Research interests
I work on software security problems that sit at the intersection of software ecosystems, automation, transparency, and empirical analysis.
Software Supply Chain Security
Problem statement
Modern software is assembled through interconnected ecosystems, automation platforms, and third-party artifacts. This creates security risks that are difficult to observe, attribute, and prioritize.
Current effort
I study how to identify, model, and assess risks in software supply chains, with emphasis on CI/CD automation, software metadata, and ecosystem-level security practices.
Reproducible Builds
Problem statement
Software artifacts often cannot be rebuilt bit-for-bit from their source and declared build environment, which weakens transparency and independent verification.
Current effort
I investigate reproducible packaging practices in open-source ecosystems and the technical or social factors that prevent reliable rebuilds.
Dependency Bloating and Software Debloating
Problem statement
Software often ships as a black box containing or referencing more resources than it actually needs, increasing maintenance and security exposure.
Current effort
I explore dependency modeling and debloating strategies that help developers understand what is included in software artifacts and reduce unnecessary attack surface.
AI-Assisted Security Analysis
Problem statement
Security analysts need scalable techniques to inspect code, configurations, and distributed systems without losing context or explainability.
Current effort
I study how AI-based methods can support vulnerability analysis, code understanding, and attack detection in software systems.
Collaborations
I am open to collaborations on software supply chain security, reproducible builds, dependency analysis, and adjacent software security topics.
Start a conversation