Change search
Link to record
Permanent link

Direct link
Saadatmand, Mehrdad, PhDORCID iD iconorcid.org/0000-0002-1512-0844
Alternative names
Publications (10 of 62) Show all publications
Ramires, R., Bashir, S., Khan, A., Saadatmand, M. & Medeiros, I. (2026). Friends or Foes? Combining Static Analysis Tools and LLMs for Vulnerability Detection. In: Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026: . Paper presented at 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026 (pp. 163-172). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Friends or Foes? Combining Static Analysis Tools and LLMs for Vulnerability Detection
Show others...
2026 (English)In: Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026, Institute of Electrical and Electronics Engineers (IEEE) , 2026, p. 163-172Conference paper, Published paper (Refereed)
Abstract [en]

Industrial products and devices (e.g., vehicles, drones) are broadly accessed and managed using web applications. These applications have been a major concern for enterprises, as they are the preferred targets of attackers due to persistent vulnerabilities in their code. To address vulnerabilities, Static analysis tools (SASTs) have been widely used for detection, alongside the growing trend of employing prompt-engineered large language models (LLMs). Although they have proven useful for detection, both techniques tend to generate false positives (FPs), thereby unnecessarily increasing manual effort in the search for non-existent vulnerabilities; moreover, SASTs tend to miss vulnerabilities. In contrast, fine-tuned LLMs have proven effective at reasoning and classification tasks, but often require expensive training with balanced corpora. In this paper, we study SASTs, both types of LLMs, and their combination to improve overall vulnerability detection in web applications. We tested two modern SAST tools and two LLM models, across seven datasets for SQL injection (SQLi) vulnerability detection. Our findings reveal that combining the results of multiple solutions can improve vulnerability detection. The best combination integrates both LLMs and a SAST, where i) the fine-tuned LLM, together with the SAST, reduces FPs, mainly produced by the prompt-engineering LLM, and ii) both LLMs overcome SAST's limitation of missing vulnerabilities. On average, the F1-Score increases by 17-60% when SASTS and LLMs are combined. In particular, it can improve from 6% (with a standalone solution) to ≈100% when LLMs are combined with SASTs

Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2026
Keywords
Fine-tuning and Prompt-engineering LLMs, Software security, Static analysis, Vulnerability detection
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:ri:diva-82228 (URN)10.1109/ICSTW72326.2026.00040 (DOI)2-s2.0-105045599548 (Scopus ID)
Conference
2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026
Available from: 2026-08-05 Created: 2026-08-05 Last updated: 2026-08-05Bibliographically approved
Saadatmand, M., Moghadam, M. H., Ul Haq, F. & Ahmad, T. (2026). Message from the ITEQS 2026 Chairs. In: Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026: . Paper presented at 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026 (pp. XVII-XVIII). Institute of Electrical and Electronics Engineers (IEEE)
Open this publication in new window or tab >>Message from the ITEQS 2026 Chairs
2026 (English)In: Proceedings - 2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026, Institute of Electrical and Electronics Engineers (IEEE) , 2026, p. XVII-XVIIIConference paper, Published paper (Refereed)
Place, publisher, year, edition, pages
Institute of Electrical and Electronics Engineers (IEEE), 2026
National Category
Electrical Engineering, Electronic Engineering, Information Engineering
Identifiers
urn:nbn:se:ri:diva-82247 (URN)10.1109/ICSTW72326.2026.00010 (DOI)2-s2.0-105045646360 (Scopus ID)
Conference
2026 IEEE International Conference on Software Testing, Verification and Validation Workshops, ICSTW 2026
Available from: 2026-08-05 Created: 2026-08-05 Last updated: 2026-08-05Bibliographically approved
Saadatmand, M., Abbas, M., Marín, B., Paiva, A. C. .., Asch, N. V., Moran, G., . . . Mendes, A. (2026). Software Testing Education and Industry Needs - Report from the ENACTEST EU Project. In: Scanniello G., Romano S., Francese R., Lenarduzzi V., Vegas S. (Ed.), Lecture Notes in Computer Science: . Paper presented at 26th International Conference on Product-Focused Software Process Improvement, PROFES 2025, Salerno (pp. 53-68). Springer Science+Business Media B.V., 16362 LNCS
Open this publication in new window or tab >>Software Testing Education and Industry Needs - Report from the ENACTEST EU Project
Show others...
2026 (English)In: Lecture Notes in Computer Science / [ed] Scanniello G., Romano S., Francese R., Lenarduzzi V., Vegas S., Springer Science+Business Media B.V., 2026, Vol. 16362 LNCS, p. 53-68Conference paper, Published paper (Refereed)
Abstract [en]

