Sign in

Marcel Böhme

@mboehme.bsky.social
946 followers 504 following 166 posts

Software Security @ MPI for Security and Privacy PhD @NUS, Dipl.-Inf. @TUDresden Research Group: mpi-softsec.github.io

PostsRepliesMedia
Marcel Böhme @mboehme.bsky.social · 27/04/2026
🔥 Our industry keynote at #FUZZING'26 is online! Where the Fuzz Are We Going? by Sergej Dechand (Code Intelligence) 🌍 fuzzing-workshop.github.io www.youtube.com/watch?v=yp-A...
youtube.com
NDSS 2026 - FUZZING 2026, Keynote 2 by Sergej Dechand
YouTube video by NDSS Symposium
130
Marcel Böhme @mboehme.bsky.social · 27/04/2026
🔥 Our academic keynote at #FUZZING'26 is online! Advancing from "What the fuzz?" to "All the Fuzz" by Mathias Payer (@gannimo.bsky.social). 🌍 fuzzing-workshop.github.io youtu.be/In3kRAVVbzQ?...
youtu.be
NDSS 2026 - FUZZING 2026, Welcome and Opening Remarks, and Keynote by Mathias Payer
YouTube video by NDSS Symposium
183
Marcel Böhme @mboehme.bsky.social · 18/04/2026
🧑‍🏫 Excited to give a 𝐤𝐞𝐲𝐧𝐨𝐭𝐞 at #ICST'26 on the Insufficiency of Benchmarking! Join us in Daejeon, Korea from 19th to 21st May: conf.researchr.org/home/icst-20... #Agentic #SE #AI #LLM #Testing
151
Marcel Böhme @mboehme.bsky.social · 17/02/2026
Thrilled to give a keynote at ACM India's ISEC'26 in Jaipur this Friday! How do we know whether our program has no bugs if we have never seen it have any, and if we don't even have anything (i.e., an oracle) that can tell us whether a behavior is a bug or feature? Stick around till Friday!
1122
Marcel Böhme @mboehme.bsky.social · 14/01/2026
Hopefully, it will allow us to refocus on what truly matters in science, on big problems, on intuition and insights, on theory building, and away from the brute mechanics of publishing and the bean counting that has put the breaks on true progress in science. hegemon.substack.com/p/the-age-of...
hegemon.substack.com
The Age of Academic Slop is Upon Us
what happens when AI automates "normal science"?
129918
Marcel Böhme @mboehme.bsky.social · 25/12/2025
Which is better? Asking your distant Uncle Barry for the Top10 restaurants in NY or consulting the Michelin Guide? Well, turns out that bug-based fuzzer benchmarking is much like Uncle Barry. Random and noisy. Accepted at #FSE26. Led by Ardi Madadi, @is-eqv.bsky.social, and @nimgnoeseel.bsky.social
1133
Marcel Böhme @mboehme.bsky.social · 18/12/2025
I have been named an ACM Distinguished Member for "contributions to software security and fuzz testing". Happy and honored! A heartfelt *Thank You* to my nominator and all of you who endorsed and supported me - today and throughout my entire career. 1/2
5294
Reposted by Marcel Böhme
Max-Planck-Gesellschaft @maxplanck.de · 17/11/2025
Many Max Planck scientists have started sharing their #research findings on #BlueSky. Follow their posts and join the conversation! 👋 go.bsky.app/BYcBy6R #StarterPack
Starter Pack: Max Planck scientists on Bluesky
511540
Reposted by Marcel Böhme
ISSTA 2026 Conference @issta.bsky.social · 17/12/2025
📢 Call for Papers for ISSTA 2026 We invite high-quality submissions on software testing and analysis from industry and academia, incl. * research papers * experience papers, and * replicability studies. 📆 29th January 2026 🖊️ issta2026.hotcrp.com 🌐 conf.researchr.org/track/issta-...
conf.researchr.org
ISSTA 2026 - Research papers - ISSTA 2026
Welcome to the website of the ISSTA 2026 conference. The ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA) is the leading research symposium on software testing and analysis...
