Thomas Durieux
Program-analysis engineer. A decade split between academia and industry; now a senior IC at Endor Labs, working on AI SAST and reachability-based software composition analysis. Named inventor on US Patent 12,430,446.
-
Senior Engineer — AI + Program Analysis
2024 — nowEndor Labs · NetherlandsWork on scanner correctness and reliability for the AI-assisted SAST platform — scan determinism, cache integrity, incremental and resumable scans across PR and main-branch flows. Help define how AI SAST quality is measured: benchmark harness, false-positive reduction, detection-confidence scoring. Named inventor on US 12,430,446 — SCA for AI-generated code.
-
Assistant Professor — Software Engineering
2022 — 2024TU Delft (SERG) · Delft, NLStudied program analysis for AI-assisted development: the security risks of LLM-generated code, container supply-chain attack surface, and empirical evaluation of static-analysis tools. Research collaboration with JetBrains. Taught the graduate program-analysis course and supervised PhD and MSc students.
-
Post-doctoral Researcher
2020 — 2022KTH Royal Institute of Technology · Stockholm, SEReachability-based dependency analysis for Java: measuring unused transitive dependencies in the Maven ecosystem and bytecode-level debloating that removes unreachable code while preserving behaviour.
-
Post-doctoral Researcher
2019 — 2020INESC-ID Lisbon & Carnegie Mellon · Lisbon / PittsburghProgram analysis for security: an empirical study of static-analysis tools on tens of thousands of smart contracts (the SmartBugs framework), and a comparative study of automated program-repair tools.
-
Ph.D., Computer Science
2015 — 2018INRIA Lille · University of Lille · Microsoft ResearchStatic and dynamic analysis for automatic patch generation at runtime; open-sourced Nopol, NPEFix, Dynamoth. Thesis: "From Runtime Failures to Patches."
-
M.Sc., Computer Science — cum laude
2013 — 2015University of LilleSpecialization: Software Engineering & Program Analysis.
-
B.Sc., Computer Science — cum laude
2010 — 2013Institut Paul Lambin, BrusselsAlso: exchange year at the University of Luxembourg (2012 — 2013).