Skip to main content

Profile

Making software secure & trustworthy.

I’m an Associate Professor at the University of Southern Denmark, working where programming languages meet software engineering — building automated analyses that hold up on real-world code.

My work develops techniques for detecting and repairing security vulnerabilities in mobile and multilingual software systems, published at premier venues including FSE, ISSTA, FM, TOSEM, and ISSRE. I have contributed to several DFG- and BMBF-funded initiatives, and currently lead and co-lead funded projects under the DIREC and Digital Lead programs.

Focus Program analysis, security, program repair & testing
Service Program Committee — ICSE, ASE, ISEC
Funding DIREC & Digital Lead — PI / Co-PI

News

  • 2026 “PrevaRank: Ranking Plausible Patches by Historic Feature Frequencies” accepted for an ASE 2026 Journal-First presentation
  • 2026 “JetTyped: A Study of Cross-Language Type Bugs in Android’s JavaScriptEngine” accepted to ISSRE 2026
  • 2026 Paper on ranking plausible patches by historic feature frequencies accepted in the Journal of Systems and Software (JSS)
  • 2026 Invited to the Program Committee of ICSE 2027
  • 2026 Invited to the Program Committee of ASE 2026
  • 2026 Four papers accepted across various SANER 2026 tracks
  • 2025 Project “Beyond Patching: Empowering organizations to stay ahead of software security threats” funded by Digital Lead
  • 2025 Project “Privacy in the Realm of Multilingual Programs: Security in Hybrid Apps” funded by DIREC

Get in touch

I look forward to connecting with prospective students, collaborators, and industry partners working on program analysis, software security, and testing. Email abti@mmmi.sdu.dk, or find me at the Maersk Mc-Kinney Møller Institute, University of Southern Denmark, Campusvej 55, 5230 Odense M, Denmark.

Focus areas

Research

My work sits at the intersection of programming languages and software engineering, with a unifying goal of making software more secure, dependable, and trustworthy — building automated analyses grounded in formal methods yet practical enough to run on real-world codebases.

Static Analysis

Scalable techniques to detect bugs and vulnerabilities: automated repair of data races, modular pointer analysis across language boundaries, and repair of security properties in Android and web applications.

  • HIPPODROME: Data Race Repair using Static Analysis Summaries — TOSEM, 2023
  • Effects of Program Representation on Pointer Analyses — FASE, 2021
  • Modular Unification of Unilingual Pointer Analyses — SCP, 2025

Language-Based Security & Information Flow

Enforcing security and privacy guarantees through information-flow control — ensuring sensitive data cannot leak across component or privilege boundaries, with applications to mobile platforms and multilingual systems.

  • Automated Repair of Information Flow Security in Android — FM, 2024
  • Demand-driven Information Flow Analysis of WebView — ISSRE, 2023
  • IIFA: Modular Inter-App Intent Information Flow Analysis — SecureComm, 2019

Android Privacy & Security

Android apps combine native code, inter-app communication, and hybrid web APIs. This work surfaces privacy violations, unsafe intent patterns, and data misuse at the scale of real app markets, staying tractable on production codebases.

  • Understanding the Impact of Fingerprinting in Hybrid Apps — MOBILESoft, 2023
  • IWANDROID: Information Flow Analysis of WebView — ISSRE, 2023
  • PIAnalyzer: Precise PendingIntent Vulnerability Analysis — ESORICS, 2018

Multilingual Program Analysis

Modern systems span multiple languages and runtimes. This research builds unified abstract models of memory, pointers, and control flow for sound, modular reasoning across language boundaries and foreign-function interfaces.

  • Modular Unification of Unilingual Pointer Analyses — SCP, 2025
  • Challenges of Multilingual Program Specification and Analysis — ISoLA, 2024
  • Towards Analyzing N-language Polyglot Programs — SANER, 2026

Software Testing

Flaky tests erode developer confidence and slow CI pipelines. This thread investigates timing-sensitive failures in GUI-driven mobile apps, reproducing and diagnosing flaky behavior through event-order exploration and targeted event delays.

  • Reproducing Timing-dependent GUI Flaky Tests — ISSTA, 2024
  • Flaky Test Detection in Android via Event Order Exploration — ESEC/FSE, 2021

Funded Projects

Privacy in the Realm of Multilingual Programs: Security in Hybrid Apps

Project Manager
Funding
Digital Research Centre Denmark (DIREC)
Grant
DKK 2,000,000
Period
2025–2027
Objectives
  • Build a multilingual analysis tool for hybrid Android apps.
  • Combine static and dynamic analysis to detect sensitive cross-language data flows.
  • Identify privacy and security issues across native, JavaScript, and FFI boundaries.
  • Validate with the industrial partner AiroFit in real development workflows.
Project page ↗

Programming Principles and Abstraction for Privacy

Participant
Funding
Deutsche Forschungsgemeinschaft (DFG)
Institution
University of Potsdam
Period
Jan 2019 – Dec 2019
Objectives
  • Build language abstractions that let developers enforce privacy by design.
  • Develop a system where developers structure code into modules with defined permissions.