052
Marcel Böhme @mboehme.bsky.social · 03/12/2025
⏱️ 9 days until submission deadline (Dec 11, 23:59 AoE). Organized by: @yannicnoller.bsky.social, @rohan.padhye.org, @ruijiemeng.bsky.social, and Laszlo (@lszekeres.bsky.social) Szekeres.
035
Reposted by Marcel Böhme
Shin Yoo @drsyoo.bsky.social · 17/11/2025
Dearly beloved, we are gathered here today to celebrate this thing called ASE 2025 ;) @aseconf.bsky.social @mboehme.bsky.social @llingming.bsky.social
0143
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 22/10/2025
🎙️ #ASE2025 Keynote Speaker Series (1 of 3) What do symbolic model checking, path profiling, and quantum simulation have in common? 🤔 Find out from Prof. Reps (University of Wisconsin-Madison) in his ASE2025 Keynote “We Will Publish No Algorithm Before Its Time”! conf.researchr.org/track/ase-20...
0103
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 28/10/2025
🎙️ ASE 2025 Keynote Speaker Series (3 of 3) Prof. Taesoo Kim (Georgia Tech) “Hyperscale Bug Finding and Fixing: DARPA AIxCC” conf.researchr.org/track/ase-20...
142
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 26/10/2025
🎙️ #ASE2025 Keynote Speaker Series (2 of 3) Dr. Cristina Cifuentes, Vice President @ Oracle Software Assurance “Oracle Parfait – Detecting Application Vulnerabilities at Scale – Past, Present and Future”
162
Marcel Böhme @mboehme.bsky.social · 08/11/2025
🧵 A human review of our AI review at #AAAI26. 📝: arxiv.org/abs/2507.00057 🦋 : bsky.app/profile/did:... We are off to a good start. While the synopsis misses the motivation (*why* this is interesting), it offers the most important points. Good abstract-length summary. 1/
120
Marcel Böhme @mboehme.bsky.social · 08/11/2025
Just accepted at #AAAI26 in Singapore: Our paper on estimating the *correctness* of LLM-generated code in the absence of oracles (e.g., a ground-truth implementation). 📝 arxiv.org/abs/2507.00057 with Thomas Valentin (ENS Paris-Saclay), Ardi Madadi, and Gaetano Sapia (#MPI_SP).
1101
Reposted by Marcel Böhme
dmnk @dmnk.bsky.social · 04/11/2025
Neat idea: Snapshot fuzzing from a certain point deeper in the target (with +- complex state), then use an AI Agent to trigger that point. Fuzzer goes brrr
041
Marcel Böhme @mboehme.bsky.social · 03/11/2025
Gaetano's paper on Scaling Security Testing by Adressing the Reachability Gap has been accepted at #ICSE26! 📝 gpsapia.github.io/files/ICSE_2... 🧑‍💻 github.com/GPSapia/Reac... How to scale automatic security testing to arbitrary systems?
1175
Reposted by Marcel Böhme
dmnk @dmnk.bsky.social · 26/10/2025
Must-read for fuzzing folks (read: tooling/algorithms/academia) by Addison Crump addisoncrump.info/research/wha...
