Publications
Here are the publications to which I have contributed. To see them organized approximately by project, see here.
Peer-reviewed conference papers, full and short
- AutoSOUP: Safety-Oriented Unit Proof Generation for Component-level Memory-Safety Verification.
P.C. Amusuo, R. Calvo, D. Anandayuvaraj, T. Le Lievre, K. Kolyakov, E. Jorgensen, A. Machiry, and Davis.
Proceedings of the 33rd ACM Conference on Computer and Communications Security (CCS) 2026.
- Do Unit Proofs Work? An Empirical Study of Compositional Bounded Model Checking for Memory Safety Verification.
P.C. Amusuo, O. Cochell, T. Le Lievre, P.V. Patil, A. Machiry, and Davis.
Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE) 2026.
- LadderSym: A Multimodal Interleaved Transformer for Music Practice Error Detection.
B.S.H. Chou, P. Jajal, N.J. Eliopoulos, Davis, G.K. Thiruvathukal, K.Y.J. Yun, and Y.H. Lu.
Proceedings of the International Conference on Learning Representations (ICLR) 2026.
- Context-Aware Trust Verification for Identity-Based Software Signing.
C. Okafor, Davis, and S. Torres-Arias.
Proceedings of the 41st IEEE/ACM International Conference on Automated Software Engineering (ASE) 2026.
- Why Johnny Adopts Identity-Based Software Signing: A Usability Case Study of Sigstore.
K.G. Kalu, S. Okorafor, T. Singla, S. Chen, S. Torres-Arias, and Davis.
Proceedings of the 35th USENIX Security Symposium (SECURITY) 2026.
- Regular Expression Denial of Service Induced by Backreferences.
arXiv 2026.
- AdaPerceiver: Transformers with Adaptive Width, Depth, and Tokens.
P. Jajal, N.J. Eliopoulos, B.S.H. Chou, G.K. Thiruvathukal, Y.H. Lu, and Davis.
The IEEE/CVF Conference on Computer Vision and Pattern Recognition 2026 – Findings Track (CVPR-Findings) 2026.
- Inference-Time Alignment of Diffusion Models via Evolutionary Algorithms.
P. Jajal, N. Eliopoulos, B.S.H. Chou, G.K. Thiruvathukal, Davis, and Y.H. Lu.
The IEEE/CVF Conference on Computer Vision and Pattern Recognition 2026 – Findings Track (CVPR-Findings) 2026.
- Anti-Phishing Training (Still) Does Not Work: A Large-Scale Reproduction of Phishing Training Inefficacy Grounded in the NIST Phish Scale.
A. Rozema and Davis.
Proceedings of the ACM Web Conference (WWW) 2026.
- ConfuGuard: Using Metadata to Detect Active and Stealthy Package Confusion Attacks Accurately and at Scale.
Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE) 2026.
- Learning From Software Failures: A Case Study at a National Space Research Center.
D. Anandayuvaraj, T. Singla, Z. Hammadeh, A. Lund, A. Holloway, and Davis.
Proceedings of the 48th IEEE/ACM International Conference on Software Engineering (ICSE) 2026.
- PickleBall: Secure Deserialization of Pickle-based Machine Learning Models.
A. Kellas, N. Christou, W. Jiang, P. Li, L. Simon, Y. David, V. Kemerlis, Davis, and J. Yang.
Proceedings of the 32nd ACM Conference on Computer and Communications Security (CCS) 2025.
- ZTD-JAVA: Mitigating Software Supply Chain Vulnerabilities via Zero-Trust Dependencies.
P.C. Amusuo, K.A. Robinson, T. Singla, H. Peng, A. Machiry, S. Torres-Arias, L. Simon, and Davis.
Proceedings of the ACM/IEEE 47th International Conference on Software Engineering (ICSE) 2025.
- Detecting Music Performance Errors with Transformers.
B.S.H. Chou, P. Jajal, N.J. Eliopoulos, T. Nadolsky, C.Y. Yang, N. Ravi, Davis, K.Y.J. Yun, and Y.H. Lu.
Proceedings of the 39th Annual AAAI Conference on Artificial Intelligence (AAAI) 2025.
