Share this page

Dominik Wermke

Assistant Professor at North Carolina State University
Academic:
Other:
GitHub dwermke, LinkedIn LinkedIn

Hi, I am an Assistant Professor in the Department of Computer Science at North Carolina State University (NC State). I am a member of the Secure Computing Institute (SCI), the Wolfpack Security and Privacy Research (WSPR) Lab, and the Secure Software Supply Chain Center (S3C2).

My research focuses on computer security, particularly human-centered security, examining how security mechanisms intersect with the practices, constraints, and decision making of software developers and related practitioners.

Interested in doing a PhD with me? I am typically open to advising new PhD students.

My Research #

Research word cloud highlighting security, developers, software, users, open source, software supply chains, and privacy.
Themes from my publication titles and abstracts, with the last three years weighted 2×.

I study how people build, maintain, and secure software, with a focus on human-centered security and privacy, software supply chain security, and open source security and trust. My recent work also examines AI, agents, and software security. You can find my recent work on the publications page.

I combine qualitative and quantitative methods, including interviews [C19, C17, C14, C13, C12, C10], surveys [C14, C6], user studies and experiments [C11, C8, C4], large-scale repository analyses [C20, C18], and analyses of online security advice [C16]. Together, these help me connect practitioners’ experiences with patterns in software development and security.

Human-Centered Security and Privacy #

I study how people understand security and privacy, make decisions, and work with security mechanisms in practice.

  • Security decisions and constraints: risk perception and adoption of security measures in small and medium-sized enterprises [C9], and how software creators anticipate and mitigate unintended consequences of security and privacy tools [C17].
  • Security advice and developer support: security and privacy advice shared during crises [C16], API-integrated advice for secure use of cryptography [C4], and IDE support for secure Android development [C3].
  • Privacy expectations and security perceptions: users’ expectations of privacy in cloud applications [C6] and perceptions of messaging security [C8].

Software Supply Chain Security #

I study where software dependencies and build processes introduce security risks, and how practitioners address them.

  • Build processes: build script quality [C20] and the challenges of reproducible builds [C13].
  • Software composition analysis: how developers integrate SCA tools into their workflows, interpret vulnerability alerts, and need contextual information about reachability, exploitability, and infrastructure to assess those alerts [C19].
  • Supply chain security practices: developers’ approaches to securing software supply chains [W3] and broader research directions [J1].

Open Source Security and Trust #

I study how trust, collaboration, and contribution practices shape security in open source communities.

  • Trust relationships and measurement: decomposing trust into specific relationships and measuring it through developers’ behavior in open source supply chains [C15].
  • Contribution authenticity: attribution of open source contributions, contributor spoofing, and adoption of commit signing [C18].
  • Project practices and ecosystem support: security policies, contributor guidance, incident handling, and resource constraints in open source projects [C10], and companies’ practices for assessing open source components and supporting the ecosystem they depend on [C12].
  • Secret leakage: prevention and handling of secret leakage in source code repositories [C14].

AI, Agents, and Software Security #

I study secure AI integration and explore how autonomous agents reshape software development and open source ecosystems.

  • Secure AI integration: how practitioners select AI components and account for security when integrating them [Preprint].
  • Autonomous agents: emerging work on adversarial and defensive uses of autonomous agents in software development.
  • Agents in development workflows: how developers use agents for software development and the security implications of delegating development tasks to them.

Contact Information #

Postal Mail:

Dominik Wermke
890 Oval Drive, Box 8206
Koch Hall
Raleigh, NC 27695-8206

Deliveries:

3320 Koch Hall
890 Oval Drive
Raleigh, NC 27695-8206