activity
20182024
most citedA Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM)

5 citations · 14 across the 8 of their papers we have counts for

collaborators

14 papers

cs.CR2024

A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models

Beatrice Casey, Joanna C. S. Santos, Mehdi Mirakhorli

The development of machine learning (ML) techniques has led to ample opportunities for developers to develop and deploy their own models. Hugging Face serves as an open source plat…

cs.SE2024

Lessons from the Use of Natural Language Inference (NLI) in Requirements Engineering Tasks

Mohamad Fazelnia, Viktoria Koscinski, Spencer Herzog +1

We investigate the use of Natural Language Inference (NLI) in automating requirements engineering tasks. In particular, we focus on three tasks: requirements classification, identi…

cs.SE2024

IPSynth: Interprocedural Program Synthesis for Software Security Implementation

Ali Shokri, Ibrahim Jameel Mujhid, Mehdi Mirakhorli

To implement important quality attributes of software such as architectural security tactics, developers incorporate API of software frameworks, as building blocks, to avoid re-inv…

cs.SE20245 cited

A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM)

Mehdi Mirakhorli, Derek Garcia, Schuyler Dillon +5

Modern software applications heavily rely on diverse third-party components, libraries, and frameworks sourced from various vendors and open source repositories, presenting a compl…

cs.SE2023

Seneca: Taint-Based Call Graph Construction for Java Object Deserialization

Joanna C. S. Santos, Mehdi Mirakhorli, Ali Shokri

Object serialization and deserialization are widely used for storing and preserving objects in files, memory, or database as well as for transporting them across machines, enabling…

cs.SE2023

A Novel Approach to Identify Security Controls in Source Code

Ahmet Okutan, Ali Shokri, Viktoria Koscinski +2

Secure by Design has become the mainstream development approach ensuring that software systems are not vulnerable to cyberattacks. Architectural security controls need to be carefu…