About SSA Lab & Collaborations

Pioneering Source-Code Security Assessment & AI-Driven Software Reliability

The Software Security Assessment (SSA) Research Lab unites academic rigor, global international partnerships, and industrial applications to discover software vulnerabilities, synthesize security patches, defend against malware, and automate software verification.

0B+
Lines of Code Analyzed
Indexed on Hadoop MapReduce
0+
Open-Source Repos Scanned
SQVDT Vulnerability Engine
0+
High-Impact Publications
Applied Soft Computing, IEEE, IET
0+
Researchers & Students Mentored
PhD, MS & BS Engineering Graduates

Core Principles

Research Pillars & Technological Capabilities

Source-Level Vulnerability Intelligence

Source-Level Vulnerability Intelligence

Indexing, matching, and tracing software vulnerabilities through AST fingerprints, patch diff signatures, and multi-terabyte code similarity lookup.

AI & LLM-Driven Program Repair

AI & LLM-Driven Program Repair

Leveraging Large Language Models, in-context learning, and Graph Neural Networks (GNN) for automated security patch synthesis and refactoring.

Automated Verification & Software Testing

Automated Verification & Software Testing

Search-based test data generation, model-based satellite CPS testing, BDD test smell detection, and log-based regression test slicing.

Obfuscation & Malware Ensemble Defense

Obfuscation & Malware Ensemble Defense

Token-based obfuscated code clone identification and advanced ensemble machine learning frameworks defending Windows, Android, and IoT systems.

Lab Evolution & Story

Research Journey & Key Milestones

Explore how SSA Lab evolved from big-data source analytics at Tsinghua University to satellite CPS testing at SnT Luxembourg and AI-driven program repair at COMSATS.

Tsinghua Era Tsinghua University — Key Lab of Info System Security (Beijing, China)

Foundations & Distributed Code Intelligence

Engineered distributed static code analysis engines indexing over 324 billion lines of code on Hadoop MapReduce and scanning 152k+ open-source repositories.

  • Built IBFET — MapReduce inverted token index scaling clone detection across 324B+ LOC.
  • Developed SQVDT — Multi-terabyte C/C++ static vulnerability fingerprinting platform.
  • Pioneered DroidSD — Obfuscated Android clone detection across 30,500 application APKs.
  • Conferred PhD from Tsinghua University and published in IEEE ICST, IET InfoSec, and JISE.
LOC: 324B+
REPOS: 152K+
PAPERS: 5+

Academic & Research Partner Universities

COMSATS University Islamabad
Tsinghua University
SnT, University of Luxembourg
SES Satellites
King Fahd University of Petroleum & Minerals

Team & Networks

Research Personnel & Global Collaborators

Explore full directory
Faculty & Co-Investigators 3D Icon

Faculty & Co-Investigators (6)

International academic partnerships spanning COMSATS Lahore, Tsinghua University, SnT Luxembourg, and KFUPM.

View Faculty & Co-Investigators
Postgraduate MS & PhD Theses 3D Icon

Postgraduate MS & PhD Theses (7)

Active Master of Science (MS CS) researchers working on LLM vulnerability detection, program repair, and GNNs.

View MS & PhD Researchers
Alumni Placements 3D Icon

Alumni Placements (7)

Graduates transitioning into top global technology advisories, cybersecurity firms, and enterprise software teams.

View Supervised Alumni