Sign in

Andreas Zeller

@andreaszeller.bsky.social
1.4K followers 148 following 143 posts

Software researcher at cispa.de, working on #Fandango, #S3, #FuzzingBook, #DebuggingBook. Testing, debugging, analyzing, and protecting software for a better world. Find me at andreas-zeller.info

PostsRepliesMedia
Andreas Zeller @andreaszeller.bsky.social · 29/09/2026
After returning from holidays, I usually find a pile of mail on my desk. This time, there was only one envelope. Big things come in small packages :-)
Andreas Zeller
has been inducted as an inaugural member of the
ACM SIGSOFT Software Engineering Academy
in recognition of lasting contributions, influence, and leadership that have shaped modern software engineering.

August 2026
Marsha Chechik
Chair, ACM SIGSOFT
Claire Le Goues
Awards Chair, ACM SIGSOFT
030
Andreas Zeller @andreaszeller.bsky.social · 27/08/2026
I will be presenting our latest #Fandango work on September 30 at the GOTO Conference in Copenhagen, Denmark. Let's meet at #GOTO! gotocph.com/2026
This is a talk announcement.

GOTO Copenhagen • Sep 28 - Oct 2, 2026
goto;

Fuzzing your way to better test inputs

Andreas Zeller
Faculty at CISPA Helmholtz Center for Information Security

gotocph.com
022
Andreas Zeller @andreaszeller.bsky.social · 24/08/2026
The #Fandango team is pulling off a long evening session because their advisor insists that the paper be ready one day _before_ the deadline
Evening dinner with the Fandango team
110
Andreas Zeller @andreaszeller.bsky.social · 20/08/2026
On my way to Bochum for the PhD exam of Niklas Risse (with co-examiners Marcel Böhme and Michael Pradel)
Train signage indicator showing arrival in Bochum at 12:14 while the actual time is 12:19
030
Andreas Zeller @andreaszeller.bsky.social · 06/08/2026
Proud greetings from the 💃 #Fandango headquarters! The all-new 1.2 release of our specification-guided #Fandango fuzzer brings many under-the-hood improvements, along with new, useful user-facing features and documentation. Check out the release notes! fandango-fuzzer.github.io/ReleaseNotes...
Norman Becker, Valentin Huber, and Tim Scheckenbach in the Fandango HQ office. The empty seats belong to Alexander Liggesmeyer and José Antonio Zamudio Amaya, two more great members of the #Fandango team.
020
Andreas Zeller @andreaszeller.bsky.social · 31/07/2026
At #Dagstuhl with my team and a few guests, setting our research agenda for the next 12 months. Big things coming!
060
Andreas Zeller @andreaszeller.bsky.social · 28/07/2026
There's an ICSE 2020 paper of mine, "Debugging Inputs", that, according to Google Scholar, has a whopping 12,800 citations. Most cited paper ever? Alas, ACM DL is closer to the truth with 1 citation (actually, a self-citation). Does anyone know how to report wrong numbers to the Google Scholar team?
Screenshot of Google Scholar, listing 12,832 citations; and contrasting screenshot of ACM DL, listing 1 citation for the same article.
200
Andreas Zeller @andreaszeller.bsky.social · 21/07/2026
In the past months, I have had a number of great PhD students pass their exams. Let me start with Masudul Hasan Masud for "Addressing Socio-Technical Blind Spots in Modern Software Systems": www.linkedin.com/feed/update/... Masudul is on the job market – highly recommended!
linkedin.com
#phd #dissertation #defense #research #saarbrücken #academicjourney | Masudul Hasan Masud | 14 comments
I am happy to share that I have successfully defended my dissertation, "Addressing Socio-Technical Blind Spots in Modern Software Systems,” at CISPA Helmholtz Center for Information Security ( Saarlan...
220
Andreas Zeller @andreaszeller.bsky.social · 17/07/2026
I have been selected into the inaugural class of the ACM SIGSOFT Software Engineering Academy: www2.sigsoft.org/academy/inau...
