
Somesh Jha
· Sheldon B. Lubar Chair and ProfessorUniversity of Wisconsin-Madison · Computer Sciences
Active 1984–2026
Academic metrics are sourced from OpenAlex and public funding records; values may differ from Google Scholar.
About
Somesh Jha is the Lubar Professor in the Computer Sciences Department at the University of Wisconsin, Madison. He holds a Ph.D. from the School of Computer Science at Carnegie Mellon University. His main research interests lie at the intersection of security and formal methods, with current active focus areas including adversarial machine learning and privacy. He has a peripheral interest in topics such as computational finance, although he has not been actively involved in that area for several years. Jha has contributed to the field through his research, and his work can be accessed via his DBLP and Google Scholar pages. He has been involved in various projects, including the Center for Trustworthy Machine Learning, and has mentored several Ph.D. students. In addition to his research, Jha teaches courses such as Introduction to Cryptography and Security and Privacy for Data Science. He has also provided expert consulting as an expert witness and has been involved with startups like Novashield and Tala Security, focusing on malware detection and web security, respectively.
Research topics
- Computer Science
- Artificial Intelligence
- Computer Security
- Data Mining
- Machine Learning
- Operating system
- Distributed computing
- Mathematics
- Telecommunications
- Data science
Selected publications
ATOM: Robustifying Out-of-Distribution Detection Using Outlier Mining
Lecture notes in computer science · 2021 · 75 citations
Senior authorCorrespondingSemantic Robustness of Models of Source Code
2022 IEEE International Conference on Software Analysis, Evolution and Reengineering (SANER) · 2022 · 71 citations
Deep neural networks are vulnerable to adversarial examples-small input perturbations that result in incorrect predictions. We study this problem for models of source code, where we want the neural network to be robust to source-code modifications that preserve code functionality. To facilitate training robust models, we define a powerful and generic adversary that can employ sequences of parametric, semantics-preserving program transformations. We then explore how, with such an adversary, one c…
OAT: Attesting Operation Integrity of Embedded Devices
2022 IEEE Symposium on Security and Privacy (SP) · 2020 · 69 citations
Senior authorCorrespondingDue to the wide adoption of IoT/CPS systems, embedded devices (IoT frontends) become increasingly connected and mission-critical, which in turn has attracted advanced attacks (e.g., control-flow hijacks and data-only attacks). Unfortunately, IoT backends (e.g., remote controllers or in-cloud services) are unable to detect if such attacks have happened while receiving data, service requests, or operation status from IoT devices (remotely deployed embedded devices). As a result, currently, IoT bac…
TRACE: Enterprise-Wide Provenance Tracking for Real-Time APT Detection
IEEE Transactions on Information Forensics and Security · 2021 · 61 citations
We present TRACE, a comprehensive provenance tracking system for scalable, real-time, enterprise-wide APT detection. TRACE uses static analysis to identify program unit structures and inter-unit dependences, such that the provenance of an output event includes the input events within the same unit. Provenance collected from individual hosts are integrated to facilitate construction of a distributed enterprise-wide causal graph. We describe the evolution of TRACE over a four-year period, during w…
Identifying and Mitigating the Security Risks of Generative AI
Foundations and Trends® in Privacy and Security · 2023-12-14 · 43 citations
articleOpen accessEvery major technical invention resurfaces the dual-use dilemma—the new technology has the potential to be used for good as well as for harm. Generative AI (GenAI) techniques, such as large language models (LLMs) and diffusion models, have shown remarkable capabilities (e.g., in-context learning, code-completion, and text-to-image generation and editing). However, GenAI can be used just as well by attackers to generate new attacks and increase the velocity and efficacy of existing attacks. This…
Recent grants
SaTC: CORE: Frontier: Collaborative: End-to-End Trustworthiness of Machine-Learning Systems
NSF · $696k · 2018–2025
CPS: Small: Self-Improving Cyber-Physical Systems
NSF · $500k · 2017–2022
SaTC: CORE: Medium: Collaborative: User-Centered Deployment of Differential Privacy
NSF · $77k · 2020–2021
Frequent coauthors
- 34 shared
Xi Wu
Chengdu University of Information Technology
- 33 shared
Thomas Reps
- 31 shared
Jiefeng Chen
Central South University
- 24 shared
Mihai Christodorescu
- 23 shared
Ninghui Li
- 23 shared
Tianhao Wang
- 21 shared
Matt Fredrikson
- 21 shared
Prasad Chalasani
Education
Ph.D.
School of Computer Science
Similar researchers at University of Wisconsin-Madison
- Resume-aware match score
- Save to shortlist
- AI-drafted outreach
See your match with Somesh Jha
PhdFit ranks faculty by your research interests, methods, and publications — grounded in their actual work, not templates.
- Free to start
- No credit card
- 30-second signup
