| 2026 | ECOOP | Scaling Bottom-Up IFDS Taint Analysis with Optimized Data-Flow Encoding. | Fabian Schiebel, Eric Bodden |
| 2026 | ICSoft | Trustworthy AI: Operationalizing Responsibility in Lifecycle-Aware AI Threat Modeling through RACI. | Faiza Tahir, Ubaid Ullah, Eric Bodden |
| 2026 | MODELSWARD | Using Attack and Failure Propagation Analysis for Context-Aware Security Control Suggestions. | Roman Trentinaglia, Thorsten Koch, Eric Bodden |
| 2026 | SANER | From Legacy Designs to Vulnerability Fixes: Understanding SAST Adoption in Non-Technological Companies. | Luis Henrique Vieira Amaral, Michael Schlichtig, Wagner Emanuel, Joilton Almeida, Carine Ferreira, Jerome Kempf, Rodrigo Bonifcio, Eric Bodden, Laerte Peotta, Gustavo Pinto, Mrcio Ribeiro |
| 2026 | SANER | Source Code-Driven GDPR Documentation: Supporting RoPA with Assessor View. | Mugdha Khedkar, Michael Schlichtig, Eric Bodden |
| 2026 | SANER | Static Analysis Traces can Help Dynamic Symbolic Execution: a Replication Study. | Sriteja Kummita, Fabian Schiebel, Eric Bodden, Miao Miao, Shiyi Wei |
| 2026 | SANER | InterGNN: Using Context for Detecting Inter-Procedural Vulnerabilities. | Sebastian Sierra, Jochen Quante, Eric Bodden |
| 2024 | ECOOP | Scaling Interprocedural Static Data-Flow Analysis to Large C/C++ Applications: An Experience Report. | Fabian Schiebel, Florian Sattler, Philipp Dominik Schubert, Sven Apel, Eric Bodden |
| 2024 | ECOOP | Java Bytecode Normalization for Code Similarity Analysis. | Stefan Schott, Serena Elisa Ponta, Wolfram Fischer, Jonas Klauke, Eric Bodden |
| 2024 | ICSE | Symbol-Specific Sparsification of Interprocedural Distributive Environment Problems. | Kadiray Karakaya, Eric Bodden |
| 2024 | ICSE | TypeEvalPy: A Micro-benchmarking Framework for Python Type Inference Tools. | Ashwin Prasad Shivarpatna Venkatesh, Samkutty Sabu, Jiawei Wang, Amir M. Mir, Li Li, Eric Bodden |
| 2024 | TACAS | SootUp: A Redesign of the Soot Static Analysis Framework. | Kadiray Karakaya, Stefan Schott, Jonas Klauke, Eric Bodden, Markus Schmidt, Linghui Luo, Dongjie He |
| 2023 | ICSE | UPCY: Safely Updating Outdated Dependencies. | Andreas Dann, Ben Hermann, Eric Bodden |
| 2023 | ICST | Two Sparsification Strategies for Accelerating Demand-Driven Pointer Analysis. | Kadiray Karakaya, Eric Bodden |
| 2023 | ICST | Model Generation For Java Frameworks. | Linghui Luo, Goran Piskachev, Ranjith Krishnamurthy, Julian Dolby, Eric Bodden, Martin Schf |
| 2022 | ISSTA | A large-scale study of usability criteria addressed by static analysis tools. | Marcus Nachtigall, Michael Schlichtig, Eric Bodden |
| 2022 | MODELSWARD | Integrating Security Protocols in Scenario-based Requirements Specifications. | Thorsten Koch, Sascha Trippel, Stefan Dziwok, Eric Bodden |
| 2022 | SCAM | To what extent can we analyze Kotlin programs using existing Java taint analysis tools? | Ranjith Krishnamurthy, Goran Piskachev, Eric Bodden |
| 2021 | AsiaCCS | A Systematic Hardening of Java's Information Hiding. | Philipp Holzinger, Eric Bodden |
| 2021 | ECOOP | Dealing with Variability in API Misuse Specification. | Rodrigo Bonifcio, Stefan Krger, Krishna Narasimhan, Eric Bodden, Mira Mezini |
| 2021 | ECOOP | Lossless, Persisted Summarization of Static Callgraph, Points-To and Data-Flow Analysis. | Philipp Dominik Schubert, Ben Hermann, Eric Bodden |