280
Andreas Zeller @andreaszeller.bsky.social · 09/07/2026
Besides code coverage, there are several execution features that can correlate with failure and thus help in localizing faults. See the talk of Marius Smytzek today 15:00 at #FSE2026: conf.researchr.org/details/fse-...
conf.researchr.org
How Execution Features Relate to Failures: An Empirical Study and Diagnosis Approach (FSE 2026 - Journal-First Paper) - FSE 2026
The ACM International Conference on the Foundations of Software Engineering (FSE) is an internationally renowned forum for researchers, practitioners, and educators to present and discuss the most rec...
020
Andreas Zeller @andreaszeller.bsky.social · 08/07/2026
Are you into program repair or automated debugging? Today at #FSE2026 - Two presentations by Marius Smytzek on how to boost fault localization: * 12:10 conf.researchr.org/details/fse-... * 16:30 conf.researchr.org/details/fse-... Paper available - see you!
conf.researchr.org
Denoising Fault Localization with Test Line Proximity (FSE 2026 - Research Papers) - FSE 2026
The ACM International Conference on the Foundations of Software Engineering (FSE) is an internationally renowned forum for researchers, practitioners, and educators to present and discuss the most rec...
010
Reposted by Andreas Zeller
CISPA Helmholtz Center for Information Security @cispa.de · 08/07/2026
Congrats to @andreaszeller.bsky.social for receiving his 11th Impact Paper Award at FSE 2026 in Montréal today! He is honored for the SZZ-algorithm, which he presented together with Jacek Śliwerski and Thomas Zimmermann in 2005. Read our interview with Andreas at cispa.de/en/interview...
cispa.de
“I have high standards when it comes to coolness”: In conversation with Professor Dr. Andreas Zeller
Today, Andreas Zeller will receive the 11th Impact Paper Award of his career at the ACM International Conference on the Foundations of Software Engineering. These special awards are reserved for scien...
231
Andreas Zeller @andreaszeller.bsky.social · 07/07/2026
Reunited after 20 years! These are Jacek Śliwerski, Tom Zimmermann, and Andreas Zeller, meeting twenty years after creating the foundational #SZZ algorithm to relate bugs to associated changes. See us telling the story of the at #FSE2026 Wednesday at 08:30: conf.researchr.org/details/fse-...
131
Andreas Zeller @andreaszeller.bsky.social · 06/07/2026
Today at noon at #SSBSE2026, see how we use Search-Based Testing to quickly solve complex input constraints in the #Fandango project – orders of magnitude faster than with traditional constraint solvers. With Pepe Zamudio and Marius Smytzek; paper available conf.researchr.org/details/ssbs...
conf.researchr.org
Search-Based Generation of Complex Inputs with FANDANGO (SSBSE 2026 - Hot-off-the-Press Track) - SSBSE 2026
Call for Contributions The Hot Off the Press (HOP) track offers authors of recent papers the opportunity to present their work to the SSBSE community (and publish a 4-page abstract in the proceedings)...
000
Andreas Zeller @andreaszeller.bsky.social · 06/07/2026
Today at 12:15 in the #FSE2026 doctoral symposium: My PhD student Alexander Liggesmeyer presents his work on protocol testing and fuzzing with #Fandango: conf.researchr.org/details/fse-... Paper available!
030
Andreas Zeller @andreaszeller.bsky.social · 06/07/2026
Today at 10:05 at #AIWARE2026: Norman Becker asks, "Can LLMs Really Reason about Code?" 2026.aiwareconf.org/details/aiwa... This exciting work was done with Tural Mammadov; paper and slides available.
2026.aiwareconf.org
Can LLMs Really Reason about Code? Studying How Well LLMs Understand the Relation between Input, Code, and Output (AIware 2026 - Main Track) - AIware 2026
“Software for all and by all” is the future of humanity. AIware, i.e., AI-powered software, has the potential to democratize software creation. We must reimagine software and software engineering (SE)...
010
Andreas Zeller @andreaszeller.bsky.social · 05/07/2026
Today at #FSE2026 in Montreal: A 180-minute tutorial on our next generation #Fandango fuzzer, bringing high quality input generation to a program near you. 14:00-17:30 in Concordia SGW Campus, MB 2.430 More about #Fandango: fandango-fuzzer.github.io Room info: conf.researchr.org/room/fse-202...
fandango-fuzzer.github.io
Fuzzing with Fandango — Fuzzing with Fandango
030
Andreas Zeller @andreaszeller.bsky.social · 03/07/2026
I’m back! Five weeks ago, an artificial lens in my eye had dislocated itself; I was effectively one-eyed, and my doctors strongly discouraged me from reading. I now had surgery, and things look good. It‘ll take me weeks to catch up with mails and reviews, but I’ll see you soon, starting at #FSE!
