Leo St. Amour

dblp:159/0120 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
5since 2021 · last 2026
0009-0005-2327-4631ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Human-computer interaction and ubiquitous computing · 4 · 3 first-author · 3 since 2021Software engineering, systems software and programming languages · 2 · 2 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 Creating Exercises with Generative AI for Teaching Introductory Secure Programming: Are We There Yet?
abstract
Despite ongoing efforts to integrate security concepts into computer science curricula, many graduates still lack practical software security skills. Active learning strategies---such as drill-and-practice---offer a promising approach to bridging this educational gap. To implement these strategies effectively, educators must design and deliver hands-on exercises focusing specifically on secure programming. However, creating effective secure programming exercises is difficult, requiring substantial time and in-depth expertise. This paper examines the potential of generative AI to aid in creating drill-and-practice exercises for introductory secure programming settings. Specifically, we prompt several large language models (LLMs) to assist in generating exercises targeting three common software vulnerability classes, with tasks aligned to the advanced beginner stage of the Dreyfus skills acquisition model. We systematically evaluate the generated exercises for correctness and instructional viability. Our results show that, for some vulnerabilities, LLMs can produce technically sound and useful exercises for advanced beginners. While many generated exercises were near classroom-ready, minor fine-tuning is often necessary to ensure quality and pedagogical alignment. These findings suggest that effective exercise generation in secure programming is best achieved through a symbiosis between generative AI and human educators.
Leo St. Amour, Eli Tilevich
SIGCSE (1)1
2025 Designing a Platform to Train Secure Programming Skills with Attack-and-Defend Exercises
abstract
The increasingly poor state of software security poses significant threats to many of modern society's critical functions. Computing educators play a pivotal role in equipping future software engineers with the necessary skills to build secure systems. However, while traditional security courses often focus on conceptual knowledge, practical application is crucial for ensuring students can develop robust, secure software. Despite the importance of hands-on experience, students often lack suitable platforms for practicing secure programming. Inspired by drill-and-practice platforms that effectively train general programming skills, we have been working on a similar platform that focuses explicitly on teaching secure coding practices through active learning strategies. In this paper, we discuss the design of our prototype implementation: SecureCoder. Rooted in active learning principles, SecureCoder's design aims to promote student-centered education by encouraging students to actively apply theoretical secure programming concepts. Specifically, SecureCoder engages students with interactive attack-and-defend exercises, challenging them to exploit or patch software vulnerabilities in a sandboxed environment. Our ultimate objective is to bridge the gap between theoretical knowledge and practical application, fostering a deeper understanding and retention of secure coding principles. Through immediate and actionable feedback on validated exercises, SecureCoder is designed to reinforce learning and empower students to iteratively refine their solutions and build confidence in their skills. To study the potential of our design, we conducted a pilot study. The study results indicate that participants found SecureCoder to be relevant and engaging. Further, participant perceptions toward the attack-and-defend exercises suggest that SecureCoder's design has the potential to enhance secure programming education. Encouraged by SecureCoder's initial positive reception, we plan to open-source the project, inviting the broader education community to contribute to and benefit from shared security expertise. These collaborative efforts are essential for educating the next generation of security-aware software engineers. By integrating hands-on practice and active learning techniques, SecureCoder's design aims to address the urgent need for practical, skill-based security education, preparing students to meet the ever-evolving challenges of engineering secure solutions in the real world.
Leo St. Amour, Eli Tilevich
EDUCON1
2025 A Metric for Measuring the Impact of Rare Paths on Program Coverage
abstract
Fuzzing has become a popular technique for discovering bugs and vulnerabilities. To increase the probability of finding bugs, developers should apply fuzzers that maximize program coverage. Program coverage typically measures the percentage of program lines or branches a fuzzer executes. However, these metrics fail to communicate the value of hitting a particular line, branch, or path. Many bugs manifest only within non-trivial control flows. To improve software quality, fuzzing non-trivial program paths should be more important than fuzzing trivial ones. This paper introduces rare-path coverage (RP-Coverage), a novel program coverage metric that conveys the value of discovering an unlikely control flow path. We have developed a new technique for estimating the probability of taking an execution path, which relies on probabilistic logic programming to declaratively express the logic for constructing and analyzing a probabilistic control flow graph. Our evaluation indicates RP-Coverage's promise as a metric for measuring fuzzing efficacy. Specifically, we observe that defects along rare paths-intuitively-substantially impact the effectiveness of fuzzers. However, we argue that existing fuzzing metrics fall short when conveying this significance. We also observe that the value of uncovering an unlikely path is better reflected by increases in RP-Coverage than existing metrics. Specifically, the average coverage increases are up to 49.5%, 11.1 %, and 15.4 % for RP-Coverage, line coverage, and branch coverage, respectively. This finding indicates that RP-Coverage is more elastic, or sensitive, to path probabilities and thus capable of more effectively quantifying a fuzzer's ability to discover unlikely program paths. As such, RP-Coverage demonstrates promise as a program coverage metric that enhances fuzzer fitness measures when supplementing standard criteria.
Leo St. Amour, Eli Tilevich, Muhammad Ali Gulzar
SANER1
2025 Bringing Probabilistic Reasoning to the IDE
Leo St. Amour, Eli Tilevich
VL/HCC1
2024 Toward Declarative Auditing of Java Software for Graceful Exception Handling
abstract
Despite their language-integrated design, Java exceptions can be difficult to use effectively. Although Java exceptions are syntactically straightforward, negligent practices often result in code logic that is not only inelegant but also unsafe. This paper explores the challenge of auditing Java software to enhance the effectiveness and safety of its exception logic. We revisit common anti-patterns associated with Java exception usage and argue that, for auditing, their detection requires a more nuanced approach than mere identification. Specifically, we investigate whether reporting such anti-patterns can be prioritized for subsequent examination. We prototype our approach as Händel, in which anti-patterns and their priority, or weight, are expressed declaratively using probabilistic logic programming. Evaluation with representative open-source code bases suggests Händel’s promise in detecting, reporting, and ranking the anti-patterns, thus helping streamline Java software auditing to ensure the safety and quality of exception-handling logic.
Leo St. Amour, Eli Tilevich
MPLR1
2015 Parallel Author Verification of E-mail (Abstract Only)
abstract
Cyber-crime is becoming alarmingly common through the use of anonymous e-mails. Author attribution helps digital forensics investigators filter through a large set of possible authors and focus traditional investigative techniques on the most probable culprits. A recent promising technique is to construct a write-print for each known author, and compare it to the write-print extracted from the anonymous message(s). A write-print is a unique digital fingerprint created by mining frequent patterns from a particular author's writing style. However, the process for generating a write-print is very slow, making it a poor choice for author attribution situations of a time-sensitive nature such as anonymous threats of attack, exposure, or ongoing harassment.
Andreas Kellas, Alexander Molnar, Leo St. Amour, Frederick Ulrich, Suzanne J. Matthews
SIGCSE3