What changes about software engineering when the reused component is a learned model?
Developers increasingly build systems on models they did not train, obtained from public registries. A pre-trained model behaves like a dependency in some respects and unlike one in others: its interface is underspecified, its provenance is often unclear, its behaviour changes when it is retrained, and the file itself may execute code when loaded.
We study models as software artifacts. Our work examines how developers find and select models, what happens when a model is integrated into a larger system, whether interoperability claims hold in practice, how model naming and documentation mislead, and what security properties a reused model brings with it.
2025
Proceedings of the 32nd ACM Conference on Computer and Communications Security (CCS)
Model serialization is an integration property. A format that executes code when loaded makes deserialization part of the reuse contract.
arXiv
Looks at AI safety from the downstream developer's position — the engineer integrating a model, not the organization training it.
arXiv
Generalizes dependency thinking to model artifacts: what a dependency is, when the dependency learns.
Empirical Software Engineering (EMSE)
Interview study of how engineers reason about pre-trained models as components, including where model naming misleads them.
Proceedings of the 7th International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT)
Recommending models for constrained devices, where the reuse decision is bounded by the hardware it has to run on.
A method for identifying naming mismatches in neural networks based on their architectural properties
US provisional patent application, held by Purdue University
Identifies naming mismatches from a network's architecture, making the naming problem detectable rather than only observable.
2024
Proceedings of the 33rd ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA)
Tested whether ONNX interoperability holds. Conversion failures show that a portability claim is an engineering obligation, not a property.
Proceedings of the 18th ACM/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)
A systematic review and quantitative study of what is known about Hugging Face, consolidating a fast-moving literature.
Proceedings of the 21st Annual Conference on Mining Software Repositories (MSR)
PeaTMOSS extends that to models as they appear inside open-source projects, linking the registry to the systems that depend on it.
Empirical Software Engineering (EMSE)
Model reengineering — reimplementing and extending published models — is a distinct and costly engineering activity; this documents what it involves.
arXiv
A partial replication across frameworks, which is where interoperability claims are tested rather than stated.
2023
Proceedings of the ACM/IEEE 45th International Conference on Software Engineering (ICSE)
The empirical study of Hugging Face reuse that established how engineers select and adapt pre-trained models at ecosystem scale.
Proceedings of the IEEE John Vincent Atanasoff Symposium on Modern Computing (JVA’23)
Framed model reuse as a software-engineering problem with its own challenges, rather than a machine-learning convenience.
Proceedings of the 20th Annual Conference on Mining Software Repositories — Data and Tool Showcase Track (MSR-Data’23)
PTMTorrent made the model ecosystem minable, so claims about it could be measured instead of asserted.
2022
Proceedings of the 1st ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED)
Characterized what is actually published alongside pre-trained models and what security practices accompany them.
Proceedings of the 30th ACM Joint Meeting on European Software Engineering Conference and Symposium on the Foundations of Software Engineering: Ideas, Visions, and Reflections track (ESEC/FSE-IVR)
Found that nominally identical pre-trained models from model zoos differ, which makes a model zoo a supply chain rather than a catalogue.
Proceedings of the 4th International Workshop on Software Engineering Research & Practices for the Internet of Things (SERP4IoT)
Asks what security practices ML-based IoT engineering uses in practice, and finds them conditional on someone requiring them.
2021
arXiv
Turned the reproducibility problem into guidance practitioners could apply.
In preparation
An Empirical Investigation of Pre-Trained Deep Learning Model Reuse in the Scientific Process
An early empirical look at pre-trained model reuse in the wild.
Improving the Reproducibility of Deep Learning Software: An Initial Investigation through a Case Study Analysis. https://arxiv.org/pdf/2505.03165. 2025
An early look at why deep-learning results are hard to reproduce, before reuse became the dominant mode.