Andreas Zeller in a hospital gown with a large white patch over his right eye
2120
Andreas Zeller @andreaszeller.bsky.social · 22/05/2026
At ICST workshops today, giving a keynote on how test generation and dynamic analysis will boost AI agents: conf.researchr.org/details/ise-...
conf.researchr.org
The power of experimentation (Intelligent SE 2026) - Intelligent SE 2026
ISE Goals Many researchers utilize AI techniques. However, AI techniques, including deep learning techniques and LLMs, have probabilistic characteristics, so it is difficult to verify and validate AI-...
020
Andreas Zeller @andreaszeller.bsky.social · 19/05/2026
Specification-based fuzzers are super-effective - but writing their formal specs needs lots of manual effort. Wednesday at 14:20, we show how to turn natural-language protocol specs (such as RFCs) into formal #Fandango specs automatically! Details and paper: conf.researchr.org/details/icst...
030
Andreas Zeller @andreaszeller.bsky.social · 19/05/2026
Meet the #Fandango makers! If you're at #ICST26 and would like to see our language-based fuzzer in action, meet us in the tools and data showcase today at 14:00 and tomorrow at 10:30. Details and paper: conf.researchr.org/details/icst...
010
Andreas Zeller @andreaszeller.bsky.social · 19/05/2026
"Please produce an input that is (1) valid, (2) as short as possible, and (3) results in a maximum of code coverage." How can you tell a fuzzer to do this? Today 14:50 at #ICST26, see the latest extension of our #Fandango fuzzer. Details and paper: conf.researchr.org/details/icst...
020
Reposted by Andreas Zeller
Bill Connelly @espnbillc.bsky.social · 17/05/2026
And the day finishes with tiny Elversberg, from a town of 13,000, getting promoted to the Bundesliga. Pretty sure every citizen of the town is in the stadium, and half of them are on the pitch.
0397
Andreas Zeller @andreaszeller.bsky.social · 17/05/2026
On my way to Daejeon, South Korea for the #ICST conference, listening to a live football audio stream. Can you guess which one?
030
Andreas Zeller @andreaszeller.bsky.social · 22/04/2026
I got interviewed by Nature on how to catch bugs in scientific software. My "Basics of Debugging 101" were: 1. Proceed systematically 2. Find out when the bug occurs 3. Explain the bug to a rubber duck 4. Write tests that replicate the bug Enjoy the read! www.nature.com/articles/d41...
nature.com
Got bugs? Here’s how to catch the errors in your scientific software
Computer scientists share their advice for ensuring that your scientific software does what it’s supposed to do.
141
Andreas Zeller @andreaszeller.bsky.social · 17/04/2026
This is the output I want. What input do I need? Today at ICSE - International Conference on Software Engineering, Tural Mammadov presented his work on Modelizer - the framework that learns from synthesized program executions to predict inputs from outputs and vice versa: dl.acm.org/doi/10.1145/...
020
Andreas Zeller @andreaszeller.bsky.social · 15/04/2026
I‘m gonna need a bigger suitcase #ICSE2026
1130
Andreas Zeller @andreaszeller.bsky.social · 14/04/2026
In the #ICSE2026 Wednesday 14:00 session, I will be giving my Harlan D. Mills Award talk (likely at 14:10 already). Enjoy! conf.researchr.org/details/icse...
280
Andreas Zeller @andreaszeller.bsky.social · 10/04/2026
On my way to Rio de Janiero, visiting #ICSE2026 - here with Tural Mammadov. See you soon!
