Marcel Böhme👨🔬
@mboehme_
Software Security @maxplanckpress (#MPI_SP), PhD @NUSComputing, Dipl.-Inf. @TUDresden_de Research Group: http://mpi-softsec.github.io
Surprising facts about #fuzzing. A thread in slides 👇

Back from @PLDI 2025, where Frédéric Recoules and I had the pleasure to give a tutorial on BINSEC and binary-level symbolic execution. Here it is, playable in your browser: binsec.github.io/tutorial-pldi2…
New from our security teams: Our AI agent Big Sleep helped us detect and foil an imminent exploit. We believe this is a first for an AI agent - definitely not the last - giving cybersecurity defenders new tools to stop threats before they’re widespread.
I wrote a short rant about what irks me when people anthropomorphize LLMs: addxorrol.blogspot.com/2025/07/a-non-…
The code for building and updating the ARVO dataset, a collection of over 5000 memory safety vulnerabilities in open source software, is now open source! Link in reply :)
This incoherence approach, and others that rely on automated fuzzing of LLM generated code for discovering differences in implementation semantics, will likely play an important role in code transformation for memory safety. Even an incremental modernization of C11/C++03 to…
Can we statistically estimate how likely an LLM-generated program is correct w/o knowing what is a correct program for that task? Sounds impossible-but it's actually really simple. In fact our oracle-less eval can reliably substitute a pass@1 based eval. arxiv.org/abs/2507.00057
🚨 Our amazing #FUZZING'25 keynotes are online! "Constraining Fuzzing without Paying Too Much" by Miryung Kim youtu.be/L90MBb6NLBE "Are you sure you belong in academia?" by Will Wilson youtu.be/qQGuQ_4V6WI // @mboehme_, @lszekeres, @moarbugs, @RuijieMeng
We had two exciting keynotes: * From academia: Miryung Kim (Prof @UCLA) and * From industry: Will Wilson (CEO and Co-Founder of @AntithesisHQ). Stay tuned for recordings!
Proud to share that our paper “Top Score on the Wrong Exam: On Benchmarking in Machine Learning for Vulnerability Detection” received an ACM Distinguished Paper Award at ISSTA 2025 in Trondheim, Norway. If you’re interested, the paper is available here: dl.acm.org/doi/10.1145/37…
One of the things I’m proud of at @XBOW is that we try to be open about the technical details - there’s a lot of AI hype and it’s reasonable to be skeptical! Here’s @nicowaisman going into the details of our climb to the top of the US H1 leaderboard:
How did @XBOW become the top-ranked hacker in the US on HackerOne? @nicowaisman takes you behind the scenes to show how it all works, from reconnaissance to zero day discovery: xbow.com/blog/top-1-how…
@TheOfficialACM Council has reaffirmed yesterday that all ACM publications and related research artifacts in the ACM Digital Library (@ACMDL) will be fully openly available after 1-1-2026. Computing science material of the highest quality freely available to all! #OpenAccess
📣 Are you interested in serving on the Program Committee for ISSTA 2026? Please let us know by filling out this form: forms.gle/MaXAKysfMSdqTg…