Clemens-Alexander Brust

dblp:159/1860 · DBLP profile ↗
← Back
9ranked-venue papers
2as first author
7since 2021 · last 2025
0000-0001-5419-1998ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 6 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorSecurity and privacy · 1 · 1 first-author · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2025 FlowStrider: Low-Friction Continuous Threat Modeling
abstract
Architectural threat modeling is a crucial technique for identifying and mitigating security threats in software systems, helping to prevent costly design flaws. While existing tools aim to reduce its resource-intensive nature through automation, they often lack key features—such as scriptability and integration capabilities—needed for practical use in development workflows.In this paper, we present FlowStrider, a tool that addresses these shortcomings by implementing a new, practice-oriented workflow and enabling CI/CD integration through scriptability. FlowStrider reduces the required manual effort, enhances the quality of analysis results, and eases integration into software development workflows, thereby lowering the adoption barrier for continuous threat modeling.Screencast: https://youtu.be/iRpeU1nubHwRepository: https://gitlab.com/dlr-dw/automated-threat-modeling/flowstrider
Bernd Gruner, Noah Erthel, Clemens-Alexander Brust
ASE3
2025 Finding Information Leaks with Information Flow Fuzzing
abstract
We present information flow fuzzing , an approach that guides fuzzers towards detecting information leaks — information that reaches a third party, but should not. The approach detects information flow by means of mutations , checking whether and how mutations to (secret) data affect output and execution: — First, the fuzzer uses information flow as a leak oracle. To this end, for each input, the fuzzer first runs the program regularly. Then, it mutates secret data such as a certificate or a password, and re-runs the program giving the original input. If the output changes, the fuzzer has revealed an information leak. — Second, the fuzzer uses information flow as guidance. The fuzzer not only maximizes coverage, but also changes in coverage and changes in data between the two runs. This increases the likelihood that a mutation will spread to the output. We have implemented a tool named flowfuzz that wraps around a C program under test to provide information flow based oracles and guidance, allowing for integration with all common fuzzers for C programs. Using a set of subjects representing common information leaks, we investigate (1) whether oracles based on information flow detect information leaks in our subjects; and (2) whether guidance based on information flow improves over standard coverage guidance. All data and tools are available for replication and reproduction.
Bernd Gruner, Clemens-Alexander Brust, Andreas Zeller
ACM Trans. Softw. Eng. Methodol.2
2025 Finding Information Leaks with Information Flow Fuzzing - RCR Report
abstract
This is the Replicated Computational Results (RCR) report for our ACM TOSEM paper, “ Finding Information Leaks with Information Flow Fuzzing ,” in which we propose information flow fuzzing . This approach directs fuzzers toward detecting information leaks . We introduce a novel leak oracle and employ information flow as guidance for the fuzzer to identify information leaks effectively. As part of this RCR report, we provide a replication package that enables the complete replication of all our results and simplifies the reuse of our FLOWFUZZ fuzzer.
Bernd Gruner, Clemens-Alexander Brust, Andreas Zeller
ACM Trans. Softw. Eng. Methodol.2
2023 Cross-Domain Evaluation of a Deep Learning-Based Type Inference System
abstract
Optional type annotations allow for enriching dynamic programming languages with static typing features like better Integrated Development Environment (IDE) support, more precise program analysis, and early detection and prevention of type-related runtime errors. Machine learning-based type inference promises interesting results for automating this task. However, the practical usage of such systems depends on their ability to generalize across different domains, as they are often applied outside their training domain.In this work, we investigate Type4Py as a representative of state-of-the-art deep learning-based type inference systems, by conducting extensive cross-domain experiments. Thereby, we address the following problems: class imbalances, out-of-vocabulary words, dataset shifts, and unknown classes.To perform such experiments, we use the datasets Many-Types4Py and CrossDomainTypes4Py. The latter we introduce in this paper. Our dataset enables the evaluation of type inference systems in different domains of software projects and has over 1,000,000 type annotations mined on the platforms GitHub and Libraries. It consists of data from the two domains web development and scientific calculation.Through our experiments, we detect that the shifts in the dataset and the long-tailed distribution with many rare and unknown data types decrease the performance of the deep learning-based type inference system drastically. In this context, we test unsupervised domain adaptation methods and fine-tuning to overcome these issues. Moreover, we investigate the impact of out-of-vocabulary words.