150
Reposted by Andreas Zeller
CISPA Helmholtz Center for Information Security @cispa.de · 09/04/2026
"If you don't test your software, someone else will." Others may discover bugs and vulnerabilities. Here’s where Fandango, CISPA’s new tool for automated software testing comes in. More from CISPA-Faculty @andreaszeller.bsky.social youtube.com/shorts/LuPgQ...
youtube.com
Andreas Zeller on software testing and it's optimization
YouTube video by CISPA
021
Andreas Zeller @andreaszeller.bsky.social · 08/04/2026
Visiting #FSE2026 in Montreal? Do not miss our #Fandango tutorial on Sunday, July 5, where we show how to systematically generate inputs and interactions for comprehensive software testing (with Pepe Zamudio, Marius Smytzek, and Alexander Liggesmeyer). Find Fandango at fandango-fuzzer.github.io
fandango-fuzzer.github.io
Fuzzing with Fandango — Fuzzing with Fandango
160
Andreas Zeller @andreaszeller.bsky.social · 19/03/2026
The IEEE Computer Society interviewed me on my past and the Future of Automated Debugging and Software Testing. Enjoy! www.computer.org/publications...
computer.org
The Future of Automated Debugging and Software Testing with Harlan D Mills Award Winner Andreas Zeller
Hardware-based protections validate what software cannot independently verify. They shift visibility from reactive observation to foundational assurance. This article takes a deeper look at the what, ...
052
Andreas Zeller @andreaszeller.bsky.social · 16/03/2026
For decades, my mission was to help developers build better software. Now I help anyone, including AI: andreas-zeller.info
Homepage of Andreas Zeller, now with the text "help build better software" rather than "help _developers_ build better software"
160
Andreas Zeller @andreaszeller.bsky.social · 10/03/2026
In a call "retrieve(account: string)", nobody checks the contents of "account". What if we could specify its type not just as a string, but as a formal language - say, a regex "[0-9]+"? In our new paper, we do exactly this - for better type checking and even test generation: doi.acm.org?doi=3799978
FLAT: Formal Languages as Types
And Their Applications in Testing
FENGMIN ZHU, CISPA Helmholtz Center for Information Security, Germany
ANDREAS ZELLER, CISPA Helmholtz Center for Information Security, Germany
Programmers regularly use strings to encode many types of data, such as Unix file paths, URLs, and email addresses. They are
conceptually different, but existing mainstream programming languages treat them as the same string type. This is problematic:
the type system allows, for instance, malicious HTML text to be passed to a function expecting an email address.
To distinguish conceptually different string types and to avoid potential vulnerabilities, we regard formal languages as types
(FLAT), thereby restricting the set of valid strings using context-free grammars and, if needed, semantic constraints. Applying
this type-based approach, we offer a unified solution for string API documentation, input validation, malicious input detection,
language-based fuzzing, and test oracles, all at once, based on user-annotated formal language types and, if necessary, pre-
and post-conditions. We implement this idea and present FLAT-PY, a testing framework for Python. By attaching annotations
directly to Python code, FLAT-PY automatically performs runtime type checking via code instrumentation and reports any
detected type errors as soon as possible. We conducted case studies on real Python code fragments: FLAT-PY can detect
logical bugs from random inputs generated by a language-based fuzzer, relying on a reasonable number of user annotations.
060
Andreas Zeller @andreaszeller.bsky.social · 09/03/2026
My successor as a professor will be some AI video tutor with the appearance of Brad Pitt, available 24/7, unlimited patience, personalized towards each student, the ability to teach any subject ever discussed in a textbook, and a cost of < 1$/hour. Good thing I can still do research! (Now wait...)
Brad Pitt in front of a classroom (AI-generated)
040
Reposted by Andreas Zeller
International Conference on Software Engineering @icseconf.bsky.social · 06/03/2026
IEEE Computer Society Harlan D. Mills Award and Talk by @andreaszeller.bsky.social Should Computer Scientists Experiment Less? On the past, present, and future of software engineering research More information at conf.researchr.org/details/icse...
IEEE Computer Society Harlan D. Mills Award and Talk by Andreas Zeller
Should Computer Scientists Experiment Less? On the past, present, and future of software engineering research
042
Andreas Zeller @andreaszeller.bsky.social · 05/03/2026
"Should Computer Scientists Experiment Less?" This is the title of my upcoming Harlan D. Mills Award Talk at ICSE 2026 on the past, present, and future of Software Engineering research. Looking forward to lots of productive discussions! conf.researchr.org/details/icse...
conf.researchr.org
IEEE Computer Society Harlan D. Mills Award and Talk by Andreas Zeller: Should Computer Scientists Experiment Less? On the past, present, and future of software engineering research (ICSE 2026 - Main ...
