| 2025 | ICAIL | From Legal Text to Tech Specs: Generative AI's Interpretation of Consent in Privacy Law. | Aniket Kesari, Travis D. Breaux, Sarah Santos, Tom Norton, Anmol Singhal |
| 2025 | RE | Generative Goal Modeling. | Ateeq Sharfuddin, Travis D. Breaux |
| 2025 | RE | Requirements Elicitation Follow-Up Question Generation. | Yuchen Shen, Anmol Singhal, Travis D. Breaux |
| 2025 | RE | Legal Requirements Translation from Law. | Anmol Singhal, Travis D. Breaux |
| 2025 | RE | Automating Translation from Legal Text to Legal Requirements Specification Language. | Caroline Witty, Sarah Santos, Travis D. Breaux |
| 2024 | RE | Toward Regulatory Compliance: A few-shot Learning Approach to Extract Processing Activities. | Pragyan K. C, Rambod Ghandiparsi, Rocky Slavin, Sepideh Ghanavati, Travis D. Breaux, Mitra Bokaei Hosseini |
| 2024 | RE | Requirements Satisfiability with In-Context Learning. | Sarah Santos, Travis D. Breaux, Thomas B. Norton, Sara Haghighi, Sepideh Ghanavati |
| 2024 | RE | Patterns of Inquiry in a Community Forum for Legal Compliance with Privacy Law. | Sarah Santos, Sara Haghighi, Sepideh Ghanavati, Travis D. Breaux, Thomas B. Norton |
| 2023 | ICSE | A Metric for Measuring Software Engineering Post-Graduate Outcomes. | Travis D. Breaux, Jennifer Moritz |
| 2023 | RE | Mobile Application Privacy Risk Assessments from User-authored Scenarios. | Tianjian Huang, Vaishnavi Kaulagi, Mitra Bokaei Hosseini, Travis D. Breaux |
| 2022 | RE | Legal Accountability as Software Quality: A U.S. Data Processing Perspective. | Travis D. Breaux, Thomas B. Norton |
| 2022 | RE | Domain Model Extraction from User-authored Scenarios and Word Embeddings. | Yuchen Shen, Travis D. Breaux |
| 2021 | RE | Ambiguity and Generality in Natural Language Privacy Policies. | Mitra Bokaei Hosseini, John Heaps, Rocky Slavin, Jianwei Niu, Travis D. Breaux |
| 2020 | ICSE | How does misconfiguration of analytic services compromise mobile privacy? | Xueling Zhang, Xiaoyin Wang, Rocky Slavin, Travis D. Breaux, Jianwei Niu |
| 2020 | REFSQ | Disambiguating Requirements Through Syntax-Driven Semantic Analysis of Information Types. | Mitra Bokaei Hosseini, Rocky Slavin, Travis D. Breaux, Xiaoyin Wang, Jianwei Niu |
| 2019 | RE | Consent Verification Under Evolving Privacy Policies. | Marco Robol, Travis D. Breaux, Elda Paja, Paolo Giorgini |
| 2019 | SACMAT | Toward Detection of Access Control Models from Source Code via Word Embedding. | John Heaps, Xiaoyin Wang, Travis D. Breaux, Jianwei Niu |
| 2018 | ICSE | GUILeak: tracing privacy policy claims on user input data for Android applications. | Xiaoyin Wang, Xue Qin, Mitra Bokaei Hosseini, Rocky Slavin, Travis D. Breaux, Jianwei Niu |
| 2018 | RE | Semantic Incompleteness in Privacy Policy Goals. | Jaspreet Bhatia, Travis D. Breaux |
| 2018 | REFSQ | Inferring Ontology Fragments from Semantic Role Typing of Lexical Variants. | Mitra Bokaei Hosseini, Travis D. Breaux, Jianwei Niu |
| 2017 | RE | A Data Purpose Case Study of Privacy Policies. | Jaspreet Bhatia, Travis D. Breaux |
| 2017 | RE | An Evaluation of Constituency-Based Hyponymy Extraction from Privacy Policies. | Morgan C. Evans, Jaspreet Bhatia, Sudarshan Wadkar, Travis D. Breaux |
| 2017 | RE | Reinforcing Security Requirements with Multifactor Quality Measurement. | Hanan Hibshi, Travis D. Breaux |
| 2016 | CCS | Privacy Risk in Cybersecurity Data Sharing. | Jaspreet Bhatia, Travis D. Breaux, Liora Friedberg, Hanan Hibshi, Daniel Smullen |
| 2016 | ICSE | Toward a framework for detecting privacy policy violations in android application code. | Rocky Slavin, Xiaoyin Wang, Mitra Bokaei Hosseini, James Hester, Ram Krishnan, Jaspreet Bhatia, Travis D. Breaux, Jianwei Niu |
| 2016 | ICSE | PVDetector: a detector of privacy-policy violations for Android apps. | Rocky Slavin, Xiaoyin Wang, Mitra Bokaei Hosseini, James Hester, Ram Krishnan, Jaspreet Bhatia, Travis D. Breaux, Jianwei Niu |
| 2016 | RE | A Theory of Vagueness and Privacy Risk Perception. | Jaspreet Bhatia, Travis D. Breaux, Joel R. Reidenberg, Thomas B. Norton |
