5 papers
Project Rachel: Can an AI Become a Scholarly Author?
Martin Monperrus, Benoit Baudry, Clément Vidal
This paper documents Project Rachel, an action research study that created and tracked a complete AI academic identity named Rachel So. Through careful publication of AI-generated…
FLAMES: Fine-tuning LLMs to Synthesize Invariants for Smart Contract Security
Mojtaba Eshghie, Gabriele Morello, Matteo Lauretano +2
Smart contract vulnerabilities cost billions of dollars annually, yet existing automated analysis tools fail to generate deployable defenses. We present FLAMES, a novel automated a…
Maven-Lockfile: High Integrity Rebuild of Past Java Releases
Larissa Schmid, Elias Lundell, Yogya Gamage +2
Modern software projects depend on many third-party libraries, complicating reproducible and secure builds. Several package managers address this with the generation of a lockfile…
GoLeash: Mitigating Golang Software Supply Chain Attacks with Runtime Policy Enforcement
Carmine Cesarano, Martin Monperrus, Roberto Natella
Modern software supply chain attacks consist of introducing new, malicious capabilities into trusted third-party software components, in order to propagate to a victim through a pa…
Causes and Canonicalization of Unreproducible Builds in Java
Aman Sharma, Benoit Baudry, Martin Monperrus
The increasing complexity of software supply chains and the rise of supply chain attacks have elevated concerns around software integrity. Users and stakeholders face significant c…