This year, ICSE 2026 innovates with an expanded Main Plenaries program—bringing a total of four exceptional keynote talks to the main conference stage. Across Wednesday to Friday, these sessions gathe...
081
Andreas Zeller @andreaszeller.bsky.social · 04/03/2026
Impact award! I am happy to report that my ICSE 2006 paper "Mining metrics to predict component failures," with Nachi Nagappan and Thomas Ball, has been selected to receive a retrospective ICSE SEIP Most Influential Paper Award. Read it here: dl.acm.org/doi/10.1145/...
dl.acm.org
Mining metrics to predict component failures | Proceedings of the 28th international conference on Software engineering
0130
Andreas Zeller @andreaszeller.bsky.social · 03/03/2026
With more and more AI-generated code, comprehensive system testing becomes more important than ever. Our new paper "Language-Based Protocol Testing" (with Alexander Liggesmeyer and Pepe Zamudio), shows how to specify and test all details of how programs interact: arxiv.org/abs/2509.20308
Over the past decade, the automated generation of test inputs has made significant advances. Modern fuzzers and test generators easily
produce complex input formats that do systematically cover the input and execution space. Testing protocols, though, has remained a
frontier for automated testing, as a test generator has to interact with the program under test, producing messages that conform to
the current state of the system.
In this paper, we introduce language-based protocol testing, the first approach to specify, automatically test, and systematically cover
the full state and input space of protocol implementations. We specify protocols as interaction grammars—an extension of context-free
grammars that tag each message element with the communication party that is in charge of producing it. Interaction grammars embed
classical state models by unifying states, messages, and transitions all into nonterminals, and can be used for producing interactions as
well as parsing them, making them ideally suited for testing protocols. Additional constraints over grammar elements allow us to
specify and test semantic features such as binary message formats, checksums, encodings, and the many ways that message features
induce states and vice versa.
To evaluate the effectiveness of language-based protocol testing, we have implemented it as part of the FANDANGO test generator. We
specify several protocols as interaction grammars, including features such as human-readable interactions (SMTP), bit-level encodings
(DNS), and dynamic port assignments (FTP), and use them to test the corresponding protocol implementations. By systematically
covering the interaction grammar and solving the associated constraints, FANDANGO achieves comprehensive coverage of the protocol
interactions, resulting in high code coverage and a thorough assessment of the program under test.
1102
Andreas Zeller @andreaszeller.bsky.social · 01/03/2026
On my way to Savannah, Georgia to an IFIP WG 4.3 meeting, where I’ll present our work on Parameterized Compiler Testing (a joint work with my fantastic co-workers Addison Crump and Alexi Turcotte)
020
Andreas Zeller @andreaszeller.bsky.social · 26/02/2026
#Fandango 1.1 is now available! With this release, #Fandango becomes a full-fledged _protocol fuzzer_, happily exploring states and messages of protocols such as FTP or DNS. Thanks to José. Valentin, Alexander, and Marius for their hard work! Find Fandango at fandango-fuzzer.github.io
161
Andreas Zeller @andreaszeller.bsky.social · 16/02/2026
About time: A multi-celebration for becoming a member of Academia Europaea, my SIGSOFT Influential Educator Award, my 60th birthday, becoming an IEEE Fellow, _and_ getting the 2026 IEEE Harlan D. Mills Award. With cake and fizzy drinks!
Andreas Zeller and PhD students
0131
Andreas Zeller @andreaszeller.bsky.social · 10/02/2026
Starting this year, I will only review for conferences that get rid of a "bidding" phase, as allowing reviewers to bid on papers they want to review opens too many opportunities for manipulation and collusion. For details, see andreas-zeller.info/2025/12/07/R... #nobidding
andreas-zeller.info
Reviewer-Author Collusion Rings and How to Fight Them
In 2012, I attended a physical meeting of the program committee responsible for selecting the best scientific papers for the ESEC/FSE 2013 conference in Saint Petersburg, Russia. This meeting was part...