| 2021 | ECSA | Ensuring threat-model assumptions by using static code analyses. | Johannes Geismann, Bastian Haverkamp, Eric Bodden |
| 2021 | ISSTA | Automated cell header generator for Jupyter notebooks. | Ashwin Prasad Shivarpatna Venkatesh, Eric Bodden |
| 2021 | SCAM | SootFX: A Static Code Feature Extraction Tool for Java and Android. | Kadiray Karakaya, Eric Bodden |
| 2021 | SCAM | SecuCheck: Engineering configurable taint analysis for software developers. | Goran Piskachev, Ranjith Krishnamurthy, Eric Bodden |
| 2021 | SCAM | Into the Woods: Experiences from Building a Dataflow Analysis Framework for C/C++. | Philipp Dominik Schubert, Richard Leer, Ben Hermann, Eric Bodden |
| 2021 | SCAM | Modeling the Effects of Global Variables in Data-Flow Analysis for C/C++. | Philipp Dominik Schubert, Florian Sattler, Fabian Schiebel, Ben Hermann, Eric Bodden |
| 2020 | CGO | CogniCrypt | Stefan Krger, Karim Ali, Eric Bodden |
| 2020 | ICSE | Heaps'n leaks: how heap snapshots improve Android taint analysis. | Manuel Benz, Erik Krogh Kristensen, Linghui Luo, Nataniel P. Borges, Eric Bodden, Andreas Zeller |
| 2020 | MODELS | Scenario-based specification of security protocols and transformation to security model checkers. | Thorsten Koch, Stefan Dziwok, Jrg Holtmann, Eric Bodden |
| 2019 | ECOOP | MagpieBridge: A General Approach to Integrating Static Analyses into IDEs and Editors (Tool Insights Paper). | Linghui Luo, Julian Dolby, Eric Bodden |
| 2019 | ESEM | The Impact of Developer Experience in Using Java Cryptography. | Mohammadreza Hazhirpasand, Mohammad Ghafari, Stefan Krger, Eric Bodden, Oscar Nierstrasz |
| 2019 | FM | AuthCheck: Program-State Analysis for Access-Control Vulnerabilities. | Goran Piskachev, Tobias Petrasch, Johannes Spth, Eric Bodden |
| 2019 | ICSA | Architectural Runtime Verification. | Lars Stockmann, Sven Laux, Eric Bodden |
| 2019 | ISSTA | Codebase-adaptive detection of security-relevant methods. | Goran Piskachev, Lisa Nguyen Quang Do, Eric Bodden |
| 2019 | PLDI | SootDiff: bytecode comparison across different Java compilers. | Andreas Dann, Ben Hermann, Eric Bodden |
| 2019 | PLDI | Know your analysis: how instrumentation aids understanding static analysis. | Philipp Dominik Schubert, Richard Leer, Ben Hermann, Eric Bodden |
| 2019 | TACAS | PhASAR: An Inter-procedural Static Analysis Framework for C/C++. | Philipp Dominik Schubert, Ben Hermann, Eric Bodden |
| 2018 | ECOOP | CrySL: An Extensible Approach to Validating the Correct Usage of Cryptographic APIs. | Stefan Krger, Johannes Spth, Karim Ali, Eric Bodden, Mira Mezini |
| 2018 | ICSE | Self-adaptive static analysis. | Eric Bodden |
| 2018 | ICSE | State of the systems security. | Eric Bodden |
| 2018 | ICSE | VISUFLOW: a debugging environment for static analyses. | Lisa Nguyen Quang Do, Stefan Krger, Patrick Hill, Karim Ali, Eric Bodden |
| 2018 | ISSTA | The secret sauce in efficient and precise static analysis: the beauty of distributive, summary-based static analyses (and how to master them). | Eric Bodden |
| 2017 | ICSE | The Soot-Based Toolchain for Analyzing Android Apps. | Steven Arzt, Siegfried Rasthofer, Eric Bodden |
| 2017 | ICSE | Cheetah: just-in-time taint analysis for Android apps. | Lisa Nguyen Quang Do, Karim Ali, Benjamin Livshits, Eric Bodden, Justin Smith, Emerson R. Murphy-Hill |
| 2017 | ISSTA | Just-in-time static analysis. | Lisa Nguyen Quang Do, Karim Ali, Benjamin Livshits, Eric Bodden, Justin Smith, Emerson R. Murphy-Hill |
