Research Group: http://mpi-softsec.github.io
📝 mpi-softsec.github.io/papers/TOSEM...
Collab w/ Eric Bodden, Tevfik Bultan, Cristian Cadar, Liu Yang, and Giuseppe Scanniello
What do symbolic model checking, path profiling, and quantum simulation have in common? 🤔
Find out from Prof. Reps (University of Wisconsin-Madison) in his ASE2025 Keynote “We Will Publish No Algorithm Before Its Time”!
conf.researchr.org/track/ase-20...
What do symbolic model checking, path profiling, and quantum simulation have in common? 🤔
Find out from Prof. Reps (University of Wisconsin-Madison) in his ASE2025 Keynote “We Will Publish No Algorithm Before Its Time”!
conf.researchr.org/track/ase-20...
Prof. Taesoo Kim (Georgia Tech)
“Hyperscale Bug Finding and Fixing: DARPA AIxCC”
conf.researchr.org/track/ase-20...
Prof. Taesoo Kim (Georgia Tech)
“Hyperscale Bug Finding and Fixing: DARPA AIxCC”
conf.researchr.org/track/ase-20...
Dr. Cristina Cifuentes, Vice President @ Oracle Software Assurance
“Oracle Parfait – Detecting Application Vulnerabilities at Scale – Past, Present and Future”
Dr. Cristina Cifuentes, Vice President @ Oracle Software Assurance
“Oracle Parfait – Detecting Application Vulnerabilities at Scale – Past, Present and Future”
📝: arxiv.org/abs/2507.00057
🦋 : bsky.app/profile/did:...
We are off to a good start. While the synopsis misses the motivation (*why* this is interesting), it offers the most important points. Good abstract-length summary.
1/
📝: arxiv.org/abs/2507.00057
🦋 : bsky.app/profile/did:...
We are off to a good start. While the synopsis misses the motivation (*why* this is interesting), it offers the most important points. Good abstract-length summary.
1/
📝 arxiv.org/abs/2507.00057
with Thomas Valentin (ENS Paris-Saclay), Ardi Madadi, and Gaetano Sapia (#MPI_SP).
📝 arxiv.org/abs/2507.00057
with Thomas Valentin (ENS Paris-Saclay), Ardi Madadi, and Gaetano Sapia (#MPI_SP).
📝 gpsapia.github.io/files/ICSE_2...
🧑💻 github.com/GPSapia/Reac...
How to scale automatic security testing to arbitrary systems?
📝 gpsapia.github.io/files/ICSE_2...
🧑💻 github.com/GPSapia/Reac...
How to scale automatic security testing to arbitrary systems?
📝 gpsapia.github.io/files/ICSE_2...
🧑💻 github.com/GPSapia/Reac...
How to scale automatic security testing to arbitrary systems?
addisoncrump.info/research/wha...
addisoncrump.info/research/wha...
If our paper gets accepted at #AAAI26, I will review our AI-generated review here 🤠
If our paper gets accepted at #AAAI26, I will review our AI-generated review here 🤠
We introduce Circuzz, the first systematic fuzzing framework for zero-knowledge (ZK) pipelines.
📄 Paper: mariachris.github.io/Pubs/CCS-202...
💻 Repo: github.com/Rigorous-Sof...
with @isychev.bsky.social, @vwuestholz.bsky.social, Maria Christakis
We introduce Circuzz, the first systematic fuzzing framework for zero-knowledge (ZK) pipelines.
📄 Paper: mariachris.github.io/Pubs/CCS-202...
💻 Repo: github.com/Rigorous-Sof...
with @isychev.bsky.social, @vwuestholz.bsky.social, Maria Christakis
📅 Early deadline: Oct 15, 2025
🧾 Regular deadline: Nov 2, 2025
All accepted papers must have at least one regular (non-student) registration for inclusion in the proceedings.
👉 Details: conf.researchr.org/attending/ase-2025/registration
📅 Early deadline: Oct 15, 2025
🧾 Regular deadline: Nov 2, 2025
All accepted papers must have at least one regular (non-student) registration for inclusion in the proceedings.
👉 Details: conf.researchr.org/attending/ase-2025/registration
Looking forward to submissions from the Security and the Software Engineering community!
──────
✨ After 5 years, we will be again co-located with NDSS!
🔗 fuzzing-workshop.github.io
📅 11. Dec (Submission)
//cc @mboehme.bsky.social (MPI-SP), @ruijiemeng.bsky.social (CISPA), @rohan.padhye.org (CMU), László Szekeres (Google)
Looking forward to submissions from the Security and the Software Engineering community!
Paper: futures.cs.utah.edu/papers/25ASE.pdf
Source: github.com/FuturesLab/GUIFuzzPlusPlus
Go test some GUIs!
Paper: futures.cs.utah.edu/papers/25ASE.pdf
Source: github.com/FuturesLab/GUIFuzzPlusPlus
Go test some GUIs!
#ASE25 #Workshop #CFP
#ASE25 #Workshop #CFP
www.youtube.com/watch?v=mrmo...
Going forward, I'll post a video 3 times a week. Please share the series with anyone who might benefit!
www.youtube.com/watch?v=mrmo...
Going forward, I'll post a video 3 times a week. Please share the series with anyone who might benefit!
Sounds impossible-but it's actually really simple. In fact, our measure of "correctness" called incoherence can be estimated (PAC guarantees).
arxiv.org/abs/2507.00057
Sounds impossible-but it's actually really simple. In fact, our measure of "correctness" called incoherence can be estimated (PAC guarantees).
arxiv.org/abs/2507.00057
"Constraining Fuzzing without Paying Too Much" by Miryung Kim
youtu.be/L90MBb6NLBE
"Are you sure you belong in academia?" by Will Wilson
youtu.be/qQGuQ_4V6WI
// @mboehme.bsky.social, László Szekeres, @rohan.padhye.org, @ruijiemeng.bsky.social
* From academia: Miryung Kim (Prof @ UCLA)
* From industry: Will Wilson (CEO and Co-Founder of @AntithesisHQ.bsky.social).
Stay tuned for recordings!
"Constraining Fuzzing without Paying Too Much" by Miryung Kim
youtu.be/L90MBb6NLBE
"Are you sure you belong in academia?" by Will Wilson
youtu.be/qQGuQ_4V6WI
// @mboehme.bsky.social, László Szekeres, @rohan.padhye.org, @ruijiemeng.bsky.social
Thanks to the organizers:
* @rohan.padhye.org
* @yannicnoller.bsky.social
* @ruijiemeng.bsky.social and
* László Szekeres (Google)
Thanks to the organizers:
* @rohan.padhye.org
* @yannicnoller.bsky.social
* @ruijiemeng.bsky.social and
* László Szekeres (Google)
Basically a long-term perspective on the field meant for both researchers and practitioners.
📝 ieeexplore.ieee.org/stamp/stamp....
Basically a long-term perspective on the field meant for both researchers and practitioners.
📝 ieeexplore.ieee.org/stamp/stamp....
The "Havoc Paradox" is about the relationship between byte-level fuzzer mutations and their effect on the inputs produced by generators for structured strings (e.g. XML/SQL). Can disruptive mutations be controlled? Should they be? Find out.
📄 dl.acm.org/doi/pdf/10.1...
The "Havoc Paradox" is about the relationship between byte-level fuzzer mutations and their effect on the inputs produced by generators for structured strings (e.g. XML/SQL). Can disruptive mutations be controlled? Should they be? Find out.
📄 dl.acm.org/doi/pdf/10.1...