Source Artifact Ingestion
Repositories, CVE benchmarks, smart contracts, APKs & patch histories
Core Pillars

Source-level assessment methods for identifying, understanding, and mitigating software vulnerabilities.

Scalable techniques and tools that trace vulnerable code through patches, fingerprints, and code similarity.

Search-based testing, automated test-data generation, regression testing, and test-smell detection.

Static and learning-based analysis of Android and cross-architecture malware at source-code level.

Large-scale detection of exact, near-miss, and obfuscated code clones across software systems.

Understanding how code, vulnerabilities, and reusable components propagate between systems.
Research workflow
Repositories, CVE benchmarks, smart contracts, APKs & patch histories
Control/data flow graphs, clone detection & obfuscation normalization
Isolating security flaws, malware behaviors & test smells (SQVDT, VCIPR)
Precision/recall evaluation, CWE ground truths & patch verification
Q1 journal papers, open-source tools deployment & student supervision
Peer-Reviewed Literature & Tools
All empirical research findings, platforms (SQVDT, VCIPR, DroidSD, DroidMD), and datasets are published with full DOI links and citations in our Publications directory.