| 2025 | CCS | It Should Be Easy but... New Users' Experiences and Challenges with Secret Management Tools. | Lorenzo Neil, Deepthi Mungara, Laurie A. Williams, Yasemin Acar, Bradley Reaves |
| 2025 | ICSE | AssetHarvester: A Static Analysis Tool for Detecting Secret-Asset Pairs in Software Artifacts. | Setu Kumar Basak, K. Virgil English, Ken Ogura, Vitesh Kambara, Bradley Reaves, Laurie A. Williams |
| 2025 | ICSE | Leveraging Large Language Models to Detect NPM Malicious Packages. | Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, Laurie A. Williams |
| 2024 | ACSAC | Towards a Taxonomy of Challenges in Security Control Implementation. | Md. Rayhanur Rahman, Brandon Wroblewski, Mahzabin Tamanna, Imranur Rahman, Andrew Anufryienak, Laurie A. Williams |
| 2024 | ICDM | ChronoCTI: Mining Knowledge Graph of Temporal Relations Among Cyberattack Actions. | Rayhanur Rahman, Brandon Wroblewski, Quinn Matthews, Brantley Morgan, Timothy Menzies, Laurie A. Williams |
| 2024 | MSR | MalwareBench: Malware samples are not enough. | Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, Laurie A. Williams |
| 2024 | SP | Just another copy and paste? Comparing the security vulnerabilities of ChatGPT generated code and StackOverflow answers. | Sivana Hamer, Marcelo d'Amorim, Laurie A. Williams |
| 2023 | ESEM | A Comparative Study of Software Secrets Reporting by Secret Detection Tools. | Setu Kumar Basak, Jamison Cox, Bradley Reaves, Laurie A. Williams |
| 2023 | ICSE | What Challenges Do Developers Face About Checked-in Secrets in Software Artifacts? | Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, Laurie A. Williams |
| 2023 | ICSE | Do Software Security Practices Yield Fewer Vulnerabilities? | Nusrat Zahan, Shohanuzzaman Shohan, Dan Harris, Laurie A. Williams |
| 2023 | MSR | SecretBench: A Dataset of Software Secrets. | Setu Kumar Basak, Lorenzo Neil, Bradley Reaves, Laurie A. Williams |
| 2022 | ICSE | What are Weak Links in the npm Supply Chain? | Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Shekhar Maddila, Laurie A. Williams |
| 2022 | MSR | Dazzle: Using Optimized Generative Adversarial Networks to Address Security Data Class Imbalance Issue. | Rui Shu, Tianpei Xia, Laurie A. Williams, Tim Menzies |
| 2021 | ESEM | A comparative study of vulnerability reporting by software composition analysis tools. | Nasif Imtiaz, Seaver Thorn, Laurie A. Williams |
| 2021 | ICSE | Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard. | Sarah Elder, Nusrat Zahan, Valeri Kozarev, Rui Shu, Tim Menzies, Laurie A. Williams |
| 2021 | ISSRE | Software Security Readiness and Deployment. | Saikath Bhattacharya, Munindar P. Singh, Laurie A. Williams |
| 2020 | ICDM | A Literature Review on Mining Cyberthreat Intelligence from Unstructured Texts. | Md. Rayhanur Rahman, Rezvan Mahdavi-Hezaveh, Laurie A. Williams |
| 2020 | ICSE | Gang of eight: a defect taxonomy for infrastructure as code scripts. | Akond Rahman, Effat Farhana, Chris Parnin, Laurie A. Williams |
| 2019 | ESEM | Characterizing Attacker Behavior in a Cybersecurity Penetration Testing Competition. | Nuthan Munaiah, Akond Rahman, Justin Pelletier, Laurie A. Williams, Andrew Meneely |
| 2019 | ICSE | The seven sins: security smells in infrastructure as code scripts. | Akond Rahman, Chris Parnin, Laurie A. Williams |
| 2019 | ISSRE | How Do Developers Act on Static Analysis Alerts? An Empirical Study of Coverity Usage. | Nasif Imtiaz, Brendan Murphy, Laurie A. Williams |
| 2019 | MSR | Challenges with responding to static analysis tool alerts. | Nasif Imtiaz, Akond Rahman, Effat Farhana, Laurie A. Williams |
