Software Security & Privacy
Secure software design, vulnerability and privacy analysis, data protection, security testing, and evidence-based assurance.
We study secure and trustworthy software through interconnected research in software security and privacy, AI, software analysis and quality, and empirical studies.
Our focus
Secure software design, vulnerability and privacy analysis, data protection, security testing, and evidence-based assurance.
Security and privacy of mobile ecosystems, including Android, malware detection and characterization, app repackaging, inter-app communication, and vulnerability analysis.
Security, reliability, evidence grounding, and responsible evaluation of AI systems used in software and security contexts.
LLMs, coding agents, and intelligent automation for software generation, testing, debugging, analysis, repair, and secure development.
Program and repository analysis, software metrics, maintainability, architecture, code smells, analytics, and security-aware quality assessment.
Evidence-driven studies of software systems, developers, tools, datasets, and engineering practices using reproducible empirical methods.
Integrated themes
We investigate software security and privacy risks at code, architecture, application, and ecosystem levels. Current interests include mobile security, malware and vulnerability analysis, privacy risks, secure code analysis, and software assurance.
We study AI as both a software-engineering capability and a source of new assurance challenges. This includes trustworthy AI, LLMs and coding agents, security analysis with AI, evidence-grounded reasoning, validation, and false assurance.
We use empirical methods and software analysis to understand software properties at scale, including metrics, quality, maintainability, architecture, software analytics, datasets, and reproducible evaluation.
Many NEXUS projects produce datasets, tools, benchmarks, and other reproducible resources to support follow-on research.