2025
"A five-year-old could understand it" versus "This is way too confusing": Exploring Non-expert Understandings and Perceptions of Cybersecurity Definitions.
Proceedings of the 2025 CHI Conference on Human Factors in Computing Systems, 2025

2023
Who Comes Up with this Stuff? Interviewing Authors to Understand How They Produce Security Advice.
Proceedings of the Nineteenth Symposium on Usable Privacy and Security, 2023

SecretBench: A Dataset of Software Secrets.
Proceedings of the 20th IEEE/ACM International Conference on Mining Software Repositories, 2023

What Challenges Do Developers Face About Checked-in Secrets in Software Artifacts?
Proceedings of the 45th IEEE/ACM International Conference on Software Engineering, 2023

Analyzing Cybersecurity Definitions for Non-experts.
Proceedings of the Human Aspects of Information Security and Assurance, 2023

2022
What are the Practices for Secret Management in Software Artifacts?
Proceedings of the IEEE Secure Development Conference, 2022

2021
Investigating Web Service Account Remediation Advice.
Proceedings of the Seventeenth Symposium on Usable Privacy and Security, 2021

2018
Mining Threat Intelligence about Open-Source Projects and Libraries from Code Repository Issues and Bug Reports.
Proceedings of the 2018 IEEE International Conference on Intelligence and Security Informatics, 2018