190
Andreas Zeller @andreaszeller.bsky.social · 05/02/2026
I am happy to report that I have been named the recipient of the 2026 Harlan D. Mills award "For sustained contributions to software debugging, program analysis, mining software repositories, and automated test generation." This is a big award – thanks to all! www.computer.org/volunteering...
1221
Andreas Zeller @andreaszeller.bsky.social · 03/02/2026
How do execution features relate to failures? In this new ACM TOSEM paper, Marius Smytzek, Martin Eberlein, Lars Grunske, and I analyze which execution features beyond code coverage correlate best with failures and lead to accurate explanations of failure causes: dl.acm.org/doi/10.1145/...
Fault localization aims to identify code regions responsible for failures. Traditional techniques primarily correlate statement
execution with failures; however, program behavior involves diverse execution features, including variable values, branch
conditions, and definition-use pairs, which can provide richer diagnostic insights.
This paper comprehensively investigates execution features for fault understanding, addressing two complementary goals.
First, we conduct an empirical study of 310 bugs across 20 projects, analyzing 17 execution features and assessing their
correlation with failure outcomes. Our findings suggest that fault localization benefits from a broader range of execution
features: (1) Scalar pairs exhibit the strongest correlation with failures; (2) Beyond line executions, def-use pairs and functions
executed are key indicators for fault localization; and (3) Combining multiple features enhances effectiveness compared to
relying on individual features.
Second, building on these insights, we introduce a debugging approach that learns relevant features from labeled test
outcomes. The approach extracts fine-grained execution features and trains a decision tree to differentiate passing and failing
runs. The trained model generates fault diagnoses that explain the underlying causes of failures.
Our evaluation demonstrates that the generated diagnoses achieve high predictive accuracy. These interpretable diagnoses
empower developers to debug software efficiently by providing deeper insights into failures.
070
Andreas Zeller @andreaszeller.bsky.social · 30/01/2026
* Mail has lost all my emails sent since Monday * Mail search is broken too * Search in reminders cannot find anything * New Keynote is full of ads!? * Invoke Python-3.13, get 3.14 instead - venvs are messed up * LaTeX "minted" crashes (likely b/c Python) So glad I'm an expert in debugging /sarcasm
130
Andreas Zeller @andreaszeller.bsky.social · 28/01/2026
Fuzzing software becomes much more effective if you can generate _valid_ inputs. We have now built the first approach to _statically_ extract complete and precise input grammars from parser code, producing syntactically valid and diverse inputs by construction. Enjoy! dl.acm.org/doi/10.1145/...
dl.acm.org
Inferring Input Grammars from Code with Symbolic Parsing | ACM Transactions on Software Engineering and Methodology
Generating effective test inputs for a software system requires that these inputs be valid, as they will otherwise be rejected without reaching actual functionality. In the absence of a specification ...
0124
Andreas Zeller @andreaszeller.bsky.social · 27/01/2026
After a visit to Max Planck Institute for Security and Privacy (MPI-SP) in Bochum, seeing my awesome colleagues @thorstenholz.bsky.social, @mboehme.bsky.social, Mathias Payer, and many more, now on my way to Paris to celebrate ten years of @softwareheritage.org with the great Roberto Di Cosmo
050
Andreas Zeller @andreaszeller.bsky.social · 08/01/2026
A researcher used more than 2,000 em-dashes in his papers, revealing AI-based manipulation in 400+ papers since 1985. Professor Zeller claims he "typed" these dashes into the paper by using "two hyphens" and a "typesetting" system.
$ cd ~/Papers/
$ grep -e '[ ~]-- ' */*.tex | wc -l
    2258
$
1181
Andreas Zeller @andreaszeller.bsky.social · 06/01/2026
Happy New Year! I am thrilled to report that Jacek Śliwerski, Tom Zimmermann, and I won the ACM SIGSOFT 2026 Impact Award 🏆 for "When do changes induce fixes?" (MSR 2005). The paper introduced the popular SZZ algorithm for linking change histories and bug databases: dl.acm.org/doi/10.1145/...
dl.acm.org
When do changes induce fixes? | ACM SIGSOFT Software Engineering Notes
As a software system evolves, programmers make changes that sometimes cause problems. We analyze CVS archives for fix-inducing changes---changes that lead to problems, indicated by fixes. We show how ...
1170