The evolving landscape of software development demands that software testers continuously adapt to new tools, practices, and acquire new skills. This study investigates software testing competency needs in industry, identifies knowledge gaps in current testing education, and highlights competencies and gaps not addressed in academic literature. This is done by conducting two focus group sessions and interviews with professionals across diverse domains, including railway industry, healthcare, and software consulting and performing a curated small-scale scoping review. The study instrument, co-designed by members of the ENACTEST project consortium, was developed collaboratively and refined through multiple iterations to ensure comprehensive coverage of industry needs and educational gaps. In particular, by performing a thematic qualitative analysis, we report our findings and observations regarding: professional training methods, challenges in offering training in industry, different ways of evaluating the quality of training, identified knowledge gaps with respect to academic education and industry needs, future needs and trends in testing education, and knowledge transfer methods within companies. Finally, the scoping review results confirm knowledge gaps in areas such as AI testing, security testing and soft skills

Place, publisher, year, edition, pages
Springer Science+Business Media B.V., 2026
Keywords
education, industry needs, knowledge transfer, software testing
National Category
Software Engineering
Identifiers
urn:nbn:se:ri:diva-80058 (URN)10.1007/978-3-032-12092-2_4 (DOI)2-s2.0-105023586729 (Scopus ID)
Conference
26th International Conference on Product-Focused Software Process Improvement, PROFES 2025, Salerno
Note

This work has been partially funded by ENACTEST (European innovation alliance for testing education) ERASMUS+ Project number 101055874, 2022\u20132025. The work is also supported by the Swedish Knowledge Foundation (KKS) through the ARRAY project. We would also like to thank the industry experts and professionals who participated in our studies and provided valuable inputs.

Available from: 2025-12-29 Created: 2025-12-29 Last updated: 2025-12-29Bibliographically approved
Ibtasham, M. S., Bashir, S., Abbas, M., Haider, Z., Saadatmand, M. & Cicchetti, A. (2025). ReqRAG: Enhancing Software Release Management through Retrieval-Augmented LLMs: An Industrial Study. Paper presented at 31st International Working Conference on Requirements Engineering: Foundation for Software Quality, REFSQ 2025. 7 April 2025 - 10 April 2025. Lecture Notes in Computer Science, 15588 LNCS, 277-292
Open this publication in new window or tab >>ReqRAG: Enhancing Software Release Management through Retrieval-Augmented LLMs: An Industrial Study
Show others...
2025 (English)In: Lecture Notes in Computer Science, ISSN 0302-9743, E-ISSN 1611-3349, Vol. 15588 LNCS, p. 277-292Article in journal (Refereed) Published
Abstract [en]