- LEMIX: Enabling Testing of Embedded Applications as Linux Applications.
S.R. Tanksalkar, S. Muralee, D.M.S.H. Danduri, P. Amusuo, A. Bianchi, Davis, and A. Machiry.
Proceedings of the 34th USENIX Security Symposium (SECURITY) 2025.
- An Industry Interview Study of Software Signing for Supply Chain Security.
K. Kalu, T. Singla, C. Okafor, S. Torres-Arias, and Davis.
Proceedings of the 34th USENIX Security Symposium (SECURITY) 2025.
- Usage and Effectiveness of Static Analysis in Open-Source Embedded Software: CodeQL Finds Hundreds of Defects.
M. Shen, A. Pillai, B.A. Yuan, Davis, and A. Machiry.
Proceedings of the 34th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA) 2025.
- SoK: A Literature and Engineering Review of Regular Expression Denial of Service.
Proceedings of the 20th ACM ASIA Conference on Computer and Communications Security (AsiaCCS) 2025.
- Pruning One More Token is Enough: Leveraging Latency-Workload Non-Linearities for Vision Transformers on the Edge.
N. Eliopoulos, P. Jajal, Davis, G. Liu, G.K. Thiruvathukal, and Y.H. Lu.
Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV) 2025.
- Token Turing Machines are Efficient Vision Models.
P. Jajal, N. Eliopoulos, B. Chou, G.K. Thiruvathukal, Davis, and Y.H. Lu.
Proceedings of the IEEE/CVF Winter Conference on Applications of Computer Vision (WACV) 2025.
- FAIL: Analyzing Software Failures from the News Using LLMs.
D. Anandayuvaraj, M. Campbell, A. Tewari, and Davis.
Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering (ASE) 2024.
- Interoperability in Deep Learning: A User Survey and Failure Analysis of ONNX Model Converters.
P. Jajal, W. Jiang, A. Tewari, E. Kocinare, J. Woo, A. Sarraf, Y.H. Lu, G.K. Thiruvathukal, and Davis.
Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA) 2024.
- What do we know about Hugging Face? A systematic literature review and quantitative validation of qualitative claims.
J. Jones, W. Jiang, N. Synovic, G.K. Thiruvathukal, and Davis.
Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) 2024.
- An Exploratory Mixed-Methods Study on General Data Protection Regulation (GDPR) Compliance in Open-Source Software.
L. Franke, H. Liang, S. Farzanehpour, A. Brantly, Davis, and C. Brown.
Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM) 2024.
- On the Contents and Utility of IoT Cybersecurity Guidelines.
J. Chen, D. Anandayuvaraj, Davis, and S. Rahaman.
Proceedings of the ACM on Software Engineering (PACMSE), Issue FSE 2024 (FSE) 2024.
- Signing in Four Public Software Package Registries: Quantity, Quality, and Influencing Factors.
T.R. Schorlemmer, K.G. Kalu, L. Chigges, K.M. Ko, E.A.M.A. Ishgair, S. Bagchi, S. Torres-Arias, and Davis.
Proceedings of the 45th IEEE Symposium on Security and Privacy (S&P) 2024.
- An Interview Study on Third-Party Cyber Threat Hunting Processes in the U.S. Department of Homeland Security.
W. Maxam and Davis.
Proceedings of the 33rd USENIX Security Symposium (SECURITY) 2024.
- PeaTMOSS: A Dataset and Initial Analysis of Pre-Trained Models in Open-Source Software.
W. Jiang, J. Yasmin, J. Jones, N. Synovic, J. Kuo, N. Bielanski, Y. Tian, G.K. Thiruvathukal, and Davis.
Proceedings of the 21st Annual Conference on Mining Software Repositories (MSR) 2024.
- An Empirical Study of Pre-Trained Model Reuse in the Hugging Face Deep Learning Model Registry.
W. Jiang, N. Synovic, M. Hyatt, T.R. Schorlemmer, R. Sethi, Y.H. Lu, G.K. Thiruvathukal, and Davis.
Proceedings of the ACM/IEEE 45th International Conference on Software Engineering (ICSE) 2023.
