Toward Efficient Identification of Exploitable Code

On February 18, 2025, the third paluno Distinguished Lecture took place. This time, we had the pleasure of welcoming Adriana Sejfia, a promising early-career researcher, as our speaker. She provided fascinating insights into her work on identifying security risks in program code.

In her talk, she explained how programming errors can lead to security vulnerabilities, creating attack vectors for potential attackers. Another major issue is the careless handling of privacy requirements, which can put user data at risk. She also discussed how malicious actors exploit third-party platforms to introduce harmful code and how challenging it is for platform operators to detect these threats in time.

To automate the detection of insecure code, Adriana presented three key methods: Static Analysis (manual patterns), Machine Learning (feature-based detection), and   Deep Learning (data-driven detection).

Each of these approaches has its strengths and weaknesses. Deep learning, in particular, still faces significant challenges: results are often not easily transferable to other systems, and the models frequently perform worse in real-world applications than the promising experimental results suggest.

Following the lecture, an open Q&A session allowed the audience to gain deeper insights into Adriana’s research as well as her impressive career path. During her PhD at the University of Southern California, she gained valuable industry experience at Google Research and GitHub.

For more information about the paluno Distinguished Lectures Series, please visit: https://paluno.uni-due.de/en/aktuelles/veranstaltungen/distinguished-lectures