Pinned
Marcel Böhme👨🔬
6,489 posts
Software Security Group @maxplanckpress
PhD @NUSComputing, Singapore
Research Group: mpi-softsec.github.io
- Reverse engineering via GDB. x.com/ClownWorld_/st…
- Absolutely thrilled to announce that I will be joining the new Max-Planck Institute for Security and Privacy in Bochum, Germany! 🥳
- Definitely in my⚡Top3 best papers! My fuzzing conjecture 2020 has just been accepted @FSEconf (2xAccept, 1xAward Quality). Turns out there is no sudden road block; more like a frontier that is exponentially harder to push. 📄: mboehme.github.io/paper/FSE20.Em… Collab w/ @gamozolabs!
- Fuzzing a formally verified compiler for six CPU years: Found unbreakable. From [PLDI'11] "Finding and Understanding Bugs in C Compilers" by Yang, Chen, Eide, and Regehr: users.cs.utah.edu/~regehr/papers…
- Starting a new research group that explores the Foundations of #Software #Security at the Max Planck Institute for Security & Privacy. Looking for PhDs and Postdocs. DMs open. Please Retweet 👍 Photo of this morning's @ruhrunibochum campus where the MPI-SP is located.
- On fire🔥! Our paper on an information-theory to explain/boost fuzzer efficiency just accepted @FSEconf (2xAward Quality, 1xAccept)! 📄(Preprint): mboehme.github.io/paper/FSE20.En… 💻(LibFuzzer): github.com/llvm/llvm-proj… 🔬(FuzzBench): fuzzbench.com/reports/2020-0… Collab @Jilyac& @sangkilc.
- For my new followers, my research group is interested in techniques that make machines attack other machines with maximal efficiency. All our tools are open-source, so people can use them to identify security bugs before they are exploited. This is how it all started.
- Me: Let's check if the upcoming addition is undefined behavior and bail out. Compiler: Nah, let's remove that check since it is undefined behavior. research.swtch.com/ub
- Two fuzzers. None finds any bugs. Which is better, in principle? Everyone: Whichever achieves more coverage 😊 We: Frequently not true 🤓 Researchers: But, there is strong correlation 🧑🏫 We: Yes, but only weak agreement 🤓 Collab w/ @lszekeres & @metzmanj Accepted at #ICSE2022
- Good news! Our ICSE'22 paper "On the Reliability of Coverage-Based Fuzzer Benchmarking" is freely available as Gold Open Access. Check out our discussions and recommendations in Sections 6 & 7 📝 mboehme.github.io/paper/ICSE22.p… 👩💻 doi.org/10.5281/zenodo… by/with @lszekeres & @metzmanj
- Looking to recruit 👩🎓 PhD students and 👩💻 interns in Software Security. Strong background in one of: * Statistics, data science, * ML (causality, security flaws), * Program analysis, system building, * Vuln. discovery, CTFs. Reach me via mboehme.github.io RT appreciated.











