Source-Level Vulnerability Intelligence
Indexing, matching, and tracing software vulnerabilities through AST fingerprints, patch diff signatures, and multi-terabyte code similarity lookup.
About SCSA Lab & Collaborations
The Source Code Security Assessment (SCSA) Research Lab unites academic rigor, global international partnerships, and industrial applications to discover software vulnerabilities, synthesize security patches, defend against malware, and automate software verification.

Institutional Network
Global research partnerships driving joint security assessments, satellite testing, and vulnerability remediation.
Core Principles
Indexing, matching, and tracing software vulnerabilities through AST fingerprints, patch diff signatures, and multi-terabyte code similarity lookup.
Leveraging Large Language Models, in-context learning, and Graph Neural Networks (GNN) for automated security patch synthesis and refactoring.
Search-based test data generation, model-based satellite CPS testing, BDD test smell detection, and log-based regression test slicing.
Token-based obfuscated code clone identification and advanced ensemble machine learning frameworks defending Windows, Android, and IoT systems.
Lab Evolution & Story
Explore how SCSA Lab evolved from big-data source analytics at Tsinghua University to satellite CPS testing at SnT Luxembourg and AI-driven program repair at COMSATS.
Engineered distributed static code analysis engines indexing over 324 billion lines of code on Hadoop MapReduce and scanning 152k+ open-source repositories.
Team & Networks

Assistant Professor & HEC-Approved PhD Supervisor leading SCSA Lab. Former Postdoc at SnT Luxembourg & SES Satellites. PhD from Tsinghua University.

Senior collaborator & co-author on advanced ensemble frameworks defending Windows, Android, and IoT malware systems (Applied Soft Computing 2025).

Academic partner collaborating on source-code security assessment, empirical software engineering, and joint student development.

Key collaborator on large-scale vulnerability detection platforms (SQVDT) and token-based clone analysis across multi-billion LOC repositories.
Collaborating researcher co-authoring high-impact cybersecurity and malware defense studies in top-tier journals.
Collaborator on ensemble frameworks for obfuscated malware identification and threat intelligence.
Thesis Topic: "Automated Search Based Test Data Generation for Complex Systems using UML Models"
Thesis Topic: "LLM Based Software Vulnerability Patch Recommendation System"
Thesis Topic: "In-context Learning of Software Vulnerability Detection Using LLMs"
Thesis Topic: "Empowering a Graph Neural Network for Feature Envy Detection and Refactoring"
Thesis Topic: "AICodeSummarizer: Optimizing Code Comment Generation through AST and CFG Structural Analysis"
Thesis Topic: "Automated Test Smell Detection and Recommendation in BDD Specifications"
Thesis Topic: "LLM-based Semantic-driven Approach to Detect Type-4 Code Clones"
A supervised final-year engineering development project combining a full-stack freelancing marketplace with AI decision assistance and blockchain payment escrow.
A running research project leveraging Large Language Models (LLMs) to detect complex software vulnerabilities in source code through fine-tuning and AST-based prompt engineering.
A running software security project building a scalable token-based semantic code clone detection platform to capture Type-3 and Type-4 clones across large open-source repositories.
A running research project developing an automated patch optimization engine powered by LLMs that synthesizes and verifies security patch suggestions for vulnerable code snippets.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.
Successfully transitioned into top technology, cybersecurity, and consulting firms following SCSA Lab supervision.