidentiality of sensitive information while ensuring compliance verification. Additionally, ZKVeil uses decentralized identifiers and verifiable credentials to ensure the authenticity of transaction data. A theoretical security analysis demonstrates the effectiveness of ZKVeil in safeguarding real sensitive data and ensuring compliance with regulations. To evaluate the performance of our scheme, we implement ZKVeil on a private blockchain of 100 nodes. Taking the shipbuilding supply chain transaction as an example, the experimental results demonstrate that ZKVeil incurs low gas consumption, execution time, and memory overhead. Dongyu Cao, Bixin Li, Lulu Wang 0001 |
IEEE Trans. Inf. Forensics Secur. | 2 |
| 2026 | A Reinforcement Learning-Driven Adversarial Attack Methods With Dynamic Perturbation Optimization
Lulu Wang 0001, Xiaoning Du 0001, Jianming Chang, Bixin Li |
IEEE Trans. Reliab. | 5 |
| 2026 | A Reinforcement Learning-Driven Adversarial Attack Methods With Dynamic Perturbation Optimization
Lulu Wang 0001, Xiaoning Du 0001, Jianming Chang, Bixin Li |
IEEE Trans. Reliab. | 5 |
| 2026 | SA.Resilience.Evaluator: Evaluate the Resilience of Software Architecture Based on Attack Surface AnalysisabstractResilience is vital to software systems and helps them maintain an acceptable level of service in the face of various attacks. However, existing methods for evaluating the resilience of software system mainly focus on implemented software system, there is no effective method to evaluate resilience at design time. In addition, existing methods only concern specific types of software systems, lacking comprehensive consideration of multi-dimensional characteristics of software systems and they often have stringent conditions when evaluated in practical applications etc. In this paper, we propose a method for evaluating the resilience of software architecture based on attack surface analysis and it is applicable to various types of software systems. Our method first identifies potential security threats and vulnerabilities in software architecture through attack surface analysis technology. Then, our method analyzes the types and severity of potential external attacks on the software architecture by combining the CAPEC software attack database. After that, our method comes to evaluate the resilience of software architecture according to the safety, reliability, and restoration of software architecture. For the convenience of conducting the case studies, we first design and implement a tool called SA.Resilience.Evaluator and then we use the tool to evaluate the effectiveness of our method in two scenarios. In the first scenario, we use the UML activity diagram of software architecture model as the input of our tool, which was obtained from architecture designer; in the second scenario, we use architecture dependency graph as the input, which was obtained from architecture recovery techniques. The results of studies show that our method is better than existing methods in both effectiveness and efficiency. Jiaxin Pan 0004, Bixin Li |
IEEE Trans. Reliab. | 3 |
| 2026 | Bridging Bug Localization and Issue Fixing: A Hierarchical Localization Framework Leveraging Large Language ModelsabstractAutomated issue fixing is a critical task in software debugging and has recently garnered significant attention from academia and industry. However, existing fixing techniques predominantly focus on the repair phase, often overlooking the importance of improving the preceding bug localization phase. As a foundational step in issue fixing, bug localization plays a pivotal role in determining the overall effectiveness of the entire process.To enhance the precision of issue fixing by accurately identifying bug locations in large-scale projects, this paper presents BugCerberus, the first hierarchical bug localization framework powered by three customized large language models. First, BugCerberus analyzes intermediate representations of bug-related programs at file, function, and statement levels and extracts bug-related contextual information from the representations. Second, BugCerberus designs three customized LLMs at each level using bug reports and contexts to learn the patterns of bugs. Finally, BugCerberus hierarchically searches for bug-related code elements through well-tuned models to localize bugs at three levels. With BugCerberus, we further investigate the impact of bug localization on the issue fixing.We evaluate BugCerberus on the widely-used benchmark SWE-bench-lite. The experimental results demonstrate that BugCerberus outperforms all baselines. Specifically, at the fine-grained statement level, BugCerberus surpasses the state-of-the-art in Top-N (N=1, 3, 5, 10) by 16.5%, 5.4%, 10.2%, and 23.1%, respectively. Moreover, in the issue fixing experiments, BugCerberus improves the fix rate of the existing issue fixing approach Agentless by 17.4% compared to the best baseline, highlighting the significant impact of enhanced bug localization on automated issue fixing. Jianming Chang, Xin Zhou 0014, Lulu Wang 0001, David Lo 0001, Bixin Li |
IEEE Trans. Software Eng. | 5 |
| 2025 | A Software Architecture Resilience Assessment Method via Dynamic Bayesian NetworksabstractResilience is essential for software to maintain continuous service under unpredictable attacks and failures. However, most existing assessment methods are domain-specific and depend on post-deployment monitoring, which limits generalizability and raises secondary development costs. This paper proposes a resilience assessment method based on dynamic Bayesian networks (DBN) at the software architecture design stage. The method quantitatively evaluates resilience by modeling architectural dependencies and simulating dynamic attack and restoration scenarios, integrating both availability and restoration. Experimental validation in five architectural styles and 11 real-world systems demonstrates its effectiveness and generality. Furthermore, the method identifies key architectural factors that influence resilience, providing actionable guidance for early-stage design optimization. Hao Chen 0109, Bixin Li |
APSEC | 2 |
| 2025 | AutoRCA: A Graph Sequence-based Automatic Root Cause Analysis Method for Microservice Systems through Multimodal DataabstractAutomatic root cause analysis (AutoRCA) of faults in microservices systems is a critical and challenging task. Existing RCA methods leverage one or more types of monitoring data, such as traces, metrics and logs, yet they face two issues: on the one hand, almost all single-modal approaches often struggle to completely identify the root cause, since faults can manifest as anomalies in different data sources; on the other hand, current almost all multimodal methods show low performance of RCA, since they cannot understand dynamic interactions between services adequately and demonstrate insufficient representational capabilities for multimodal data. To address these two issues, we introduce AutoRCA, a novel RCA approach based on multimodal data and graph sequence structures. The key innovations and contributions of our study lie in the construction of graph sequence structures and the integration of multimodal data to comprehensively model service behaviors for RCA. AutoRCA employs Graph Attention Network (GAT) to extract features of each graph and construct a time-series representation of services across the entire period from the graph sequence, thereby achieving accurate root cause localization. Experimental results on two widely used datasets demonstrate that AutoRCA significantly outperforms state-of-the-art methods in performance. Specifically, it achieves a Top-1 accuracy exceeding 0.7 and an average Top-5 accuracy surpassing 0.9. The results of two ablation experiments further show that the impact of multimodal data and model components to the performance of AutoRCA is positive. Yingying Shen, Bixin Li |
APSEC | 3 |
| 2025 | TrustFabric: A Privacy-Preserving Method for Hyperledger Fabric Using Trusted Execution EnvironmentabstractHyperledger Fabric has experienced widespread adoption across various domains, concurrently revealing the gradual emergence of privacy-related concerns. Trusted Execution Environment (TEE) is a secure and isolated environment for sensitive computations. The current TEE-based privacy protection method for Fabric has been proposed, but the method suffers from scalability issues, limited compatibility, and security problems. We present TrustFabric, a novel privacy protection method for Fabric leveraging TEE. TrustFabric transfers contracts involving private data to the TEE cluster for execution. Sensitive data are transmitted in encrypted form to ensure data privacy. We implement TrustFabric based on Intel SGX and Fabric. We analyze the effectiveness and anti-attack ability of TrustFabric, and evaluate the performance by experiments. The results indicate that TrustFabric can effectively protect the privacy data involved in the contract and mitigate Denial-ofService attacks, side-channel attacks, and masquerade attacks. Furthermore, TrustFabric has better performance in highly concurrent application scenarios. Dongyu Cao, Bixin Li, Lulu Wang 0001 |
ICPADS | 2 |
| 2025 | Towards Task-Harmonious Vulnerability Assessment Based on LLMabstractSoftware vulnerabilities seriously jeopardize software security. It would be highly beneficial if developers could receive severity reminders regarding vulnerabilities when developing software systems. Therefore, when handling numerous vulnerabilities, it's crucial to prioritize the most critical ones and assess their severity early for effective resolution. Vulnerability assessment needs to train multiple assessment tasks simultaneously. Previous works suffer from task-disharmonious issues when conducting vulnerability assessments because they fail to balance the magnitude of gradients across multiple tasks and the conflicts in gradient directions. Additionally, they use identical code embedding for all classifiers without extracting task-related features. In this study, we are the first to conduct vulnerability assessment in a task-harmonious way by harmonizing gradient direction and magnitude, and filtering out task-specific features for each classifier. In addition, we use finer-grained contextual information than existing works by program slicing to further boost the model performance. According to experiment results, our model has demonstrated state-of-the-art performance at both the commit and function levels. Specifically, in function-level tasks, our model achieves an average of 0.819 in F1-Score and 0.742 in MCC, outperforming all baseline models. For commitlevel, our model enhances the average performance of the best baseline model by 29.6 % and 64.7 % in F1-Score and MCC, respectively. Zaixing Zhang, Jianming Chang, Tianyuan Hu, Lulu Wang 0001, Bixin Li |
ICPC | 5 |
| 2025 | A Method to Evaluate the Credibility of Domain Knowledge Network Using Validated Expert KnowledgeabstractWe are living in an era of knowledge explosion, where all kinds of knowledge are emerging and becoming more and more complicated with the development of new techniques and new ideas. When we study knowledge and apply them to understand and solve problems, the credibility of knowledge is becoming our main concerns. Usually, high credible domain knowledge can guide us correctly understand all concepts and the relationships between them in this domain. Due to its good layer structure and scalability, domain knowledge network is widely used to represent knowledge in knowledge engineering, artificial intelligence and others in recent years. How to ensure the credibility of domain knowledge network? This is an important and interesting topic. In this paper, we propose a method to evaluate the knowledge credibility for domain knowledge network, which means that we can start from the layer structure of domain knowledge network, and evaluate the credibility of knowledge layer by layer using validated expert knowledge such as domain dictionary, domain ontology and domain expert experience. We conduct experiments with six domain knowledge network constructed based on network data and six domain knowledge network constructed manually based on published books or domain dictionaries, which describe the same domain knowledge in pairs. Experimental results show that the knowledge credibility of domain knowledge network constructed from validated expert knowledge is significantly higher than the knowledge credibility of domain knowledge network constructed directly from network data, which satisfy our expectation and also prove the effectiveness of our credibility evaluation method. Bixin Li |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2025 | Dynamic information utilization for securing Ethereum smart contracts: A literature review
Tianyuan Hu, Bixin Li |
Inf. Softw. Technol. | 2 |
| 2025 | A Random Mixing Scheme for Protecting Transaction Privacy on Ethereum
Dongyu Cao, Bixin Li |
J. Comput. Sci. Technol. | 3 |
| 2025 | SeMi_Detector: Multilayer Perceptron-Based Selfish Mining Detection
Qihao Bao, Bixin Li, Lulu Wang 0001 |
Peer Peer Netw. Appl. | 2 |
| 2025 | A privacy-preserving method for cross-chain interoperability using homomorphic encryption
Dongyu Cao, Bixin Li, Jingyuan Cai |
Peer Peer Netw. Appl. | 2 |
