Marcelo D'Amorim
Bio
My research interests are in Software Engineering and Programming Languages, with a focus on improving software reliability through program analysis and systematic testing. Software bugs are expensive and inevitable as software is mostly written by humans or automatically synthesized via ML. My research focuses at developing practical methods to prevent, detect, and fix bugs in code. As part of my research, I develop tools to automate software testing and debugging activities.
Education
Ph.D. University of Illinois Urbana-Champaign 2007
M.S. Universidade Federal de Pernambuco 2001
B.A. Universidade Federal de Pernambuco 1996
Area(s) of Expertise
Artificial Intelligence and Intelligent Agents
Software Engineering and Programming Languages
Publications
- An Empirical Analysis of Cross-OS Portability Issues in Python Projects , International Conference on Mining Software Repositories (MSR) (2026)
- Configuration Defects in Kubernetes , IEEE Transactions on Software Engineering (2026)
- Fine-Grained Analyses for Evolution-Aware Runtime Verification , IEEE/ACM International Conference on Software Engineering (ICSE) (2026)
- How Effective Is Coverage-Guided Fuzzing to Test Deep Learning Library APIs? , IEEE International Conference on Software Testing, Verification and Validation (ICST) (2026)
- Improving Deep Learning Library Testing with Machine Learning , (2026)
- Improving Deep Learning Library Testing with Machine Learning , arXiv (Cornell University) (2026)
- Learning Compiler Fuzzing Mutators from Historical Bugs , International Conference on Mining Software Repositories (MSR) (2026)
- Misbehavior Forecasting for Focused Autonomous Driving Systems Testing , IEEE/ACM International Conference on Software Engineering (ICSE) (2026)
- PyMOP: A Runtime Verification Tool for Python , (2026)
- SmartOracle -- An Agentic Approach to Mitigate Noise in Differential Oracles , arXiv (Cornell University) (2026)
Grants
Configuration scripts are used to manage system configurations and provision infrastructure at scale. Configuration scripts are susceptible of including security weaknesses such as hard-coded passwords, which can facilitate large-scale data breaches, as well as provisioned systems being compromised. We propose an automated technique to identify security weaknesses so that configuration scripts do not cause large-scale security attacks and data breaches. We will build upon our recent research and construct eSLIC, which will overcome previous limitations of our initial prototype and facilitate wide-spread security static analysis of infrastructure. We will make eSLIC available for OSS and practitioners in industry.