@inproceedings{shen2026democratizing,title={Democratizing False Positives Filtering Through Learning Assisted Reasoning},author={Shen, Mingjie and Tanksalkar, Sai Ritvik and Hauser, Christophe and Machiry, Aravind},booktitle={Proceedings of the 29th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2026), to appear},year={2026},}
In this experience paper, we report on a large-scale empirical study of Static Application Security Testing (SAST) in Open-Source Embedded Software (EMBOSS) repositories. We apply CodeQL to 258 EMBOSS projects, characterize the defects it reports, and share the lessons learned about using SAST on large real-world embedded codebases.
@article{shen2025codeql,author={Shen, Mingjie and Pillai, Akul Abhilash and Yuan, Brian A. and Davis, James C. and Machiry, Aravind},title={Finding 709 Defects in 258 Projects: An Experience Report on Applying
CodeQL to Open-Source Embedded Software (Experience Paper)},journal={Proc. {ACM} Softw. Eng.},volume={2},number={{ISSTA}},pages={1077--1100},year={2025},doi={10.1145/3728923},}
@inproceedings{hashmat2024insights,author={Hashmat, Fabiha and Aljaali, Zeyad Alwaleed and Shen, Mingjie and Machiry, Aravind},title={Insights from Running 24 Static Analysis Tools on Open Source Software Repositories},booktitle={International Conference on Information Systems Security (ICISS 2024)},series={Lecture Notes in Computer Science},volume={15416},pages={225--245},publisher={Springer},year={2024},doi={10.1007/978-3-031-80020-7_13},}
@inproceedings{shen2023layering,author={Shen, Mingjie and Davis, James C. and Machiry, Aravind},editor={Egger, Bernhard and Lee, Dongyoon},title={Towards Automated Identification of Layering Violations in Embedded
Applications {(WIP)}},booktitle={Proceedings of the 24th {ACM} {SIGPLAN/SIGBED} International Conference
on Languages, Compilers, and Tools for Embedded Systems ({LCTES} 2023)},pages={143--147},publisher={{ACM}},year={2023},doi={10.1145/3589610.3596271},}