- Systematically Detecting Packet Validation Vulnerabilities in Embedded Network Stacks.
Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering (ASE) 2023.
- Improving Developers’ Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix Strategies.
S.A. Hassan, Z. Aamir, D. Lee, Davis, and F. Servant.
Proceedings of the 44th IEEE Symposium on Security and Privacy (S&P) 2023.
- Directed Acyclic Graph-based Neural Networks for Tunable Low-Power Computer Vision.
A. Goel, C. Tung, N. Eliopoulos, X. Hu, G.K. Thiruvathukal, Davis, and Y.H. Lu.
ACM/IEEE International Symposium on Low Power Electronics and Design (ISLPED) 2022.
- Exploiting Input Sanitization for Regex Denial of Service.
E. Barlas, X. Du, and Davis.
Proceedings of the ACM/IEEE 44th International Conference on Software Engineering (ICSE) 2022.
- An Empirical Study on the Impact of Parameters on Mobile App Energy Usage.
Q. Xu, Davis, Y.C. Hu, and A. Jindal.
Proceedings of the 29th IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) 2022.
- Low-Power Multi-Camera Object Re-Identication using Hierarchical Neural Networks.
ACM/IEEE International Symposium on Low Power Electronics and Design (ISLPED) 2021.
- Using Selective Memoization to Defeat Regular Expression Denial of Service (ReDoS).
Davis, F. Servant, and D. Lee.
IEEE Security & Privacy (S&P) 2021.
- A Principled Approach to GraphQL Query Cost Analysis.
A. Cha, E. Wittern, G. Baudart, Davis, L. Mandel, and J. Laredo.
Proceedings of the 28th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE) 2020.
- Improving Reproducibility of Data Science Pipelines through Transparent Provenance Capture.
L. Rupprecht, Davis, C. Arnold, Y. Gur, and D. Bhagwat.
Proceedings of the 46th International Conference on Very Large Databases: Industry track (VLDB-Industry) 2020.
- Testing Regex Generalizability And Its Implications: A Large-Scale Many-Language Measurement Study.
Davis, D. Moyer, A. Kazerouni, and D. Lee.
Proceedings of the 34th IEEE/ACM International Conference on Automated Software Engineering (ASE) 2019.
- Regexes are Hard: Decision-making, Difficulties, and Risks in Programming Regular Expressions.
L. Michael, J. Donohue, Davis, D. Lee, and F. Servant.
Proceedings of the 34th IEEE/ACM International Conference on Automated Software Engineering (ASE) 2019.
- Why Aren’t Regular Expressions a Lingua Franca? An Empirical Study on the Re-use and Portability of Regular Expressions.
Davis, L. Michael, C. Coghlan, F. Servant, and D. Lee.
Proceedings of the 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE) 2019.
- An Empirical Study of GraphQL Schemas.
E. Wittern, A. Cha, Davis, G. Baudart, L. Mandel.
Proceedings of the 17th International Conference on Service-Oriented Computing (ICSOC) 2019.
- EdgeWise: A Better Stream Processing Engine for the Edge.
X. Fu, T. Ghaffar, Davis, and D. Lee.
Proceedings of the 2019 USENIX Annual Technical Conference (USENIX ATC) 2019.
- The Impact of Regular Expression Denial of Service (REDOS) in Practice: an Empirical Study at the Ecosystem Scale.
Davis, C. Coghlan, F. Servant, and D. Lee.
Proceedings of the 26th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE) 2018.
- A Sense of Time for JavaScript and Node.js: First-Class Timeouts as a Cure for Event Handler Poisoning.
Davis, E.R. Williamson, and D. Lee.
Proceedings of the 27th USENIX Security Symposium (SECURITY) 2018.
- Node.fz: Fuzzing the server-side event-driven architecture.
Davis, A. Thekumparampil, and D. Lee.
Proceedings of the European Conference on Computer Systems (EuroSys) 2017.
Peer-reviewed journal and magazine papers
- AI Safety in the Eyes of the Downstream Developer: A First Look at Concerns, Practices, and Challenges.
