2026 – 2029
Research project funded by the Deutsche Forschungsgemeinschaft (DFG) focused on foundational research in code-level security testing. SToCC analyzes the profile of security tests and design methods to automatically generate tests that discover unknown vulnerabilities in source code. SToCC also addresses the oracle problem in security testing and evaluates how test cases are impacted by changes to the production code. To achieve this, SToCC combines established software testing techniques with generative AI. Dr. Emanuele Iannone is the principal investigator.
Sept 2026 – Aug 2029
Research project funded by the Deutsche Forschungsgemeinschaft (DFG), focused on foundational research in automated detection and repair of design-level vulnerabilities. DeVulnIX investigates methods to address these issues by directly analyzing and transforming source code beyond traditional architectural and threat models. To achieve this, DeVulnIX combines established software engineering techniques with generative AI. Prof. Riccardo Scandariato is the principal investigator together with Prof. Uwe Zdun from Universität Wien (Austria).
Oct 2023 – Sept 2026
Research and Innovation Action funded by the European Union under the Horizon Europe framework. Sec4AI4Sec brings together 12 academic and industrial partners to increase the security of software systems through AI and advance the security of AI-enabled systems. Prof. Riccardo Scandariato serves as one of the project’s scientific leaders and leads the work package on automated vulnerability repair. Within the project, the SoftSec group released a curated dataset of reproducible software vulnerabilities, developed novel AI-driven techniques for automated vulnerability repair, and carried out empirical studies to evaluate human developers’ attitudes toward AI-generated security patches. Learn more: https://www.sec4ai4sec-project.eu/
Oct 2020 – Sept 2023
Research and Innovation Action funded by the EU under the H2020 framework. Prof. Dr-Ing. Riccardo Scandariato was the scientific leader and a workpackage leader. In collaboration with academic and industrial partnenrs we devised innovative techniques (also based on AI) to make modern software projects more secure. The focus is on open, multi-party software. In particular, he was working on reconstructing lightweigh models from code (e.g., micro-services) and on using such models for security analysis.