5 citations · 14 across the 8 of their papers we have counts for
14 papers
A Large-Scale Exploit Instrumentation Study of AI/ML Supply Chain Attacks in Hugging Face Models
Beatrice Casey, Joanna C. S. Santos, Mehdi Mirakhorli
The development of machine learning (ML) techniques has led to ample opportunities for developers to develop and deploy their own models. Hugging Face serves as an open source plat…
Lessons from the Use of Natural Language Inference (NLI) in Requirements Engineering Tasks
Mohamad Fazelnia, Viktoria Koscinski, Spencer Herzog +1
We investigate the use of Natural Language Inference (NLI) in automating requirements engineering tasks. In particular, we focus on three tasks: requirements classification, identi…
IPSynth: Interprocedural Program Synthesis for Software Security Implementation
Ali Shokri, Ibrahim Jameel Mujhid, Mehdi Mirakhorli
To implement important quality attributes of software such as architectural security tactics, developers incorporate API of software frameworks, as building blocks, to avoid re-inv…
A Landscape Study of Open Source and Proprietary Tools for Software Bill of Materials (SBOM)
Mehdi Mirakhorli, Derek Garcia, Schuyler Dillon +5
Modern software applications heavily rely on diverse third-party components, libraries, and frameworks sourced from various vendors and open source repositories, presenting a compl…
Seneca: Taint-Based Call Graph Construction for Java Object Deserialization
Joanna C. S. Santos, Mehdi Mirakhorli, Ali Shokri
Object serialization and deserialization are widely used for storing and preserving objects in files, memory, or database as well as for transporting them across machines, enabling…
A Novel Approach to Identify Security Controls in Source Code
Ahmet Okutan, Ali Shokri, Viktoria Koscinski +2
Secure by Design has become the mainstream development approach ensuring that software systems are not vulnerable to cyberattacks. Architectural security controls need to be carefu…