| 2026 | ACL | SeCuRepair: Semantics-Aligned, Curriculum-Driven, and Reasoning-Enhanced Vulnerability Repair Framework. | Chengran Yang, Ting Zhang, Jinfeng Jiang, Xin Zhou, Haoye Tian, Mingzhe Du, Jieke Shi, Junkai Chen, Yikun Li, Eng Lieh Ouh, Lwin Khin Shar, David Lo |
| 2026 | ICSE | PenForge: On-the-Fly Expert Agent Construction for Automated Penetration Testing. | Huihui Huang, Jieke Shi, Junkai Chen, Ting Zhang, Yikun Li, Chengran Yang, Eng Lieh Ouh, Lwin Khin Shar, David Lo |
| 2025 | APSEC | Virtualization-based Penetration Testing Study for Detecting Accessibility Abuse Vulnerabilities in Banking Apps in East and Southeast Asia. | Wei Minn, Phong Phan, Vikas Kumar Malviya, Benjamin Adolphi, Yan Naing Tun, Henning Benzon Treichl, Albert Ching, Lwin Khin Shar, David Lo |
| 2025 | ICECCS | Runtime Anomaly Detection for Drones: An Integrated Rule-Mining and Unsupervised-Learning Approach. | Ivan Tan, Wei Minn, Christopher M. Poskitt, Lwin Khin Shar, Lingxiao Jiang |
| 2024 | ICSE | DronLomaly: Runtime Log-based Anomaly Detector for DJI Drones. | Wei Minn, Yan Naing Tun, Lwin Khin Shar, Lingxiao Jiang |
| 2024 | KES | Empirical Evaluation of Hyper-parameter Optimization Techniques for Deep Learning-based Malware Detectors. | Lwin Khin Shar, Ta Nguyen Binh Duong, Yao Cong Yeo, Jiani Fan |
| 2022 | APSEC | DronLomaly: Runtime Detection of Anomalous Drone Behaviors via Log Analysis and Deep Learning. | Lwin Khin Shar, Wei Minn, Ta Nguyen Binh Duong, Jiani Fan, Lingxiao Jiang, Daniel Lim Wai Kiat |
| 2022 | ICSE | UIPDroid: Unrooted Dynamic Monitor of Android App UIs for Fine-Grained Permission Control. | Mulin Duan, Lingxiao Jiang, Lwin Khin Shar, Debin Gao |
| 2022 | ITiCSE | XSS for the Masses: Integrating Security in a Web Programming Course using a Security Scanner. | Lwin Khin Shar, Christopher M. Poskitt, Kyong Jin Shim, Li Ying Leonard Wong |
| 2022 | NSS | Differentiated Security Architecture for Secure and Efficient Infotainment Data Communication in IoV Networks. | Jiani Fan, Lwin Khin Shar, Jiale Guo, Wenzhuo Yang, Dusit Niyato, Kwok-Yan Lam |
| 2021 | APSEC | Empirical Evaluation of Minority Oversampling Techniques in the Context of Android Malware Detection. | Lwin Khin Shar, Ta Nguyen Binh Duong, David Lo |
| 2020 | APSEC | SmartFuzz: An Automated Smart Fuzzing Approach for Testing SmartThings Apps. | Lwin Khin Shar, Ta Nguyen Binh Duong, Lingxiao Jiang, David Lo, Wei Minn, Glenn Kiah Yong Yeo, Eugene Kim |
| 2020 | ICSE | Experimental comparison of features and classifiers for Android malware detection. | Lwin Khin Shar, Biniam Fisseha Demissie, Mariano Ceccato, Wei Minn |
| 2018 | ICSE | AnFlo: detecting anomalous sensitive information flows in Android apps. | Biniam Fisseha Demissie, Mariano Ceccato, Lwin Khin Shar |
| 2017 | ICSE | Search-driven string constraint solving for vulnerability detection. | Julian Thom, Lwin Khin Shar, Domenico Bianculli, Lionel C. Briand |
| 2015 | ICSE | Mining Patterns of Unsatisfiable Constraints to Detect Infeasible Paths. | Sun Ding, Hee Beng Kuan Tan, Lwin Khin Shar |
| 2015 | ISSRE | Security slicing for auditing XML, XPath, and SQL injection vulnerabilities. | Julian Thom, Lwin Khin Shar, Lionel C. Briand |
| 2014 | SEKE | Empirical Comparison of Intermediate Representations for Android Applications. | Yauhen Arnatovich, Hee Beng Kuan Tan, Sun Ding, Kaiping Liu, Lwin Khin Shar |
| 2013 | APSEC | Towards a Hybrid Framework for Detecting Input Manipulation Vulnerabilities. | Sun Ding, Hee Beng Kuan Tan, Lwin Khin Shar, Bindu Madhavi Padmanabhuni |
| 2013 | ICSE | Mining SQL injection and cross site scripting vulnerabilities using hybrid program analysis. | Lwin Khin Shar, Hee Beng Kuan Tan, Lionel C. Briand |
| 2012 | APSEC | Semi-Automated Verification of Defense against SQL Injection in Web Applications. | Kaiping Liu, Hee Beng Kuan Tan, Lwin Khin Shar |
| 2012 | ICSE | Mining input sanitization patterns for predicting SQL injection and cross site scripting vulnerabilities. | Lwin Khin Shar, Hee Beng Kuan Tan |
| 2010 | SECRYPT | Auditing the Defense Against Cross Site Scripting in Web Applications. | Lwin Khin Shar, Hee Beng Kuan Tan |