H. Gao, M. Zahedi, W. Jiang, H.Y. Lin, Davis, and C. Treude.
arXiv 2025.
- Software Dependencies 2.0: An Empirical Study of Reuse and Integration of Pre-Trained Models in Open-Source Projects.
J. Yasmin, W. Jiang, Davis, and Y. Tian.
arXiv 2025.
- SysLLMatic: Large Language Models are Software System Optimizers.
arXiv 2025.
- ‘I see models being a whole other thing’: An Empirical Study of Pre-Trained Model Naming Conventions and A Tool for Enhancing Naming Consistency.
W. Jiang, M. Kim, C. Cheung, H. Kim, G.K. Thiruvathukal, and Davis.
Empirical Software Engineering (EMSE) 2025.
- Engineering Patterns for Trust and Safety on Social Media Platforms: A Case Study of Mastodon and Diaspora.
G. Cramer, W. Maxam, and Davis.
Journal of Systems and Software (JSS) 2025.
- Establishing Provenance Before Coding: Traditional and Next-Gen Software Signing.
T.R. Schorlemmer, E. Burmane, K. Kalu, S. Torres-Arias, and Davis.
IEEE Security & Privacy Magazine – Special Issue ‘Secure Software Before Codeing’ 2025.
- Fostering Systems Thinking through Engineering Study Abroad Programs.
European Journal of Engineering Education (EJEE) 2024.
- Challenges and Practices of Deep Learning Model Reengineering: A Case Study on Computer Vision.
W. Jiang, V. Banna, N. Vivek, A. Goel, N. Synovic, G.K. Thiruvathukal, and Davis.
Empirical Software Engineering (EMSE) 2024.
- Evolution of Winning Solutions in the 2021 Low-Power Computer Vision Challenge.
X. Hu, Z. Jiao, A. Kocher, Z. Wu, J. Liu, Davis, G.K. Thiruvathukal, and Y.H. Lu.
IEEE Computer 2023.
- Applying Experiential Learning Theory to Understand Study Abroad Leaders’ Experiences Using Real-Time Perspectives.
K. Davis, J. Deters, D. Ozkan, Davis, and H. Murzi.
Frontiers: The Interdisciplinary Journal of Study Abroad, Vol. 34, No. 2 (Frontiers) 2022.
- Tree-based Unidirectional Neural Networks for Low-Power Computer Vision.
A. Goel, C. Tung, N. Eliopoulos, A. Wang, Davis, G.K. Thiruvathukal, and Y.H. Lu.
IEEE Design & Test 2022.
- Fast and Accurate Incremental Feedback for Students’ Software Tests Using Selective Mutation Analysis.
A. Kazerouni, Davis, A. Basak, C. Shaffer, F. Servant, and S. Edwards.
Journal of Systems and Software (JSS) 2021.
- A Fine-grained Data Set and Analysis of Tangling in Bug Fixing Commits.
Empirical Software Engineering (EMSE) (also presented at ICSE’22-JournalFirst) 2021.
- Expectations and Experiences of Short-Term Study Abroad Leadership Teams.
Journal of International Engineering Education (JIEE) 2020.
Peer-reviewed workshop papers
- An Empirical Investigation of Pre-Trained Deep Learning Model Reuse in the Scientific Process.
N. Synovic, K. Ryzka, A.V.V. Solari, K. Lyons, Davis, and G.K. Thiruvathukal.
Proceedings of the 22nd IEEE International eScience Conference (short paper) (eScience) 2026. - How Do Agents Perform Code Optimization? An Empirical Study.
Proceedings of the 23rd International Mining Software Repositories Conference – Mining Challenge track (MSR-MiningChallenge) 2026.
- Software Supply Chains are Dead: Use-Case-Oriented Regeneration.
T. Singla and Davis.
Proceedings of the 20th International Symposium on Empirical Software Engineering and Measurement - Emerging Results, Vision, and Reflection Track (ESEM-ERVR) 2026.
- Lessons from Mitigating False Positives in Google’s OSS-Fuzz-Gen.
ACM International Conference on the Foundations of Software Engineering – Industry track (FSE-Industry) 2026.
- Towards the Systematic Testing of Regular Expression Engines.
