GIACOMO PRIAMO

PhD Graduate

PhD program:: XXXVIII



Thesis title: Protecting Software from the Ground Up: Compiler-assisted Defenses for Software Security

Compilers can be powerful tools not only for generating optimized code but also for enhancing the security posture of software. In this thesis, we show that the wealth of information they carry about the programs we are building, coupled with the features of modern compiler infrastructures, can offer several opportunities to achieve this goal. We investigate this claim from two different angles. One is related to finding bugs and security vulnerabilities before threat actors do, thus preventing them from mounting sophisticated attacks that may cause service disruptions, data leaks, and severe economic damage, consequently harming the reputation of companies and public institutions alike. The other one is conceived to assist security practitioners in the software maintenance task and relieve them from the burden of manually fixing all the occurrences of identical bugs across the same, and even different, codebases. Our first contribution is a methodology aimed at refining the feedback mechanism of mainstream coverage-guided fuzzers, which for efficiency reasons only collect coarse-grained information about the program being explored (edge coverage). We show that tracking execution paths, which has so far been considered too costly for fuzzing, would offer a richer coverage view to the fuzzer, enhancing its ability to detect subtle bugs even in well-tested software. To counter the resulting seed explosion, we evaluate two strategies: culling and opportunistic path-aware fuzzing, that balance precision and throughput. Our findings show that path-awareness, when properly guided, uncovers more bugs and reveals untapped potential in fuzzing research. Our second contribution leverages the knowledge the compiler produces internally during the building phase of a program, which is detached from its syntactic representation, and elevates it to a more abstract form that is better able to grasp its intended behavior. Starting from the intuition that changes to the source code of a program should be tightly correlated with the compiler's internal perception of it, we devise a framework that captures the meaning of textual software patches at the level of program dependencies, and produces edit patterns capable of targeting the semantics of code, thus amplifying their applicability to different code areas. We argue that this approach can be employed to enhance existing techniques by proposing to tackle an extensively studied problem from a different perspective. This dissertation therefore indicates that software can be protected from its very foundations: the compilation phase, allowing security architects to design defenses that can be seamlessly integrated into its development lifecycle.

Research products

11573/1769557 - 2026 - Towards Path-Aware Coverage-Guided Fuzzing
Priamo, Giacomo; D'elia, Daniele Cono; Payer, Mathias; Querzoni, Leonardo - 04b Atto di convegno in volume
conference: International Symposium on Code Generation and Optimization (Sydney; Australia)
book: [Proceedings of the] 2026 IEEE/ACM International Symposium on Code Generation and Optimization (CGO) - (9798331592882)

11573/1665969 - 2022 - Principled Composition of Function Variants for Dynamic Software Diversity and Program Protection
Priamo, Giacomo; D'elia, Daniele Cono; Querzoni, Leonardo - 04b Atto di convegno in volume
conference: Automated Software Engineering Conference (Rochester; USA)
book: ASE '22: Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering - (9781450394758)

© Università degli Studi di Roma "La Sapienza" - Piazzale Aldo Moro 5, 00185 Roma