AI · Software Engineering · Security

Nusrat
Zahan

Incoming Postdoctoral Fellow, Columbia University · Data Science Institute

I'm an applied researcher working across AI, software engineering, and security, using data, machine learning, and large language models to make software measurably safer. I earned my Ph.D. in Computer Science at North Carolina State University with Prof. Laurie Williams in the RealSearch Group, running large-scale studies of real software ecosystems to turn security guesswork into evidence. Through research internships at Socket and Microsoft Research, I've taken this work into practice, and several of my methods and datasets are now used in industry tools.

Nusrat Zahan

01 · About

Work that bridges software engineering, security, and AI.

My research brings together software engineering, security, and AI. I combine empirical measurement across large software ecosystems, statistical and causal analysis, and automated reasoning with large language models. One question connects the work: which security practices matter, how can they be measured, and how much do they actually reduce risk?

The security signals and risk metrics I proposed in my research are now integrated into widely used supply-chain security tools, including Socket, PackJ, and GuardDog. More broadly, my work has produced tools, datasets, and metrics used across industry, including Datadog, npm, Microsoft, Fortinet, and the Google/OpenSSF Scorecard team. It has drawn interest from government stakeholders such as the U.S. DoD and DHS, been covered by The Register, The Daily Swig, and The Record, and published at ICSE, TOSEM, EMSE, MSR, and IEEE Security & Privacy.

Looking ahead, I'm extending this work toward secure, agentic AI: building and evaluating AI agents that are robust, aligned, and resilient enough to be trusted in real-world settings.

Secure & Agentic AI Trustworthy AI Agents AI Robustness & Alignment Adversarial Resilience Applied ML & LLMs Threat & Malware Detection Large-scale Empirical Analysis Software Security Security Metrics Automation Supply Chain Security Data-Driven Decision Making

Education

Ph.D., Computer Science
North Carolina State University
Jan 2020 – Dec 2025
B.Sc., Electronics & Communication Engineering
Khulna University of Engineering & Technology
Jul 2011 – Jun 2015

02 · Experience

Where I've worked.

Research and security roles across academia and industry, from NC State's RealSearch Group to Socket, Microsoft, and NEC.

Research Assistant · RealSearch Group, NC State
May 2020 – 2025
  • Published 7 top-tier papers, 5 co-authored papers, and 3 technical reports.
  • Led empirical research on the effectiveness of software security practices in improving real-world security.
  • Designed and executed large-scale qualitative and quantitative studies across open-source ecosystems (npm, PyPI), combining statistical analysis and machine learning to develop novel security metrics.
  • Worked on an NSF-funded grant and collaborated with sponsors at Google and Cisco.
Collaboration: Microsoft · Google · GitHub · npm · Cisco  •  Skills: BigQuery · Statistical Modeling · MySQL · Empirical Research · Python · Supply Chain Security · Data Mining · ML
Security Research Intern · Socket, Inc.
Aug 2023 – Jan 2024
  • Built an LLM pipeline integrating static analysis with GPT-3.5/GPT-4, improving automated malicious package detection across millions of npm packages.
  • Investigated prompt strategies (CoT, Iterative Self-Refinement, LLM-as-a-Judge) to extract key threat indicators.
  • Optimized pipeline efficiency by reducing LLM-invoked files by 78%, cutting analysis costs by over 76%.
  • Built data infrastructure to construct a benchmark dataset for evaluating malware detection.
Skills: LLM · CodeQL · MySQL · Empirical Research · Python · Supply Chain Security · JS · ML
Research Intern · Microsoft Research (SAINTES Group)
May 2021 – Aug 2021
  • Conducted an empirical analysis of 1.63 million npm packages to identify data-driven novel attacks.
  • Developed a comparison system using attack metrics to detect thousands of compromised npm accounts.
  • Collaborated with npm and GitHub to strengthen defense strategies; ran a survey that uncovered eight new security weaknesses.
  • Presented findings to Microsoft, npm, GitHub, and Cisco.
Skills: Human Factors · Survey Research · SQL · Python · Supply Chain Security · npm · Large-scale Data Analysis
Teaching Assistant · CSC 515 Software Security · NC State
Jan 2020 – Apr 2020
  • Developed laboratory exercises and assessments.
  • Delivered lectures on software supply chain security.
  • Prepared material and guidelines for different security tools and techniques.
  • Supervised students for independent research projects.
Security Specialist · NEC Corporation
Apr 2016 – Aug 2018
  • Integrated and deployed biometric sensing systems (fingerprint and facial recognition) on an embedded access-control platform.
  • Conducted system-level testing of biometric pipelines, assessing sensor reliability, robustness, and recognition error rates.
  • Analyzed video and sensor data to identify physical adversarial conditions and enhance system accuracy.

03 · Research Projects

Selected work.

Empirical studies and tools across LLM-based malware detection, evidence-based security practices, and open-source ecosystem risk. Each one connects large-scale measurement, machine learning, and security evidence.

01

Prioritization of Evidence-based Practices Adoption

Investigated the relationship between publicly available security-practice adoption data and security outcomes. Aggregated adoption is associated with 5.2 fewer vulnerabilities, 216.8 days faster MTTR, and 52.3 days faster MTTU. Code Review, diverse contributors, License, CI-Tests, and Pinned Dependencies showed the strongest associations.

Read paper →
02

Leveraging LLMs to Detect npm Malicious Packages

SocketAI, a malicious-code review workflow. GPT-4 reaches 99% precision and 97% F1; GPT-3 offers a cost-effective 91% precision / 94% F1. Prescreening files with a static analyzer reduces LLM-analyzed files by 77.9% and cuts costs by up to 76.1%.

