| 2026 | MSR | A Match Made in Heaven? AI-driven Matching of Vulnerabilities and Security Unit Tests. | Emanuele Iannone, Quang-Cuong Bui, Riccardo Scandariato |
| 2026 | SANER | VULTERMINATOR: Bringing Back Template-Based Automated Repair for Fixing Java Vulnerabilities. | Quang-Cuong Bui, Emanuele Iannone, Riccardo Scandariato |
| 2025 | SANER | Impact of Identifier Normalization on Vulnerability Detection Techniques. | Torge Hinrichs, Tim Diercks, Riccardo Scandariato |
| 2024 | ICSE | CATMA: Conformance Analysis Tool For Microservice Applications. | Clinton Cao, Simon Schneider, Nicols E. Daz Ferreyra, Sicco Verwer, Annibale Panichella, Riccardo Scandariato |
| 2024 | MSR | What Can Self-Admitted Technical Debt Tell Us About Security? A Mixed-Methods Study. | Nicols E. Daz Ferreyra, Mojtaba Shahin, Mansooreh Zahedi, Sodiq Quadri, Riccardo Scandariato |
| 2023 | CHI | Regret, Delete, (Do Not) Repeat: An Analysis of Self-Cleaning Practices on Twitter After the Outbreak of the COVID-19 Pandemic. | Nicols Emilio Daz Ferreyra, Gautam Kishore Shahi, Catherine Tony, Stefan Stieglitz, Riccardo Scandariato |
| 2023 | MSR | microSecEnD: A Dataset of Security-Enriched Dataflow Diagrams for Microservice Applications. | Simon Schneider, Tufan zen, Michael Chen, Riccardo Scandariato |
| 2023 | MSR | LLMSecEval: A Dataset of Natural Language Prompts for Security Evaluations. | Catherine Tony, Markus Mutas, Nicols E. Daz Ferreyra, Riccardo Scandariato |
| 2022 | EASE | Conversational DevBots for Secure Programming: An Empirical Study on SKF Chatbot. | Catherine Tony, Mohana Balasubramanian, Nicols E. Daz Ferreyra, Riccardo Scandariato |
| 2022 | ISSTA | Maestro: a platform for benchmarking automatic program repair tools on software vulnerabilities. | Eduard Pinconschi, Quang-Cuong Bui, Rui Abreu, Pedro Ado, Riccardo Scandariato |
| 2022 | MSR | Vul4J: A Dataset of Reproducible Java Vulnerabilities Geared Towards the Study of Program Repair Techniques. | Quang-Cuong Bui, Riccardo Scandariato, Nicols E. Daz Ferreyra |
| 2022 | QRS | GitHub Considered Harmful? Analyzing Open-Source Projects for the Automatic Generation of Cryptographic API Call Sequences. | Catherine Tony, Nicols E. Daz Ferreyra, Riccardo Scandariato |
| 2021 | ICSE | Secure Software Development in the Era of Fluid Multi-party Open Software and Services. | Ivan Pashchenko, Riccardo Scandariato, Antonino Sabetta, Fabio Massacci |
| 2020 | ICAART | Perception and Acceptance of an Autonomous Refactoring Bot. | Marvin Wyrich, Regina Hebig, Stefan Wagner, Riccardo Scandariato |
| 2020 | MODELS | Automating the early detection of security design flaws. | Katja Tuma, Laurens Sion, Riccardo Scandariato, Koen Yskout |
| 2020 | SEC | JavaScript Malware Detection Using Locality Sensitive Hashing. | Stefan Carl Peiser, Ludwig Friborg, Riccardo Scandariato |
| 2019 | ECSA | Inspection guidelines to identify security design flaws. | Katja Tuma, Danial Hosseini, Kyriakos Malamas, Riccardo Scandariato |
| 2019 | ICSA | Flaws in Flows: Unveiling Design Flaws via Information Flow Analysis. | Katja Tuma, Riccardo Scandariato, Musard Balliu |
| 2019 | ICSE | Current and future bots in software development. | Linda Erlenhov, Francisco Gomes de Oliveira Neto, Riccardo Scandariato, Philipp Leitner |
| 2019 | MODELS | Secure Data-Flow Compliance Checks between Models and Code Based on Automated Mappings. | Sven Peldszus, Katja Tuma, Daniel Strber, Jan Jrjens, Riccardo Scandariato |
| 2018 | ECSA | Two Architectural Threat Analysis Techniques Compared. | Katja Tuma, Riccardo Scandariato |
| 2018 | ICISSP | Back to the Drawing Board - Bringing Security Constraints in an Architecture-centric Software Development Process. | Stefanie Jasser, Katja Tuma, Riccardo Scandariato, Matthias Riebisch |