addisoncrump.info
What the hell are we doing? · Addison Crump
Homepage for Addison Crump
13011
Marcel Böhme @mboehme.bsky.social · 25/10/2025
AAAI'26 has been adopting AI reviews in two stages of the review process. I can see that we have to handle the reviewer overload, but I don't think AI reviews are beneficial, at all, for our scientific progress. If our paper gets accepted at #AAAI26, I will review our AI-generated review here 🤠
1110
Reposted by Marcel Böhme
Christoph Hochrainer @chochrainer.bsky.social · 15/10/2025
Presented our #CCS25 paper yesterday in Taipei! 🎤 We introduce Circuzz, the first systematic fuzzing framework for zero-knowledge (ZK) pipelines. 📄 Paper: mariachris.github.io/Pubs/CCS-202... 💻 Repo: github.com/Rigorous-Sof... with @isychev.bsky.social, @vwuestholz.bsky.social, Maria Christakis
043
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 13/10/2025
The early bird registration for #ASE2025 is still open! 📅 Early deadline: Oct 15, 2025 🧾 Regular deadline: Nov 2, 2025 All accepted papers must have at least one regular (non-student) registration for inclusion in the proceedings. 👉 Details: conf.researchr.org/attending/ase-2025/registration
conf.researchr.org
Registration - ASE 2025
Welcome to the website of the 40th IEEE/ACM International Conference on Automated Software Engineering, ASE 2025. The ASE conference is the premier research forum for Automated Software Engineering. E...
043
Marcel Böhme @mboehme.bsky.social · 08/10/2025
After 5 years, we are back at NDSS in San Diego! Looking forward to submissions from the Security and the Software Engineering community!
052
Reposted by Marcel Böhme
Tanner Rowlett @trowlett0.bsky.social · 24/09/2025
GUIFuzz++ is the first general-purpose fuzzer for desktop GUI software! Fuzzing by translating AFL++ random input into user interaction with GUIs, leading to the discovery of 23 new bugs! Paper: futures.cs.utah.edu/papers/25ASE.pdf Source: github.com/FuturesLab/GUIFuzzPlusPlus Go test some GUIs!
11811
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 21/08/2025
Paper deadlines for ASE’25 co-located workshops are approaching! This year, nine exciting workshops are co-located with ASE’25, covering diverse SE topics. Deadlines vary, but most are due Aug 26 ⏳. Check each workshop’s website for details! conf.researchr.org/track/ase-20... #ASE25 #Workshop #CFP
conf.researchr.org
ASE 2025 - Workshops - ASE 2025
Welcome to the website of the 40th IEEE/ACM International Conference on Automated Software Engineering, ASE 2025. The ASE conference is the premier research forum for Automated Software Engineering. E...
022
Reposted by Marcel Böhme
Andreas Zeller @andreaszeller.bsky.social · 22/08/2025
25 years of delta debugging! On this day in 2000, I presented “Simplifying Failure-Inducing Inputs” at ISSTA - now one of the most influential works in the 50-year history of Transactions on Software Engineering. Read all about its genesis and impact at doi.ieeecomputersociety.org/10.1109/TSE....
25yrs of delta dbg
0204
Reposted by Marcel Böhme
Dave Aitel @daveaitel.bsky.social · 08/08/2025
Aixcc results !
082
Reposted by Marcel Böhme
Jonathan Aldrich @jonathanaldrich.bsky.social · 08/08/2025
Released today: the second video in my Programming Language Pragmatics series, covering Compilation, Interpretation, and Environments! www.youtube.com/watch?v=mrmo... Going forward, I'll post a video 3 times a week. Please share the series with anyone who might benefit!
youtube.com
PLP 1.3-1.4: Compilation, interpretation, and environments
YouTube video by Jonathan Aldrich
1227
Marcel Böhme @mboehme.bsky.social · 02/07/2025
Can we statistically estimate how likely an LLM-generated program is correct w/o knowing what is a correct program for that task? Sounds impossible-but it's actually really simple. In fact, our measure of "correctness" called incoherence can be estimated (PAC guarantees). arxiv.org/abs/2507.00057
arxiv.org
Estimating Correctness Without Oracles in LLM-Based Code Generation
Generating code from natural language specifications is one of the most successful applications of Large Language Models (LLMs). Yet, they hallucinate: LLMs produce outputs that may be grammatically c...