| 2018 | ICSE | Identifying security issues in software development: are keywords enough? | Patrick Morrison, Tosin Daniel Oyetoyan, Laurie A. Williams |
| 2018 | ICSE | Are vulnerabilities discovered and resolved like other defects? | Patrick J. Morrison, Rahul Pandita, Xusheng Xiao, Ram Chillarege, Laurie A. Williams |
| 2018 | ICSE | What questions do programmers ask about configuration as code? | Akond Rahman, Asif Partho, Patrick Morrison, Laurie A. Williams |
| 2018 | ICSE | Defect prediction metrics for infrastructure as code scripts in DevOps. | Akond Rahman, Jonathan Stallings, Laurie A. Williams |
| 2018 | ICSE | Continuously integrating security. | Laurie A. Williams |
| 2018 | ICST | Characterizing Defective Configuration Scripts Used for Continuous Deployment. | Akond Rahman, Laurie A. Williams |
| 2017 | ESORICS | Teaching Secure Software Development Through an Online Course. | Christopher Theisen, Ted Zhu, Kevin M. Oliver, Laurie A. Williams |
| 2017 | ICSE | How good is a security policy against real breaches?: a HIPAA case study. | zgr Kafali, Jasmine Jones, Megan Petruso, Laurie A. Williams, Munindar P. Singh |
| 2017 | ICSE | Characterizing Experimentation in Continuous Deployment: A Case Study on Bing. | Katja Kevic, Brendan Murphy, Laurie A. Williams, Jennifer Beckmann |
| 2017 | ICSE | Measuring Security Practice Use: A Case Study at IBM. | Patrick Morrison, Benjamin H. Smith, Laurie A. Williams |
| 2017 | ICSE | Which Factors Influence Practitioners' Usage of Build Automation Tools? | Akond Rahman, Asif Partho, David Meder, Laurie A. Williams |
| 2017 | ICSE | Predicting Android Application Security and Privacy Risk with Static Code Metrics. | Akond Rahman, Priysha Pradhan, Asif Partho, Laurie A. Williams |
| 2017 | ICSE | Writing good software engineering research papers: revisited. | Christopher Theisen, Marcel Dunaiski, Laurie A. Williams, Willem Visser |
| 2017 | ICSE | Risk-Based Attack Surface Approximation: How Much Data Is Enough? | Christopher Theisen, Kim Herzig, Brendan Murphy, Laurie A. Williams |
| 2016 | ESEM | DIGS: A Framework for Discovering Goals for Security Requirements Engineering. | Maria Riaz, Jonathan Stallings, Munindar P. Singh, John Slankas, Laurie A. Williams |
| 2016 | ICSE | Software security in DevOps: synthesizing practitioners' perceptions and practices. | Akond Ashfaque Ur Rahman, Laurie A. Williams |
| 2016 | ICSE | Continuous deployment at Facebook and OANDA. | Tony Savor, Mitchell Douglas, Michael Gentili, Laurie A. Williams, Kent L. Beck, Michael Stumm |
| 2016 | ICSE | Software security education at scale. | Christopher Theisen, Laurie A. Williams, Kevin M. Oliver, Emerson R. Murphy-Hill |
| 2016 | RE | NANE: Identifying Misuse Cases Using Temporal Norm Enactments. | zgr Kafali, Munindar P. Singh, Laurie A. Williams |
| 2016 | RE | Systematically Developing Prevention, Detection, and Response Patterns for Security Requirements. | Maria Riaz, Sarah Elder, Laurie A. Williams |
| 2015 | ICSE | Approximating Attack Surfaces with Stack Traces. | Christopher Theisen, Kim Herzig, Patrick Morrison, Brendan Murphy, Laurie A. Williams |
| 2015 | SCAM | Discovering likely mappings between APIs using text mining. | Rahul Pandita, Raoul Praful Jetley, Sithu D. Sudarsan, Laurie A. Williams |
| 2014 | ACSAC | Relation extraction for inferring access control rules from natural language artifacts. | John Slankas, Xusheng Xiao, Laurie A. Williams, Tao Xie |
| 2014 | ESEM | Using templates to elicit implied security requirements from functional requirements - a controlled experiment. | Maria Riaz, John Slankas, Jason Tyler King, Laurie A. Williams |