SmartPriv

Participant
Funding
German Federal Ministry of Education and Research (BMBF)
Institution
University of Potsdam
Period
Mar 2017 – Mar 2019
Objectives
  • Make the technical description of Android permissions clearer.
  • Show how apps access and share personal information.
  • Let users revoke or grant permissions at runtime while preserving functionality.

SMAPPER

Participant
Funding
EIT Digital
Institution
Saarland University
Period
Jan 2016 – Sep 2016
Objectives
  • Provide reliable third-party evaluation of mobile app security levels.
  • Enable early detection of risky or unusual permissions before installation.

Research output

Publications

My work spans static program analysis, information-flow security, automated program repair, and software testing across mobile, multilingual, and concurrent systems.

All Publications

2026

  • PrevaRank: Ranking Plausible Patches by Historic Feature Frequencies
    Journal of Systems and Software, Vol. 240, 112921 · also ASE 2026 Journal-First
    A technique for ranking plausible patches produced by automated program repair tools using feature similarity with historic programmer-written fixes.
  • JetTyped: A Study of Cross-Language Type Bugs in Android's JavaScriptEngine
    ISSRE 2026, Research Track
    An empirical study of Jetpack JavaScriptEngine adoption that identifies cross-language type bugs in Android apps using a hybrid analysis framework.
  • Towards Analyzing N-language Polyglot Programs
    SANER 2026, Early Research Achievement Track
    A research vision on the analysis of three-language (and beyond) polyglot systems.
  • A Measurement Study on the Adoption of Pledges and Unveils in the OpenBSD Operating System
    SANER 2026, Short Paper Track
    A longitudinal empirical study of the adoption of pledge and unveil in OpenBSD, covering 19 releases.
  • Modular Unification of Unilingual Pointer Analyses to Multilingual FFI-based Programs
    SANER 2026, Journal-First Track
    Introduces a unified pointer analysis approach across multilingual and FFI-based systems.
  • Empirical Derivations from an Evolving Test Suite
    VST 2026, SANER 2026 Workshops
    A longitudinal empirical analysis of the NetBSD automated test suite, from its early introduction to late 2025.
  • From Commits to Corrections: Toward Lightweight Mining of Python Bug-Fix Patterns from GitHub
    ISEC 2026
    A lightweight pipeline for mining GitHub Python repositories to infer semantic patterns between bug types and patch fixes.

2025

  • Modular Unification of Unilingual Pointer Analyses to Multilingual FFI-based Programs
    Science of Computer Programming, Elsevier, Vol. 243
    Introduces a unified pointer analysis approach across multilingual and FFI-based systems.
  • Vulnerability Patching Across Software Products and Software Components: A Case Study of Red Hat's Product Portfolio
    arXiv:2509.13117
    Empirical case study on vulnerability patching across product portfolios.
  • Towards Systematic Specification and Verification of Fairness Requirements: A Position Paper
    IEEE REW 2025, pp. 405–411
    Position paper proposing systematic fairness specification and verification directions.
  • Empirical Derivations from an Evolving Test Suite
    arXiv:2511.00915
    Empirical analysis of trends from an evolving test suite.

2024

  • Challenges of Multilingual Program Specification and Analysis
    ISoLA 2024 (LNCS 15224), Springer, pp. 124–143
    Surveys the open challenges of specifying and analyzing programs written in multiple languages, covering FFI boundaries and cross-language analysis.
  • Automated Repair of Information Flow Security in Android Implicit Inter-App Communication
    FM 2024 (LNCS 14933), Springer, pp. 285–303
    Automated repair techniques for information flow vulnerabilities in Android implicit inter-app communication.
  • Ranking Plausible Patches by Historic Feature Frequencies
    arXiv:2407.17240
    Ranking plausible program patches using historical feature frequencies.
  • Reproducing Timing-Dependent GUI Flaky Tests in Android Apps via a Single Event Delay
    ISSTA 2024, pp. 1504–1515
    Technique for reproducing timing-dependent GUI flaky tests using a single event delay.

2023

  • Hippodrome: Data Race Repair Using Static Analysis Summaries
    ACM TOSEM, Vol. 32, No. 2, pp. 41:1–41:33
    Data race repair approach employing static analysis summaries to propose fixes.
  • Demand-driven Information Flow Analysis of WebView in Android Hybrid Apps
    ISSRE 2023, pp. 415–426
    Demand-driven information flow analysis tailored for WebView in hybrid Android apps.
  • IWANDROID: Demand-driven Information Flow Analysis of WebView in Android Hybrid Apps
    Zenodo Artifact
    Artifact for demand-driven information flow analysis for WebView.

2021

  • Flaky Test Detection in Android via Event Order Exploration
    ESEC/FSE 2021, pp. 367–378
    Detection of flaky tests in Android via exploration of event order.

