🎉 Our paper got accepted at #ASE2026! We protect open-source stacks from backdoor injections with fast, precise, fuzzing-based detection right in the CI & release pipelines. 🛡️ 👏 Congrats to my PhD student Dimitri Kokkonis, w/ Stefano Zacchiroli. 📄 Preprint and artefact coming soon!
Michaël Marcozzi
@marcozzi.net
🇪🇺🇧🇪 Permanent researcher in cybersecurity (fuzzing). Works at CEA List Institute from Université Paris-Saclay (France). http://www.marcozzi.net I make software safer by viciously torturing it to reveal its flaws. I can be kind too.
🚨 Postdoc opening (24 months) in software security & fuzzing! Join our BINSEC team at Université Paris-Saclay (CEA List) to work on smarter fuzzing for supply‑chain security. 📍 Paris‑Saclay 🇫🇷 🔗 Apply: binsec.github.io/jobs/open/20... #Postdoc #Cybersecurity #Fuzzing #BinaryAnalysis
Finding backdoors in software is like hunting for a needle that’s actively trying to hide. 🪡🕵️ Check out our FOSDEM talk on using fuzzing to automate the search! 📺 Watch: mirrors.dotsrc.org/fosdem/2026/... 📜 ICSE Paper: binsec.github.io/assets/publi...
mirrors.dotsrc.org
The Annual French Research Day on Software Testing will be held in beautiful Grenoble on Dec 11! See you there! 😀 Info and registration: gdr-gpl.cnrs.fr?cat=25
Happy to have presented our SECUBIC project to the French research community in system security (RESSI'25)! 🏠 secubic-ptcc.github.io 🧑🔬 Sébastien Bardin, Jean-Yves Marion, Stefano Zacchiroli Thanks to the RESSI organizers who had even provided a pool to finish my #OOPSLA reviews! 😇
Check out our ROSARUM benchmark, part of our #icse2025 paper on backdoors and fuzzing: ▶️ It is a fuzzing benchmark (can fuzzers trigger backdoors reliably and fast?) ▶️ It is a backdoor detection benchmark (can code analyses find backdoors reliably?) ⬇️ github.com/binsec/rosarum
GitHub - binsec/rosarum: A novel backdoor detection benchmark
A novel backdoor detection benchmark. Contribute to binsec/rosarum development by creating an account on GitHub.
github.com
How to detect backdoors efficiently? 🗣️ The slides of our #icse2025 presentation on "Finding Backdoors with Fuzzing" are now available at ⬇️ binsec.github.io/assets/publi...
"Finding backdoors with fuzzing" --> presentation at @icseconf.bsky.social on Friday at 4pm by the great Dimitri Kokkonis! 👇
How to detect backdoors efficiently? ▶️ Backdoors were found in firmware & open-source code ▶️ Detection requires much manual reverse-engineering ▶️ Fuzzers cannot see backdoors Our @icseconf.bsky.social preprint on finding backdoors with fuzzing is at binsec.github.io/nutshells/ic...
📢 I am looking for a postdoc on fuzzing, to prevent backdoors and supply-chain attacks! Come and join the team here in Paris (or spread the word)! 🙂 Details and application: secubic-ptcc.github.io/jobs/open/20...
🏆 Our ROSA tool for backdoor detection has won a best artifact award at @icseconf.bsky.social! Try it out: github.com/binsec/rosa Huge thanks and congrats to my student Dimitri Kokkonis for his huge and great work! 👏👏👏
#FUZZING'25 Deadline Extension ────── If you have not finished your #FUZZING paper yet, you are in luck! :) We decided to extend the deadline to March 26, 2025! 🔗 fuzzingworkshop.github.io //cc @rohan.padhye.org, László Szekeres, @ruijiemeng.bsky.social, @mboehme.bsky.social
FUZZING'25 Workshop @ ISSTA
The 4th International Fuzzing Workshop (FUZZING) 2025 welcomes all researchers, scientists, engineers and practitioners to present their latest research findings, empirical analyses, t...
fuzzingworkshop.github.io
Congrats to my PhD student Frank @fbusse.bsky.social for a successful viva! It's been wonderful working together all these years, and I'm looking forward to our next joint projects!
I am looking to recruit a PhD student (fully funded at UK home tuition rate) to work on automated testing and verification of machine learning compilers and runtimes! Deadline: 30th April. Please spread the word! Details here: www.doc.ic.ac.uk/~afd/PhD-Adv...
doc.ic.ac.uk
Our ROSA tool for backdoor detection is available! Try it out! 👇 Tool: github.com/binsec/rosa Benchmark: github.com/binsec/rosarum This work received both Available & Reusable badges at @icseconf.bsky.social 🥳
GitHub - binsec/rosa: ROSA: Finding Backdoors with Fuzzing
ROSA: Finding Backdoors with Fuzzing. Contribute to binsec/rosa development by creating an account on GitHub.
github.com
Happy to read such enthusiastic reactions to our @icseconf.bsky.social paper! ☺️ "ROSA Sets a New Standard for Backdoor Detection." "If you work in cybersecurity, penetration testing, or software auditing, ROSA is a must-try in the fight against hidden threats." medium.com/@itsissachar...
ROSA: A Breakthrough in Backdoor Detection with Fuzzing
The security industry is constantly battling against hidden backdoors—maliciously planted vulnerabilities that grant attackers undocumented…
medium.com
How to detect backdoors efficiently? ▶️ Backdoors were found in firmware & open-source code ▶️ Detection requires much manual reverse-engineering ▶️ Fuzzers cannot see backdoors Our @icseconf.bsky.social preprint on finding backdoors with fuzzing is at binsec.github.io/nutshells/ic...
ICSE'25: research paper
BINSEC: ICSE'25: research paper
binsec.github.io
I am happy to welcome Andy Zalcman as a new PhD student on better fuzzing guidance! Looking forward to doing fun research together! 🥳 Details: binsec.github.io/people/zalcm...
🥳📰 Very happy and proud that our paper on finding backdoors with fuzzing was accepted at the main track of @icseconf.bsky.social! More details to follow soon 🙂 Congratulations and thank you to my students Dimitri Kokkonis and Emilien Decoux and co-supervisor Stefano Zacchiroli!
Thank you @mu00d8.bsky.social for presenting your work on improving fuzzer evaluation practices to our team's webinar! This was an enlighting talk and I recommend every fuzzing person to check out the corresponding paper (Distinguished Paper award at S&P'24)! oaklandsok.github.io/papers/schlo...
Trying and building a list of CS research people on Bluesky... bsky.app/profile/mich...