[Context and Motivation] Engineers often need to refer back to release notes, manuals, and system architecture documents to understand, modify, or upgrade functionalities in alignment with new software releases. This is crucial to ensure that new stakeholder requirements align with the existing system, maintaining compatibility and preventing integration issues. [Problem] In practice, the manual process of retrieving the relevant information from technical documentation is time-intensive and frequently results in inefficient software release management. [Principal ideas/results] In this paper, we propose a question-answering chatbot, ReqRAG, leveraging Retrieval Augmented Generation (RAG) with Large Language Models (LLMs) to deliver accurate and up-to-date information from technical documents in response to given queries. We employ various context retrieval techniques paired with state-of-the-art LLMs to evaluate the ReqRAG approach in industrial settings. Furthermore, we conduct human evaluations of the results in collaboration with experts from Alstom to gain practical insights. Our results indicate that, on average, 70% of the generated responses are adequate, useful, and relevant to the practitioners. [Contribution] Fewer studies have comprehensively evaluated RAG-based approaches in industrial settings. Therefore, this work provides technical considerations for domain-specific chatbots, guiding researchers and practitioners facing similar challenges. 

Place, publisher, year, edition, pages
Springer Science and Business Media Deutschland GmbH, 2025
Keywords
Information management; Online searching; Problem oriented languages; System program documentation; Chatbots; Industrial settings; Industry study; Language model; Large language model; Release management; Retrieval augmented generation; Software release; Software release management; Systems architecture; Search engines
National Category
Natural Sciences Computer and Information Sciences
Identifiers
urn:nbn:se:ri:diva-78437 (URN)10.1007/978-3-031-88531-0_20 (DOI)2-s2.0-105002728440 (Scopus ID)
Conference
31st International Working Conference on Requirements Engineering: Foundation for Software Quality, REFSQ 2025. 7 April 2025 - 10 April 2025
Available from: 2025-09-17 Created: 2025-09-17 Last updated: 2025-09-23Bibliographically approved
Bashir, S., Ferrari, A., Khan, A., Strandberg, P. E., Haider, Z., Saadatmand, M. & Bohlin, M. (2025). Requirements Ambiguity Detection and Explanation with LLMS: An Industrial Study. In: : . Paper presented at 41st IEEE International Conference on Software Maintenance and Evolution, ICSME 2025 (pp. 620-631).
Open this publication in new window or tab >>Requirements Ambiguity Detection and Explanation with LLMS: An Industrial Study
Show others...
2025 (English)Conference paper, Published paper (Refereed)
Abstract [en]

Developing large-scale industrial systems requires high-quality requirements to avoid costly rework and project delays. However, linguistic ambiguities in natural language (NL) requirements have been a long-standing challenge, often introducing misinterpretations and inconsistencies that propagate throughout the development lifecycle. Such ambiguous NL requirements necessitate early detection and well-reasoned explanations to clarify and prevent further misunderstandings among stakeholders. While solutions have been developed to detect ambiguities in NL requirements, the advent of generative large language models (LLMs) offers new avenues for explanation-augmented requirements ambiguity detection. This paper empirically investigates LLMs for ambiguity detection and explanation in real-world industrial requirements by adopting an in-context learning paradigm. Our results from three industrial datasets show that LLMs achieve a 20.2% average performance increase in classifying ambiguous requirements when prompted with ten relevant in-context demonstrations (10 -shot), compared to no demonstrations (0 -shot). Additionally, we conducted human evaluations of the LLM-generated outputs with eight industry experts along four dimensions-naturalness, adequacy, usefulness and relevance-to gain practical insights. The results show an average rating of 3.84 out of 5 across evaluation criteria, indicating that the approach is effective in providing supporting explanations for requirement ambiguities

Keywords
in-context learning, large language models, requirements ambiguity, requirements classification
National Category
Computer Sciences
Identifiers
urn:nbn:se:ri:diva-79889 (URN)10.1109/ICSME64153.2025.00063 (DOI)2-s2.0-105022457767 (Scopus ID)9798331595876 (ISBN)
Conference
41st IEEE International Conference on Software Maintenance and Evolution, ICSME 2025
Available from: 2025-12-04 Created: 2025-12-04 Last updated: 2025-12-04Bibliographically approved
Abbas, M., Bashir, S., Saadatmand, M., Enoiu, E. P. & Sundmark, D. (2025). Requirements Similarity and Retrieval. In: Handbook on Natural Language Processing for Requirements Engineering: (pp. 61-88). Springer Nature
Open this publication in new window or tab >>Requirements Similarity and Retrieval
Show others...
2025 (English)In: Handbook on Natural Language Processing for Requirements Engineering, Springer Nature , 2025, p. 61-88Chapter in book (Other academic)
Abstract [en]