2020

  • A Large Scale Analysis of Android–Web Hybridization
    Journal of Systems and Software, Elsevier, Vol. 170
    Large-scale analysis of Android–web hybridization in applications.

2019

  • Enhancing Users' Privacy: Static Resolution of the Dynamic Properties of Android
    PhD Thesis, University of Potsdam, pp. 1–111
    Static techniques to reason about dynamic Android properties for privacy.
  • IIFA: Modular Inter-App Intent Information Flow Analysis of Android Applications
    SecureComm 2019 (LNICST 305), Springer, pp. 335–349
    Modular inter-app intent information flow analysis for Android apps.
  • LUDroid: A Large Scale Analysis of Android–Web Hybridization
    SCAM 2019, pp. 256–267
    Large-scale static analysis of Android–web hybridization, examining how apps integrate web content via WebView.

2018

  • PIAnalyzer: A Precise Approach to PendingIntent Vulnerability Analysis
    ESORICS 2018 (LNCS 11099), Springer, pp. 41–59
    PIAnalyzer: precise analysis for PendingIntent vulnerabilities.
  • A Formal Logic Framework for the Automation of the Right to Be Forgotten
    SecureComm 2018 (LNICST 254), Springer, pp. 95–111
    Formal logic framework for automating right-to-be-forgotten requirements.

2017

  • ThiefTrap: An Anti-theft Framework for Android
    SecureComm 2017 (LNICST 238), Springer, pp. 167–184
    Anti-theft framework design and evaluation for Android devices.

In the classroom

Teaching

Teaching Philosophy

Each class contains students with diverse backgrounds, prior knowledge, and unique ways of understanding the world. No single teaching approach fits all, so I balance several: getting to know students, learning by example, and active engagement through group work.

Because assumptions about students' backgrounds can hinder learning, I run a brief get-to-know-you survey at the start of each course, asking what students expect to learn, what interests them, and what challenges they anticipate — helping me build an inclusive, responsive environment from the outset.

Motivation ignites learning, so I use relatable examples. When teaching mobile security, I opened with real malicious applications; some students had those very apps installed and were immediately engaged. I also promote peer-based group work, which fosters the teamwork and leadership valued across software careers.

Courses Taught

CourseRolePeriodInstitutionStudents / Level
Engineering Research in SoftwareSupervisor & Coordinator2025University of Southern Denmark67 / Masters
Advanced Software Engineering MethodologiesLecturerAutumn 2024University of Southern Denmark148 / Masters
Programming ParadigmsLecturerSummer 2023University of Passau40 / Bachelor & Master
Automated Program RepairLecturerSummer 2022 & 2023University of Passau25 & 13 / Masters
Mobile SecurityLecturerSummer 2022University of Passau45 / Masters
Android SecurityLecturer / TASummer 2019University of Potsdam28 / Masters
Research Seminar in Software EngineeringTeaching AssistantSummer 2018–19University of Potsdam
Secure Information FlowTeaching AssistantWinter 2018–19University of Potsdam

Supervision

  • Master's projects — University of Southern Denmark (19 students)
  • Bachelor's theses — Università della Svizzera italiana (1 student)
  • Master's theses — University of Passau (5 students)
  • Bachelor's theses — University of Potsdam (4 students)

Pedagogical Training

  • Lecture Training Program, University of Southern Denmark
  • PhD Supervision
  • Students as Learners
  • Research-based Teaching
  • Tools for e-learning activities in teaching
  • Evaluation and data collection

Community

Academic Service

Program Committees

  • ICSE 2027 — Research Track
  • ASE 2026 — Research Track
  • ISEC 2026 — Research Track
  • ASE 2025 — Research Track
  • ISEC 2025 — Research Track
  • ICSE 2025 — ACM Student Research Competition
  • ASE 2024 — Research Track
  • TACAS 2024 — AEC Track
  • PLDI 2023 — AEC Track
  • ISSTA 2023 — AEC Track
  • VMCAI 2023 — AEC Track
  • ISSTA 2022 — AEC Track
  • SCAM 2021 — NIER Track

Other Conference Roles

  • Social Media & Web Chair — ICSA 2025
  • Social Media & Web Chair — FormaliSE 2024

Journal Reviewing

  • Journal of Computer Security
  • ACM Transactions on Software Engineering and Methodology (TOSEM)
  • IEEE Transactions on Dependable and Secure Computing (TDSC)
  • Empirical Software Engineering (EMSE)

Junior PCs & Sub-reviewing

  • Junior PC — MSR 2023
  • Sub-reviewer — ISSTA 2021
  • Sub-reviewer — MSR 2020
  • Shadow PC — IEEE Security & Privacy (S&P) 2021

Accreditation & Expert Panels

  • Expert Panel — reaccreditation of doctoral programs, University of Zagreb
  • Expert Panel — reaccreditation of doctoral programs, University of Zadar