1123
Reposted by Marcel Böhme
dmnk @dmnk.bsky.social · 01/07/2025
LibAFLGo adds directed fuzzing to #LibAFL Neat! (not related to Golang) github.com/vusec/libaflgo
github.com
GitHub - vusec/libaflgo: LibAFLGo: Evaluating and Advancing Directed Greybox Fuzzing
LibAFLGo: Evaluating and Advancing Directed Greybox Fuzzing - vusec/libaflgo
071
Reposted by Marcel Böhme
Yannic Noller @yannicnoller.bsky.social · 29/06/2025
🚨 Our amazing #FUZZING'25 keynotes are online! "Constraining Fuzzing without Paying Too Much" by Miryung Kim youtu.be/L90MBb6NLBE "Are you sure you belong in academia?" by Will Wilson youtu.be/qQGuQ_4V6WI // @mboehme.bsky.social, László Szekeres, @rohan.padhye.org, @ruijiemeng.bsky.social
1116
Marcel Böhme @mboehme.bsky.social · 29/06/2025
It was great to see the community come together again at our 4th #FUZZING workshop in Trondheim this year! We drew a big crowd. Enjoyed the super lively discussions. Thanks to the organizers: * @rohan.padhye.org * @yannicnoller.bsky.social * @ruijiemeng.bsky.social and * László Szekeres (Google)
2213
Marcel Böhme @mboehme.bsky.social · 19/06/2025
Thrilled to share a recent opinion piece at the IEEE Security and Privacy (Vol. 23, Issue 3). Basically a long-term perspective on the field meant for both researchers and practitioners. 📝 ieeexplore.ieee.org/stamp/stamp....
092
Reposted by Marcel Böhme
Andreas Zeller @andreaszeller.bsky.social · 04/06/2025
Knowing the input language of a software system greatly facilitates its (automated) testing. In our new GDBMiner work, we use the GNU debugger (GDB) to extract precise input grammars from any recursive descent parser that can be traced via GDB: doi.org/10.4230/LITE...
doi.org
GDBMiner: Mining Precise Input Grammars on (Almost) Any System
0163
Reposted by Marcel Böhme
halvarflake.bsky.social @halvarflake.bsky.social · 05/06/2025
My short impulse presentation from Cycon is online: youtu.be/qllU_B_Rmis?...
youtu.be
Fireside Chat: Gentleman Hackers with Thomas Dullien
YouTube video by natoccdcoe
4219
Reposted by Marcel Böhme
Rohan Padhye @rohan.padhye.org · 06/06/2025
Just Accepted to ACM TOSEM! The "Havoc Paradox" is about the relationship between byte-level fuzzer mutations and their effect on the inputs produced by generators for structured strings (e.g. XML/SQL). Can disruptive mutations be controlled? Should they be? Find out. 📄 dl.acm.org/doi/pdf/10.1...
2203
Marcel Böhme @mboehme.bsky.social · 03/06/2025
Massive 1.2k submissions to #ASE25 in Korea! 🎉 📈
0162
Marcel Böhme @mboehme.bsky.social · 28/05/2025
🖊️ Register here: ntnu.eventsair.com/fse2025-isst... (FUZZING is a co-located workshop)
ntnu.eventsair.com
Welcome to FSE 2025 + ISSTA 2025
053
Reposted by Marcel Böhme
Rohan Padhye @rohan.padhye.org · 27/05/2025
We also have an excellent program of research talks and *fuzzing nuggets*. Detailed schedule coming soon. conf.researchr.org/home/issta-2...
List of Accepted Papers at the FUZZING Workshop
033
Reposted by Marcel Böhme
Rohan Padhye @rohan.padhye.org · 27/05/2025
We're excited to announce two keynote speakers for the #FUZZING'25 workshop (part of @issta_conf at Trondheim, Norway): [*] Will Wilson, CEO and Co-Founder of Antithesis [*] Miryung Kim, Professor and Vice Chair of Graduate Studies at UCLA conf.researchr.org/home/issta-2...
183
Reposted by Marcel Böhme
Jonathan Aldrich @jonathanaldrich.bsky.social · 19/05/2025
All @acm.org publications will be 100% Open Access as of January 2026. When we announced this at POPL and CHI this year, conference participants spontaneously erupted in applause. The CS community is excited about ACM's move to OA!