Requirement Engineering (RE) is crucial for identifying, analysing and documenting stakeholders’ needs and constraints for developing software systems. In most safety-critical domains, maintaining requirements and their links to other artifacts is also often required by regulatory bodies. Furthermore, in such contexts, requirements for new products often share similarities with previous existing projects performed by the company. Therefore, similar requirements can be retrieved to facilitate the feasibility analysis of new projects. In addition, when a new customer requests a new product, retrieval of similar requirements can enable requirements-driven software reuse and avoid redundant development efforts. Manually retrieving similar requirements for reuse is typically dependent on the engineer’s experience and is not scalable, as the set could be quite large. In this regard, applying natural language processing (NLP) techniques for automated similarity computation and retrieval ensures the independence of the process from the human experience and makes the process scalable. This chapter introduces linguistic similarity and several NLP-based similarity computation techniques that leverage linguistic features for similarity computation. Specifically, we cover techniques for computing similarity ranging from lexical to state-of-the-art deep neural network-based methods. We demonstrate their application in two example cases: (a) requirements reuse and (b) requirements-driven software retrieval. The practical guidance and example cases presented in the chapter can help practitioners apply the concepts to improve their processes where similarity computation is relevant.

Place, publisher, year, edition, pages
Springer Nature, 2025
Keywords
Accident prevention; Computational grammars; Computer operating systems; Enterprise software; Human engineering; Requirements engineering; Software design; Language processing; Natural language processing; Natural languages; Requirement engineering; Requirement retrieval; Requirement similarities; Requirement-driven; Requirements reuse; Similarity computation; Software-reuse; Computer software reusability
National Category
Computer and Information Sciences
Identifiers
urn:nbn:se:ri:diva-78579 (URN)10.1007/978-3-031-73143-3_3 (DOI)2-s2.0-105004625813 (Scopus ID)9783031731433 (ISBN)
Available from: 2025-06-23 Created: 2025-06-23 Last updated: 2025-09-23Bibliographically approved
Fasolino, A. R., Marín, B., Vos, T. E. .., Mendes, A., Paiva, A. C. .., Cammaerts, F., . . . Tramontana, P. (2025). Teachers' Perspective on Software Testing Education. ACM Transactions on Computing Education, 26(1)
Open this publication in new window or tab >>Teachers' Perspective on Software Testing Education
Show others...
2025 (English)In: ACM Transactions on Computing Education, E-ISSN 1946-6226, Vol. 26, no 1Article in journal (Refereed) Published
Abstract [en]

Context. Software testing is a critical aspect of the software development lifecycle, yet it remains underrepresented in academic curricula. Despite advances in pedagogical practices and increased attention from the academic community, challenges persist in effectively teaching software testing. Understanding these challenges from the teachers' perspective is crucial to aligning education with industry needs.Objective. To analyze the characteristics, practices, tools, and challenges of software testing courses in higher education, from the perspective of educators, and to assess the integration of recent pedagogical approaches in software testing education.Method. A structured survey consisting of 52 questions was distributed to 143 software testing educators across Western European universities, resulting in 49 valid responses. The survey explored topics taught, course organization, teaching practices, tools and materials used, gamification approaches, and teacher satisfaction.Results. The survey revealed significant variability in course content, structure, and teaching methods. Most dedicated software testing courses are offered at the master's level and are elective, whereas testing is introduced earlier in less specialized (NST) courses. There is low adoption of formal guidelines (e.g., ACM, SWEBOK), limited integration of non-functional testing types, and a high diversity in textbooks and tools used. While modern practices like Test-Driven Development and automated assessment are increasingly adopted, gamification and active learning approaches remain underutilized. Teachers expressed a need for improved and more consistent teaching materials.Conclusion. The study highlights a mismatch between academic practices and industry expectations in software testing education. Greater integration of standardized curricula, broader adoption of modern teaching tools, and increased support for teachers through high-quality, adaptable teaching materials are needed to enhance the effectiveness of software testing education. © 2025