| 2014 | ISSRE | Access Control Policy Evolution: An Empirical Study. | JeeHyun Hwang, Da Young Lee, Laurie A. Williams, Mladen A. Vouk |
| 2014 | RE | Towards a framework to measure security expertise in requirements analysis. | Hanan Hibshi, Travis D. Breaux, Maria Riaz, Laurie A. Williams |
| 2014 | RE | Hidden in plain sight: Automatically identifying security requirements from natural language artifacts. | Maria Riaz, Jason Tyler King, John Slankas, Laurie A. Williams |
| 2013 | ESEM | Have Agile Techniques been the Silver Bullet for Software Development at Microsoft? | Brendan Murphy, Christian Bird, Thomas Zimmermann, Laurie A. Williams, Nachiappan Nagappan, Andrew Begel |
| 2013 | ICSE | Proposing regulatory-driven automated test suites for electronic health record systems. | Patrick Morrison, Casper Holmgreen, Aaron Massey, Laurie A. Williams |
| 2013 | ISSRE | An experience report for software quality evaluation in highly iterative development methodology using traditional metrics. | Kumi Jinzenji, Takashi Hoshino, Laurie A. Williams, Kenji Takahashi |
| 2013 | ISSRE | Using software reliability models for security assessment - Verification of assumptions. | Da Young Lee, Mladen A. Vouk, Laurie A. Williams |
| 2013 | ISSRE | To branch or not to branch that is the question. | Brendan Murphy, Laurie A. Williams |
| 2013 | ISSRE | Non-operational testing of software for security issues. | Shweta Subramani, Mladen A. Vouk, Laurie A. Williams |
| 2012 | ISSRE | Metric-Based Quality Evaluations for Iterative Software Development Approaches Like Agile. | Kumi Jinzenji, Takashi Hoshino, Laurie A. Williams, Kenji Takahashi |
| 2012 | RE | Security requirements patterns: understanding the science behind the art of pattern writing. | Maria Riaz, Laurie A. Williams |
| 2011 | ESEM | One Technique is Not Enough: A Comparison of Vulnerability Discovery Techniques. | Andrew Austin, Laurie A. Williams |
| 2011 | ESEM | Scrum + Engineering Practices: Experiences of Three Microsoft Teams. | Laurie A. Williams, Gabe Brown, Adam Meltzer, Nachiappan Nagappan |
| 2011 | ICSE | Evaluating access control of open source electronic health record systems. | Eric Helms, Laurie A. Williams |
| 2011 | ICSE | Socio-technical developer networks: should we trust our measurements? | Andrew Meneely, Laurie A. Williams |
| 2011 | ICSE | An initial study on the use of execution complexity metrics as indicators of software vulnerabilities. | Yonghee Shin, Laurie A. Williams |
| 2011 | ICST | Using SQL Hotspots in a Prioritization Heuristic for Detecting All Types of Web Application Vulnerabilities. | Ben H. Smith, Laurie A. Williams |
| 2011 | ICST | An Empirical Study on the Relation between Dependency Neighborhoods and Failures. | Thomas Zimmermann, Nachiappan Nagappan, Kim Herzig, Rahul Premraj, Laurie A. Williams |
| 2011 | RE | The role of data use agreements in specifying legally compliant software requirements. | Jessica Young Schmidt, Annie I. Antn, Laurie A. Williams, Paul N. Otto |
| 2010 | ESEM | Strengthening the empirical analysis of the relationship between Linus' Law and software security. | Andrew Meneely, Laurie A. Williams |
| 2010 | ICSE | Towards improved security criteria for certification of electronic health record systems. | Andrew Austin, Ben H. Smith, Laurie A. Williams |
| 2010 | ICSE | Improving developer activity metrics with issue tracking annotations. | Andrew Meneely, Mackenzie Corcoran, Laurie A. Williams |
| 2010 | ICST | Does Hardware Configuration and Processor Load Impact Software Fault Observability? | Raza Abbas Syed, Brian Robinson, Laurie A. Williams |