ICSE Journal Ahead Workshop (JAWs) 2026.
- AgentHub: A Registry for Discoverable, Verifiable, and Reproducible AI Agents.
ICSE Journal Ahead Workshop (JAWs) 2026.
- ARMS: A Vision for Actor Reputation Metric Systems in the Open-Source Software Supply Chain.
K.G. Kalu, S. Okorafor, B. Durak, K. Laine, R.C. Moreno, S. Torres-Arias, and Davis.
ICSE Journal Ahead Workshop (JAWs) 2026.
- Towards a Benchmark for Dependency Decision-Making.
ICSE Journal Ahead Workshop (JAWs) 2026.
- Operationalizing Research Software for Supply Chain Security.
K. Kalu, S. Rattan, T.R. Schorlemmer, G.K. Thiruvathukal, J.C. Carver, and Davis.
ICSE Journal Ahead Workshop (JAWs) 2026.
- Beyond Local Code Optimization: Multi-Agent Reasoning for Software System Optimization.
H. Peng, P.V. Patil, A.Z. Qiu, G.K. Thiruvathukal, and Davis.
ICSE Journal Ahead Workshop (JAWs) 2026.
- A Unit Proofing Framework for Code-level Verification: A Research Agenda.
P.C. Amusuo, P.V. Patil, O. Cochell, T. Le Lievre, and Davis.
Proceedings of the 47th IEEE/ACM International Conference on Software Engineering - New Ideas and Emerging Results Track (ICSE-NIER) 2025.
- Recommending Pre-Trained Models for IoT Devices.
P.V. Patil, W. Jiang, H. Peng, D. Lugo, K.G. Kalu, J. LeBlanc, L. Smith, H. Heo, N. Aou, and Davis.
Proceedings of the 7th International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT) 2025.
- Introducing Systems Thinking as a Framework for Teaching and Assessing Threat Modeling Competency.
S. Joshi, P. Mukherjee, K.A. Davis, and Davis.
Annual Conference of the American Society for Engineering Education (ASEE) 2024.
- An Exploratory Study on Upper-Level Computing Students’ Use of Large Language Models as Tools in a Semester-Long Project.
B.A. Tanay, L. Arinze, S. Joshi, K.A. Davis, and Davis.
Annual Conference of the American Society for Engineering Education (ASEE) 2024.
- Reusing Deep Learning Models: Challenges and Directions in Software Engineering.
Davis, P. Jajal, W. Jiang, T.R. Schorlemmer, N. Synovic, and G.K. Thiruvathukal.
Proceedings of the IEEE John Vincent Atanasoff Symposium on Modern Computing (JVA’23) 2023.
- Towards Rehosting Embedded Applications as Linux Applications.
J. Srinivasan, S.R. Tanksalkar, P. Amusuo, Davis, and A. Machiry.
Proceedings of the 53rd Annual IEEE/IFIP International Conference on Dependable Systems and Networks — Disrupt track (DSN-Disrupt) 2023.
- Towards Automated Identification of Layering Violations in Embedded Applications (WIP).
M. Shen, Davis, and A. Machiry.
Proceedings of the 24th ACM SIGPLAN/SIGBED International Conference on Languages, Compilers, and Tools for Embedded Systems (LCTES) 2023.
- Reflecting on the use of the Policy-Process-Product Theory in Empirical Software Engineering.
K.G. Kalu, T.R. Schorlemmer, S. Chen, K.A. Robinson, and Davis.
Proceedings of the 31st ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering: Ideas, Visions, and Reflections track (ESEC/FSE-IVR) 2023.
- PTMTorrent: A Dataset for Mining Open-source Pre-trained Model Packages.
W. Jiang, N. Synovic, P. Jajal, T.R. Schorlemmer, A. Tewari, B. Pareek, G.K. Thiruvathukal, and Davis.
Proceedings of the 20th Annual Conference on Mining Software Repositories — Data and Tool Showcase Track (MSR-Data’23) 2023.
- An Empirical Study on Using Large Language Models to Analyze Software Supply Chain Security Failures.