| 2017 | SP | Hardening Java's Access Control by Abolishing Implicit Privilege Elevation. | Philipp Holzinger, Ben Hermann, Johannes Lerch, Eric Bodden, Mira Mezini |
| 2016 | CCS | An In-Depth Study of More Than Ten Years of Java Exploitation. | Philipp Holzinger, Stefan Triller, Alexandre Bartel, Eric Bodden |
| 2016 | ECOOP | Boomerang: Demand-Driven Flow- and Context-Sensitive Pointer Analysis for Java. | Johannes Spth, Lisa Nguyen Quang Do, Karim Ali, Eric Bodden |
| 2016 | ICSE | StubDroid: automatic inference of precise data-flow summaries for the android framework. | Steven Arzt, Eric Bodden |
| 2016 | ICSE | Jumping through hoops: why do Java developers struggle with cryptography APIs? | Sarah Nadi, Stefan Krger, Mira Mezini, Eric Bodden |
| 2016 | ISoLA | Information Flow Analysis for Go. | Eric Bodden, Ka I Pun, Martin Steffen, Volker Stolz, Anna-Katharina Wickert |
| 2016 | NDSS | Harvesting Runtime Values in Android Applications That Feature Anti-Analysis Techniques. | Siegfried Rasthofer, Steven Arzt, Marc Miltenberger, Eric Bodden |
| 2016 | PLDI | Towards cross-platform cross-language analysis with soot. | Steven Arzt, Tobias Kussmaul, Eric Bodden |
| 2016 | PLDI | Toward an automated benchmark management system. | Lisa Nguyen Quang Do, Michael Eichberg, Eric Bodden |
| 2015 | ICSE | IccTA: Detecting Inter-Component Privacy Leaks in Android Apps. | Li Li, Alexandre Bartel, Tegawend F. Bissyand, Jacques Klein, Yves Le Traon, Steven Arzt, Siegfried Rasthofer, Eric Bodden, Damien Octeau, Patrick D. McDaniel |
| 2015 | ICSE | Mining Apps for Abnormal Usage of Sensitive Data. | Vitalii Avdiienko, Konstantin Kuznetsov, Alessandra Gorla, Andreas Zeller, Steven Arzt, Siegfried Rasthofer, Eric Bodden |
| 2015 | OOPSLA | Towards secure integration of cryptographic software. | Steven Arzt, Sarah Nadi, Karim Ali, Eric Bodden, Sebastian Erdweg, Mira Mezini |
| 2015 | PLDI | Using targeted symbolic execution for reducing false-positives in dataflow analysis. | Steven Arzt, Siegfried Rasthofer, Robert Hahn, Eric Bodden |
| 2015 | RAID | jk: Using Dynamic Analysis to Crawl and Test Modern Web Applications. | Giancarlo Pellegrino, Constantin Tschrtz, Eric Bodden, Christian Rossow |
| 2015 | WISTP | How Current Android Malware Seeks to Evade Automated Code Analysis. | Siegfried Rasthofer, Irfan Asrar, Stephan Huber, Eric Bodden |
| 2014 | CCS | Denial-of-App Attack: Inhibiting the Installation of Android Apps on Stock Phones. | Steven Arzt, Stephan Huber, Siegfried Rasthofer, Eric Bodden |
| 2014 | ICSE | Reviser: efficiently updating IDE-/IFDS-based data-flow analyses in response to incremental program changes. | Steven Arzt, Eric Bodden |
| 2014 | NDSS | A Machine-learning Approach for Classifying and Categorizing Android Sources and Sinks. | Siegfried Rasthofer, Steven Arzt, Eric Bodden |
| 2014 | OOPSLA | Variational Data Structures: Exploring Tradeoffs in Computing with Variability. | Eric Walkingshaw, Christian Kstner, Martin Erwig, Sven Apel, Eric Bodden |
| 2014 | PLDI | FlowDroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. | Steven Arzt, Siegfried Rasthofer, Christian Fritz, Eric Bodden, Alexandre Bartel, Jacques Klein, Yves Le Traon, Damien Octeau, Patrick D. McDaniel |
| 2014 | PLDI | TS4J: a fluent interface for defining and computing typestate analyses. | Eric Bodden |
