Teaching
Project group — Conceived & Led, Paderborn University, Department of Computer Science
Winter 2024 – Summer 2025
Year-long project group (Winter 2024 – Summer 2025) in which Master’s students developed a SonarQube plugin for detecting security vulnerabilities in AI-enabled software systems. The group produced the SecAI plugin, integrating static analysis with LLM-assisted repair suggestions.
Bachelor's course — Teaching Assistant, Paderborn University, Department of Computer Science
Summer 2020
Undergraduate course on secure software development practices. Topics include threat modeling, secure coding guidelines, cryptographic APIs, static analysis for security, and common vulnerability classes (OWASP Top 10).
Bachelor's practical course — Teaching Assistant, Paderborn University, Department of Computer Science
Winter 2021, Winter 2022
Undergraduate practical course in which student teams develop a software project over one semester applying software engineering methods including requirements engineering, design, testing, and agile practices.
Master's course — Teaching Assistant, Paderborn University, Department of Computer Science
Winter 2019, Winter 2020, Winter 2021, Winter 2023, Winter 2024
Graduate course covering the design and implementation of static program analyses for large-scale software systems. Topics include data-flow analysis, pointer analysis, taint analysis, and the use of frameworks such as Soot and WALA.
Thesis Supervision
Bachelor's and master's theses supervised at Paderborn University and TU Darmstadt, spanning static analysis, cryptographic API misuse, AI-assisted repair, Android privacy, benchmarking, usability, and quantum key distribution post-processing.
Interested in writing a thesis under my supervision? See the Information for Students page for topics, formalities, and guidance.
- Automated Privacy Assessment for Android Applications: A DPV Visualisation Approach (2025)
- Improving Security in LLM-Generated Code: A Static-Analysis-Driven Code Generation Approach for Enhanced Security (2025)
- Automatically Generating the Data Safety Section Using AutoPRICE (2025)
- Explaining Privacy-Relevant Program Slices to Android App Developers (2025)
- Extending CrySL and CogniCrypt to Enable the Specification and Detection of More FUM Types (2023)
- Optimisation of Low-Density Parity-Check Codes for Quantum Key Distribution Post-Processing (2023)
- Comparison of Information Reconciliation Protocol Cascade to LDPC in Quantum Key Distribution (2023)
- CamBenchCAP — Creating a Benchmark to Test Analysis Capabilities of Java Cryptographic API Misuse Detectors (2022)
- Extending CogniCryptSAST to Detect and Understand Subsequent Errors for Crypto Misuses in the Wild (2022)
- Improved Presentation of Subsequent Errors in Analysis Results of CogniCryptSAST (2022)
- The Comparison of Two Static Analysis Tools for Security Testing — Codyze and CogniCryptSAST (2022)
- Improving Documentation Generation for Cryptographic APIs — A Reinterpretation of CogniCryptDOC (2021)
- Testing and Evaluation of CogniCrypt and CrySL in the Context of Non-Cryptography-Related API Misuses (2020)
- Automatically Applying Recommendations from Regulators to Cryptography Specification Codes (2020)