| 2025 | Why Smart Contracts Reported as Vulnerable Were Not Exploited?abstractSmart contract security is crucial for blockchain applications. While studies suggest that only a small fraction of reported vulnerabilities are exploited, no follow-up research has investigated the reasons behind this. Our goal is to understand the factors contributing to the low exploitation rate to improve vulnerability detection and defense mechanisms. We collected 136,969 real-world smart contracts and analyzed them using seven vulnerability detectors. We applied Strauss’ grounded theory to gain insights into exploitability and analyzed transaction logs to trace the historic exploitations. Among the 4,364 smart contracts flagged as vulnerable, a significant 75.25% were found to be unexploitable, meaning they were either false positives or posed no security risk. We identified ten reasons for reporting unexploitable vulnerabilities. Furthermore, we found that only 66 out of 1,080 (6%) exploitable contracts had been exploited. We compared the characteristics of exploited versus non-exploited vulnerabilities and identified five factors that may reduce the likelihood of exploitation. Our findings highlight the importance of not treating smart contracts as conventional object-oriented (OO) applications. Researchers must account for the unique features of Solidity, smart contract design principles, and execution environments. Based on these insights, we propose six recommendations to improve smart contract vulnerability detection, prioritization, and mitigation. Tianyuan Hu, Jingyue Li, Bixin Li, André Storhaug |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2025 | How Do Characteristic Parameters Affect the Security of Proof-of-Work Blockchain?abstractThe Proof of Work (PoW) consensus protocol stands as one of the most prevalent mechanisms in blockchain technology. However, its inherent proof mechanism inevitably leads to forking, making it vulnerable to security risks such as double-spending attacks, selfish mining, and whale attacks. Through research, blockchain characteristic parameters such as block generation time, block size, block propagation speed, number of nodes, and network connectivity will affect the fork rate of PoW blockchain. However, the existing studies only considered the effect of some of the parameters on the fork rate. There is no specific and detailed analysis of the effect factors of the fork rate, and there is no relevant quantitative evaluation. In this paper, we employ a quantitative evaluation model to delve into the effect of various characteristic parameters of the blockchain on the security of PoW in three distinct scenarios: 1) uniform computing power among all nodes; 2) selective non-participation of nodes in the computing power competition; and 3) collusion among honest nodes forming mining pools. Our analysis uncovers that smaller blocks, extended block generation time, fewer nodes, and higher network connectivity contribute to bolstering the security of the PoW blockchain. Moreover, a higher number of non-participating nodes correlates with a lower fork rate. Interestingly, collusion among nodes in mining pools exhibits no discernible effect on the fork rate of blockchain. Our findings are further validated through simulation results. The experimental results show that the block generation time should be maintained between 5 and 10 minutes and the block size should be maintained around 2 MB. For block propagation speed, the faster the better. With the increase in the number of nodes in the system, the network connectivity should be improved promptly. Furthermore, we provide security recommendations tailored for PoW blockchain designers, aimed at fortifying the resilience of their systems against potential threats. Qihao Bao, Bixin Li, Dongyu Cao |
IEEE Trans. Netw. Serv. Manag. | 2 |
| 2025 | IATT: Interpretation Analysis-based Transferable Test Generation for Convolutional Neural NetworksabstractConvolutional Neural Networks (CNNs) have been widely used in various fields. However, it is essential to perform sufficient testing to detect internal defects before deploying CNNs, especially in security-sensitive scenarios. Generating error-inducing inputs to trigger erroneous behavior is the primary way to detect CNN model defects. However, in practice, when the model under test is a black-box CNN model without accessible internal information, in some scenarios it is still necessary to generate high-quality test inputs within a limited testing budget. In such a new scenario, a potential approach is to generate transferable test inputs by analyzing the internal knowledge of other white-box CNN models similar to the model under test, and then use transferable test inputs to test the black-box CNN model. The main challenge in generating transferable test inputs is how to improve their error-inducing capability for different CNN models without changing the test oracle. We found that different CNN models make predictions based on features of similar important regions in images. Adding targeted perturbations to important regions will generate transferable test inputs with high realism. Therefore, we propose the Interpretable Analysis-based Transferable Test (IATT) Generation method for CNNs, which employs interpretation methods of CNN models to explain and localize important regions in test inputs, using backpropagation optimizer and perturbation mask process to add targeted perturbations to these important regions, thereby generating transferable test inputs. This process is repeated to iteratively optimize the transferability and realism of the test inputs. To verify the effectiveness of IATT, we perform experimental studies on nine deep learning models, including ResNet-50 and Vit-B/16, and commercial computer vision system Google Cloud Vision , and compared our method with four state-of-the-art baseline methods. Experimental results show that transferable test inputs generated by IATT can effectively cause black-box target models to output incorrect results. Compared to existing testing and adversarial attack methods, the average Error-inducing Success Rate (ESR) in different testing scenarios is 18.1%–52.7% greater than the baseline methods. Additionally, the test inputs generated by IATT achieve high ESR while maintaining high realism. Ruilin Xie, Xiang Chen 0005, Qifan He, Bixin Li, Zhanqi Cui |
ACM Trans. Softw. Eng. Methodol. | 4 |
| 2025 | PonziFinder: Attention-Based Edge-Enhanced Ponzi Contract DetectionabstractPonzi contractsare fraudulent investment scams that promise high returns with little risk to investors. However, existing methods for detecting Ponzi contracts have several limitations. For example, they struggle to deal with the class imbalance problem, and their analysis of function call transactions is inadequate, resulting in redundant features. To tackle the challenges of detecting Ponzi contracts, we present PonziFinder, a novel approach that leverages convolutional-based edge-enhanced graph neural network and attention mechanism for the classification of contract transaction graphs. In contrast to previous methods, we not only consider transaction value and timestamp but also analyze transaction input to standardize and sort transactions. We extract node and edge features that capture the unique characteristics of Ponzi contracts. The edge feature, reflecting interaccount correlation, enhances the propagation and updating of node features for effective Ponzi contract detection. To prevent oversmoothing of node embedding caused by the shallow transaction graph and extract important account node information, we introduce an attention-based global layerwise aggregation mechanism (ALGA) for generating the final contract graph representation for classification. Moreover, we optimize the node feature set and use an effective strategy based on undersampling and ensemble learning to address the issue of class imbalance. Experimental results show that PonziFinder can detect all types of Ponzi contracts (100%) with 97% accuracy when there is sufficient transaction data, outperforming other models. The analysis of input values and the ALGA mechanism are experimentally shown to improve accuracy by 4% and 2%, respectively. In summary, PonziFinder is a novel and effective method for detecting Ponzi contracts. Our approach addresses the limitations of existing methods and demonstrates significant improvements in accuracy and efficiency. Bixin Li, Yan Xiao 0002, Xiaoning Du 0001 |
IEEE Trans. Reliab. | 2 |
| 2025 | VulFinder: Exploring Chaincode Vulnerabilities More Effectively and Efficiently Using Knowledge Graph Based Defect Pattern MatchingabstractHyperledger Fabric is an open-source project of Linux Foundation, it is a modular blockchain framework and has become an unofficial standard for enterprise blockchain platforms. In Hyperledger Fabric, smart contract is also known as chaincode, which are usually written using general-purpose languages, including Go, Java or Node.js etc. Although there are some vulnerability detection methods for Java and Node.js, there are very few vulnerability detection methods for Go, especially when it is used as a smart contract programming language in Hyperledger Fabric.In this article, we propose a knowledge graph based defect pattern matching method and develop a tool calledVulFinderto detect vulnerabilities in chaincode, i.e. the smart contracts written using Go language. Knowledge graph is used because it can fully retain the syntax and logic information of smart contracts. The method consists of two key steps: a knowledge graph is constructed fromGo language specificationand chaincode source code, including the definition of ontology layer and the construction of instance layer; the defect patterns are defined and SPARQL query statements are used to match and locate vulnerabilities on the knowledge graph. To evaluate the detection effectiveness and efficiency ofVulFinder, we construct two datasets through manual analysis and vulnerabilities injection due to the lack of public datasets. Experimental results show thatVulFindercan detect 22 kinds of typical vulnerabilities of chaincode effectively, and therecallis as high as 98.87%, while thefalse negative rateis as low as 1.13% . Bixin Li, Tianyuan Hu, Xiangfei Xu, Lulu Wang 0001 |
IEEE Trans. Software Eng. | 1 |
| 2024 | Learning Graph-based Patch Representations for Identifying and Assessing Silent Vulnerability FixesabstractSoftware projects are dependent on many third-party libraries, therefore high-risk vulnerabilities can propagate through the dependency chain to downstream projects. Owing to the subjective nature of patch management, software vendors commonly fix vulnerabilities silently. Silent vulnerability fixes cause downstream software to be unaware of urgent security issues in a timely manner, posing a security risk to the software. Presently, most of the existing works for vulnerability fix identification only consider the changed code as a sequential textual sequence, ignoring the structural information of the code.In this paper, we propose GRAPE, a GRAph-based Patch rEpresentation that aims to 1) provide a unified framework for getting vulnerability fix patches representation; and 2) enhance the understanding of the intent and potential impact of patches by extracting structural information of the code. GRAPE employs a novel joint graph structure (MCPG) to represent the syntactic and semantic information of silent fix patches and embeds both nodes and edges. Subsequently, a carefully designed graph convolutional neural network (NE-GCN) is utilized to fully learn structural features by leveraging the attributes of the nodes and edges. Moreover, we construct a dataset containing 2251 silent fixes. For the experimental section, we evaluated patch representation on three tasks, including vulnerability fix identification, vulnerability types classification, and vulnerability severity classification. Experimental results indicate that, in comparison to baseline methods, GRAPE can more effectively reduce false positives and omissions of vulnerability fixes identification and provide accurate vulnerability assessments. Lulu Wang 0001, Jianming Chang, Bixin Li |
ISSRE | 4 |
| 2024 | Test Case Generation for Access Control Based on UML Activity DiagramabstractAccess control is a vital component of information system security, ensuring that resources are only accessible to authorized users with specific permissions. However, traditional testing methods still face challenges when solving complex access control scenarios, such as third-party login and authorization/authentication. To address these challenges, this paper presents a method for generating access control test cases based on UML activity diagrams. The method focuses on two key scenarios in access control: third-party login and authorization/authentication. For the third-party login scenario, the method incorporates the OAuth 2.0 protocol and conducts a detailed analysis of security issues associated with third-party login processes. For the authorization and authentication scenario, the method models the permission control workflow and performs a comprehensive parse and traversal of the activity diagram structure. Lastly, an empirical study utilizing seven distinct combinations of third-party login and two widely used authentication frameworks provides successful validation of the proposed method. This validation demonstrates the significant impact of the method in uncovering seven specific security issues. Furthermore, the method exhibits efficient problem identification capabilities for potential vulnerabilities within the authorization authentication system. It effectively exposes three types of security flaws that are commonly difficult to detect. Ao Fan, Lulu Wang 0001, Bixin Li |
QRS | 4 |
| 2024 | OTCP-ISVM: Online Test Case Prioritization Based on Incremental Support Vector MachineabstractAs software development technology becomes increasingly mature, the challenge to software testing efficiency is also increasing. Giving developers faster feedback on their code is essential for developing software. Test Case Prioritization (TCP) is one of the most popular techniques to optimize software testing. However, most TCP techniques rely on coverage information extracted from source code or execution history obtained from past executions and cannot be applied to preliminary software testing. What’s more, offline TCP technology cannot provide timely feedback to testers, affecting testing efficiency. To address the problem, this paper proposes a novel online TCP technique based on Incremental Support Vector Machine, which is called OTCP-ISVM. OTCP-ISVM dynamically reprioritizes the test cases when new failures are detected by using support vectors from previous training round and adapting the segmentation hyperplane. We have evaluated OTCP-ISVM on a large-scale project. The experimental results showed that OTCP-ISVM can achieve dynamic prioritization of the test cases. Compared with SVM algorithm and random algorithm, the fault detection speed of OTCP-ISVM algorithm is improved by 22% and 14% respectively. Huaixu Lin, Bixin Li, Lulu Wang 0001, Jianming Chang |
QRS | 2 |
| 2024 | Graph-Based Salient Class Classification in CommitsabstractIn software engineering, code review is an important process when a project is to be upgraded. Reviewers need to assess the validity of a commit, even if they are not familiar with the files in the commit. In a typical commit, one or more mainly modified classes referred to as salient classes, may cause modifications in other classes. Salient Class Identification is such a method that can help reviewers review commits more effectively. In this way, after identifying salient classes, reviewers can allocate most of their efforts to analyzing the salient class, comprehending the commit, and providing reasoned assessments. The existing Salient Class Identification model is based on the static features of the code and does not analyze the internal logical information, such as the relationships between statements. We thoroughly consider both internal and external code information in commits, using a detailed Code-Change Dependency Graph (CCDG) to depict the code structure. CCDG includes various node and edge types, supporting complex syntax scenarios, which can capture fine-grained dependencies. Finally, based on a heterogeneous graph neural network, we extract nuanced features embedding from CCDG, which can further boost the performance of our model. The experiment result shows that our model outperforms existing models in Salient Class Identification, achieving an overall $88 \%$ accuracy. Jiahao Ren, Jianming Chang, Lulu Wang 0001, Zaixing Zhang, Bixin Li |
