APP Computer Science Professors Receive $771,822 in NSF Awards to Advance Software Reliability, Cybersecurity

August 26, 2026

APP Division of Computer Science and Engineering Assistant Professors Umar Farooq and Phani Vadrevu have received $771,822 in National Science Foundation (NSF) funding to advance research addressing two critical challenges in computing: ensuring the reliability and security of modern software and protecting online services from increasingly sophisticated malicious bot campaigns.

Farooq received a $300,000 NSF FutureCore award for his project “Documentation-Guided Adaptable Static Analysis” while Vadrevu received a $471,822 NSF grant for his project “Understanding Bot Farms to Measure and Mitigate Internet Bot Attacks.”

Together, the projects highlight the breadth of APP Computer Science research in developing innovative approaches to some of the most pressing challenges facing today's digital infrastructure.

Making Software Analysis More Adaptable

Umar Farooq

APP Division of Computer Science and Engineering Assistant Professor Umar Farooq

Modern software applications increasingly rely on frameworks with extensive and continually evolving documentation that describes the rules and requirements developers must follow to build secure and reliable systems. However, these rules are often scattered across textual descriptions, diagrams and code examples, making it difficult for developers and existing analysis tools to determine whether applications comply with framework guidelines.

Farooq's research will develop methods that can understand framework documentation, translate its guidance into formal rules, analyze application code against those rules and explain violations.

A central innovation of the project is the automatic translation of informal, multimodal framework documentation into formal specifications that can be used to analyze application code. Using targeted retrieval and controlled generation, the research will build models of framework behavior and identify the obligations applications must satisfy.

The project will then combine these specifications with reachability analysis to selectively reason about object- and event-dependent behavior without requiring every possible execution path to be examined. This approach will support multiple forms of analysis, including witness-based checking, safety-violation detection, obligation-discharge reasoning and object-sensitive, demand-driven protocol-conformance analysis.

The research will also generate explanations that connect detected violations to the underlying framework rules and identify the relevant locations in application code. These explanations could help enable targeted automated repair, particularly in environments with limited computing resources.

By connecting framework documentation directly to program analysis, Farooq's work has the potential to help developers identify errors earlier, improve debugging and testing workflows, and increase the reliability, security and performance of software systems.

The project will also provide training opportunities for students in program analysis and artificial intelligence, preparing students to work at the intersection of these rapidly developing fields.

Understanding and Defending Against Bot Farms

Phani Vadrevu

APP Division of Computer Science and Engineering Assistant Professor Phani Vadrevu

While Farooq's project focuses on making software analysis more adaptable, Vadrevu's research addresses another growing challenge to the digital ecosystem: malicious bot campaigns and the human-operated bot farms behind them.

Malicious bot campaigns increasingly threaten online services, including ticketing platforms, government services, travel websites, retail stores and gaming systems. These operations can involve real workers operating through organized bot farms to bypass modern anti-bot protections, enabling fraud and other malicious activity at large scale.

Despite increasing reports of economic losses and service disruptions associated with these campaigns, there remains limited scientific understanding of how bot-farm ecosystems operate in practice and how they can be effectively measured and mitigated.

Vadrevu's project will develop new methods for measuring, characterizing and mitigating malicious bot campaigns by studying the operational workflows of bot farms.

The research will establish a longitudinal bot-farm measurement framework designed to collect forensic data from real-world campaigns targeting websites across multiple sectors and geographic regions. The project will combine qualitative and automated analysis to develop taxonomies, identify long-term threat patterns and examine the operational behavior of bot farms through social media analysis, interviews and observational studies.

The project will also investigate defensive techniques based on network provenance, browser fingerprinting, timing analysis and behavioral biometrics to identify traffic associated with bot-farm operations. By combining these signals, the research aims to strengthen defenses against evolving campaigns while creating high-quality labeled datasets that can support future anti-bot research.

The resulting tools, datasets and research findings will be shared with affected organizations, cybersecurity practitioners, researchers and educational programs to help strengthen defenses against large-scale malicious online campaigns.

The project will also support broader cybersecurity education and outreach, including efforts benefiting small businesses and students.

Advancing APP's Computing Research

Although the projects address different problems, both demonstrate the importance of combining advanced computing techniques with real-world security and reliability challenges.

Farooq's research seeks to make software analysis more capable of adapting to the rapidly changing frameworks on which modern applications depend. Vadrevu's research seeks to deepen scientific understanding of human-in-the-loop cybercrime ecosystems and develop practical defenses against malicious online activity.

Farooq has previously been awarded an NSF CAREER Award to secure softwater for the quantum era: /eng/news-stories/2026/05/umar-farooq-nsf-career.php.

Vadrevu has previously been awarded an NSF CAREER Award to turn scammers’ games against them: /eng/news-stories/2026/06/phani-vadrevu-nsf-career-award.php.

Together, the $771,822 in NSF funding will support research, student training and the development of tools and datasets designed to improve the security, reliability and resilience of digital systems.

“The problems Umar and Phani are addressing are not theoretical problems sitting on a shelf,” APP Division of CSE Chair Abe Baggili said. “They affect the software people depend on and the online systems we use every day. This is exactly where a great computer science program should be: working on difficult problems before they become even bigger ones.”

The awards further strengthen APP's role in advancing research at the intersection of artificial intelligence, software engineering, program analysis and cybersecurity, while creating opportunities for students to contribute to research addressing emerging challenges in computing.