| 2010 | ICST | Searching for a Needle in a Haystack: Predicting Security Vulnerabilities for Windows Vista. | Thomas Zimmermann, Nachiappan Nagappan, Laurie A. Williams |
| 2009 | CCS | Secure open source collaboration: an empirical study of linus' law. | Andrew Meneely, Laurie A. Williams |
| 2009 | ICST | Predicting Attack-prone Components. | Michael Gegick, Pete Rotella, Laurie A. Williams |
| 2009 | ICST | A Model Building Process for Identifying Actionable Static Analysis Alerts. | Sarah Smith Heckman, Laurie A. Williams |
| 2009 | ISSRE | On the Effectiveness of Unit Test Automation at Microsoft. | Laurie A. Williams, Gunnar Kudrjavets, Nachiappan Nagappan |
| 2009 | SIGCSE | On preparing students for distributed software development with a synchronous, collaborative development platform. | Andrew Meneely, Laurie A. Williams |
| 2008 | CCS | Prioritizing software security fortification throughcode-level metrics. | Michael Gegick, Laurie A. Williams, Jason A. Osborne, Mladen A. Vouk |
| 2008 | CCS | Is complexity really the enemy of software security? | Yonghee Shin, Laurie A. Williams |
| 2008 | ESEM | On establishing a benchmark for evaluating static analysis alert prioritization and classification techniques. | Sarah Smith Heckman, Laurie A. Williams |
| 2008 | ESEM | An empirical model to predict security vulnerabilities using code complexity metrics. | Yonghee Shin, Laurie A. Williams |
| 2008 | ICSE | MimEc: intelligent user notification of faults in the eclipse IDE. | Lucas Layman, Laurie A. Williams, Robert St. Amant |
| 2008 | ICSE | Proposing SQL statement coverage metrics. | Ben H. Smith, Yonghee Shin, Laurie A. Williams |
| 2008 | ICST | Empirical Software Change Impact Analysis using Singular Value Decomposition. | Mark Sherriff, Laurie A. Williams |
| 2008 | ISSRE | Ranking Attack-Prone Components with a Predictive Model. | Michael Gegick, Laurie A. Williams |
| 2008 | ITiCSE | ROSE: a repository of education-friendly open-source projects. | Andrew Meneely, Laurie A. Williams, Edward F. Gehringer |
| 2008 | OOPSLA | Privacy and security: what are you doing to keep the community safe? | Steven Fraser, Djenana Campara, Robert Gleichauf, Harriet Pearson, Peter P. Swire, Laurie A. Williams |
| 2008 | RE | Examining the Relationships between Performance Requirements and "Not a Problem" Defect Reports. | Chih-Wei Ho, Laurie A. Williams, Brian Robinson |
| 2007 | ESEM | Toward Reducing Fault Fix Time: Understanding Developer Behavior for the Design of Automated Fault Detection Tools. | Lucas Layman, Laurie A. Williams, Robert St. Amant |
| 2007 | ICSE | Using Automated Fix Generation to Secure SQL Statements. | Stephen Thomas, Laurie A. Williams |
| 2007 | ICSE | On the Impact of a Collaborative Pedagogy on African American Millennial Students in Software Engineering. | Laurie A. Williams, Lucas Layman, Kelli M. Slaten, Sarah B. Berenson, Carolyn B. Seaman |
| 2007 | ISSRE | Using In-Process Testing Metrics to Estimate Post-Release Field Quality. | Nachiappan Nagappan, Laurie A. Williams, Mladen A. Vouk, Jason A. Osborne |
| 2007 | ISSRE | Prioritization of Regression Tests using Singular Value Decomposition with Empirical Change Records. | Mark Sherriff, Mike Lake, Laurie A. Williams |
| 2007 | RE | Improving Performance Requirements Specifications from Field Failure Reports. | Chih-Wei Ho, Laurie A. Williams, Annie I. Antn |
| 2007 | SIGCSE | Note to self: make assignments meaningful. | Lucas Layman, Laurie A. Williams, Kelli M. Slaten |
| 2006 | ICSE | Applying regression test selection for COTS-based applications. | Jiang Zheng, Brian Robinson, Laurie A. Williams, Karen Smiley |