QRS | 5 |
| 2024 | A Business-Oriented Methodology to Evaluate the Security of Software Architecture QuantitativelyabstractSoftware architecture security design is a key stage in developing business-oriented system, such as business-critical system, ICT system and AI system. Many typical accidents also remind us that the security of software architecture even plays a more important role than the code security in most software systems. However, there are very few researches which focus on the security of software architecture. Especially, we don’t find a systematic and feasible quantitative method to evaluate the security of software architecture. To fill this gap, we launched a research project focusing on software architecture security since 2019 and try to provide a series of quantitative methods for evaluating the security of software architecture. In this paper, a business-oriented quantitative method was proposed to evaluate the security of software architecture from the view of business-critical security insurance. In our method, both business dependency graph (BDG) and multi-hierarchical dependency graph (MHDG) are defined and constructed first for describing businesses and their relationships, and system components and their relationships; then, attack points and business key-points are identified and labeled on BDG and MHDG; and further, all potential attack paths and effective attack paths in the system based on MHDG are detected; and finally, a set of security indicators is defined and used to evaluate the security of software architecture quantitatively. For more effective experiments, we use software architectures with different styles and different evolution versions. Experimental results show that our method can reflect effectively the security characteristics of software architecture with different styles, can find the security changes of different architecture evolution versions for the same system, and can perform quantitative evaluation of software architecture security efficiently. Hao Chen 0109, Shengyang Zhou, Zheng Dai, Bixin Li |
Int. J. Softw. Eng. Knowl. Eng. | 5 |
| 2024 | EsArCost: Estimating repair costs of software architecture erosion using slice technology
Bixin Li |
J. Syst. Softw. | 2 |
| 2024 | SoliTester: Detecting exploitable external-risky vulnerability in smart contracts using contract account triggering methodabstractAbstract The vulnerability in smart contracts (SCs) on the blockchain system may lead to severe security compromises. The SC can be invoked from an externally owned account (EOA) or a contract account (CA). The account a user creates to receive or send ether is an EOA. A CA contains codes that can interact with SCs. In Solidity SC, some vulnerabilities can only be exploited by the interactions between CAs and vulnerable SCs, which can be named external‐risky vulnerabilities. Most state‐of‐the‐art (SOTA) detectors detect external‐risky vulnerabilities by executing contract codes as an EOA user, thus reporting many unexploitable vulnerabilities. Therefore, we propose a CA‐triggering method to identify exploitable external‐risky vulnerabilities in Solidity SCs. We first designed agent contracts to simulate CAs' interactions with the target SCs in the real blockchain environment. We then detect vulnerability exploitation by analyzing transaction logs between agent contracts and target SCs and identifying successful exploits. We implemented the CA‐triggering method in a tool named SoliTester and evaluated it using three benchmark datasets, which contain three types of external‐risky vulnerabilities, namely, Reentancy (RE), Unchecked Call (UcC), and TxOrigin (TO). The results show that SoliTester can efficiently detect exploitable external‐risky vulnerabilities with significantly better precisions and recalls than SOTA detectors. Tianyuan Hu, Jingyue Li, Xiangfei Xu, Bixin Li |
J. Softw. Evol. Process. | 4 |
| 2024 | Detect Defects of Solidity Smart Contract Based on the Knowledge GraphabstractSmart contract security is one of the core issues in any application based on blockchain. There are many techniques focusing on smart contract security, however, due to the diversity of Solidity versions and limitations of detection time, it is difficult for them to comprehensively localize defects in different versions of smart contracts. In this article, we propose a static defect detection method based on the knowledge graph of the Solidity language and present a defect detection tool calledSoliDetector. First, we define the ontology layer of the knowledge graph and construct the instance layer in which syntactic and logical relationships are captured. Second, we introduce the defect pattern to describe each defect and design inference rules to infer complex relationships and judge whether a defect exists. Finally, we localize defects by executing SPARQL queries.SoliDetectorcan support the detection of 20 kinds of defects and the automatic SPARQL query generation. We conducted several experiments on multiple datasets.SoliDetectorobtains a highF-score(i.e., 92.97% on Dataset1 and 91.54% on the SmartBug dataset). To compareSoliDetectorwithSmartCheck,Slither, andMythril, we conducted experiments on a labeled benchmark Dataset3 and real-world contracts.SoliDetectorhas a highF-scoreof 94.04% and is faster than other tools with an average time of 0.37 s for each contract. Tianyuan Hu, Bixin Li, Zhenyu Pan |
IEEE Trans. Reliab. | 2 |
| 2023 | CCDetector: Detect Chaincode Vulnerabilities Based on Knowledge Graph
Xiangfei Xu, Tianyuan Hu, Bixin Li |
COMPSAC | 3 |
| 2023 | A Quality-Driven Iterative Evolution Approach for Software ArchitectureabstractThe quality attributes of software architecture (SA) determine whether SA can be easily understood, tested, modified and so on, so quality-driven architecture evolution is important for keeping the viability and competitiveness. SA evolution is a process, and it contains multiple steps, such as SA quality measurement, SA modification, code co-evolution and so on. In order to guarantee that the software can be continuously improved and iteratively evolved in the future, we need to focus on all steps. However, most existing approaches only focus on one aspect, so they did not pay attention to how to finish the evolution process. In this paper, we propose a quality-driven iterative evolution approach for SA. This approach focuses on the whole process. In the first step, we use a quantitative approach to measure the architecture quality. Then, we construct the conflict graph to detect conflicts between evolution requirements to generate the final evolution scheme. In the third step, we modify architecture based on the evolution scheme. Finally, we co-evolve file dependency graph (FDG) based on the modified architecture. By focusing on the above steps, our approach can support a complete quality-driven architecture evolution process and obtain the maximum benefit in terms of the combined SA quality. We conduct our experiments with four open source projects, the experimental results indicate that our approach can improve SA quality, and our approach can effectively co-evolve the FDG to lay the foundation for the next evolution. Bixin Li, Lingyuan Zhu |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2023 | A Hierarchical Model for Quality Evaluation of Mixed Source Software Based on ISO/IEC 25010abstractWith the emergence of mixed source software, the existing quality models are not able to better assess the community quality and autonomy controllability of mixed source software. To fill this gap, we propose a hierarchical model in this paper for quality assessment of mixed source software. In our model, the new attributes are proposed to meet the quality requirements of mixed source software based on the ISO/IEC 25010 standards, and a set of metrics are designed for the new attributes. The model evaluates the quality of mixed source software through quality attributes that have been quantified by the metrics. Applying our quality model to some mixed source software and comparing the model results with the actual situation, we verify whether our proposed two quality attributes, community intensity and autonomy controllability, can effectively assess the quality of mixed source software. The results of the experiments show that our model is indeed effective in assessing the quality of mixed source software. An important feature of our model is that the model has good flexibility, and the set of quality attributes and metrics can be adjusted freely, which provides a flexible and feasible way for various software quality assessment requirements. Bixin Li, Lulu Wang 0001, Haixin Xu, Tao Shao |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2023 | A survey of blockchain consensus safety and security: State-of-the-art, challenges, and future work
Qihao Bao, Bixin Li, Tianyuan Hu, Xueyong Sun |
J. Syst. Softw. | 2 |
| 2023 | An empirical study of software architecture resilience evaluation methods
Jiaxin Pan 0004, Lulu Wang 0001, Bixin Li |
J. Syst. Softw. | 5 |
| 2023 | Microservice architecture recovery based on intra-service and inter-service features
Lulu Wang 0001, Xianglong Kong, Wenjie Ouyang, Bixin Li, Haixin Xu, Tao Shao |
J. Syst. Softw. | 5 |
| 2022 | Model Checking the Safety of Raft Leader Election AlgorithmabstractWith the wide application of the Raft consensus algorithm in blockchain systems, its safety has attracted more and more attention. However, although some researchers have formally verified the safety of the Raft consensus algorithm in most scenarios, there are still some safety problems with Raft consensus algorithm in some special scenarios, and cause problems now and then. For example, as a core part of the Raft consensus algorithm, the Raft leader election algorithm usually faces some safety problems in following scenarios: if the network communication between some nodes is abnormal, the leader node could be unstable or even cannot be elected, or the log entry cannot be updated, etc. In this paper, we model check the safety of the Raft leader election algorithm throughly using Spin. We use Promela language to model the Raft leader election algorithm and use Linear-time Temporal Logic (LTL) formulae to characterize three safety properties including stability, liveness, and uniqueness. The verification results show that the Raft leader election algorithm does not hold stability and liveness when some nodes are faulty and node log entries are inconsistent. For these safety problems, we give the suggestions for improving safety by analyzing counter examples. Qihao Bao, Bixin Li, Tianyuan Hu, Dongyu Cao |
QRS | 2 |
| 2022 | A BiLSTM-Attention Model for Detecting Smart Contract Defects More AccuratelyabstractSmart contracts are applications running on the blockchain which control many virtual currencies. Since smart contracts are composed of code, they inevitably have defects. In recent years, many smart contract defects have caused lots of economic losses and harmful impacts. A contract that has defects may have some errors that cause unwanted results. As smart contracts cannot be modified once deployed, it is necessary to ensure that they are free from defects. In this paper, we focus on eleven defects of smart contracts and construct a deep learning-based model to detect these contract defects more accurately. Our model regards the smart contract’s operation codes as a sequential sentence and uses an Attention-based bidirectional long short term memory (BiLSTM-Attention) model to find smart contract defects. We evaluate our model’s and other models’ performance on 45622 real-world smart contracts. The experimental results show that our model can achieve higher accuracy (95.40%) and F1-score (95.38%). In addition, our model is highly efficient and can quickly detect large numbers of contracts. Tianyuan Hu, Bixin Li |
QRS | 3 |
| 2022 | Can PoW Consensus Protocol Resist the Whale Attack?abstractProof of Work (PoW) is the most widely used consensus protocol. However, due to the hash rate competition mechanism, longest chain principle, and transaction fee mechanism of the PoW consensus protocol, malicious nodes can launch attacks to obtain more relative revenue than honest mining, which will discourage honest miners from packing transactions into blocks and verifying blocks. As a result, the speed of the nodes reaching consensus in the network is slowed down, or even consensus cannot be reached, which ultimately affects the security of the PoW consensus protocol.In this paper, the Markov Decision Process (MDP) is used to simulate the whale attack launched by malicious nodes, and evaluate the capability of PoW consensus protocol against the whale attack. The experimental results show that the PoW consensus protocol is secure in the Bitcoin network when the transaction fee is set in the range of 0.002-0.3 block rewards and the transaction volume should not exceed 21.09 block rewards. In addition, the PoW consensus protocol will be more secure with the adjustment of parameters such as the number of block confirmations, block generation interval and block size. Xueyong Sun, Qihao Bao, Bixin Li |
QRS | 3 |
| 2022 | An incremental software architecture recovery technique driven by code changesabstractIt is difficult to keep software architecture up to date with code changes during software evolution. Inconsistency is caused by the limitations of standard development specifications and human power resources, which may impact software maintenance. To solve this problem, we propose an incremental software architecture recovery (ISAR) technique. Our technique obtains dependency information from changed code blocks and identifies different strength-level dependencies. Then, we use double classifiers to recover the architecture based on the method of mapping code-level changes to architecture-level updates. ISAR is evaluated on 10 open-source projects, and the results show that it performs more effectively and efficiently than the compared techniques. We also find that the impact of low-quality architectural documentation on effectiveness remains stable during software evolution. Li Wang 0096, Xianglong Kong, Bixin Li |
Frontiers Inf. Technol. Electron. Eng. | 4 |
| 2022 | Software defect prediction employing BiLSTM and BERT-based semantic feature
Md Nasir Uddin, Bixin Li, Zafar Ali, Pavlos Kefalas, Inayat Khan, Islam Zada |