Read paper →
03

What are Weak Links in the npm Supply Chain?

Studied the npm ecosystem from a data-driven attacker's view and proposed six signals of supply chain weakness: expired email domains, install scripts, unmaintained packages, too many maintainers, too many contributors, and overloaded maintainers.

Read paper →
Media & adoption PortSwigger Top 10 · The Record · The Register · Aqua Security
Signals integrated into Socket, packj, guarddog, sdc-check.
04

OpenSSF Scorecard: Toward Ecosystem-wide Automated Security Metrics

Evaluated OpenSSF Scorecard metrics across npm and PyPI to identify security gaps and recommend automated practices. ML models highlighted Code-Review, Maintained, Branch Protection, and Security Policy as the most important metrics for package security.

Read paper →
05

Do I Really Need All This Work to Find Vulnerabilities?

Compared six categories of vulnerability detection and prevention techniques (SMPT, EMPT, DAST, IAST, RASP, and SAST) on a large Java open-source medical-records application, giving practitioners guidance on selecting techniques to remove the most vulnerabilities within limited resources.

Read paper →
06

Software Bills of Materials: Are We There Yet?

Examined the state and readiness of SBOM adoption for securing the software supply chain, published in IEEE Security & Privacy Magazine.

See in publications →

04 · Publications

Research publications.

Peer-reviewed work at ICSE, TOSEM, MSR, EMSE, IEEE S&P Magazine and more. Author name in bold.

2025
Leveraging Large Language Models to Detect npm Malicious Packages
Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, Laurie Williams
ICSE 2025, IEEE/ACM 47th International Conference on Software Engineering
Research Directions in Software Supply Chain Security
Laurie Williams, et al.
ACM Transactions on Software Engineering and Methodology (TOSEM)
Comparing Effectiveness and Efficiency of IAST and RASP Tools
Aishwarya Seth, Saikath Bhattacharya, Sarah Elder, Nusrat Zahan, Laurie Williams
Empirical Software Engineering (EMSE)
Can the Rising Tide of Software Supply Chain Attacks Raise All Software Engineering Boats?Keynote
Laurie Williams, Sivana Hamer, Nusrat Zahan
Companion Proceedings of FSE 2025
2024
MalwareBench: Malware Samples Are Not Enough
Nusrat Zahan, Philipp Burckhardt, Mikola Lysenko, Feross Aboukhadijeh, Laurie Williams
MSR 2024, IEEE/ACM 21st International Conference on Mining Software Repositories
Industry Secure Supply Chain Summit
Nusrat Zahan, Yasemin Acar, Michel Cukier, William Enck, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, Laurie Williams
2023
Do Software Security Practices Yield Fewer Vulnerabilities?
Nusrat Zahan, Parth Kanakiya, Brian Hambleton, Shohanuzzaman Shohan, Laurie Williams
ICSE-SEIP 2023
OpenSSF Scorecard: On the Path Toward Ecosystem-Wide Automated Security Metrics
Nusrat Zahan, Parth Kanakiya, Brian Hambleton, Shohanuzzaman Shohan, Laurie Williams
IEEE Security & Privacy Magazine (2023)
Software Supply Chain Risk Assessment Framework
Nusrat Zahan
ICSE-Companion 2023
Software Bills of Materials Are Required. Are We There Yet?
Nusrat Zahan, Elizabeth Lin, Mahzabin Tamanna, William Enck, Laurie Williams
IEEE Security & Privacy Magazine (2023)
2022
What are Weak Links in the npm Supply Chain?
Nusrat Zahan, Thomas Zimmermann, Patrice Godefroid, Brendan Murphy, Chandra Maddila, Laurie Williams
ICSE-SEIP 2022
Do I Really Need All This Work to Find Vulnerabilities? An Empirical Case Study on a Java Application
Sarah Elder, Nusrat Zahan, Rui Shu, Monica Metro, Valeri Kozarev, Tim Menzies, Laurie Williams
Empirical Software Engineering (EMSE)
2021
Structuring a Comprehensive Software Security Course Around the OWASP Application Security Verification Standard
Sarah Elder, Nusrat Zahan, Valeri Kozarev, Rui Shu, Tim Menzies, Laurie Williams
ICSE-SEET 2021
IN
SUB.
How Quickly Do Development Teams Update Their Vulnerable Dependencies?
Imranur Rahman, Nusrat Zahan, Stephen Magill, William Enck, Laurie Williams

05 · Mentorship

Students I've mentored.

Mentorship goes both ways: I share what I know, and I get better at mentoring and communicating in the process. During my Ph.D. I had the chance to work with these smart, creative students at different stages of their studies.

Graduate Students

Ummay Kulsum
Ph.D. Student
Mahzabin Tamanna
Ph.D. Student
Imranur Rahman
Ph.D. Student
Shanmukh Pawan
MS Student
Parth Kanakiya
MS · last known: Amazon
Anupam Devulapalli
MS · last known: MGM
Aniqa Zaida Khanom
MS · last known: Microsoft
Jack Macdonald
MS · last known: Amazon
Anna Owens
MS · last known: Microsoft
Aishwarya Seth
MS · last known: Microsoft

Undergraduate Students

Dylan Crooks
Undergrad · last known: Cisco
Maxwell Harkness
Undergrad · last known: Fidelity Investments
Brian Hambleton
Undergrad
Jamison Cox
Undergrad
Dipen Patel
Undergrad

Get in touch.

Interested in research collaboration across AI, software engineering, and security? I'd be glad to hear from you.