Seminars
View all Seminars | Download ICal for this eventApplying LLMs to Secure Software Development
Series: Department Seminar
Speaker: Balakrishnan Dasarathy
Date/Time: Oct 23 10:30:00
Location: CSA Auditorium, (Room No. 104, Ground Floor)
Abstract:
Code-focused large language models (LLMs) such as GitHub Copilot, Claude Code, and Google Gemini are transforming software engineering by enabling natural languageâ??driven code generation, refactoring, debugging, testing, and documentation. These Code LLMs promise unprecedented productivity gains, accelerated development cycles, reduced cognitive burden, and democratized access to programming capabilities. Yet serious risks remain. Empirical studies reveal that Code LLMs generate vulnerable code at alarming ratesâ??ranging from 33% to 70% depending on the programming language, task complexity, and model employed.
A SPARC (The Scheme for Promotion of Academic and Research Collaboration) project (see Link funded by the Government of India, addresses this critical gap at the intersection of artificial intelligence and software security. The main goal is to show practitioners how to safely harness these powerful tools (Code LLMs and related AI-infused tools such as intelligent IDEs and editors) in secure software development workflows. It provides evidence-based guidelines for secure development and deployment. The projectâ??s deliverables include a scholarly monograph, practitioner-oriented guidelines, a two-week, hands-on course, and an international workshop to foster a community of practice in AI-guided secure software development.
In this talk, I will describe this SPARC project, the research questions addressing security challenges and where I am in answering them, and the gaps I am finding and where I could work with faculty and students at IISc. A critical part of my work is developing hands-on laboratory exercisesâ?? building, porting, and assessing a non-trivial, three-tier ledger applicationâ??that practitioners can appreciate and benefit from as they learn to use Code LLM technology. I will demonstrate this application.
Speaker Bio:
Dr. Balakrishnan Dasarathy is a distinguished academic and industry professional specializing in computer sciences. He is currently associated with the University of Maryland Global Campus as an Adjunct Faculty member, after serving for 9 years as a Collegiate Professor and Program Chair for Information Assurance in their graduate school. Before joining UMGC in September 2012, Dr. Dasarathy earned over three decades of R&D and R&D management experience, including at GTE Laboratories (now part of Verizon), Bellcore/Telcordia (now part of Ericsson), and JPMorgan in software and related areas. Throughout his career, he has applied his expertise to both commercial and military systems. His scholarly contributions include extensive publications in information assurance, communication networks, middleware, and distributed computing. His recent focus is on applying Machine Learning techniques to cyber threat and attack detection, and LLM technology to large-scale secure software development.
Dr. Dasarathy holds a Doctorate in Computer and Information Science from The Ohio State University. He is a Certified Information Systems Security Professional (CISSP).
Host Faculty: Deepak D'Souza
