Blog

InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience

Jan 1, 2026. | By: Joanna C. S. Santos

Our work, “InstruMate: A Systematic Framework for Assessing Android App Repackaging Resilience,” was published in 33rd IEEE International Conference on Software Analysis, Evolution and Reengineering.

[Read More]

Automated Detection of Configuration-Specific Security Vulnerabilities via Patch Analysis

Jan 1, 2026. | By: Joanna C. S. Santos

Our work, “Automated Detection of Configuration-Specific Security Vulnerabilities via Patch Analysis,” was published in ACM International Conference on the Foundations of Software Engineering.

[Read More]

CodeGuard: Improving LLM Guardrails in CS Education

Jan 1, 2026. | By: Joanna C. S. Santos

Our work, “CodeGuard: Improving LLM Guardrails in CS Education,” was published in Findings of the Association for Computational Linguistics: EACL 2026.

[Read More]

Cyber-AI Supply Chain Vulnerabilities

Jan 1, 2026. | By: Joanna C. S. Santos

Our work, “Cyber-AI Supply Chain Vulnerabilities,” was published in AI for Cybersecurity: Research and Practice.

[Read More]

Challenges to Using Large Language Models in Code Generation and Repair

Jan 1, 2025. | By: Joanna C. S. Santos

Our work, “Challenges to Using Large Language Models in Code Generation and Repair,” was published in IEEE Security & Privacy.

[Read More]

"Large Language Models in Computer Science Education: A Systematic Literature Review" accepted at SIGCSE TS 2025

Oct 1, 2024. | By: Mohammed Latif Siddiq

Full research paper got accepted at the 56th ACM Technical Symposium on Computer Science Education (SIGCSE TS 2025).

[Read More]

"SALLM: Security Assessment of Generated Code" accepted at ASYDE 2024 (ASE Workshop)

Sep 7, 2024. | By: Mohammed Latif Siddiq

Full research paper got accepted at the 6th International Workshop on Automated and verifiable Software sYstem Development co-located with Automated Software Engineering Conference (ASE 2024).

[Read More]

"FRANC: A Lightweight Framework for High-Quality Code Generation" and "The Fault in our Stars: Quality Assessment of Code Generation Benchmarks " accepted at SCAM 2022

Aug 29, 2024. | By: Joanna C. S. Santos

Two papers got accepted at the 24th IEEE International Conference on Source Code Analysis and Manipulation (SCAM 2024) in the research track. .

[Read More]

"Using Large Language Models to Generate JUnit Tests: An Empirical Study" accepted at EASE 2024.

Mar 7, 2024. | By: Mohammed Latif Siddiq

Our paper, "Using Large Language Models to Generate JUnit Tests: An Empirical Study", got accepted for the 28th International Conference on Evaluation and Assessment in Software Engineering (EASE 2024) in the research track.

[Read More]

"Understanding Regular Expression Denial of Service (ReDoS): Insights from LLM-Generated Regexes and Developer Forums" accepted at ICPC 2024.

Feb 1, 2024. | By: Mohammed Latif Siddiq

Our paper, "Understanding Regular Expression Denial of Service (ReDoS): Insights from LLM-Generated Regexes and Developer Forums", got accepted for the 32nd ACM/IEEE International Conference on Program Comprehension (ICPC 2024).

[Read More]

"Large Language Models in Computer Science Education: A Systematic Literature Review" accepted at SIGCSE TS 2025

Jan 23, 2024. | By: Joanna C. S. Santos

Full research paper got accepted at the findings of the 2025 Annual Conference of the Nations of the Americas Chapter of the Association for Computational Linguistics (NAACL 2025 Findings) .

[Read More]

Quality Assessment of ChatGPT Generated Code and their Use by Developers

Jan 1, 2024. | By: Joanna C. S. Santos

Our work, “Quality Assessment of ChatGPT Generated Code and their Use by Developers,” was published in 21st International Conference on Mining Software Repositories, Mining Challenge Track (MSR 2024).

[Read More]

"Re(gEx|DoS)Eval: Evaluating Generated Regular Expressions and their Proneness to DoS Attacks" accepted at ICSE-NIER 2024.

Nov 22, 2023. | By: Mohammed Latif Siddiq

Our paper, "Re(gEx|DoS)Eval: Evaluating Generated Regular Expressions and their Proneness to DoS Attack", got accepted for The 46th International Conference on Software Engineering - New Ideas and Emerging Results Track.