Place, publisher, year, edition, pages
Association for Computing Machinery (ACM), 2025
Keywords
Software Testing Education, Software Testing Education Practices, Teachers' perspective on software testing education, Teachers' Survey
National Category
Software Engineering
Identifiers
urn:nbn:se:ri:diva-80988 (URN)10.1145/3772090 (DOI)2-s2.0-105029062517 (Scopus ID)
Note

QC 20260318

Available from: 2026-03-12 Created: 2026-03-12 Last updated: 2026-03-18Bibliographically approved
Helali Moghadam, M., Borg, M., Saadatmand, M., Mousavirad, S., Bohlin, M. & Lisper, B. (2024). Machine learning testing in an ADAS case study using simulation-integrated bio-inspired search-based testing. Journal of Software: Evolution and Process (5), Article ID e2591.
Open this publication in new window or tab >>Machine learning testing in an ADAS case study using simulation-integrated bio-inspired search-based testing
Show others...
2024 (English)In: Journal of Software: Evolution and Process, ISSN 2047-7473, E-ISSN 2047-7481, no 5, article id e2591Article in journal (Refereed) Published
Abstract [en]

This paper presents an extended version of Deeper, a search-based simulation-integrated test solution that generates failure-revealing test scenarios for testing a deep neural network-based lane-keeping system. In the newly proposed version, we utilize a new set of bio-inspired search algorithms, genetic algorithm (GA), (Formula presented.) and (Formula presented.) evolution strategies (ES), and particle swarm optimization (PSO), that leverage a quality population seed and domain-specific crossover and mutation operations tailored for the presentation model used for modeling the test scenarios. In order to demonstrate the capabilities of the new test generators within Deeper, we carry out an empirical evaluation and comparison with regard to the results of five participating tools in the cyber-physical systems testing competition at SBST 2021. Our evaluation shows the newly proposed test generators in Deeper not only represent a considerable improvement on the previous version but also prove to be effective and efficient in provoking a considerable number of diverse failure-revealing test scenarios for testing an ML-driven lane-keeping system. They can trigger several failures while promoting test scenario diversity, under a limited test time budget, high target failure severity, and strict speed limit constraints. 

Place, publisher, year, edition, pages
John Wiley and Sons Ltd, 2024
Keywords
advanced driver assistance systems, deep learning, evolutionary computation, lane-keeping system, machine learning testing, search-based testing, Automobile drivers, Biomimetics, Budget control, Deep neural networks, Embedded systems, Genetic algorithms, Learning systems, Particle swarm optimization (PSO), Software testing, Case-studies, Lane keeping, Machine-learning, Software Evolution, Software process, Test scenario
National Category
Software Engineering
Identifiers
urn:nbn:se:ri:diva-65687 (URN)10.1002/smr.2591 (DOI)2-s2.0-85163167144 (Scopus ID)
Note

 Correspondence Address: M.H. Moghadam; Smart Industrial Automation, RISE Research Institutes of Sweden, Västerås, Stora Gatan 36, 722 12, Sweden;  

This work has been funded by Vinnova through the ITEA3 European IVVES ( https://itea3.org/project/ivves.html ) and H2020‐ECSEL European AIDOaRT ( https://www.aidoart.eu/ ) and InSecTT ( https://www.insectt.eu/ ) projects. Furthermore, the project received partially financial support from the SMILE III project financed by Vinnova, FFI, Fordonsstrategisk forskning och innovation under the grant number: 2019‐05871.