| 2006 | ISSRE | DevCOP: A Software Certificate Management System for Eclipse. | Mark Sherriff, Laurie A. Williams |
| 2006 | SIGCSE | Personality types, learning styles, and an agile approach to software engineering education. | Lucas Layman, Travis Cornwell, Laurie A. Williams |
| 2005 | ICSE | Matching attack patterns to security vulnerabilities in software-intensive system designs. | Michael Gegick, Laurie A. Williams |
| 2005 | ICSE | Towards increasing the compatibility of student pair programmers. | Neha Katira, Laurie A. Williams, Jason A. Osborne |
| 2005 | ICSE | Early estimation of software quality using in-process testing metrics: a controlled case study. | Nachiappan Nagappan, Laurie A. Williams, Mladen A. Vouk, Jason A. Osborne |
| 2005 | ISSRE | How Should Software Reliability Engineering Be Taught? | John D. Musa, Laurie A. Williams |
| 2005 | ISSRE | Providing Test Quality Feedback Using Static Source Code and Automatic Test Suite Metrics. | Nachiappan Nagappan, Laurie A. Williams, Jason A. Osborne, Mladen A. Vouk, Pekka Abrahamsson |
| 2005 | ISSRE | Teaching an Active-Participation University Course in Software Reliability and Testing. | Laurie A. Williams |
| 2005 | ISSRE | An Initial Study of a Lightweight Process for Change Identification and Regression Test Selection When Source Code Is Not Available. | Jiang Zheng, Brian Robinson, Laurie A. Williams, Karen Smiley |
| 2004 | ISSRE | GERT: An Empirical Reliability Estimation and Testing Feedback Tool. | Martin Davidsson, Jiang Zheng, Nachiappan Nagappan, Laurie A. Williams, Mladen A. Vouk |
| 2004 | ISSRE | Preliminary Results On Using Static Analysis Tools For Software Inspection. | Nachiappan Nagappan, Laurie A. Williams, John P. Hudepohl, Will Snipes, Mladen A. Vouk |
| 2004 | SIGCSE | Teaching software development methods: the case of extreme programming. | Joe Bergin, James Caristi, Yael Dubinsky, Orit Hazzan, Laurie A. Williams |
| 2004 | SIGCSE | On understanding compatibility of student pair programmers. | Neha Katira, Laurie A. Williams, Eric N. Wiebe, Carol Miller, Suzanne Balik, Edward F. Gehringer |
| 2003 | ICSE | Assessing Test-Driven Development at IBM. | E. Michael Maximilien, Laurie A. Williams |
| 2003 | ISSRE | Test-Driven Development as a Defect-Reduction Practice. | Laurie A. Williams, E. Michael Maximilien, Mladen A. Vouk |
| 2003 | OOPSLA | "Good enough" software reliability estimation plug-in for Eclipse. | Nachiappan Nagappan, Laurie A. Williams, Mladen A. Vouk |
| 2003 | SAC | An Initial Investigation of Test Driven Development in Industry. | Boby George, Laurie A. Williams |
| 2003 | SIGCSE | Improving the CS1 experience with pair programming. | Nachiappan Nagappan, Laurie A. Williams, Miriam Ferzli, Eric N. Wiebe, Kai Yang, Carol Miller, Suzanne Balik |
| 2003 | SEKE | On Identifying Deficiencies in a Knowledge Management System. | Prashant Baheti, Laurie A. Williams, Aldo Dagnino, Andrew Cordes |
| 2001 | RE | Evolving Beyond Requirements Creep: A Risk-Based Evolutionary Prototyping Model. | Ryan A. Carter, Annie I. Antn, Laurie A. Williams, Aldo Dagnino |
| 2001 | SIGCSE | Collaboration vs plagiarism in computer science programming courses. | Carolee Stewart-Gardiner, David G. Kay, Joyce Currie Little, Joseph D. Chase, John Fendrich, Laurie A. Williams, Ursula Wolz |
| 2001 | SIGCSE | In support of student pair-programming. | Laurie A. Williams, Richard L. Upchurch |
| 2000 | OOPSLA | Hacker or hero? - extreme programming today (panel session). | Steven Fraser, Kent L. Beck, Ward Cunningham, Ron Crocker, Martin Fowler, Linda Rising, Laurie A. Williams |