T. Singla, D. Anandayuvaraj, K.G. Kalu, T.R. Schorlemmer, and Davis.
Proceedings of the 2nd ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) 2023.
- Incorporating Failure Knowledge into Design Decisions for IoT Systems: A Controlled Experiment on Novices.
D. Anandayuvaraj, P. Thulluri, J. Figueroa, H. Shandilya, and Davis.
Proceedings of the 5th International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT) 2023.
- An Empirical Study of Artifacts and Security Practices in the Pre-trained Model Supply Chain.
W. Jiang, N. Synovic, R. Sethi, A. Indarapu, M. Hyatt, T.R. Schorlemmer, G.K. Thiruvathukal, and Davis.
Proceedings of the 1st ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) 2022.
- Efficient Computer Vision on Edge Devices with Pipeline-Parallel Hierarchical Neural Network.
A. Goel, C. Tung, X. Hu, G.K. Thiruvathukal, Davis, and Y.H. Lu.
Proceedings of the 27th Asia and South Pacific Design Automation Conference (ASP-DAC) 2022.
- Reflecting on Recurring Failures in IoT Development.
D. Anandayuvaraj and Davis.
Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering: New Ideas and Emerging Results track (ASE-NIER) 2022.
- Discrepancies among Pre-trained Deep Neural Networks: A New Threat to Model Zoo Reliability.
D. Montes, P. Peerapatanapokin, J. Schultz, C. Guo, W. Jiang, and Davis.
Proceedings of the 30th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering: Ideas, Visions, and Reflections track (ESEC/FSE-IVR) 2022.
- Reflections on Software Failure Analysis.
P. Amusuo, A. Sharma, S.R. Rao, A. Vincent, and Davis.
Proceedings of the 30th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering: Ideas, Visions, and Reflections track (ESEC/FSE-IVR) 2022.
- SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties.
C. Okafor, T.R. Schorlemmer, S. Torres-Arias, and Davis.
Proceedings of the 1st ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED) 2022.
- Snapshot Metrics Are Not Enough: Analyzing Software Repositories with Longitudinal Metrics.
Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering: Demonstrations track (ASE-Demonstrations) 2022.
- “If security is required”: Engineering and Security Practices for Machine Learning-based IoT Devices.
N. Gopalakrishna, D. Anandayuvaraj, A. Detti, F. Bland, S. Rahaman, and Davis.
Proceedings of the 4th International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT) 2022.
- Experience Paper: A First Offering of Software Engineering.
Davis, P. Amusuo, and J.R. Bushagour.
Proceedings of the 1st International Workshop on Designing and Running Project-Based Courses in Software Engineering Education (DREE) 2022.
- Establishing Trust in Vehicle-to-Vehicle Coordination: A Sensor Fusion Approach.
N. Veselsky, J. West, I. Ahlgren, A. Goel, W. Jiang, K. Lee, Y. Kim, Davis, G.K. Thiruvathukal, and N. Klingensmith.
Proceedings of the 23rd Annual International Workshop on Mobile Computing Systems and Application (HotMobile) 2022.
- A Replication of ‘DeepBugs: A Learning Approach to Name-based Bug Detection’.
J.M. Winkler, A. Agarwal, C. Tung, D.R. Ugalde, Y.J. Jung, and Davis.
Proceedings of the 29th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering: Artifacts Track (ESEC/FSE-Artifacts) 2021.
- On the Impact and Defeat of Regex DoS.
Davis.
ACM Student Research Competition (Grand Finals) 2020. - Rethinking Regex Engines to Address ReDoS.
Davis.
Proceedings of the 27th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering (ESEC/FSE’19) — Student research competition. 2019.
- Ursprung: Provenance for Large-Scale Analytics Environments.
L. Rupprecht, Davis, C. Arnold, A. Lubbock, D. Tyson, and D. Bhagwat.
Proceedings of the 2019 International Conference on Management of Data: Demonstrations track (SIGMOD-Demonstrations) 2019.
- The case of the poisoned event handler: Weaknesses in the Node.js event-driven architecture.
Davis, G. Kildow, and D. Lee.
Proceedings of the 10th European Workshop on Systems Security (EuroSec) 2017.