Available from: 2023-08-10 Created: 2023-08-10 Last updated: 2025-09-23Bibliographically approved
Kiss, A., Marín, B. & Saadatmand, M. (2023). 13th Workshop on Automating Test Case Design, Selection and Evaluation (A-TEST 2022) Co-Located with ESEC/FSE Conference. Software Engineering Notes: an Informal Newsletter of The Specia, 48(1), 76-78
Open this publication in new window or tab >>13th Workshop on Automating Test Case Design, Selection and Evaluation (A-TEST 2022) Co-Located with ESEC/FSE Conference
2023 (English)In: Software Engineering Notes: an Informal Newsletter of The Specia, ISSN 0163-5948, E-ISSN 1943-5843, Vol. 48, no 1, p. 76-78Article in journal (Refereed) Published
Abstract [en]

The Workshop on Automating Test Case Design, Selection and Evaluation (A-TEST) has provided a venue for researchers and industry members alike to exchange and discuss trending views, ideas, state of the art, work in progress, and scientific results on automated testing. Up until now it has run 13 editions since 2009. The 13th edition of the A-TEST workshop has been performed as an in-person workshop in Singapore during 17 to 18 of November, 2022. This edition of the A-TEST workshop was co-located with ESEC/FSE 2022 conference.

Place, publisher, year, edition, pages
Association for Computing Machinery, 2023
National Category
Computer Systems
Identifiers
urn:nbn:se:ri:diva-65768 (URN)10.1145/3573074.3573093 (DOI)
Available from: 2023-08-14 Created: 2023-08-14 Last updated: 2025-09-23Bibliographically approved
Abbas, M., Hamayouni, A., Helali Moghadam, M., Saadatmand, M. & Strandberg, P. E. (2023). Making Sense of Failure Logs in an Industrial DevOps Environment. In: Advances in Intelligent Systems and Computing book series (AISC,volume 1445): 20th International Conference on Information Technology New Generations. Paper presented at 20th International Conference on Information Technology New Generations (pp. 217-226). Springer International Publishing, 1445
Open this publication in new window or tab >>Making Sense of Failure Logs in an Industrial DevOps Environment
Show others...
2023 (English)In: Advances in Intelligent Systems and Computing book series (AISC,volume 1445): 20th International Conference on Information Technology New Generations, Springer International Publishing , 2023, Vol. 1445, p. 217-226Conference paper, Published paper (Refereed)
Abstract [en]

Processing and reviewing nightly test execution failure logs for large industrial systems is a tedious activity. Furthermore, multiple failures might share one root/common cause during test execution sessions, and the review might therefore require redundant efforts. This paper presents the LogGrouper approach for automated grouping of failure logs to aid root/common cause analysis and for enabling the processing of each log group as a batch. LogGrouper uses state-of-art natural language processing and clustering approaches to achieve meaningful log grouping. The approach is evaluated in an industrial setting in both a qualitative and quantitative manner. Results show that LogGrouper produces good quality groupings in terms of our two evaluation metrics (Silhouette Coefficient and Calinski-Harabasz Index) for clustering quality. The qualitative evaluation shows that experts perceive the groups as useful, and the groups are seen as an initial pointer for root cause analysis and failure assignment.

Place, publisher, year, edition, pages
Springer International Publishing, 2023
National Category
Computer Sciences
Identifiers
urn:nbn:se:ri:diva-67432 (URN)
Conference
20th International Conference on Information Technology New Generations
Available from: 2023-09-28 Created: 2023-09-28 Last updated: 2025-09-23Bibliographically approved
Organisations
Identifiers
ORCID iD: ORCID iD iconorcid.org/0000-0002-1512-0844

Search in DiVA

Show all publications

Profile pages

LinkedInRISE Profile page