Research Snapshot
I study how AI agents behave on real software systems: what context they read, which actions they choose, and what evidence they leave behind.
Full research statementSelected work
News
Jun 2026: Started remote UIUC research internship. Started a remote summer research internship at the University of Illinois Urbana-Champaign through UIUC++ Summer Rese...
Feb 2026: Paper submitted to TOSEM 2026. Resubmitted 'An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems' to ACM Transac...
Oct 2025: Paper submitted to MSR 2026. Submitted 'An Empirical Study on Remote Code Execution in Machine Learning Model Hosting Ecosystems' to the Mining So...
View all news
Research & Publications
Selected papers and manuscripts. The full research page has the current agenda and active collaborations.
TOSEM 2026 submission / ML model hosting security
Large-scale study of roughly 45,000 repositories across major ML model hosting ecosystems, measuring unsafe deserialization, eval injection, malware signals, and recurring developer security misconceptions.
TACL manuscript in preparation / SHIFT aligned backdoor audit
SHIFT checks whether a trigger changes which valid option an LLM agent chooses, then asks whether that movement favors the attacker's target rather than ordinary option quality. Manuscript work with Chowdhury Rakin Haider.
Database schema generation / multi-agent verification
Multi-agent framework for generating relational database schemas and ER diagrams from requirements, with auto-repair and formal verification.
Undergraduate thesis / blockchain healthcare
Patient-centric blockchain framework for electronic health records using encrypted off-chain IPFS storage and Ethereum-based access control.
See more researchAll publications
Skills
Languages & Systems: Rust, C#/.NET Core, C++, Go, Java, Shell
AI & Agents: Python, LangGraph, MCP, RAG, PyTorch, LLM Evaluation
Web & Backend: TypeScript, Node.js/Express, React/Next.js, Microservices, REST APIs, EF Core
Data & Storage: PostgreSQL, MongoDB, SQL Server, Oracle/PLSQL, DynamoDB, SQLAlchemy
Cloud & DevOps: AWS, Docker, Kubernetes, Terraform, GitHub Actions
Security & Research Tooling: CodeQL, Semgrep, Bandit, YARA, Z3, Solidity/Web3