Bernd Gruner, Tim Sonnekalb, Thomas S. Heinze, Clemens-Alexander Brust
MSR4
2023 TIPICAL - Type Inference for Python In Critical Accuracy Level
abstract
Type inference methods based on deep learning are becoming increasingly popular as they aim to compensate for the drawbacks of static and dynamic analysis approaches, such as high uncertainty. However, their practical application is still debatable due to several intrinsic issues such as code from different software domains will involve data types that are unknown to the type inference system.In order to overcome these problems and gain high-confidence predictions, we thus present TIPICAL, a method that combines deep similarity learning with novelty detection. We show that our method can better predict data types in high confidence by successfully filtering out unknown and inaccurate predicted data types and achieving higher F1 scores to the state-of-the-art type inference method Type4Py. Additionally, we investigate how different software domains and data type frequencies may affect the results of our method.
Jonathan Elkobi, Bernd Gruner, Tim Sonnekalb, Clemens-Alexander Brust
SERA4
2023 ROMEO: A binary vulnerability detection dataset for exploring Juliet through the lens of assembly language
Clemens-Alexander Brust, Tim Sonnekalb, Bernd Gruner
Comput. Secur.1
2022 Generalizability of Code Clone Detection on CodeBERT
abstract
Transformer networks such as CodeBERT already achieve outstanding results for code clone detection in benchmark datasets, so one could assume that this task has already been solved. However, code clone detection is not a trivial task. Semantic code clones, in particular, are challenging to detect.
Tim Sonnekalb, Bernd Gruner, Clemens-Alexander Brust, Patrick Mäder
ASE3
2020 Making Every Label Count: Handling Semantic Imprecision by Integrating Domain Knowledge
abstract
Noisy data, crawled from the web or supplied by volunteers such as Mechanical Turkers or citizen scientists, is considered an alternative to professionally labeled data. There has been research focused on mitigating the effects of label noise. It is typically modeled as inaccuracy, where the correct label is replaced by an incorrect label from the same set. We consider an additional dimension of label noise: imprecision. For example, a non-breeding snow bunting is labeled as a bird. This label is correct, but not as precise as the task requires. Standard softmax classifiers cannot learn from such a weak label because they consider all classes mutually exclusive, which non-breeding snow bunting and bird are not. We propose CHILLAX (Class Hierarchies for Imprecise Label Learning and Annotation eXtrapolation), a method based on hierarchical classification, to fully utilize labels of any precision. Experiments on noisy variants of NABirds and ILSVRC2012 show that our method outperforms strong baselines by as much as 16.4 percentage points, and the current state of the art by up to 3.9 percentage points.
Clemens-Alexander Brust, Björn Barz, Joachim Denzler
ICPR1
2019 Registration of High Resolution Sar and Optical Satellite Imagery Using Fully Convolutional Networks
abstract
Multi-modal image registration is a crucial step when fusing images which show different physical/chemical properties of an object. Depending on the compared modalities and the used registration metric, this process exhibits varying reliability. We propose a deep metric based on a fully convo-lutional neural network (FCN). It is trained from scratch on SAR-optical image pairs to predict whether certain image areas are aligned or not. Tests on the affine registration of SAR and optical images showing suburban areas verify an enormous improvement of the registration accuracy in comparison to registration metrics that are based on mutual information (MI).
Stefan Hoffmann 0007, Clemens-Alexander Brust, Maha Shadaydeh, Joachim Denzler
IGARSS2