| 2014 | PLDI | How to build the perfect Swiss army knife, and keep it sharp?: Challenges for the soot program-analysis framework in the light of past, current and future demands. | Eric Bodden |
| 2013 | CCS | Easily instrumenting android applications for security purposes. | Eric Bodden |
| 2013 | PLDI | SPL | Eric Bodden, Trsis Toldo, Mrcio Ribeiro, Claus Brabrand, Paulo Borba, Mira Mezini |
| 2013 | RV | Instrumenting Android and Java Applications as Easy as abc. | Steven Arzt, Siegfried Rasthofer, Eric Bodden |
| 2013 | RV | Distributed Finite-State Runtime Monitoring with Aggregated Events. | Kevin Falzon, Eric Bodden, Rahul Purandare |
| 2012 | ISoLA | Delta-Oriented Monitor Specification. | Eric Bodden, Kevin Falzon, Ka I Pun, Volker Stolz |
| 2012 | ISoLA | Challenges in Defining a Programming Language for Provably Correct Dynamic Analyses. | Eric Bodden, Andreas Follner, Siegfried Rasthofer |
| 2012 | ISSTA | RefaFlex: safer refactorings for reflective Java programs. | Andreas Thies, Eric Bodden |
| 2012 | PLDI | Static flow-sensitive & context-sensitive information-flow analysis for software product lines: position paper. | Eric Bodden |
| 2012 | PLDI | Inter-procedural data-flow analysis with IFDS/IDE and Soot. | Eric Bodden |
| 2012 | PLDI | InvokeDynamic support in Soot. | Eric Bodden |
| 2011 | ICSE | Taming reflection: Aiding static analysis in the presence of reflection and custom class loaders. | Eric Bodden, Andreas Sewe, Jan Sinschek, Hela Oueslati, Mira Mezini |
| 2011 | ISSTA | Continuation equivalence: a correctness criterion for static optimizations of dynamic analyses. | Eric Bodden |
| 2011 | RV | MOPBox: A Library Approach to Runtime Verification - (Tool Demonstration). | Eric Bodden |
| 2010 | IRI | Effective API navigation and reuse. | Awny Alnusair, Tian Zhao, Eric Bodden |
| 2010 | ICSE | Efficient hybrid typestate analysis by determining continuation-equivalent states. | Eric Bodden |
| 2010 | RV | Clara: Partially Evaluating Runtime Monitors at Compile Time - Tutorial Supplement. | Eric Bodden, Patrick Lam |
| 2010 | RV | Clara: A Framework for Partially Evaluating Finite-State Runtime Monitors Ahead of Time. | Eric Bodden, Patrick Lam, Laurie J. Hendren |
| 2010 | RV | Reducing Configurations to Monitor in a Software Product Line. | Chang Hwan Peter Kim, Eric Bodden, Don S. Batory, Sarfraz Khurshid |
| 2008 | ISSTA | Racer: effective race detection using aspectj. | Eric Bodden, Klaus Havelund |
| 2007 | ECOOP | A Staged Static Program Analysis to Improve the Performance of Runtime Monitoring. | Eric Bodden, Laurie J. Hendren, Ondrej Lhotk |
| 2007 | ICSoft | Domain-Specific Modelling With Atom3. | Hans Vangheluwe, Ximeng Sun, Eric Bodden |
| 2007 | OOPSLA | The design and implementation of formal monitoring techniques. | Eric Bodden |
| 2007 | RV | Collaborative Runtime Verification with Tracematches. | Eric Bodden, Laurie J. Hendren, Patrick Lam, Ondrej Lhotk, Nomair A. Naeem |
| 2006 | MPC | Aspects and Data Refinement. | Pavel Avgustinov, Eric Bodden, Elnar Hajiyev, Oege de Moor, Neil Ongkingco, Damien Sereni, Ganesh Sittampalam, Julian Tibble |
| 2006 | OOPSLA | Efficient trace monitoring. | Pavel Avgustinov, Julian Tibble, Eric Bodden, Laurie J. Hendren, Ondrej Lhotk, Oege de Moor, Neil Ongkingco, Ganesh Sittampalam |
| 2004 | OOPSLA | A lightweight LTL runtime verification tool for java. | Eric Bodden |
| 2003 | OOPSLA | A high-level view of Java applications. | Eric Bodden |