Nusrat
Zahan
Incoming Postdoctoral Fellow, Columbia University · Data Science Institute
I'm an applied researcher working across AI, software engineering, and security, using data, machine learning, and large language models to make software measurably safer. I earned my Ph.D. in Computer Science at North Carolina State University with Prof. Laurie Williams in the RealSearch Group, running large-scale studies of real software ecosystems to turn security guesswork into evidence. Through research internships at Socket and Microsoft Research, I've taken this work into practice, and several of my methods and datasets are now used in industry tools.
Work that bridges software engineering, security, and AI.
My research brings together software engineering, security, and AI. I combine empirical measurement across large software ecosystems, statistical and causal analysis, and automated reasoning with large language models. One question connects the work: which security practices matter, how can they be measured, and how much do they actually reduce risk?
The security signals and risk metrics I proposed in my research are now integrated into widely used supply-chain security tools, including Socket, PackJ, and GuardDog. More broadly, my work has produced tools, datasets, and metrics used across industry, including Datadog, npm, Microsoft, Fortinet, and the Google/OpenSSF Scorecard team. It has drawn interest from government stakeholders such as the U.S. DoD and DHS, been covered by The Register, The Daily Swig, and The Record, and published at ICSE, TOSEM, EMSE, MSR, and IEEE Security & Privacy.
Looking ahead, I'm extending this work toward secure, agentic AI: building and evaluating AI agents that are robust, aligned, and resilient enough to be trusted in real-world settings.
Education
Where I've worked.
Research and security roles across academia and industry, from NC State's RealSearch Group to Socket, Microsoft, and NEC.
- Published 7 top-tier papers, 5 co-authored papers, and 3 technical reports.
- Led empirical research on the effectiveness of software security practices in improving real-world security.
- Designed and executed large-scale qualitative and quantitative studies across open-source ecosystems (npm, PyPI), combining statistical analysis and machine learning to develop novel security metrics.
- Worked on an NSF-funded grant and collaborated with sponsors at Google and Cisco.
- Built an LLM pipeline integrating static analysis with GPT-3.5/GPT-4, improving automated malicious package detection across millions of npm packages.
- Investigated prompt strategies (CoT, Iterative Self-Refinement, LLM-as-a-Judge) to extract key threat indicators.
- Optimized pipeline efficiency by reducing LLM-invoked files by 78%, cutting analysis costs by over 76%.
- Built data infrastructure to construct a benchmark dataset for evaluating malware detection.
- Conducted an empirical analysis of 1.63 million npm packages to identify data-driven novel attacks.
- Developed a comparison system using attack metrics to detect thousands of compromised npm accounts.
- Collaborated with npm and GitHub to strengthen defense strategies; ran a survey that uncovered eight new security weaknesses.
- Presented findings to Microsoft, npm, GitHub, and Cisco.
- Developed laboratory exercises and assessments.
- Delivered lectures on software supply chain security.
- Prepared material and guidelines for different security tools and techniques.
- Supervised students for independent research projects.
- Integrated and deployed biometric sensing systems (fingerprint and facial recognition) on an embedded access-control platform.
- Conducted system-level testing of biometric pipelines, assessing sensor reliability, robustness, and recognition error rates.
- Analyzed video and sensor data to identify physical adversarial conditions and enhance system accuracy.
Selected work.
Empirical studies and tools across LLM-based malware detection, evidence-based security practices, and open-source ecosystem risk. Each one connects large-scale measurement, machine learning, and security evidence.
Prioritization of Evidence-based Practices Adoption
Investigated the relationship between publicly available security-practice adoption data and security outcomes. Aggregated adoption is associated with 5.2 fewer vulnerabilities, 216.8 days faster MTTR, and 52.3 days faster MTTU. Code Review, diverse contributors, License, CI-Tests, and Pinned Dependencies showed the strongest associations.
Read paper →Leveraging LLMs to Detect npm Malicious Packages
SocketAI, a malicious-code review workflow. GPT-4 reaches 99% precision and 97% F1; GPT-3 offers a cost-effective 91% precision / 94% F1. Prescreening files with a static analyzer reduces LLM-analyzed files by 77.9% and cuts costs by up to 76.1%.
Read paper →What are Weak Links in the npm Supply Chain?
Studied the npm ecosystem from a data-driven attacker's view and proposed six signals of supply chain weakness: expired email domains, install scripts, unmaintained packages, too many maintainers, too many contributors, and overloaded maintainers.
Read paper →Signals integrated into Socket, packj, guarddog, sdc-check.
OpenSSF Scorecard: Toward Ecosystem-wide Automated Security Metrics
Evaluated OpenSSF Scorecard metrics across npm and PyPI to identify security gaps and recommend automated practices. ML models highlighted Code-Review, Maintained, Branch Protection, and Security Policy as the most important metrics for package security.
Read paper →Do I Really Need All This Work to Find Vulnerabilities?
Compared six categories of vulnerability detection and prevention techniques (SMPT, EMPT, DAST, IAST, RASP, and SAST) on a large Java open-source medical-records application, giving practitioners guidance on selecting techniques to remove the most vulnerabilities within limited resources.
Read paper →Software Bills of Materials: Are We There Yet?
Examined the state and readiness of SBOM adoption for securing the software supply chain, published in IEEE Security & Privacy Magazine.
See in publications →Research publications.
Peer-reviewed work at ICSE, TOSEM, MSR, EMSE, IEEE S&P Magazine and more. Author name in bold.
Students I've mentored.
Mentorship goes both ways: I share what I know, and I get better at mentoring and communicating in the process. During my Ph.D. I had the chance to work with these smart, creative students at different stages of their studies.
Graduate Students
Undergraduate Students
Get in touch.
Interested in research collaboration across AI, software engineering, and security? I'd be glad to hear from you.