Soft Comput. | 2 |
| 2022 | ReDefender: Detecting Reentrancy Vulnerabilities in Smart Contracts AutomaticallyabstractAs one of the most complex types of vulnerabilities, reentrancy poses a significant threat to smart contract development. Indeed, millions of dollars have evaporated due to reentrancy vulnerabilities of smart contracts in past years. In this article, we propose a new approach to detect reentrancy vulnerabilities using fuzz testing and develop a novel tool named ReDefender. Our approach consists of three main steps: 1)preprocess contract to be detected:when a contract is uploaded, its source code will be preprocessed to extract candidate pool for fuzzing and dependency graph which guides the automatic deployment of contracts; 2)fuzzing input generation:fuzzing input is generated to constitute transactions which will be sent to an agent contract to stimulate attacks, where runtime information is collected and recorded in the execution log during each execution; and 3)vulnerability verification:the execution log is analyzed to determine whether a reentrancy process occurs and whether the reentrancy process is malicious. We conduct comparative experiments on 204 tagged smart contracts and 90 injected contracts. The results show higher accuracy and lower false negative rate of ReDefender than that of the other three famous tools. Moreover, we conduct an experiment on 4776 real-world contracts demonstrating the ability of ReDefender to find reentrancy vulnerabilities that really cause economic losses. Bixin Li, Zhenyu Pan, Tianyuan Hu |
IEEE Trans. Reliab. | 1 |
| 2021 | ReDefender: A Tool for Detecting Reentrancy Vulnerabilities in Smart Contracts EffectivelyabstractReentrancy, one of the most complex type of vulner-abilities, poses significant threat to smart contract development. Indeed, millions of dollars have evaporated due to reentrancy vulnerabilities of smart contracts in past years. In this paper, we propose a new approach to detect reentrancy vulnerabilities using fuzz testing and develop a novel tool named ReDefender. Our approach and tool consists of four main steps: (1)preprocess contract to be detected: when a contract uploaded, its source code will be preprocessed by ReDefender to extract candidate pool for fuzzing; (2) generate fuzzing input: fuzzing input will be generated by fuzz engine; (3) collect runtime information: an agent contract is constructed to interact with and attack all contracts to be detected. Runtime information is collected during the execution of every fuzzing input; (4) analyze execution log and find reentrancy: the execution log is analyzed to determine whether a malicious reentrancy occurs. We conduct experiments on 204 tagged smart contracts and show the higher accuracy and lower false positive rate of ReDefender than that of other three famous tools. Moreover, we conduct a new experiment and find 4 reentrancy vulnerabilities in 395 on-chain contract accounts which have managed more than 1000 transactions. Zhenyu Pan, Tianyuan Hu, Bixin Li |
QRS | 4 |
| 2021 | SolDetector: Detect Defects Based on Knowledge Graph of Solidity Smart ContractabstractSmart contract security is one of core security issues in the application of blockchain.In recent years, attacks on smart contracts occur frequently, there are a lot of researches concerning on smart contract security issues.However, almost all solutions proposed in these researches are low precision and high False Negative Rate(FNR).In this paper, we propose a defect detection method for checking security of Solidity smart contract based on knowledge graph.Therefore, we first construct knowledge graph of smart contracts by fully integrating syntax and semantic information of Solidity source code; then, we define defect patterns by analyzing defect characteristics; furthermore, we define inference rules for defects based on knowledge graph and defect patterns; finally, we detect defects by SPARQL query.We also implement a tool named SolDetector and perform experiment on three different datasets, which shows that SolDetector is effective and efficient. Tianyuan Hu, Zhenyu Pan, Bixin Li |
SEKE | 3 |
| 2020 | A Combined Method for Usage of NLP Libraries Towards Analyzing Software Documents
Xinyun Cheng, Xianglong Kong, Bixin Li |
CAiSE | 4 |
| 2020 | An Empirical Investigation into the Effects of Code Comments on Issue ResolutionabstractComments are beneficial for developers to understand and maintain the code in software development life cycle. Well-commented code can generally help developers to resolve issues efficiently. Due to the complexity of code implementation, code comments may be generated to represent different types of information. And it is hard to keep all the code well-commented in real-world projects. In this case, it is meaningful to investigate how the different types of comments impact the resolution of issues. Then we can maintain the code comments purposefully, and we can also provide some suggestions for the comment generation techniques. To analyze the efforts of different comments on issue resolution, we classify code comments into two categories, i.e., functionality-aspect and non-functionality-aspect comments. In this paper, we analyze the effects of 53k pieces of code comments on the issues from 10 open-source projects within a period of 24 months. The results show that the majority of code comments are used to represent the functionality, e.g., the summary and purpose of code. Nevertheless, the other non-functionality-aspect comments have much stronger correlation with the resolution of software issues. For the resolved patches, the non-functionality-aspect comments are more frequently to be updated or added than the functionality-aspect comments. These findings confirm the important role of non-functionality-aspect comments during issue resolution, although their proportion is far less than that of functionality-aspect comments. Qiwei Song, Xianglong Kong, Lulu Wang 0001, Bixin Li |
COMPSAC | 4 |
| 2020 | An Analysis of Utility for API Recommendation: Do the Matched Results Have the Same Efforts?abstractThe current evaluation of API recommendation systems mainly focuses on correctness, which is calculated through matching results with ground-truth APIs. However, this measurement may be affected if there exist more than one APIs in a result. In practice, some APIs are used to implement basic functionalities (e.g., print and log generation). These APIs can be invoked everywhere, and they may contribute less than functionally related APIs to the given requirements in recommendation. To study the impacts of correct-but-useless APIs, we use utility to measure them. Our study is conducted on more than 5,000 matched results generated by two specification-based API recommendation techniques. The results show that the matched APIs are heavily overlapped, 10% APIs compose more than 80% matched results. The selected 10% APIs are all correct, but few of them are used to implement the required functionality. We further propose a heuristic approach to measure the utility and conduct an online evaluation with 15 developers. Their reports confirm that the matched results with higher utility score usually have more efforts on programming than the lower ones. Huidan Li, Rensong Xie, Xianglong Kong, Lulu Wang 0001, Bixin Li |
QRS | 5 |
| 2020 | A Co-evolutionary Method Between Architecture and Code
Bixin Li, Lingyuan Zhu |
SEKE | 2 |
| 2020 | Distinguishing Similar Design Pattern Instances through Temporal Behavior AnalysisabstractDesign patterns (DPs) encapsulate valuable design knowledge of object-oriented systems. Detecting DP instances helps to reveal the underlying rationale, thus facilitates the maintenance of legacy code. Resulting from the internal similarity of DPs, implementation variants, and missing roles, approaches based on static analysis are unable to well identify structurally similar instances. Existing approaches further employ dynamic techniques to test the runtime behaviors of candidate instances. Automatically verifying the runtime behaviors of DP instances is a challenging task in multiple aspects. This paper presents an approach to improve the verification process of existing approaches. To exercise the runtime behaviors of DP instances in cases that test cases of legacy systems are often unavailable, we propose a markup language, TSML (Test Script Markup Language), to direct the generation of test cases by putting a DP instance into use. The execution of test cases is monitored based on a trace method that enables us to specify runtime events of interest using regular expressions. To characterize runtime behaviors, we introduce a modeling and specification method employing Allen's interval-based temporal relations, which supports variant behaviors in a flexible way without hard-coded algorithms. A prototype tool has been implemented and evaluated on six open source systems to verify 466 instances reported by five existing approaches with respect to five DPs. The results show that the dynamic analysis increases the F1-score by 53.6% in distinguishing similar DP instances. Renhao Xiong, David Lo 0001, Bixin Li |
SANER | 3 |
| 2020 | An analysis of correctness for API recommendation: are the unmatched results useless?
Xianglong Kong, Weina Han, Bixin Li |
Sci. China Inf. Sci. | 4 |
| 2020 | Type slicing: An accurate object oriented slicing based on sub-statement level dependence graph
Lulu Wang 0001, Bixin Li, Xianglong Kong |
Inf. Softw. Technol. | 2 |
| 2019 | HiRec: API Recommendation using Hierarchical ContextabstractContext-aware API recommendation techniques aim to generate a ranked list of candidate APIs on an editing position during development. The basic context used in traditional API recommendation mainly focuses on the APIs from third-party libraries, limit or even ignore the usage of project-specific code. The limited usage of project-specific code may result in the lack of context information, and degrade the effectiveness of API recommendation. To address this problem, we introduce a novel type of context, i.e., hierarchical context, which can leverage the hidden information of project-specific code by analyzing the call graph. In hierarchical context, a project-specific API is presented as a sequence of low-leveled APIs from third-party libraries. We propose an approach, i.e., HiRec, which builds on the basis of hierarchical context. HiRec is evaluated on 108 projects and the results show that HiRec can obtain much more accurate results than all the other selected approaches in terms of top-5 and top-10 accuracy due to the strong ability of context representation. And HiRec performs closely to the outstanding tools in terms of top-1 accuracy. The average time of recommending execution is less than 1 seconds in most cases, which is acceptable for interaction in an IDE. Unlike current approaches, the effectiveness of HiRec is not impacted much by editing positions. And we can obtain more accurate results from HiRec with larger sizes of training data and hierarchical context. Rensong Xie, Xianglong Kong, Lulu Wang 0001, Bixin Li |
ISSRE | 5 |
| 2019 | Analyzing Software Architecture Evolvability Based on Multiple Architectural Attributes MeasurementsabstractWhen the erosion of software architecture occurs, there is an increase in software maintenance costs, a decrease in software quality, and degradation of software performance, etc. Therefore, it is particularly crucial to find a feasible way to evaluate software architecture to detect and avoid the erosion of software architecture in a timely manner. Through empirical study, we find that software architecture (SA) evolvability is one of the critical causes that leads to the erosion of software architecture. In this paper, we propose an approach to analyze SA evolvability based on multiple architectural attribute measurements and further solve the above problems in software architecture evolution. Our approach consists of the following steps: first, according to the evolutionary process, we propose four corresponding architectural attributes; second, these attributes are measured based on basic information and dependency information; third, SA evolvability is measured based on multiple architectural attribute measurements. Our experiments are conducted on thirteen Java open-source projects to verify the effectiveness of our approach. The experimental results show that our approach can effectively reflect the SA evolvability from the following two aspects: a single attribute can reflect a specific aspect of the SA evolvability; the composition of attributes can reflect the composite SA evolvability. Furthermore, we can locate the causes of the erosion of SA by combining the measurements and the evolutionary activities, and we further propose evolutionary proposals to improve the SA evolvability. Bixin Li |
QRS | 2 |
| 2019 | A Multilevel Analysis Method for Architecture ErosionabstractDuring the evolution of software, improper change operations may cause architecture erosion.Architecture erosion creates problems on evolutionary costs, software performance and software quality.Many methods have been proposed to analyze architecture erosion.Architecture depends on the implementation of code, that is, architecture erosion is caused by code.However, few methods analyze the reasons for architecture erosion based on code.Besides, architecture is eroded with software evolution, but most methods do not analyze architecture erosion based on the change of software.In this paper, we propose a multilevel analysis method for architecture erosion.Our method contains three steps.Firstly, we detect the changed pairs based on two architectures by performing a multilevel change detection method.Secondly, we detect whether the corresponding code elements of changed pairs are erosion points by calculating erosion degree.Thirdly, we establish a cost-benefit model of repairing architecture erosion for repairing architecture erosion more effectively with repaired few erosion points.We illustrate our method through an open source project, and the experimental results indicate that our method can detect the erosion points of each level and the cost-benefit model is effectively. Bixin Li |
SEKE | 3 |