| 2018 | ICSE | Generative secure design, defined. | Riccardo Scandariato, Jennifer Horkoff, Robert Feldt |
| 2017 | ADBIS | Theta Architecture: Preserving the Quality of Analytics in Data-Driven Systems. | Vasileios Theodorou, Ilias Gerostathopoulos, Sasan Amini, Riccardo Scandariato, Christian Prehofer, Miroslaw Staron |
| 2017 | ESORICS | Towards Security Threats that Matter. | Katja Tuma, Riccardo Scandariato, Mathias Widman, Christian Sandberg |
| 2017 | ICSA | Traceability Metrics as Early Predictors of Software Defects? | Bashar Nassar, Riccardo Scandariato |
| 2017 | ICSE | A Model for Provably Secure Software Design. | Alexander van Den Berghe, Koen Yskout, Riccardo Scandariato, Wouter Joosen |
| 2016 | ESEM | Static Analysis and Penetration Testing from the Perspective of Maintenance Teams. | Mariano Ceccato, Riccardo Scandariato |
| 2016 | ESEM | Is Newer Always Better?: The Case of Vulnerability Prediction Models. | Aram Hovsepyan, Riccardo Scandariato, Wouter Joosen |
| 2016 | ISoLA | A Privacy-Aware Conceptual Model for Handling Personal Data. | Thibaud Antignac, Riccardo Scandariato, Gerardo Schneider |
| 2015 | ICSE | MASC: Modelling Architectural Security Concerns. | Laurens Sion, Koen Yskout, Alexander van Den Berghe, Riccardo Scandariato, Wouter Joosen |
| 2015 | ICSE | Do Security Patterns Really Help Designers? | Koen Yskout, Riccardo Scandariato, Wouter Joosen |
| 2015 | MODELS | SoSPa: A system of Security design Patterns for systematically engineering secure systems. | Phu Hong Nguyen, Koen Yskout, Thomas Heyman, Jacques Klein, Riccardo Scandariato, Yves Le Traon |
| 2014 | ISSRE | Predicting Vulnerable Components: Software Metrics vs Text Mining. | James Walden, Jeff Stuckman, Riccardo Scandariato |
| 2013 | ISSRE | Static analysis versus penetration testing: A controlled experiment. | Riccardo Scandariato, James Walden, Wouter Joosen |
| 2012 | ICSE | Does organizing security patterns focus architectural choices? | Koen Yskout, Riccardo Scandariato, Wouter Joosen |
| 2011 | ESEM | Preserving Aspects via Automation: A Maintainability Study. | Aram Hovsepyan, Riccardo Scandariato, Stefan Van Baelen, Wouter Joosen, Serge Demeyer |
| 2011 | ICSE | Composition of least privilege analysis results in software architectures (position paper). | Koen Buyens, Riccardo Scandariato, Wouter Joosen |
| 2010 | COMPSAC | Security in Context: Analysis and Refinement of Software Architectures. | Thomas Heyman, Riccardo Scandariato, Wouter Joosen |
| 2010 | ECSA | Automated Detection of Least Privilege Violations in Software Architectures. | Riccardo Scandariato, Koen Buyens, Wouter Joosen |
| 2010 | ISoLA | SecureChange: Security Engineering for Lifelong Evolvable Systems. | Riccardo Scandariato, Fabio Massacci |
| 2009 | ESEM | Measuring the interplay of security principles in software architectures. | Koen Buyens, Riccardo Scandariato, Wouter Joosen |
| 2007 | COMPSAC | Process Activities Supporting Security Principles. | Koen Buyens, Riccardo Scandariato, Wouter Joosen |
| 2007 | ICSE | On the Secure Software Development Process: CLASP and SDL Compared. | Johan Grgoire, Koen Buyens, Bart De Win, Riccardo Scandariato, Wouter Joosen |
| 2007 | ICSE | An Analysis of the Security Patterns Landscape. | Thomas Heyman, Koen Yskout, Riccardo Scandariato, Wouter Joosen |
| 2006 | AINA | Remote Trust with Aspect-Oriented Programming. | Paolo Falcarin, Riccardo Scandariato, Mario Baldi |
| 2006 | CCS | Towards a measuring framework for security properties of software. | Riccardo Scandariato, Bart De Win, Wouter Joosen |
| 2004 | SRDS | The Design and Evaluation of a Defense System for Internet Worms. | Riccardo Scandariato, John C. Knight |