Books and book chapters
- Model-Based Agentic Software Engineering.
Davis.
- Epilogue: The Computer Engineer as Tool-User.
Davis.
Technical reports
- Model-Based Agentic Software Engineering.
Davis, K. Kalu, H. Peng, and P.V. Patil. - Cheap Code, Costly Judgment: A Case Study on Governable Agentic Software Engineering.
Davis, P. Amusuo, T. Singla, B. Çakar, and K.A. Davis. - Reproducibility is Not Enough: Artifact Verifiability in Decentralized-Build Package Ecosystems.
O. Solarin, K. Kalu, Davis, and P. Amusuo. - Is US Defense Acquisition Ready to Acquire AI-Enabled Capabilities? Assessing the DoD Software Acquisition Pathway Through a Scenario-Based Policy Analysis.
D. Lugo and Davis. - Measuring Delivery Consistency in Practice: A DORA Extension from a Multi-Platform Release Setting.
L. Parente and Davis. - AgOSS: A Dataset and Multi-Layer Characterization of Open-Source Agricultural Software.
V. Dudhaiya, M. Golovenchits, A. Bannerjee, and Davis. - SAGE: Structured Agentic Graph Editing for Software Diagrams.
T. Sivertsen, N. Singh, and Davis. - A Longitudinal Study of Usability in Identity-Based Software Signing.
K. Kalu, H. Tran, S. Torres-Arias, S. Jeong, and Davis.
arXiv 2026.
- A Guide to Stakeholder Analysis for Cybersecurity Researchers.
Davis, S. Chen, H. Peng, P. Amusuo, and K. Kalu.
arXiv 2025.
- Is Reuse All You Need? A Systematic Comparison of Regular Expression Composition Strategies.
arXiv 2025.
- Improving the Reproducibility of Deep Learning Software: An Initial Investigation through a Case Study Analysis. https://arxiv.org/pdf/2505.03165. 2025.
N. Ravi, A. Goel, Davis, and G.K. Thiruvathukal.
2025. - Reactive Bottom-Up Testing.
S. Muralee, S. Cherupattamoolayil, Davis, A. Bianchi, and A. Machiry.
arXiv 2025.
- Large Language Models for Energy-Efficient Code: Emerging Results and Future Directions.
arXiv 2024.
- A Partial Replication of MaskFormer in TensorFlow on TPUs for the TensorFlow Model Garden.
V. Purohit, W. Jiang, A.R. Ravikiran, and Davis.
arXiv 2024.
- An Experience Report on Machine Learning Reproducibility: Guidance for Practitioners and TensorFlow Model Garden Contributors.
V. Banna, A. Chinnakotla, Z. Yan, A. Vegesana, N. Vivek, K. Krishnappa, W. Jiang, Y.H. Lu, G.K. Thiruvathukal, and Davis.
arXiv 2021.
US patents
- A method for identifying naming mismatches in neural networks based on their architectural properties.
Jiang, Cheung, Kim, Kim, Davis.
US provisional patent application, held by Purdue University 2025. - Determining a validity of an event emitter based on a rule.
Davis, Davis.
US patent, held by IBM 2024.
- Verification of the Integrity of Data Files Stored in Copy-on-Write (CoW) Based File System Snapshots.
Davis, Davis.
US patent, held by IBM 2021.
- Injection of simulated hardware failure(s) in a file system for establishing file system tolerance-to-storage-failure(s).
Davis, Davis.
US patent, held by IBM 2021.
- Performing hierarchical provenance collection.
Davis, Rupprecht, Bhagwat, Arnold, Sawdon.
US patent, held by IBM 2021.
- File metadata verification in a distributed file system.
Davis, Davis.
US patent, held by IBM 2020.
- Testing of lock managers in computing environments.
Davis, Davis.
US patent, held by IBM 2018.
- Detection of file corruption in a distributed file system.
Davis, Davis, Knop.
US patent, held by IBM 2018.
Posters
- Advancing Jailbreak Strategies: A Hybrid Approach to Exploiting LLM Vulnerabilities and Bypassing Modern Defenses.