[Read More]

"Zero-shot Prompting for Code Complexity Prediction Using GitHub Copilot" accepted at NLBSE'23 (co-located with ICSE'23).

Feb 24, 2023. | By: Joanna C. S. Santos

Our short paper, "Zero-shot Prompting for Code Complexity Prediction Using GitHub Copilot", got accepted at the 2nd Intl. Workshop on Natural Language-based Software Engineering (NLBSE'23) co-located with ICSE 2023.

[Read More]

"Empirical Validation of Automated Vulnerability Curation and Characterization" accepted at TSE

Feb 14, 2023. | By: Joanna C. S. Santos

Our manuscript, "Empirical Validation of Automated Vulnerability Curation and Characterization", got accepted at IEEE Transactions on Software Engineering (TSE).

[Read More]

"Counterfeit Object-Oriented Programming Vulnerabilities: An Empirical Study in Java" accepted at MSR4P&S 2022 (co-located with ESEC/FSE'22)

Oct 6, 2022. | By: Joanna C. S. Santos

Our paper, "Counterfeit Object-Oriented Programming Vulnerabilities: An Empirical Study in Java", got accepted for The 1st International Workshop on Mining Software Repositories Applications for Privacy and Security(MSR4P&S' 22) co-located with ESEC/FSE 2022.

[Read More]

"SecurityEval Dataset: Mining Vulnerability Examples to Evaluate Machine Learning-Based Code Generation Techniques" accepted at MSR4P&S 2022 (co-located with ESEC/FSE'22)

Aug 16, 2022. | By: Mohammed Latif Siddiq

Our dataset paper, "SecurityEval Dataset: Mining Vulnerability Examples to Evaluate Machine Learning-Based Code Generation Techniques", got accepted for The 1st International Workshop on Mining Software Repositories Applications for Privacy and Security(MSR4P&S' 22) co-located with ESEC/FSE 2022 in the short paper track.

[Read More]

Tutorial on Program Analysis using WALA accepted at ESEC/FSE 2022

Aug 1, 2022. | By: Joanna C. S. Santos

Our tutorial proposal ("Program Analysis using WALA") got accepted at ESEC/FSE.

[Read More]

"An Empirical Study of Code Smells in Transformer-based Code Generation Techniques" accepted at SCAM 2022

Jul 28, 2022. | By: Mohammed Latif Siddiq

Our paper, "An Empirical Study of Code Smells in Transformer-based Code Generation Techniques", got accepted for the 22nd IEEE International Working Conference on Source Code Analysis and Manipulation (SCAM 2022) in the research track.

[Read More]

"BERT-Based GitHub Issue Report Classification" accepted at NLBSE 2022 (co-located with ICSE'22).

Mar 2, 2022. | By: Mohammed Latif Siddiq

Our paper, "BERT-Based GitHub Issue Report Classification", got accepted for The 1st Intl. Workshop on Natural Language-based Software Engineering (NLBSE'22) co-located with ICSE 2022 in the tool competition.

[Read More]

A Methodological Approach to Verify Architecture Resiliency

Jan 1, 2022. | By: Joanna C. S. Santos

Our work, “A Methodological Approach to Verify Architecture Resiliency,” was published in 2nd International Workshop on Designing and Measuring Security in Software Architecture (co-located with ECSA'22).

[Read More]

Serialization-Aware Call Graph Construction

Jan 1, 2021. | By: Joanna C. S. Santos

Our work, “Serialization-Aware Call Graph Construction,” was published in 10th ACM SIGPLAN International Workshop on the State of the Art in Program Analysis.

[Read More]

ArCode: Facilitating the Use of Application Frameworks to Implement Tactics and Patterns

Jan 1, 2021. | By: Joanna C. S. Santos

Our work, “ArCode: Facilitating the Use of Application Frameworks to Implement Tactics and Patterns,” was published in 2021 IEEE International Conference on Software Architecture.

[Read More]

Looking for Software Defects? First Find the Nonconformists - An Outlier-Based Defect Prediction Approach

Jan 1, 2020. | By: Joanna C. S. Santos

Our work, “Looking for Software Defects? First Find the Nonconformists - An Outlier-Based Defect Prediction Approach,” was published in 20th IEEE International Working Conference on Source Code Analysis and Manipulation.