| 2016 | RE | Automated Extraction of Regulated Information Types Using Hyponymy Relations. | Jaspreet Bhatia, Morgan C. Evans, Sudarshan Wadkar, Travis D. Breaux |
| 2015 | RE | Towards an information type lexicon for privacy policies. | Jaspreet Bhatia, Travis D. Breaux |
| 2015 | RE | Detecting repurposing and over-collection in multi-party privacy requirements specifications. | Travis D. Breaux, Daniel Smullen, Hanan Hibshi |
| 2015 | RE | Comparing and analyzing definitions in multi-jurisdictions. | Sepideh Ghanavati, Travis D. Breaux |
| 2015 | RE | Assessment of risk perception in security requirements composition. | Hanan Hibshi, Travis D. Breaux, Stephen B. Broomell |
| 2014 | HCOMP | Crowdsourcing the Extraction of Data Practices from Privacy Policies. | Florian Schaub, Travis D. Breaux, Norman M. Sadeh |
| 2014 | RE | Scaling requirements extraction to the crowd: Experiments with privacy policies. | Travis D. Breaux, Florian Schaub |
| 2014 | RE | The role of legal expertise in interpretation of legal requirements and definitions. | David G. Gordon, Travis D. Breaux |
| 2014 | RE | Towards a framework to measure security expertise in requirements analysis. | Hanan Hibshi, Travis D. Breaux, Maria Riaz, Laurie A. Williams |
| 2014 | RE | Managing security requirements patterns using feature diagram hierarchies. | Rocky Slavin, Jean-Michel Lehker, Jianwei Niu, Travis D. Breaux |
| 2013 | RE | Preserving traceability and encoding meaning in legal requirements extraction. | Travis D. Breaux, David G. Gordon |
| 2013 | RE | Mapping legal requirements to IT controls. | Travis D. Breaux, David G. Gordon, Nick Papanikolaou, Siani Pearson |
| 2013 | RE | Formal analysis of privacy requirements specifications for multi-tier applications. | Travis D. Breaux, Ashwini Rao |
| 2013 | RE | Assessing regulatory change through legal requirements coverage modeling. | David G. Gordon, Travis D. Breaux |
| 2013 | RE | Toward benchmarks to assess advancement in legal requirements modeling. | Ivan Jureta, Travis D. Breaux, Alberto Siena, David G. Gordon |
| 2013 | REFSQ | Regulatory Requirements Traceability and Analysis Using Semi-formal Specifications. | Travis D. Breaux, David G. Gordon |
| 2012 | RE | Towards a framework for pattern experimentation: Understanding empirical validity in requirements engineering patterns. | Travis D. Breaux, Hanan Hibshi, Ashwini Rao, Jean-Michel Lehker |
| 2012 | RE | Reconciling multi-jurisdictional legal requirements: A case study in requirements water marking. | David G. Gordon, Travis D. Breaux |
| 2011 | CCS | Managing multi-jurisdictional requirements in the cloud: towards a computational legal landscape. | David G. Gordon, Travis D. Breaux |
| 2011 | RE | Governance and accountability in the new data ecology. | Travis D. Breaux, Thomas A. Alspaugh |
| 2011 | RE | Comparing requirements from multiple jurisdictions. | David G. Gordon, Travis D. Breaux |
| 2010 | RE | A method to acquire compliance monitors from regulations. | Travis D. Breaux |
| 2009 | RE | Exercising Due Diligence in Legal Requirements Acquisition: A Tool-supported, Frame-Based Approach. | Travis D. Breaux |
| 2009 | SAC | Identifying vulnerabilities and critical requirements using criminal court proceedings. | Travis D. Breaux, Jonathan D. Lewis, Paul N. Otto, Annie I. Antn |
| 2008 | ER | Automating the Extraction of Rights and Obligations for Regulatory Compliance. | Nadzeya Kiyavitskaya, Nicola Zeni, Travis D. Breaux, Annie I. Antn, James R. Cordy, Luisa Mich, John Mylopoulos |
| 2008 | RE | Legal Requirements, Compliance and Practice: An Industry Case Study in Accessibility. | Travis D. Breaux, Annie I. Antn, Kent Boucher, Merlin Dorfman |
| 2006 | RE | Towards Regulatory Compliance: Extracting Rights and Obligations to Align Requirements with Regulations. | Travis D. Breaux, Matthew W. Vail, Annie I. Antn |
| 2005 | RE | Analyzing Goal Semantics for Rights, Permissions, and Obligations. | Travis D. Breaux, Annie I. Antn |