| 2019 | Recover and Optimize Software Architecture Based on Source Code and Directory Hierarchies (S)abstractSoftware architecture helps developers understand and maintain software, so how to obtain accurate architecture is critical.The architecture recovery technique is a widely used method for obtaining architecture.In order to improve the accuracy and efficiency of the architecture recovery technique, we propose a method for recovering and optimizing software architecture based on source code and directory hierarchies.Our method consists of three steps: first, we extract architecturerelated information from source code and directory hierarchies and construct a file dependency graph; then, we preprocess and cluster code elements to construct a preliminary architecture; finally, we optimize architecture by clustering code elements based on the structural similarity and renaming components.We perform our method on four representative open source projects and compare our method with representative architecture recovery techniques.The experimental results show that the architectures recovered by our method has higher accuracy with higher efficiency than the compared architecture recovery techniques. Yelian Zhang, Xufang Gong, Bixin Li |
SEKE | 4 |
| 2019 | Identify MVC architectural pattern based on ontologyabstractMVC architectural pattern is widely used in software architecture design.It helps decouple the processing and the visualization of system data.Identified MVC architectural pattern helps understand how the software is actually implemented based on MVC architectural pattern, and further improve the consistency between design and source code.This paper proposes an ontology-based MVC architectural pattern identification method.Firstly, we use the combination of design patterns to describe the structure of MVC architectural pattern, so as to construct the MVC ontology of concept layer.Then we construct a program dependency graph by extracting the dependencies between entities in the target system, and build the ontology of instance layer.Finally, the MVC architectural pattern ontology of the specific target system is inferred by ontology reasoner in order to obtained MVC architectural pattern and the pattern elements included in each component.We use open source projects as the benchmark, and the experimental results show that our method effectively identify the MVC architectural pattern and the pattern elements in software system. Qiang Yin 0009, Lulu Wang 0001, Bixin Li |
SEKE | 3 |
| 2019 | Identify Blackboard Pattern Based on OntologyabstractBlackboard pattern identification is significant for the programmer to maintain the software system. Whether and how the system uses the blackboard pattern could help the programmers unfamiliar with the target system. This paper proposes a blackboard-instance identification approach based on ontology, which not only judges whether the target system uses the blackboard pattern but also provides the blackboard pattern implementation of the target system. The target system is described by ontology and input into the ABox of the knowledge base, the blackboard pattern is described by ontology and input into the TBox of the knowledge base. And the inference engine will reason out the raw pattern instance. Finally, the final pattern instance will be outputted by iterative refinement. To study the accuracy of our approach, sixty-eight projects have been tested and two of them have been analyzed the components' identification accuracy. Lihui Tang, Lulu Wang 0001, Bixin Li |
TASE | 3 |
| 2019 | Software Multiple-Level Change Detection Based on Two-Step MPAT MatchingabstractDuring software evolution, change detection plays an important role in software maintenance. For example, according to the changes, developers need to verify whether the evolved contents are consistent with the evolution plan, and making a regression testing plan. Right now, the text-based method and the AST-based matching method are widely used to detect changes. However, the text-based method cannot identify updating and renaming, so the accuracy of its detecting result is not high enough; the AST-based matching method only reflects the changes between files, so its detecting result is incomplete for understanding software evolution from an overall perspective. In order to solve the above problems, we propose a software multiple-level change detection method based on two-step MPAT (multilevel program analysis tree) matching, which detects changes between two programs from multiple levels to improve accuracy and proposes comprehensive change information. Our approach consists of three steps. Firstly, we construct MPAT for each program. Secondly, we implement the two-step matching algorithm to detect changes based on the two MPATs. Thirdly, these changes are classified and clustered. Finally, we develop ChangeAnalyzer to implement our approach, and conduct our experiments on six projects to evaluate the accuracy, performance and usefulness of ChangeAnalyzer. Bixin Li |
SANER | 4 |
| 2019 | Accurate Design Pattern Detection Based on Idiomatic Implementation Matching in Java Language ContextabstractDesign patterns (DPs) are widely accepted as solutions to recurring problems in software design. While numerous approaches and tools have been proposed for DP detection over the years, the neglect of language-specific mechanism that underlies the implementation idioms of DPs leads to false or missing DP instances since language-specific features are not captured and similar characteristics are not distinguished. However, there is still a lack of research that emphasizes the idiomatic implementation in the context of a specific language. A vital challenge is the representation of software systems and language mechanism. In this work, we propose a practical approach for DP detection from source code, which exploits idiomatic implementation in the context of Java language. DPs are formally defined under the blueprint of the layered knowledge graph (LKG) that models both language-independent concepts of DPs and Java language mechanism. Based on static analysis and inference techniques, the approach enables flexible search strategies integrating structural, behavioral and semantic aspects of DPs for the detection. Concerning emerging patterns and pattern variants, the core methodology supports pluggable pattern templates. A prototype implementation has been evaluated on five open source software systems and compared with three other approaches. The evaluation results show that the proposed approach improves the accuracy with higher precision (85.7%) and recall (93.8%). The runtime performance also supports its practical applicability. Renhao Xiong, Bixin Li |
SANER | 2 |
| 2019 | Tracking runtime concurrent dependences in java threads using thread control profiling
Lulu Wang 0001, Jingyue Li, Bixin Li |
J. Syst. Softw. | 3 |
| 2019 | Erratum to "Tracking runtime concurrent dependences in java threads using thread control profiling" [The Journal of Systems and Software 148 (2019) 116-131]
Lulu Wang 0001, Jingyue Li, Bixin Li |
J. Syst. Softw. | 3 |
| 2018 | Verifying CPS for Self-AdaptabilityabstractCPS (Cyber-Physical Systems) are physical and engineered systems featuring a tight combination of computation and physical processes by communication networks. CPS are mainly applied in some critical domains, so it is very essential to ensure the correctness of CPS. As a very important method for verifying system correctness, formal verification has been successfully applied in the verification of CPS; however, the high theoretical level of formal modeling techniques in formal verification and the lack of generality of formal models make it difficult to integrate formal verification with enterprise standard system development process. In this paper, we model CPS by HybridUML, an extension of UML which is now the de facto standard modeling language in system development practice, and then transform HybridUML model into the input language of theorem prover KeYmaera-QHP(Quantified Hybrid Program), and finally verify the QHP code with KeYmaera. When transforming a HybridUML model, we define the metamodels of HybridUML and QHP, and then find the association between them based on semantic consisteency, and finally define transformation rules using ATL (ATLAS Transformation Language) and template based code generation method to achieve transformation. Xufang Gong, Jiakai Li, Bixin Li |
ICIS | 4 |
| 2018 | A Framework for CPS Modeling and Verification Based on dLabstractWith the development of sensor network and embedded system, CPS integrating computation, communication and control is becoming the focus of attention gradually. Obvious problems have emerged when CPS applying to various industries. It is crucial that the designed CPS can work as expect. A growing number of researchers are concerned about the property verification of CPS since verification technique has played a key role in improving the security and reliability of systems. It is a commonly used method that transforming generic model to formal model for verification. A formal method of theorem proving has well applied to verify CPS based on differential dynamic logic which operating model named Hybrid Program proposed by A. Platzer. This paper introduced HybridUML to model CPS, presented a method based on model transformation which mapped from HybridUML to Hybrid Program, and verified a case study with the resulting model finally. Xufang Gong, Bixin Li |
ICIS | 3 |
| 2018 | Are Smell-Based Metrics Actually Useful in Effort-Aware Structural Change-Proneness Prediction? An Empirical StudyabstractBad code smells (also named as code smells) are symptoms of poor design choices in implementation. Existing increases the likelihood of subsequent changes (i.e., change-proness). However, to the best of our knowledge, no prior studies have leveraged smell-based metrics to predict particular change type (i.e., structural changes). Moreover, when evaluating the effectiveness of smell-based metrics in structural change-proneness prediction, none of existing studies take into account of the effort inspecting those change-prone source code. In this paper, we consider five smell-based metrics for effort-aware structural change-proneness prediction and compare these metrics with a baseline of well-known CK metrics in predicting particular categories of change types. Specifically, we first employ univariate logistic regression to analyze the correlation between each smell-based metric and structural change-proneness. Then, we build multivariate prediction models to examine the effectiveness of smell-based metrics in effort-aware structural change-proneness prediction when used alone and used together with the baseline metrics, respectively. Our experiments are conducted on six Java open-source projects with up to 60 versions and results indicate that: (1) all smell-based metrics are significantly related to structural change-proneness, except metric ANOS in hive and SCM in camel after removing confounding effect of file size; (2) in most cases, smell-based metrics outperform the baseline metrics in predicting structural change-proneness; and (3) when used together with the baseline metrics, the smell-based metrics are more effective to predict change-prone files with being aware of inspection effort. Yijun Yu 0001, Bixin Li, Yibiao Yang, Ru Jia |
APSEC | 3 |
| 2018 | Evaluate How Cyclomatic Complexity Changes in the Context of Software EvolutionabstractCyclomatic complexity (CC) is often used as a factor to evaluate the quality of source code. Many researchers have studied the relationships between CC and LOC, between CC and basic testing paths, and between CC and code maintainability etc. However, few researchers studied how software evolution affects CC. In this paper, we propose a methodology based on source code change analysis and develop a supporting tool, called CCEvaluator, to evaluate CC variation during software evolution. By empirical studies on six pieces of typical open source projects, a series of interesting findings including six commonness and five differences have been obtained. To explain why these commonness and differences are produced during software evolution, code change information among successive versions are captured and used in this paper. Xufang Gong, Bixin Li |
COMPSAC (2) | 4 |
| 2018 | Exploring the Impact of Code Smells on Fine-Grained Structural Change-PronenessabstractCode smells are used to describe the bad structures in the source code, which could hinder software maintainability, understandability and changeability. Nowadays, scholars mainly focus on the impact of smell on textual change-proneness. However, in comparison to textual changes, structural changes could better reveal the change nature. In practice, not all code change types are equally important in terms of change risk severity levels, and software developers are more interested in particular changes relevant to their current tasks. Therefore, we investigate the relationship between smells and fine-grained structural change-proneness to solve these issues. Our experiment was conducted on 11 typical open source projects. We first employed Fishers exact test and Mann–Whitney test to explore whether smelly files (affected by at least one smell type) had higher structural change-proneness than other files, and whether files with more smell instances are more likely to undergo structural changes, respectively. Multivariate logistic regression model was built to study the relation between each kind of smell and change-proneness with respect to five change categories. Our results showed that: (1) in most cases, smelly files were more prone to structural changes and files with more smell instances tend to undergo higher structural changes; (2) quite a few smell types were related to structural change-proneness, particularly, Refused Parent Bequest (RPB), Message Chains (MCH), Divergent Change (DIVC), Feature Envy (FE) and Shotgun Surgery (SS) increased structural changes for some change categories. However, when controlling the file size Lines of Code (LOC), significant change-proneness of some smells disappeared or the magnitude of significance decreased more or less. Bixin Li, Yibiao Yang, Wanwangying Ma, Ru Jia |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2018 | The impacts of techniques, programs and tests on automated program repair: An empirical study
Xianglong Kong, Lingming Zhang 0001, W. Eric Wong, Bixin Li |
J. Syst. Softw. | 4 |
| 2017 | Understanding the syntactic rule usage in java
Dong Qiu, Bixin Li, Earl T. Barr, Zhendong Su 0001 |
J. Syst. Softw. | 2 |
| 2016 | A technique to evaluate software evolution based on architecture metricabstractSoftware evolution is always happening during its lifetime. In a software evolution process, the change in software structure often leads to software quality degradation, makes it difficult to maintain or transfer to other platform. In this paper, we propose a technique to evaluate software evolution based on architecture metric. We split the whole architecture evolution process into a series of atomic evolution operation steps, analyze the impact of each atomic change operation with examples, and then find out the general evolution trend. Our purpose is to analyze how architecture changes influence the relevant software quality attributes, which helps to maintain good software quality and keep software healthily evolving. Bixin Li, Jingwen Si |