[Read More]

Towards Automated Evidence Generation for Rapid and Continuous Software Certification

Jan 1, 2020. | By: Joanna C. S. Santos

Our work, “Towards Automated Evidence Generation for Rapid and Continuous Software Certification,” was published in 10th IEEE International Workshop on Software Certification.

[Read More]

An Automated Approach to Recover the Use-case View of an Architecture

Jan 1, 2020. | By: Joanna C. S. Santos

Our work, “An Automated Approach to Recover the Use-case View of an Architecture,” was published in 2020 IEEE International Conference on Software Architecture - New and Emerging Ideas.

[Read More]

Salsa: Static Analysis of Serialization Features

Jan 1, 2020. | By: Joanna C. S. Santos

Our work, “Salsa: Static Analysis of Serialization Features,” was published in 22th ACM SIGPLAN International Workshop on Formal Techniques for Java-Like Programs.

[Read More]

Towards an Automated Approach for Detecting Architectural Weaknesses in Critical Systems

Jan 1, 2020. | By: Joanna C. S. Santos

Our work, “Towards an Automated Approach for Detecting Architectural Weaknesses in Critical Systems,” was published in 1st International Workshop on Engineering and Cybersecurity of Critical Systems.

[Read More]

An Empirical Study of Tactical Vulnerabilities

Jan 1, 2019. | By: Joanna C. S. Santos

Our work, “An Empirical Study of Tactical Vulnerabilities,” was published in Journal of Systems and Software.

[Read More]

Achilles’ Heel of Plug-and-Play Software Architectures: A Grounded Theory Based Approach

Jan 1, 2019. | By: Joanna C. S. Santos

Our work, “Achilles’ Heel of Plug-and-Play Software Architectures: A Grounded Theory Based Approach,” was published in 2019 ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering.

[Read More]

A Large-Scale Study on the Usage of Testing Patterns That Address Maintainability Attributes (Patterns for Ease of Modification, Diagnoses, and Comprehension)

Jan 1, 2017. | By: Joanna C. S. Santos

Our work, “A Large-Scale Study on the Usage of Testing Patterns That Address Maintainability Attributes (Patterns for Ease of Modification, Diagnoses, and Comprehension),” was published in Proceedings of the 14th International Conference on Mining Software Repositories.

[Read More]

A Catalog of Security Architecture Weaknesses

Jan 1, 2017. | By: Joanna C. S. Santos

Our work, “A Catalog of Security Architecture Weaknesses,” was published in 2017 IEEE International Conference on Software Architecture Workshops.

[Read More]

Understanding Software Vulnerabilities Related to Architectural Security Tactics: An Empirical Investigation of Chromium, PHP and Thunderbird

Jan 1, 2017. | By: Joanna C. S. Santos

Our work, “Understanding Software Vulnerabilities Related to Architectural Security Tactics: An Empirical Investigation of Chromium, PHP and Thunderbird,” was published in 2017 IEEE International Conference on Software Architecture.

[Read More]

BUDGET: a Tool for Supporting Software Architecture Traceability Research

Jan 1, 2016. | By: Joanna C. S. Santos

Our work, “BUDGET: a Tool for Supporting Software Architecture Traceability Research,” was published in Proceedings of the 13th Working IEEE/IFIP Conference on Software Architecture.

[Read More]

A search engine for finding and reusing architecturally significant code

Jan 1, 2016. | By: Joanna C. S. Santos

Our work, “A search engine for finding and reusing architecturally significant code,” was published in Journal of Systems and Software.

[Read More]

Automated training-set creation for software architecture traceability problem

Jan 1, 2016. | By: Joanna C. S. Santos

Our work, “Automated training-set creation for software architecture traceability problem,” was published in Empirical Software Engineering.

[Read More]

A Model-Driven Solution for Automatic Software Deployment in the Cloud

Jan 1, 2015. | By: Joanna C. S. Santos

Our work, “A Model-Driven Solution for Automatic Software Deployment in the Cloud,” was published in Proceedings of the 13th International Conference on Information Technology: New Generations.

[Read More]

ERLab: a middleware for remote access electronic laboratories

Jan 1, 2012. | By: Joanna C. S. Santos

Our work, “ERLab: a middleware for remote access electronic laboratories,” was published in Proceedings of the 6th Euro American Conference on Telematics and Information Systems.

[Read More]

About

Security and Software Engineering Lab at University of Notre Dame, Notre Dame, IN USA 46556

twitter github

Where We Are

University of Notre Dame
College of Engineering
382 Fitzpatrick Hall
Notre Dame, IN 46556