Publications

Supply Chain Reaction: Enhancing the Precision of Vulnerability Triage using Code Reachability Information
Harshvardhan Patel, Alexander Snit, Michalis Polychronakis
Annual Computer Security Applications Conference (ACSAC), 2025 PDF Code

Research Experience

Hexlab @ Stony Brook University Research Assistant
May 2023 - Present
New York, USA
Software Supply Chain Security
  • Applying program analysis techniques to improve the precision of vulnerability-risk assessment for C/C++ binaries.
Container Security
  • Developing solutions to improve vulnerability-risk assessment for containerized applications.
de.ci.phe.red lab @ IIT Bhilai Project Scientist (Part-Time)
Aug 2021 - Mar 2022
Chhattisgarh, India
Secure Boot for Embedded Devices
  • Implemented TPM-based Verified and Measured Boot for Raspberry Pi 4 Model B by patching the U-Boot bootloader.

Industry Experience

Tesla Security Engineering Intern
May 2025 - Aug 2025
Palo Alto, CA, USA
Agentic System for Reviewing Security Alerts
  • Developed an agentic system to analyze security alerts generated from static code analysis tools and identify false positives.
Static Analysis for Security and Reliability of Rust Codebases
  • Used Miri to discover undefined behavior in internal Rust codebases and third-party dependencies. Formally verified critical Rust functions using Kani.
Atonarp Member of Technical Staff
Aug 2020 - Jul 2022
Bangalore, India
Embedded Linux & Firmware
  • Developed custom Linux device drivers, kernel modules for inter-processor communication (RPMSG), and FreeRTOS applications for proprietary hardware.
Secure DevOps
  • Established secure DevOps practices by building security-hardened Debian images and managing Docker pipelines and private repositories.
Bosch-RBEI Security Intern
May 2019 - Jul 2019
Bangalore, India
Container Security & Optimization
  • Optimized and secured containerized Python applications by creating minimal, hardened, and distroless Docker images, achieving 85% size reduction.
Max Secure Software SDE Intern
May 2018 - Jul 2018
Pune, India
Malware Detection
  • Developed a random forest-based malware classifier for Windows executables integrated as a DLL, and a proof-of-concept Android malware detector.