SERA | 1 |
| 2016 | Trust analysis of composite service evolutionabstractChanges to a composite service need to be well analyzed in order to ensure its trust is maintained. In this paper, we propose a trust analysis model to analyze the impact of three kinds of evolution operations performed on a composite service: business process changes, binding changes and interface changes. A trust dependency graph is introduced to analyze the impact on the trust of component services; a XBFG (eXtensible BPEL Flow Graph) is introduced to evaluate the impact on the trust of the composite service. Three metrics are introduced to evaluate the impact of these evolution operations. The case study shows how these evolution operations affect the trust of other component services and the composite service. ShanShan Qi, Bixin Li |
SERA | 3 |
| 2016 | A new method to encode calling contexts with recursions
Lulu Wang 0001, Bixin Li, Hareton K. N. Leung |
Sci. China Inf. Sci. | 2 |
| 2016 | IPSETFUL: an iterative process of selecting test cases for effective fault localization by exploring concept lattice of program spectra
Xiaobing Sun 0001, Xin Peng 0001, Bin Li 0006, Bixin Li, Wanzhi Wen |
Frontiers Comput. Sci. | 4 |
| 2016 | Understanding the API usage in Java
Dong Qiu, Bixin Li, Hareton K. N. Leung |
Inf. Softw. Technol. | 2 |
| 2016 | Efficient online cycle detection technique combining with Steensgaard points-to informationabstractSummary Pointer analysis is a key static analysis during compilation. Several client analyses and transformations rely on precise pointer information to optimize programs. Therefore, it is paramount to improve the efficiency of pointer analysis. A critical piece of an inclusion‐based pointer analysis is online cycle detection. The efficiency of pointer analysis is significantly influenced by the efficacy of detecting cycles. Existing approaches perform poorly when theyguesscycle formation in the constraint graph. Thus, the number of false cycle‐detection triggers of the state‐of‐the‐art methods is considerably high (over 99% on Standard Performance Evaluation Corporation (SPEC) benchmarks). In this paper, we propose bootstrapping as a way to improve cycle detection predictability of pointer analysis. The main idea is to run a sequence of increasingly precise analyses to feed into the next more precise analysis to improve the efficiency of the latter analysis. In this process, we develop a new notion of pointer equivalence called constraint equivalence. Using Steensgaard's fast unification algorithm as the bootstrap, we devise a new cycle detection method for Andersen's inclusion‐based analysis. We measure the effectiveness of our approach using a suite of programs including SPEC 2000 benchmarks and two open‐source programs, and find that our method can reduce the number of false cycle detections by almost 22× compared with a state‐of‐the‐art method. This leads to an overall analysis time improvement of 18% on an average. Copyright © 2015 John Wiley & Sons, Ltd. Fei Liu 0019, Bixin Li, Rupesh Nasre |
Softw. Pract. Exp. | 2 |
| 2015 | Experience report: How do techniques, programs, and tests impact automated program repair?abstractAutomated program repair can save tremendous manual efforts in software debugging. Therefore, a huge body of research efforts have been dedicated to design and implement automated program repair techniques. Among the existing program repair techniques, genetic-programming-based techniques have shown promising results. Recently, researchers found that random-search-based and adaptive program repair techniques can also produce effective results. In this work, we performed an extensive study for four program repair techniques, including genetic-programming-based, random-search-based, brute-force-based and adaptive program repair techniques. Due to the extremely large time cost of the studied techniques, the study was performed on 153 bugs from 9 small to medium sized programs. In the study, we further investigated the impacts of different programs and test suites on effectiveness and efficiency of program repair techniques. We found that techniques that work well with small programs become too costly or ineffective when applied to medium sized programs. We also computed the false positive rates and discussed the ratio of the explored search space to the whole search space for each studied technique. Surprisingly, all the studied techniques except the random-search-based technique are consistent with the 80/20 rule, i.e., about 80% of successful patches are found within the first 20% of search space. Xianglong Kong, Lingming Zhang 0001, W. Eric Wong, Bixin Li |
ISSRE | 4 |
| 2015 | MSR4SM: Using topic models to effectively mining software repositories for software maintenance tasks
Xiaobing Sun 0001, Bixin Li, Hareton K. N. Leung, Bin Li 0006, Yun Li 0010 |
Inf. Softw. Technol. | 2 |
| 2015 | Static change impact analysis techniques: A comparative study
Xiaobing Sun 0001, Bixin Li, Hareton K. N. Leung, Bin Li 0006, Junwu Zhu |
J. Syst. Softw. | 2 |
| 2014 | Profiling selected paths with loops
Bixin Li, Lulu Wang 0001, Hareton K. N. Leung |
Sci. China Inf. Sci. | 1 |
| 2014 | Change impact analysis and changeability assessment for a change proposal: An empirical study ☆☆
Xiaobing Sun 0001, Hareton K. N. Leung, Bin Li 0006, Bixin Li |
J. Syst. Softw. | 4 |
| 2014 | PHAT: A Preference and Honesty Aware Trust Model for Web ServicesabstractTrust is one of the most critical factors for a service requestor when selecting a service from a large pool of candidate services. However, existing web service trust models either do not consider users' preferences for different quality of service (QoS) attributes, or ignore the impact of vicious ratings on trust evaluation. To address these gaps, PHAT, a dynamic trust evaluation model with dual consideration of users' preferences and false ratings, is proposed in this paper. The model introduces an approach to automatically mine users' preferences from their requirements. The preferences are then used to determine the weight of each QoS attribute when integrating trust into multi-dimensional QoS attributes. The “local” trust on a service is derived by combining the trust on QoS attributes and the user's subjective ratings. Then, the users are divided into different groups according to their QoS preferences, and the honesty of each group is assessed by filtering out dishonest users based on a hybrid approach combining rating consistency clustering with an average method. Finally, the weight on ratings is dynamically adjusted according to the results of honesty assessment when calculating the global trustworthiness, namely, the reputation of a service. The proposed model is evaluated with real-world QoS data, and the results indicate that PHAT works well on personalized evaluation of trust, and can effectively dilute the influence of malicious ratings. Bixin Li, Hareton K. N. Leung, Rui Song 0010 |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2013 | ELCD: an efficient online cycle detection technique for pointer analysis
Fei Liu 0019, Lulu Wang 0001, Bixin Li |
SEKE | 3 |
| 2013 | Testing Configurable Architectures For Component-Based Software Using an Incremental Approach
Chuanqi Tao, Bixin Li, Jerry Zeyu Gao |
SEKE | 2 |
| 2013 | An empirical analysis of the co-evolution of schema and code in database applicationsabstractModern database applications are among the most widely used and complex software systems. They constantly evolve, responding to changes to data, database schemas, and code. It is challenging to manage these changes and ensure that everything co-evolves consistently. For example, when a database schema is modified, all the code that interacts with the database must be changed accordingly. Although database evolution and software evolution have been extensively studied in isolation, the co-evolution of schema and code has largely been unexplored. Dong Qiu, Bixin Li, Zhendong Su 0001 |
ESEC/SIGSOFT FSE | 2 |
| 2013 | Analyzing Impact Rules of Different Change Types to Support Change Impact AnalysisabstractSoftware change impact analysis (CIA) is a key technique for identifying unpredicted and potential effects caused by changes made to software. Different changes have different ripple effects to other parts in the program, even some changes do not affect other entities in spite of some dependencies existing between these entities and the modified one. This induces imprecision if such a factor is neglected. This article proposes a static CIA technique which considers the impact rules of different change types to predict the change effects. Input of our CIA includes changed classes, class methods and class fields, and the output is composed of potentially affected classes, class methods, and class fields. Precision improvement of the CIA technique relies on three aspects: change types of a modified entity, dependencies between the modified entity and other entities, and a precise initial impact set (IIS), on which the final impact set (FIS) is computed. Experimental case studies demonstrate the effectiveness of our technique, and present its potential applications in software maintenance. Xiaobing Sun 0001, Bixin Li, Wanzhi Wen, Sai Zhang 0001 |
Int. J. Softw. Eng. Knowl. Eng. | 2 |
| 2013 | FCA-CIA: An approach of using FCA to support cross-level change impact analysis for object oriented Java programs
Bixin Li, Xiaobing Sun 0001, Jacky W. Keung |
Inf. Softw. Technol. | 1 |
| 2013 | A survey of code-based change impact analysis techniquesabstractSUMMARY Software change impact analysis (CIA) is a technique for identifying the effects of a change, or estimating what needs to be modified to accomplish a change. Since the 1980s, there have been many investigations on CIA, especially for code‐based CIA techniques. However, there have been very few surveys on this topic. This article tries to fill this gap. And 30 papers that provide empirical evaluation on 23 code‐based CIA techniques are identified. Then, data was synthesized against four research questions. The study presents a comparative framework including seven properties, which characterize the CIA techniques, and identifies key applications of CIA techniques in software maintenance. In addition, the need for further research is also presented in the following areas: evaluating existing CIA techniques and proposing new CIA techniques under the proposed framework, developing more mature tools to support CIA, comparing current CIA techniques empirically with unified metrics and common benchmarks, and applying the CIA more extensively and effectively in the software maintenance phase. Copyright © 2012 John Wiley & Sons, Ltd. Bixin Li, Xiaobing Sun 0001, Hareton K. N. Leung, Sai Zhang 0001 |
Softw. Test. Verification Reliab. | 1 |
| 2013 | Verifying the Concurrent Properties in BPEL Based Web Service Composition ProcessabstractThe relatively new web service software paradigm involves services which are loosely coupled, highly reusable and flexible. By specifying the workflow of individual services, Web service composition enhances the ability to handle more complex business processes and provides many value-added services. In this article, we propose an extended control flow graph (XCFG) to formally model the workflow of Web service composition specified in BPEL, and corresponding techniques to verify concurrent properties, such as deadlock-free, non-conflict, and link non-redundant. XCFG can model not only the workflow of BPEL but also the synchronization control dependencies among concurrent activities. Meanwhile, each element of XCFG keeps record of related information of corresponding activity in BPEL so as to support further analysis and verification. Experimental study validates the effectiveness and efficiency of the proposed XCFG-based technique. Bixin Li, Shunhui Ji, Dong Qiu, Hareton K. N. Leung, Gongyuan Zhang |
IEEE Trans. Netw. Serv. Manag. | 1 |
| 2012 | Data Depedency Based Trust Evaluation for BPEL ProcessesabstractComposite services implement value-added functionality by composing service components with smaller granularity. Trust is an important criterion to judge whether a composite service can behave as expected. A feasible trust evaluation method for composite services is needed, which can guide service selection for users and the trust-based optimization and evolution for composite services. In this paper, a data dependency based trust evaluation approach for composite services in Business Process Execution Language (BPEL) is proposed. Firstly, we derive define-use pairs of variables to describe data dependency between service components in BPEL processes modeled by extensible BPEL Flow Graph (XBFG), in addition, dependency links including both direct and indirect data dependencies are used to evaluate the trust values of these service components, furthermore, on the basis of BPEL structure and XBFG, reduction rules are proposed to evaluate the global trust values of BPEL processes. Experiment results demonstrate that the proposed approach is effective for the trust evaluation of BPEL composite services and stable enough with the growing number of service components in BPEL. Cuicui Liu, Bixin Li, ShanShan Qi, Xiaona Wu, Rui Song 0010 |
APSEC | 2 |
| 2012 | A Trust Impact Analysis Model for Composite Service EvolutionabstractChanges to a composite service need to be well analyzed in order to ensure the trust of it. The analysis can be driven by identifying the impact caused by the changes on the trust of other component services as well as the composite service. In this paper, we propose a trust impact analysis model to analyze the impact of two kinds of evolution operations performed on a composite service: binding changes and business process changes. First, trust dependency graph is introduced to analyze the impact on the trust of component services. It not only identifies the affected component services but also quantifies the impact degree on the trust of them. Then we introduce control flow graph to evaluate the impact on the trust of the composite service. Three metrics are introduced to evaluate the impact of these evolution operations. The case study shows how these evolution operations affect the trust of other component services and the composite service which provides a foundation for the evaluation of composite service evolution. ShanShan Qi, Bixin Li, Cuicui Liu, Xiaona Wu, Rui Song 0010 |
APSEC | 2 |