M. Ahmed, M. Abdelmouty, M. Kim, G. Kandula, A. Park, and Davis.
IEEE Secure Development Conference (SecDev) – Poster Track 2025.
- A First Look at the General Data Protection Regulation (GDPR) in Open-Source Software.
L. Franke, H. Liang, A. Brantly, Davis, and C. Brown.
Proceedings of the ACM/IEEE 46th International Conference on Software Engineering – Poster Track (ICSE-Poster) 2024.
- An Intercultural Engineering Module for Software Engineers.
N. Hornbrook and Davis.
2021 Annual Colloquium for International Engineering Education (ACIEE) 2021.
- Exemplars for Machine Learning: Towards Software Engineering & Reproducibility.
N. Vivek, A. Chinnakotla, V. Banna, A. Vegesana, Z. Yan, Davis, Y.H. Lu, and G.K. Thiruvathukal.
SIAM Conference on Computational Science and Engineering (CSE) 2020. - Navigating Software Supply Chain Risks: Practitioner Perspectives on Software Signing. 2024 Purdue CERIAS Symposium (CERIAS’24).
K.G. Kalu, S. Torres-Arias, and Davis. - Machine Learning Supply Chain Security. 2023 Purdue CERIAS Symposium (CERIAS’23).
T.R. Schorlemmer, W. Jiang, and Davis. - Trustworthy Re-use of Pre-trained Neural Networks. 2023 Purdue CERIAS Symposium (CERIAS’23).
W. Jiang, T.R. Schorlemmer, and Davis. - Plan for an evaluation of government cyber threat hunting processes. 2022 Purdue CERIAS Symposium (CERIAS’22).
W. Maxam and Davis. - Investigating Software Provenance Consistency in the Open Source Publishing Pipeline.
K.G. Kalu and Davis. - Is Reuse All You Need? A Systematic Comparison of Regular Expression Composition Strategies.
- Towards Scalable and Performance-Aware Code Optimization with LLMs.
- Optimizing Multi-Agent Collaboration in Software Engineering.
L. Yadava, P. Kumar, Z. Homrich, R. Potta, P. Kapila, and Davis. - Software Signing: Practical Adoption, Challenges, and Tooling Usability. 2025 Purdue CERIAS Symposium (CERIAS’25).
K.G. Kalu, S. Torres-Arias, and Davis. - Exploring Deep Neural Network Reuse in Computational Natural Science.
N. Synovic, K. Ryzka, A.V. Solari, Davis, and G.K. Thiruvathukal. - LeMix: Rehosting Embedded Systems as Linux Applications for Effective Vulnerability Detection. 2024 Purdue CERIAS Symposium (CERIAS’24).
S.R. Tanksalkar, J. Srinivasan, S. Danduri, P. Amusuo, Davis, and A. Machiry.
Theses
Doctoral
- Systematic and Scalable Memory Safety Assurance for Embedded Software Systems.
Amusuo.
PhD, Electrical & Computer Engineering, Purdue University 2026.
- Trustworthy Reuse in the Machine Learning Model Supply Chain.
Jiang.
PhD, Electrical & Computer Engineering, Purdue University 2025.
- On the Impact and Defeat of Regular Expression Denial of Service.
Davis.
PhD, Computer Science and Applications, Virginia Tech 2020.
Master’s
- Cross-Select: A Transformer Framework for Pre-Trained Model Recommendation.
Patil.
MSc, Electrical & Computer Engineering, Purdue University 2025.
- A Quantitative Comparison of Pre-Trained Model Registries to Traditional Software Package Registries.
Jones.
MSc, Electrical & Computer Engineering, Purdue University 2024.
- Software Supply Chain Security: Attacks, Defenses, and the Adoption of Signatures.
Schorlemmer.
MSc, Electrical & Computer Engineering, Purdue University 2024.
- An Empirical Study of Trust & Safety Engineering in Open-Source Social Media Platforms.
Cramer.
MSc, Electrical & Computer Engineering, Purdue University 2023.
- Discovering U.S. Government Threat Hunting Processes and Improvements.
Maxam.
MSc, Electrical & Computer Engineering, Purdue University 2023.
