About SCSA Lab & Collaborations

Pioneering Source-Code Security Assessment & AI-Driven Software Reliability

The Source Code Security Assessment (SCSA) Research Lab unites academic rigor, global international partnerships, and industrial applications to discover software vulnerabilities, synthesize security patches, defend against malware, and automate software verification.

SCSA Research Group Official Branding Logo

Institutional Network

Academic & Industrial Partners

Global research partnerships driving joint security assessments, satellite testing, and vulnerability remediation.

324B+
Lines of Code Analyzed
Indexed on Hadoop MapReduce
152,823+
Open-Source Repos Scanned
SQVDT Vulnerability Engine
50+
Researchers & Students Mentored
PhD, MS & BS Engineering Graduates
5
Global Academic & Industry Partners
COMSATS, Tsinghua, SnT, SES, KFUPM
15+
High-Impact Publications
Applied Soft Computing, IEEE, IET

Core Principles

Research Pillars & Technological Capabilities

Source-Level Vulnerability Intelligence

Indexing, matching, and tracing software vulnerabilities through AST fingerprints, patch diff signatures, and multi-terabyte code similarity lookup.

AI & LLM-Driven Program Repair

Leveraging Large Language Models, in-context learning, and Graph Neural Networks (GNN) for automated security patch synthesis and refactoring.

Automated Verification & Software Testing

Search-based test data generation, model-based satellite CPS testing, BDD test smell detection, and log-based regression test slicing.

Obfuscation & Malware Ensemble Defense

Token-based obfuscated code clone identification and advanced ensemble machine learning frameworks defending Windows, Android, and IoT systems.

Lab Evolution & Story

Research Journey & Key Milestones

Explore how SCSA Lab evolved from big-data source analytics at Tsinghua University to satellite CPS testing at SnT Luxembourg and AI-driven program repair at COMSATS.

Tsinghua Era Tsinghua University — Key Lab of Info System Security (Beijing, China)

Foundations & Distributed Code Intelligence

Engineered distributed static code analysis engines indexing over 324 billion lines of code on Hadoop MapReduce and scanning 152k+ open-source repositories.

  • Built IBFET — MapReduce inverted token index scaling clone detection across 324B+ LOC.
  • Developed SQVDT — Multi-terabyte C/C++ static vulnerability fingerprinting platform.
  • Pioneered DroidSD — Obfuscated Android clone detection across 30,500 application APKs.
  • Conferred PhD from Tsinghua University and published in IEEE ICST, IET InfoSec, and JISE.
LOC: 324B+
REPOS: 152K+
PAPERS: 5+

Team & Networks

Collaborators & Research Personnel

Dr. Junaid Akram

Dr. Junaid Akram

Lab Director
Lab Director & Principal Investigator

Assistant Professor & HEC-Approved PhD Supervisor leading SCSA Lab. Former Postdoc at SnT Luxembourg & SES Satellites. PhD from Tsinghua University.

Focus: Source Code Security, Vulnerability Repair, Code Clone Detection, Software Testing
Dr. Danish Vasan

Dr. Danish Vasan

International Collaborator
Senior Co-Investigator & International Collaborator

Senior collaborator & co-author on advanced ensemble frameworks defending Windows, Android, and IoT malware systems (Applied Soft Computing 2025).

Focus: Obfuscated Malware Detection, Ensemble Learning, IoT & Android Security
Dr. Majid Mumtaz

Dr. Majid Mumtaz

Academic Partner
Co-Investigator & Academic Partner

Academic partner collaborating on source-code security assessment, empirical software engineering, and joint student development.

Focus: Software Security & System Architecture
Prof. Ping Luo

Prof. Ping Luo

Tsinghua Advisor
Academic Mentor & Research Collaborator

Key collaborator on large-scale vulnerability detection platforms (SQVDT) and token-based clone analysis across multi-billion LOC repositories.

Focus: Information Security & Program Analysis
D

Dr. Mohammad Hammoudeh

Journal Co-Author
Research Collaborator

Collaborating researcher co-authoring high-impact cybersecurity and malware defense studies in top-tier journals.