| 2012 | A Preference and Honesty Aware Trust Model for Web ServicesabstractTrust is one of the most critical factors for a service requestor when selecting the best one from a large pool of services. However, existing web service trust models either do not focus on satisfying customer's preference for different quality of service (QoS) attributes, or do not pay enough attention to the impact of malicious ratings on trust evaluation. To address these gaps, a dynamic trust evaluation model considering customer's preference and false ratings is proposed in this paper. The model introduces an approach automatically mining customer's preference from their requirements. The preference is used to determine the weights on each QoS attribute when integrating trust of the multi-dimensional QoS attributes. The local trust of a service for the customer is derived by combining trust of QoS attributes and customer's ratings. Then, the customers are divided into different groups according to their preferences, and the honesty of each group is assessed by filtering out dishonest customers based on a hybrid approach combining rating consistency clustering and average method. Finally, the weight on ratings is dynamically adjusted according to the results of honesty assessment when calculating the global trustworthiness of a service for the user group. The simulation results indicate that the model works well on personalized evaluation of trust, and it can effectively dilute the influence of malicious ratings. Rui Song 0010, Bixin Li, Xiaona Wu, Cuicui Liu, ShanShan Qi |
APSEC | 2 |
| 2012 | Trust-Based Service Composition and OptimizationabstractAs an important method for creating value-added services by composing existing services, Web service composition technology has attracted an increasing attention in recent years. Most current service composition and optimization methods utilize quality of service (QoS) attributes to decide which concrete services to invoke. However, trust which is of critical importance to service composition processes is ignored in these methods. To solve the problem, a trust-based service composition and optimization method is proposed in this paper. First, the trust of service composition is defined in terms of the trust of component service selection processes, composition processes and optimal binding plans. Second, a framework is proposed to guarantee the trust of service composition. In the framework, the trust of component service selection processes is guaranteed by filtration, and the trust of composition processes is guaranteed by interface-based service clustering methods. In order to find a trustworthy binding plan, a trust evaluation method is also included in the framework. Finally, a case study based on real Web services is presented, and the experimental results show that the framework can effectively guarantee the trust of service composition and optimization processes. Xiaona Wu, Bixin Li, Rui Song 0010, Cuicui Liu, ShanShan Qi |
APSEC | 2 |
| 2012 | A Change Proposal Driven Approach for Changeability Assessment Using FCA-Based Impact AnalysisabstractGiven a change proposal, how can we evaluate the changeability of the original system to absorb this change proposal before change implementation? Changes to software often have unexpected ripple effects. To avoid this and alleviate the risk of performing undesirable changes, a predictive measurement of these ripple effects should be conducted and a decision of acceptance or rejection should be made on this change proposal. In this paper, we propose an approach to evaluate a software system's changeability with two steps. First, our approach uses formal concept analysis to perform change impact analysis ($CIA$), which estimates the ripple effects of the change proposal. Then, we propose a novel impactness metric to indicate the system's changeability to absorb this change proposal. Case studies on three real-world programs show the effectiveness of our changeability assessment approach. Xiaobing Sun 0001, Bixin Li, Qiandong Zhang |
COMPSAC | 2 |
| 2012 | A comparative study of static CIA techniquesabstractSoftware Change Impact Analysis (CIA) is an essential technique to identify the unpredicted and potential effects caused by software changes. A rich body of different CIA techniques, especially static CIA techniques, have continuously emerged in recent years. However, it is difficult for researchers or practitioners to decide which technique is most appropriate for their needs, or which CIA technique is more effective. Unfortunately, there was only a few work on the comparison of the CIA techniques. This paper presents a comparison study of different types of popular static CIA approaches, i.e., structural static analysis, textual analysis, and historical analysis. For each kind of static CIA approach, we introduce a representative technique, that is FCA -- CIA, ROSE, and IRC2M, respectively. Finally, some empirical studies are conducted on three real-world programs to compare the accuracy of these CIA techniques based on the precision and recall metrics. The results show that the accuracy of these three CIA techniques is different, and FCA - CIA has the best precision while the IRC2M has the best recall. Xiaobing Sun 0001, Bin Li 0006, Bixin Li, Wanzhi Wen |
Internetware | 3 |
| 2012 | A HybridUML and QdL Based Verification Method for CPS Self-Adaptability
Jiakai Li, Bixin Li, Qiaoqiao Chen, Shunhui Ji, Xiaoxiang Zhai |
SEKE | 2 |
| 2012 | Using FCA-based Change Impact Analysis for Regression Testing
Xiaobing Sun 0001, Bixin Li, Chuanqi Tao, Qiandong Zhang |
SEKE | 2 |
| 2012 | Verification of Cyber-Physical Systems Based on Differential-Algebraic Temporal Dynamic Logic
Xiaoxiang Zhai, Bixin Li, Jiakai Li, Qiaoqiao Chen, Shunhui Ji |
SEKE | 2 |
| 2012 | Mining Call Graph for Change Impact Analysis
Qiandong Zhang, Bixin Li, Xiaobing Sun 0001 |
SEKE | 2 |
| 2012 | HybridUML Based Verification of CPS Using Differential Dynamic Logic
Bixin Li, Jiakai Li, Qiaoqiao Chen, Xiaoxiang Zhai, Shunhui Ji |
SEKE | 2 |
| 2012 | Automatic test case selection for regression testing of composite service based on extensible BPEL flow graph
Bixin Li, Dong Qiu, Hareton K. N. Leung |
J. Syst. Softw. | 1 |
| 2012 | Profiling all paths: A new profiling technique for both cyclic and acyclic paths
Bixin Li, Lulu Wang 0001, Hareton K. N. Leung, Fei Liu 0019 |
J. Syst. Softw. | 1 |
| 2011 | A Technique of Profiling Selective PathsabstractPath profiling records the frequency of each path in an executed routine. To accomplish profiling, probes are instrumented in a program and executed as the program runs. So the number of probes has important influences on the efficiency of a profiling technique. To profile only a subset of paths, existing techniques try to improve the profiling efficiency by reducing probes, optimizing path encoding, and so on. However, they mainly lack accuracy, waste time on running uninterested paths, and only deal with acyclic paths. In this paper, a novel technique called PSP (Profiling Selective Paths) has been introduced to profile selective paths, which can handle selection for both acyclic and cyclic paths, and increase the execution efficiency by early termination on uninterested paths. PSP is implemented in two ways, PSP1 and PSP2. Theoretical comparison and experimental evaluation indicate that PSP1 and PSP2 perform differently but both effectively. Lulu Wang 0001, Bixin Li |
COMPSAC | 2 |
| 2011 | Ontology-Based Reliability Evaluation for Web ServiceabstractReliability has become a major quality metric for Web service. However, current reliability evaluation approaches lack a formal semantic representation and the support of incomplete or uncertain information. We propose a Web service reliability ontology (WSRO) serving as a basis to characterize the knowledge of Web service. And based on WSRO, a mapping to the probability graphical model is constructed. The Web service reliability evaluation results are obtained by the causality reasoning. Some evaluation results reveal that our approach is applicable and effective. Xifeng Wang, Bixin Li, Chunli Xie |
COMPSAC | 2 |
| 2011 | An Effective Approach for Automatic Generation of Class Integration Test OrderabstractA common problem in object-oriented software integration testing is to determine the order in which classes are integrated and tested. This paper proposes an effective approach to automatically generate a (near) optimal test order from Java source code. This approach includes three aspects: constructing an extended test dependency graph to represent classes and inter-class dependencies, measuring inter-class coupling information to estimate stub complexity, and providing a fast heuristic algorithm to break cycles. Zhengshan Wang, Bixin Li, Lulu Wang 0001 |
COMPSAC | 2 |
| 2011 | A Staged Model for Web Service ReliabilityabstractIn SOA (Service-oriented Architecture), web services consist of five steps: service publishing, service discovery, service composition, service binding and service execution. Faults may occur during every step and cause failure of service execution. Traditional architecture-based reliability models are inapplicable to web services. In this paper, a staged reliability model for web services is proposed which divides the model into multistage model based on the faults occurred at every step. This model considers more failure factors than traditional model. Chunli Xie, Bixin Li, Xifeng Wang |
COMPSAC | 2 |
| 2011 | Using Formal Concept Analysis to support change analysisabstractSoftware needs to be maintained and changed to cope with new requirement, existing faults and change requests as software evolves. One particular issue in software maintenance is how to deal with a change proposal before change implementation? Changes to software often cause unexpected ripple effects. To avoid this and alleviate the risk of performing undesirable changes, some predictive measurement should be conducted and a change scheme of the change proposal should be presented. This research intends to provide a unified framework for change analysis, which includes dependencies extraction, change impact analysis, changeability assessment, etc. We expect that our change analysis framework will contribute directly to the improvement of the accuracy of these predictive measures before change implementation, and thus provide more accurate change analysis results for software maintainers, improve quality of software evolution and reduce the software maintenance effort and cost. Xiaobing Sun 0001, Bixin Li |
ASE | 2 |
| 2011 | Multithreaded Pointer Analysis Based on Petri Net
Fei Liu 0019, Bixin Li |
SEKE | 2 |
| 2011 | A Model-based Approach to Regression Testing of Component-based Software
Chuanqi Tao, Bixin Li, Jerry Zeyu Gao |
SEKE | 2 |
| 2011 | A Technology of Profiling Inter-procedural Paths
Lulu Wang 0001, Bixin Li |
SEKE | 2 |
| 2011 | A Brief Survey on Automatic Integration Test Order Generation
Zhengshan Wang, Bixin Li, Lulu Wang 0001 |
SEKE | 2 |
| 2011 | Program slicing spectrum-based software fault localization
Wanzhi Wen, Bixin Li, Xiaobing Sun 0001, Jiakai Li |
SEKE | 2 |
| 2011 | A Web Service Reliability Model Based on Birth-Death Process
Chunli Xie, Bixin Li, Xifeng Wang |
SEKE | 2 |
| 2010 | A Way to Model Flow Construct and Its Three Properties Verification for BPEL SpecificationabstractA kind of concurrent-based model of control flow is proposed for the analysis and verification of interactions of composite web services which are specified in BPEL. First, a verification framework of concurrent construct is presented, then we convert the choice flow into concurrent flow with link semantics to simplify the description and verification methods of formal model. Furthermore, deadlock-free, meaning-full and non-conflict, three properties of this model are defined. Meanwhile, the meaning and verification methods for the three properties are discussed. Finally, an example of composite service is given to prove the usability of the model and verification methods. Gongyuan Zhang, Bixin Li |
APSCC | 2 |
| 2010 | Evaluating the Reliability of Web Services Based on BPEL Code Structure Analysis and Run-Time Information CaptureabstractIn this article, an approach is proposed to evaluate the reliability of Web services, where three kinds of Web services are discussed, they are atomic service without the structural information, structural activity based composite service which is composed from other services by using a structural activity mechanism, and BPEL flow process based composite service which composes all kinds of atomic services and activity based composite services using BPEL language in an orchestration style. Firstly, the reliability of atomic service is evaluated based on an extended UDDI model, then, the reliability of activity based composite services is evaluated using BPEL code structure analysis, the reliability of atomic service, and function transition probability, finally, the reliability of BPEL flow process based composite web service was evaluated by a recursive algorithm. Case study and experimental results show the significance of the approach. Bixin Li, Xiaocong Fan, Zhiyong Su |
APSEC | 1 |
| 2010 | A Hierarchical Model for Regression Test Selection and Cost Analysis of Java ProgramsabstractRegression testing is an important but expensive stage of software maintenance. Regression test selection addresses the problem of reducing testing cost through selecting a subset of the existing test cases or rerun. Cost-effectiveness is an indispensable factor to consider when developing a regression testing technique. Cost models are created for the purpose of assessing cost-effectiveness of these techniques. The current regression test selection strategies or cost analysis seldom consider hierarchy, which is an inherent characteristic of object-oriented program. In addition, selecting test cases at different levels influences the precision and efficiency of selection. This paper presents a hierarchical regression test selection technique for Java programs to stepwise select test cases from high level of program to low level of program. To effectively evaluate the correlative overall cost, this paper also proposes a hierarchical cost model for analyzing the cost-effectiveness of selection level according to hierarchy step by step. The empirical studies show that our approach can reduce the total cost and achieve more cost-effective results. Chuanqi Tao, Bixin Li, Xiaobing Sun 0001 |
APSEC | 2 |
| 2010 | Change Impact Analysis Based on a Taxonomy of Change TypesabstractSoftware change impact analysis (CIA) is a key technique for identifying unpredicted and potential effects caused by changes made to software. Different change types often have different impact mechanisms, even some changes do not impact other entities in programs in spite of some dependences existed between these entities and the modified entity. In this paper, we propose a static CIA technique, which considers different impact mechanisms and rules of different change types, to calculate the impact sets. Precision improvement of the impact sets relies on 3 aspects: change types of a modified entity, dependences between the modified entity and other entities, and the intuition that to win at the start -- if the initial impact set is estimated more accurately, then the final impact set depending on this initial impact set will be more precise. Experimental case study demonstrates the effectiveness of our technique, and its potential applications in software maintenance. Xiaobing Sun 0001, Bixin Li, Chuanqi Tao, Wanzhi Wen, Sai Zhang 0001 |
