Share this page

Dominik Wermke

Assistant Professor at North Carolina State University
Academic:
Other:
GitHub dwermke, LinkedIn LinkedIn

Hi, I am an Assistant Professor in the Department of Computer Science at North Carolina State University (NC State). I am a member of the Secure Computing Institute (SCI), the Wolfpack Security and Privacy Research (WSPR) Lab, and the Secure Software Supply Chain Center (S3C2).

My research focuses on computer security, taking a human-centered approach to software supply chain security and open source security. More recently, I have also been exploring AI, agents, and software security.

Interested in doing a PhD with me? I am typically open to advising new PhD students.

My Research #

Research word cloud highlighting security, developers, software, users, open source, software supply chains, and privacy.
Themes from my publication titles and abstracts, with the last three years weighted 2×.

My research focuses on the people who build and maintain the software we depend on. I take a human-centered approach to software supply chain security and open source security. More recently, I have been exploring how AI and autonomous agents change the work of developing and securing software. See the publications page for papers and details.

I often combine studies of people’s experiences with large-scale analyses of software and development practices, drawing on both qualitative and quantitative methods.

Software Supply Chain Security #

I study security across the software supply chain, from authoring code and managing source to builds, dependencies, and distribution. My focus is on the developers and other practitioners who shape these processes.

  • Build processes: build script quality [C20] and the challenges of reproducible builds [C13].
  • Software composition analysis: how developers use SCA tools and assess vulnerability alerts in context [C19].
  • Supply chain security practices: developers’ approaches to securing their supply chains [W3] and broader research directions [J1].

Open Source Security #

I study open source as a foundation of our software ecosystem, focusing on how maintainers and contributors secure and sustain their projects under practical constraints. My work also examines collaboration and support from organizations that depend on these projects.

  • Project practices and ecosystem support: maintainers’ security practices and resource constraints [C10], and how companies assess and support the open source projects they depend on [C12].
  • Contribution authenticity: attribution of open source contributions, contributor spoofing, and adoption of commit signing [C18].
  • Secret leakage: prevention and handling of secret leakage in source code repositories [C14].
  • Trust relationships and measurement: understanding and measuring trust through developers’ behavior [C15].

Human-Centered Security and Privacy #

I sometimes also study broader questions in human-centered and usable security, including how people understand security and privacy, make decisions, and interact with security tools.

  • Security decisions and constraints: security decisions in small and medium-sized enterprises [C9], and how software creators address unintended consequences of security and privacy tools [C17].
  • Security advice and developer support: security and privacy advice shared during crises [C16], library-integrated guidance for secure cryptography use [C4], and IDE support for secure Android development [C3].
  • Privacy expectations and security perceptions: users’ expectations of privacy in cloud applications [C6] and perceptions of messaging security [C8].

AI, Agents, and Software Security #

More recently, I have been studying secure AI integration and exploring how autonomous agents reshape development practices and software ecosystems.

  • Secure AI integration: how practitioners select and securely integrate AI components [Preprint].
  • Autonomous agents: emerging work on adversarial and defensive uses of autonomous agents in software development.
  • Agents in development workflows: security implications of developers delegating work to agents.

Contact Information #

Postal Mail:

Dominik Wermke
890 Oval Drive, Box 8206
Koch Hall
Raleigh, NC 27695-8206

Deliveries:

3320 Koch Hall
890 Oval Drive
Raleigh, NC 27695-8206