info

Thomas Durieux

Program-analysis engineer. A decade split between academia and industry; now a senior IC at Endor Labs, working on AI SAST and reachability-based software composition analysis. Named inventor on US Patent 12,430,446.

10+years · program analysis
41peer-reviewed papers
3,800+citations
experience
  1. Senior Engineer — AI + Program Analysis

    Endor Labs · Netherlands

    Work on scanner correctness and reliability for the AI-assisted SAST platform — scan determinism, cache integrity, incremental and resumable scans across PR and main-branch flows. Help define how AI SAST quality is measured: benchmark harness, false-positive reduction, detection-confidence scoring. Named inventor on US 12,430,446 — SCA for AI-generated code.

  2. Assistant Professor — Software Engineering

    TU Delft (SERG) · Delft, NL

    Studied program analysis for AI-assisted development: the security risks of LLM-generated code, container supply-chain attack surface, and empirical evaluation of static-analysis tools. Research collaboration with JetBrains. Taught the graduate program-analysis course and supervised PhD and MSc students.

  3. Post-doctoral Researcher

    KTH Royal Institute of Technology · Stockholm, SE

    Reachability-based dependency analysis for Java: measuring unused transitive dependencies in the Maven ecosystem and bytecode-level debloating that removes unreachable code while preserving behaviour.

  4. Post-doctoral Researcher

    INESC-ID Lisbon & Carnegie Mellon · Lisbon / Pittsburgh

    Program analysis for security: an empirical study of static-analysis tools on tens of thousands of smart contracts (the SmartBugs framework), and a comparative study of automated program-repair tools.

education
  1. Ph.D., Computer Science

    INRIA Lille · University of Lille · Microsoft Research

    Static and dynamic analysis for automatic patch generation at runtime; open-sourced Nopol, NPEFix, Dynamoth. Thesis: "From Runtime Failures to Patches."

  2. M.Sc., Computer Science — cum laude

    University of Lille

    Specialization: Software Engineering & Program Analysis.

  3. B.Sc., Computer Science — cum laude

    Institut Paul Lambin, Brussels

    Also: exchange year at the University of Luxembourg (2012 — 2013).

contact

Say hello