Projects

DevSSATD: Developer-Centred Management of Self-Admitted Technical Debt for Security

2026 – 2029

Technical Debt (TD) is a long-standing challenge in software development that can hinder system maintenance and evolution while also introducing exploitable weaknesses and vulnerabilities. Yet, the security implications of TD remain largely underexplored. This project investigates how security-related Self-Admitted Technical Debt (SATD) can support the timely identification, prioritisation, and remediation of software vulnerabilities. By mining Open Source Software repositories and conducting empirical studies with developers, we will study the interplay between SATD and software vulnerabilities and translate the resulting evidence into novel AI-enhanced methods and tools for automatically identifying, assessing, and remediating security-related SATD.

SToCC: Security Testing of Code Components

2026 – 2029

Research project funded by the Deutsche Forschungsgemeinschaft (DFG) focused on foundational research in code-level security testing. SToCC analyzes the profile of security tests and design methods to automatically generate tests that discover unknown vulnerabilities in source code. SToCC also addresses the oracle problem in security testing and evaluates how test cases are impacted by changes to the production code. To achieve this, SToCC combines established software testing techniques with generative AI. Dr. Emanuele Iannone is the principal investigator.

DeVulnIX

Sept 2026 – Aug 2029

Research project funded by the Deutsche Forschungsgemeinschaft (DFG), focused on foundational research in automated detection and repair of design-level vulnerabilities. DeVulnIX investigates methods to address these issues by directly analyzing and transforming source code beyond traditional architectural and threat models. To achieve this, DeVulnIX combines established software engineering techniques with generative AI. Prof. Riccardo Scandariato is the principal investigator together with Prof. Uwe Zdun from Universität Wien (Austria).

KiThreat: Threat and Risk Assessment Methods for Generative AI-Based Software

June 2025 – November 2025

KiThreat investigated methods for systematically identifying, assessing, and prioritizing security threats in software systems incorporating Generative Artificial Intelligence (GenAI). The project focused particularly on threats affecting the architectural components and interactions of GenAI-based software systems.

As part of the project, existing Threat and Risk Assessment (TaRA) methods from the literature were evaluated with respect to their suitability for GenAI-based systems. The assessment considered aspects such as threat coverage, level of granularity, and the ability to identify domain-specific security threats.

The methods were evaluated through an industrial case study provided by CREATUM GmbH. TUHH led the threat and risk assessment activities in close cooperation with CREATUM, with the broader objective of establishing a systematic approach for analyzing and prioritizing security threats in industrial GenAI-enabled software.

Sec4AI4Sec: Cybersecurity for AI-Augmented Systems

Oct 2023 – Sept 2026

Research and Innovation Action funded by the European Union under the Horizon Europe framework. Sec4AI4Sec brings together 12 academic and industrial partners to increase the security of software systems through AI and advance the security of AI-enabled systems. Prof. Riccardo Scandariato serves as one of the project’s scientific leaders and leads the work package on automated vulnerability repair. Within the project, the SoftSec group released a curated dataset of reproducible software vulnerabilities, developed novel AI-driven techniques for automated vulnerability repair, and carried out empirical studies to evaluate human developers’ attitudes toward AI-generated security patches. Learn more: https://www.sec4ai4sec-project.eu/

AssureMOSS: Assurance and Certification in Secure Multi-party Open Software and Services

Oct 2020 – Sept 2023

Research and Innovation Action funded by the EU under the H2020 framework. Prof. Dr-Ing. Riccardo Scandariato was the scientific leader and a workpackage leader. In collaboration with academic and industrial partnenrs we devised innovative techniques (also based on AI) to make modern software projects more secure. The focus is on open, multi-party software. In particular, he was working on reconstructing lightweigh models from code (e.g., micro-services) and on using such models for security analysis.