Making complex software easier to analyse and secure
My research combines program analysis, runtime evidence, machine learning, and large language models to understand software behavior and automate security-relevant tasks. I work across mobile applications, complex software ecosystems, embedded systems, and Internet of Things devices, with a particular focus on the places where conventional analysis remains incomplete.
The overarching objective is to make automated analysis more comprehensive, technically grounded, and useful in practice. This involves improving analysis soundness, localizing security-relevant behavior, studying the limits of AI-assisted techniques, and translating research results into methods that can support analysts, developers, and operational security teams.
Evidence firstClaims are grounded in executable behavior, empirical data, and reproducible analysis.
Hybrid by designStatic, dynamic, and learned techniques are combined according to their strengths.
Practical impactMethods are shaped by security-relevant questions and operational constraints.