Focus: Cybersecurity, IoT Security & Ensemble Learning
D

Dr. Adel F. Ahmed

Journal Co-Author
Research Collaborator

Collaborator on ensemble frameworks for obfuscated malware identification and threat intelligence.

Focus: Machine Learning & Software Security
MM

Mahzaib Mukhtar

FA23-RCS-005
MS Computer Science

Thesis Topic: "Automated Search Based Test Data Generation for Complex Systems using UML Models"

Research Focus: Software Testing & Search-Based Algorithms
Active MS Thesis Research
ZUA

Zain Ul Abdeen

FA23-RCS-011
MS Computer Science

Thesis Topic: "LLM Based Software Vulnerability Patch Recommendation System"

Research Focus: LLM Fine-Tuning & Program Repair
Active MS Thesis Research
MO

Muhammad Orangzaib

FA24-RCS-018
MS Computer Science

Thesis Topic: "In-context Learning of Software Vulnerability Detection Using LLMs"

Research Focus: In-Context Prompt Engineering & Security
Active MS Thesis Research
AN

Ahsan Nisar

FA24-RCS-017
MS Computer Science

Thesis Topic: "Empowering a Graph Neural Network for Feature Envy Detection and Refactoring"

Research Focus: Graph Neural Networks & Code Smells
Active MS Thesis Research
MH

Muhammad Haris

SP25-RCS-012
MS Computer Science

Thesis Topic: "AICodeSummarizer: Optimizing Code Comment Generation through AST and CFG Structural Analysis"

Research Focus: Code Summarization & AST/CFG Analysis
Active MS Thesis Research
FI

Farina Iqbal

SP25-RCS-004
MS Computer Science

Thesis Topic: "Automated Test Smell Detection and Recommendation in BDD Specifications"

Research Focus: BDD Specifications & Test Quality
Active MS Thesis Research
HB

Hafsa Butt

SP25-RCS-008
MS Computer Science

Thesis Topic: "LLM-based Semantic-driven Approach to Detect Type-4 Code Clones"

Research Focus: Semantic Code Clones & Deep Learning
Active MS Thesis Research

MegiLance

BS Software Engineering · 2022–2026

A supervised final-year engineering development project combining a full-stack freelancing marketplace with AI decision assistance and blockchain payment escrow.

Student Team: Ghulam Mujtaba, Muhammad Waqar Ul Mulk

Software Vulnerability Detection using LLM Model

BS Software Engineering · 2023–2027 (Session SP23)

A running research project leveraging Large Language Models (LLMs) to detect complex software vulnerabilities in source code through fine-tuning and AST-based prompt engineering.

Student Team: Syed Muhammad Irtaza Shahid, Muhammad Waleed, Muhammad Muneeb Azhar

Token-Based Semantic Code Clone Detection

BS Software Engineering · 2023–2027 (Session SP23)

A running software security project building a scalable token-based semantic code clone detection platform to capture Type-3 and Type-4 clones across large open-source repositories.

Student Team: Ali Muhammad, Ali Murtaza, Hafiz Muhammad Shams ul Huda

LLM-based Software Vulnerability Patch Optimizer

BS Software Engineering · 2023–2027 (Session FA23)

A running research project developing an automated patch optimization engine powered by LLMs that synthesizes and verifies security patch suggestions for vulnerable code snippets.

Student Team: Urwa Kamal, Maha Khawar, Laiba Amir

Mak Sue Sun

Fall 2020 Alumni
Ernst & Young Advisory Services Sdn. Bhd.

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Li SiHan

Fall 2020 Alumni
Maxwell Cloud Technology Sdn. Bhd.

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Lan YuLin

Fall 2020 Alumni
China ASEAN Information Harbor

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Chen Yu

Spring 2021 Alumni
Beijing Megvii Corporation, Ltd.

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Gao HongXu

Spring 2021 Alumni
Returnstar Interactive Technology

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Guo Yuhu

Spring 2021 Alumni
Zoho Technology Co., Hangzhou

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.

Liang TianWen

Spring 2021 Alumni
Meiya Pico, Xiamen Software Park

Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.