| 2014 | ICST | Automated Test Generation from Vulnerability Signatures. | Abdulbaki Aydin, Muath Alkhalaf, Tevfik Bultan |
| 2014 | ISSTA | Semantic differential repair for input validation and sanitization. | Muath Alkhalaf, Abdulbaki Aydin, Tevfik Bultan |
| 2012 | ICSE | Verifying client-side input validation functions using string analysis. | Muath Alkhalaf, Tevfik Bultan, Jose L. Gallegos |
| 2012 | ISSTA | ViewPoints: differential string analysis for discovering client- and server-side input validation inconsistencies. | Muath Alkhalaf, Shauvik Roy Choudhary, Mattia Fazzini, Tevfik Bultan, Alessandro Orso, Christopher Kruegel |
| 2011 | ICSE | Patching vulnerabilities with sanitization synthesis. | Fang Yu, Muath Alkhalaf, Tevfik Bultan |
| 2010 | TACAS | Stranger: An Automata-Based String Analysis Tool for PHP. | Fang Yu, Muath Alkhalaf, Tevfik Bultan |
| 2009 | ICSOC | Generating Interface Grammars from WSDL for Automated Verification of Web Services. | Sylvain Hall, Graham Hughes, Tevfik Bultan, Muath Alkhalaf |
| 2008 | ISSTA | Client and server verification for web services using interface grammars. | Graham Hughes, Tevfik Bultan, Muath Alkhalaf |