EDBT 2026 Demo / reviewers in the wild / expert
Neil Perry
dblp:324/2094
· DBLP profile ↗
2ranked-venue papers
1as first author
2since 2021 · last 2025
0009-0009-4254-4712ORCID · reported
Domains — the database's venue-derived domains; a paper can count in several
Artificial intelligence and machine learning · 1 · 1 since 2021Security and privacy · 1 · 1 first-author · 1 since 2021
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Network and information security
2 papers |
Systems and software security · 66% Usable security · 34% | |
| Artificial intelligence
1 paper |
Language models and text generation · 77% Trustworthy machine learning · 23% | |
| Human-computer interaction and pervasive computing
1 paper |
Human-AI interaction · 100% |
Topics — the 7 heaviest of 7, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Natural language and speech › Language models and text generation
LLM agents |
0.9 | 1 | 2025 | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · ICLR 2025 |
Systems and software security
vulnerability discovery |
0.9 | 1 | 2025 | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · ICLR 2025 |
Usable security › security behavior
developer security behavior |
0.7 | 1 | 2023 | Do Users Write More Insecure Code with AI Assistants? · CCS 2023 |
Machine learning › Trustworthy machine learning › model validation
evaluation of language model capabilities |
0.3 | 1 | 2025 | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models · ICLR 2025 |
Human-AI interaction › AI-mediated work
AI-assisted programming |
0.2 | 1 | 2023 | Do Users Write More Insecure Code with AI Assistants? · CCS 2023 |
Systems and software security
insecure code generation |
0.2 | 1 | 2023 | Do Users Write More Insecure Code with AI Assistants? · CCS 2023 |
Systems and software security › secure software development
secure coding |
0.2 | 1 | 2023 | Do Users Write More Insecure Code with AI Assistants? · CCS 2023 |
Methods — techniques the papers use, named apart from their topics
subtask decomposition · 1.7agent scaffolding · 1.7user study · 1.3
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language ModelsabstractLanguage Model (LM) agents for cybersecurity that are capable of autonomously identifying vulnerabilities and executing exploits have potential to cause real-world impact. Policymakers, model providers, and researchers in the AI and cybersecurity communities are interested in quantifying the capabilities of such agents to help mitigate cyberrisk and investigate opportunities for penetration testing. Toward that end, we introduce Cybench, a framework for specifying cybersecurity tasks and evaluating agents on those tasks. We include 40 professional-level Capture the Flag (CTF) tasks from 4 distinct CTF competitions, chosen to be recent, meaningful, and spanning a wide range of difficulties. Each task includes its own description, starter files, and is initialized in an environment where an agent can execute commands and observe outputs. Since many tasks are beyond the capabilities of existing LM agents, we introduce subtasks for each task, which break down a task into intermediary steps for a more detailed evaluation. To evaluate agent capabilities, we construct a cybersecurity agent and evaluate 8 models: GPT-4o, OpenAI o1-preview, Claude 3 Opus, Claude 3.5 Sonnet, Mixtral 8x22b Instruct, Gemini 1.5 Pro, Llama 3 70B Chat, and Llama 3.1 405B Instruct. For the top performing models (GPT-4o and Claude 3.5 Sonnet), we further investigate performance across 4 agent scaffolds (structured bash, action-only, pseudoterminal, and web search). Without subtask guidance, agents leveraging Claude 3.5 Sonnet, GPT-4o, OpenAI o1-preview, and Claude 3 Opus successfully solved complete tasks that took human teams up to 11 minutes to solve. In comparison, the most difficult task took human teams 24 hours and 54 minutes to solve. Anonymized code and data are available at https://drive.google.com/file/d/1kp3H0pw1WMAH-Qyyn9WA0ZKmEa7Cr4D4 and https://drive.google.com/file/d/1BcTQ02BBR0m5LYTiK-tQmIK17_TxijIy. Andy K. Zhang, Neil Perry, Riya Dulepet, Joey Ji, Celeste Menders, Justin W. Lin, Eliot Jones, Gashon Hussein, Samantha Liu, Donovan Jasper, Pura Peetathawatchai, Ari Glenn, Vikram Sivashankar, Daniel Zamoshchin, Leo Glikbarg, Derek Askaryar, Haoxiang Yang, Aolin Zhang, Rishi Alluri, Nathan Tran |
ICLR | 2 |
| 2023 | Do Users Write More Insecure Code with AI Assistants?abstractAI code assistants have emerged as powerful tools that can aid in the software development life-cycle and can improve developer productivity. Unfortunately, such assistants have also been found to produce insecure code in lab environments, raising significant concerns about their usage in practice. In this paper, we conduct a user study to examine how users interact with AI code assistants to solve a variety of security related tasks. Overall, we find that participants who had access to an AI assistant wrote significantly less secure code than those without access to an assistant. Participants with access to an AI assistant were also more likely to believe they wrote secure code, suggesting that such tools may lead users to be overconfident about security flaws in their code. To better inform the design of future AI-based code assistants, we release our user-study apparatus to researchers seeking to build on our work. Neil Perry, Megha Srivastava, Deepak Kumar 0006, Dan Boneh |
CCS | 1 |