Mingjie Shen

PhD student @ Purdue ECE

prof_pic.jpg

I am a PhD student in the Elmore Family School of Electrical and Computer Engineering at Purdue University, advised by Prof. Aravind Machiry. Before Purdue, I received my Bachelor’s degree in Computer Science and Technology from Nanjing University.

My research interests span software security, static program analysis, and AI for software engineering, with a focus on making static analysis more effective for large, real-world software systems. I study how static analysis tools are used in practice and why they fall short on large codebases (ISSTA 2025, ICISS 2024). Motivated by these practical challenges, I explore how AI agents can improve the precision, adaptability, and automation of static analysis. My recent work includes using tool-augmented LLM agents to filter false positives from SAST tools (RAID 2026), generating repository-specific CodeQL queries for vulnerability discovery, and learning symbolic program-transformation rules to automate large-scale collateral evolution.

My research has practical impact beyond papers. Applying static analysis to over 250 open-source embedded projects uncovered more than 700 defects, over half of which were confirmed by maintainers. I submitted patches for many of them, and over 100 of those patches have been merged upstream into projects including Apache NuttX, Contiki-NG, Mbed OS, RIOT, and SDL; maintainers fixed further reported bugs themselves.

I am currently looking for full-time positions in industry. If you think I would be a good fit for your team, please get in touch by email.

news

Jul 30, 2026 Our paper “Democratizing False Positives Filtering Through Learning Assisted Reasoning” has been accepted to RAID 2026.
Jul 01, 2025 Our experience paper on applying CodeQL to open-source embedded software, which found 709 defects across 258 projects, appears at ISSTA 2025.

selected publications

  1. Democratizing False Positives Filtering Through Learning Assisted Reasoning
    Mingjie Shen, Sai Ritvik Tanksalkar, Christophe Hauser, and Aravind Machiry
    In Proceedings of the 29th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2026), to appear, 2026
  2. Finding 709 Defects in 258 Projects: An Experience Report on Applying CodeQL to Open-Source Embedded Software (Experience Paper)
    Mingjie Shen, Akul Abhilash Pillai, Brian A. Yuan, James C. Davis, and Aravind Machiry
    Proc. ACM Softw. Eng., 2025
  3. Insights from Running 24 Static Analysis Tools on Open Source Software Repositories
    Fabiha Hashmat, Zeyad Alwaleed Aljaali, Mingjie Shen, and Aravind Machiry
    In International Conference on Information Systems Security (ICISS 2024), 2024
  4. Towards Automated Identification of Layering Violations in Embedded Applications (WIP)
    Mingjie Shen, James C. Davis, and Aravind Machiry
    In Proceedings of the 24th ACM SIGPLAN/SIGBED International Conference on Languages, Compilers, and Tools for Embedded Systems (LCTES 2023), 2023