COMPSAC | 2 |
| 2010 | Automatic test case selection and generation for regression testing of composite service based on extensible BPEL flow graphabstractServices are highly reusable, flexible and loosely coupled, which makes the evolution and the maintenance of composite services more complex. Evolution of BPEL composite service covers changes of processes, bindings and interfaces. In this paper, an approach is proposed to select and generate test cases during the evolution of BPEL composite service. The approach identifies the changes by using control-flow analysis technique and comparing the paths in new composite service version and the old one using extensible BPEL flow graph (or XBFG). Message flow is appended to the control flow so that XBFG can describe the behavior of composite service integrally. The binding and predicate constraint information added in XBFG elements can be used in path selection and test case generation. Theory analysis and case study both show that the approach is effective, and test cases coverage rate is high for the changes of processes, bindings and interfaces. Bixin Li, Dong Qiu, Shunhui Ji |
ICSM | 1 |
| 2010 | WS-PSC Monitor: A Tool Chain for Monitoring Temporal and Timing Properties in Composite Service Based on Property Sequence Chart
Pengcheng Zhang 0001, Zhiyong Su, Yuelong Zhu, Wenrui Li 0002, Bixin Li |
RV | 5 |
| 2010 | Generating Test Cases of Composite Services Based on OWL-S and eh-CPNabstractIn web service times, the techniques for composing services are based on service reuse and automatic integration. A new web service will be generated by composing some existing web services. These web services cooperate with each other to provide a new more complex function. It is necessary and very important to test the interaction behavior between any two web services during composition. In this paper, a kind of enhanced hierarchical color petri-net (or EH-CPN) is introduced to generate test cases for testing the interaction, where EH-CPN is transformed from OWL-S document, and both control flow and data flow information in EH-CPN are analyzed and used to generate an executable test sequence, and further test cases are created by combining the test sequence and test data in an XML file. Bixin Li, Shunhui Ji, Dong Qiu, Ju Cai |
Int. J. Softw. Eng. Knowl. Eng. | 1 |
| 2010 | Model and Verification of WS-CDL Based on UML DiagramsabstractThe Web Services Choreography Description Language (WS-CDL) is a specification developed by the W3C and can be viewed as a blueprint for the development of end-point services. Consequently, it is worth providing a systematic approach for its modeling, analysis and verification. The Unified Modeling Language (UML) is an industry standard for modeling. Applying UML to model WS-CDL is obviously a promising solution to bring together academics and practitioners through a unique standard language. In this paper, we propose to use different UML diagrams to model WS-CDL. UML Component Diagram is used to model the underlying structure of WS-CDL. UML Sequence Diagram is utilized to model the activities in WS-CDL. UML State Machine Diagram is utilized to model the behaviors of each role participating in a WS-CDL specification. We then enrich the UML State Machine Diagram with data by the use of UML Class Diagram. Given the UML specification of WS-CDL, we then provide a systematic way of formally analyzing and verifying WS-CDL against desired properties. Some experiments show that our approach can verify structural, behavioral and data properties in a middle-scale data-enriched WS-CDL specification. Pengcheng Zhang 0001, Henry Muccini, Yuelong Zhu, Bixin Li |
Int. J. Softw. Eng. Knowl. Eng. | 4 |
| 2010 | Timed Property Sequence Chart
Pengcheng Zhang 0001, Bixin Li, Lars Grunske |
J. Syst. Softw. | 2 |
| 2010 | A classification and comparison of model checking software architecture techniques
Pengcheng Zhang 0001, Henry Muccini, Bixin Li |
J. Syst. Softw. | 3 |
| 2009 | Model-Driven Automatic Generation of Verified BPEL Code for Web Service CompositionabstractService composition, which provides a more effective way to combine several single services into a composite service, is a kind of software reuse techniques. However, one of the most important problems is how to perform service composition correctly and effectively so as to produce high-quality source codes for describing the resulted composite service. In this paper, we propose a model-driven method to solve this problem, where UML 2.0 sequence diagrams are extended to model the composition of Web services, extended statecharts are synthesized from sequence diagrams, then the statecharts are further transferred to the input language of a model checker for behavior consistency checking, and finally verified BPEL codes can be generated from improved sequence diagrams. Case studies have been performed to demonstrate the whole process and illustrate the significance of our approach. Bixin Li, Yu Zhou 0010, Jun Pang 0001 |
APSEC | 1 |
| 2009 | A Formal Syntax for Probabilistic Timed Property Sequence ChartsabstractProbabilistic properties are considered as the most important requirements for a variety of software systems, since they are used to formulate extra-functional requirements such as reliability, availability, safety, security and performance requirements. Currently, several probabilistic logics have been proposed to specify such important properties. However, due to the inherent complexity of the underlying temporal logics, these probabilistic logics are rather complex and software developers have problems using them to correctly specify the intended properties. To overcome this problem, we define a formal and graphical property specification language called probabilistic timed property sequence charts (PTPSC) which is a probabilistic extension of property sequence charts (PSC). We illustrate the use of PTPSC in the context of a vehicle-to-vehicle communication device for avoiding traffic accidents. Pengcheng Zhang 0001, Lars Grunske, Antony Tang, Bixin Li |
ASE | 4 |
| 2009 | Generating Test Cases of Composite Services Based on OWL-S and EH-CPN
Bixin Li, Ju Cai, Dong Qiu, Shunhui Ji |
SEKE | 1 |
| 2009 | WSTester: Testing Web Service for Behavior Conformance
Bixin Li, Shunhui Ji, Dong Qiu, Xufang Gong |
SEKE | 1 |
| 2008 | Extending PSC for Monitoring the Timed Properties in Composite ServicesabstractDue to the dynamically evolving attribute, validation of composite services must be extended from design time to run-time. Dynamical verification techniques, such as runtime monitoring, have been first class activities to be performed during the execution of composite services. For a kind of composite services, nonfunctional properties, such as timed properties, are as important as functional properties and need to be monitored at run-time. However, using traditional logic and formalism, these timed properties are not easily represented for general software engineers. In order to deal with this problem, we first extend a novel notation (Property Sequence Chart) with time constructs. Then, we give its semantics in terms of timed Buchi automata and measure its expressiveness based on recently proposed real-time specification patterns. Finally, we propose a novel framework to monitor two kinds of timed properties in composite services: the accomplished time of basic service operations and some additional timed assumptions of the composition process. Our framework provides a completely graphical front-end which can friendly help general software engineers to monitor the timed properties in composite services. Pengcheng Zhang 0001, Bixin Li, Zhiyong Su, Mingjie Sun |
APSEC | 2 |
| 2008 | A PSC-Based Approach to Monitor the Timed Properties in Web Service CompositionsabstractRuntime monitoring is significantly essential for web service compositions. For a kind of composite services, nonfunctional properties, such as timed properties, are as important as functional properties and need to be monitored in runtime. In this paper, we extend properly sequence chart into timed properly sequence chart and propose a new approach to monitor two kinds of timed properties in web service compositions: the accomplished time of basic service operations and some additional timed assumptions of the composition process. Our approach is more intuitive than traditional monitoring approaches. Pengcheng Zhang 0001, Bixin Li, Mingjie Sun, Xufang Gong |
COMPSAC | 2 |
| 2008 | Data-Enriched Modeling and Verification of WS-CDL Based on UML ModelsabstractThe Web Services Choreography Description Language (WS-CDL) is a specification developed by the W3C that can be viewed as a blueprint for the development of end-point services. Considering that it is the W3C candidate recommendation for web service choreography, it is worth providing a systematic approach for its modeling, analysis and verification. The Unified Modeling Language (UML) is the de facto industry standard for modeling. Applying UML to model WS-CDL is obviously a promising solution to bring together academics and practitioners in through a unique standard language. This paper proposes to use different UML diagrams to model WS-CDL. Given the UML specification of WS-CDL, we then provide a systematic way of formally analyzing and verifying WS-CDL. Pengcheng Zhang 0001, Bixin Li, Henry Muccini, Yu Zhou 0010, Mingjie Sun |
ICWS | 2 |
| 2008 | A user-oriented Web service reliability modelabstractIn this article, a user-oriented software reliability model was proposed to evaluate the reliability of Web services Two kinds of Web services were discussed: atomic services without the structural information and the composite services consisting of atomic services. Firstly, the reliability of atomic service was evaluated based on an extended UDDI model. Then, the overall reliability of composite service was evaluated using BPEL structure chart-based model and the reliabilities of all atomic services being used. A case study is designed, implemented, and analyzed to support our model. The experimental results show the significances of the model. Bixin Li, Zhiyong Su, Xufang Gong |
SMC | 1 |
| 2007 | A Formal Model for Web Service Composition and Its Application AnalysisabstractThe formal description of Web service is the basis for analyzing and verifying the Web service composition. In this article, a simple pattern-oriented mathematical model for Web service composition is introduced according to following steps: firstly, single service model is formally defined; secondly, several kinds of interaction logics between services are discussed and the composition pattern is presented, the realization of the interaction logics are given at the same time; thirdly, the definition of Web service composition model and the algorithms are presented; finally, a running example is discussed based on our model. The model can express the interactive logic relationships between messages well and it can also be used to simulate the interaction between services via message passing. Bixin Li, Yu Zhou 0010, Xufang Gong |
APSCC | 1 |
| 2006 | An Extension to Robustness Slicing Algorithm Based on Dynamic ArrayabstractSince it was introduced in 1979, program slicing has been used widely in many aspects of software engineering, such as code debugging, program comprehension, software maintenance and reverse engineering etc. Since 1995, many people have studied and developed some methods and tools to help programmers use program slicing technique in software testing, and some valuable results have been obtained by theoretic and empirical analysis and evaluation. Research results show that program slicing is very useful for regression testing and simplifying testing. In this article, we try to extend the ability of Harman and Danicic’s robust slicing algorithm by considering how to deal with dynamically allocated storage. Especially, we discuss how to compute the robustness slice when the subscripts of an array are dynamic. Bixin Li, Xufang Gong |
SNPD | 2 |
| 2005 | Analyzing the Conditions of Coupling Existence Based on Program Slicing and Some Abstract Information-FlowabstractIn this article, we pay more attention to the discussion of the conditions, which possibly produces software coupling between basic components in object-oriented programs. Six possible conditions are discussed in this article with some illuminations. Bixin Li, Junhui Mo |
SNPD | 1 |
| 2005 | A Study of Model Layers and ReflectionabstractSystems of reflection ability can change their structure and behavior during their own execution to adapt to changed environment. This paper studies an approach to reflection realization from the point of view of model layers and language and presents a prototype framework incarnating reflection ideas. Reflection can be obtained from modeling languages that can change model elements structure and behavior with changed condition. Existing meta models stress specification of structure of languages and care little about their behavior. This paper explicitly introduces operations into meta models to control the structure and behavior of model elements. Bixin Li |
SNPD | 2 |
| 2004 | Modular Monadic Program SlicingabstractProgram slicing is widely used in applications such as program comprehension, software testing, debugging, measurement, and reengineering. This paper proposes a new approach for program slicing, called modular monadic slicing, basing on modular monadic semantics of the program analysed. We abstract the computation of program slicing as a language-independence entity: slice monad transformer. On the basis of this, we present and illustrate modular monadic dynamic and static slice algorithms in detail. We conclude that modular monadic slicing has excellent flexibility and reusability properties comparing with the existing program slicing algorithms. It computes program slices on abstract syntax directly without intermediate structures such as dependence graphs. Yingzhou Zhang, Baowen Xu, Bixin Li |
COMPSAC | 4 |
| 2004 | Model for Slicing JAVA Programs Hierarchically
Bixin Li, Xiaocong Fan, Jun Pang 0001, Jianjun Zhao 0001 |
J. Comput. Sci. Technol. | 1 |
| 2003 | A technique to analyze information-flow in object-oriented programs
Bixin Li |
Inf. Softw. Technol. | 1 |