17332
Marcel Böhme @mboehme.bsky.social · 03/05/2025
✨️ Now that #ICSE25 is over, it's time to get your papers ready for #ASE25 (30th May)! 📢 Here is what's new: * Major Revision v2.0 * Review criteria for tech. & experience papers * Policy on LLM-assisted Reviews * Auto-bidding (TPMS) * Rapid Response Reliable Reviewers 👇 For more details, read on.
12413
Reposted by Marcel Böhme
International Conference on Automated Software Engineering (ASE) @aseconf.bsky.social · 30/04/2025
📆 One month to go! The ASE 2025 Research Papers submission deadline is approaching: 30 May. We welcome impactful ideas and results that advance the state of the art in software engineering. 😉 #ASE2025 #SoftwareEngineering #CallForPapers
074
Marcel Böhme @mboehme.bsky.social · 28/04/2025
I'll be at #ICSE'25 in Ottawa for the week. If you see me, come and say Hi 👋 Looking forward to amazing research discussions!
The Maman sculpture, which depicts a spider, is among the world's largest, measuring over 30 ft high and over 33 ft wide (9.27 x 8.91 x 10.24 metres).
0150
Marcel Böhme @mboehme.bsky.social · 26/04/2025
Feature of our #ICLR'25 Spotlight paper, just presented in Singapore. www.mpi-sp.org/81927/news_p...
mpi-sp.org
How solving classic probability problems can help computer scientists find bugs
How solving classic probability problems can help computer scientists find bugs
0133
Marcel Böhme @mboehme.bsky.social · 24/04/2025
Our paper "Top Score on the Wrong Exam" paper will be presented at #ISSTA25 🐣 in Trondheim! 📝https://mpi-softsec.github.io/papers/ISSTA25-topscore.pdf 🧑‍💻https://github.com/niklasrisse/TopScoreWrongExam // @nrisse.bsky.social @fuzzing.bsky.social
1205
Reposted by Marcel Böhme
Fredrik Dahlgren @fegge.bsky.social · 16/04/2025
My team at Trail of Bits is hiring! 🎉 If you enjoy building and breaking novel cryptographic protocols like threshold signature schemes and zero-knowledge proof systems please come and work with us! apply.workable.com/trailofbits/...
apply.workable.com
Senior Security Engineer, Cryptography - Trail of Bits
Who We AreFounded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most ch...
043
Marcel Böhme @mboehme.bsky.social · 13/04/2025
😒 Citing a paper in 2020: Google Search gives you 20 entries. Non contains a bibtex. 🥴 Citing a paper in 2025: Google Search gives you a bibtex. 2 authors are made up and 6 missed.
2302
Marcel Böhme @mboehme.bsky.social · 12/04/2025
Benchmarks are our measures of progress. Or are they? Looking forward to exploring promises & perils of measuring tool capabilities @ SBFT'25! Thanks Gunel, Vincenzo, and Matteo for the invite! 👩‍🏭 sbft25.github.io (co-located w/ ICSE'25 in Ottawa) 📅 28.04. 11:00 GMT-4 (Also, live on Twitch)
091
Reposted by Marcel Böhme
Advanced Fuzzing League @aflplusplus.bsky.social · 31/03/2025
🚨 LibAFL 0.15.2 🚨 - Rust 2024 edition - LibAFL_Unicorn - Use LibAFL rand types for other crates - Allow logging to StatsD - LibAFL_QEMU updates like binary-only ASan in Rust 🦀🦀🦀, inputs via StdIn, better snapshots And so much more: github.com/AFLplusplus/... #LibAFL #Fuzzing #AFLplusplus
github.com
Release 0.15.2 · AFLplusplus/LibAFL
What's Changed Add statistics. Move client stats from Monitor to EventManager by @Evian-Zhang in #2940 Update MIGRATION by @Evian-Zhang in #2947 Move to just by @tokatoka in #2924 Small improveme...
0174