Primary Supervisor
- Position
- Senior Lecturer in Cybersecurity
- Division / Faculty
- Faculty of Science
Other QUT supervisors
- Position
- Senior Lecturer in Cybersecurity
- Division / Faculty
- Faculty of Science
Overview
AI tools now help uncover thousands of software vulnerabilities every month, but most run on external, often overseas, servers. Even with data retention agreements, organisations may be reluctant to send sensitive code to a third party. Locally-hosted models avoid this by running on hardware the organisation owns or rents, keeping all data in-house, and have become more practical as smaller models grow more capable.
This project evaluates how well these smaller, locally-hosted models detect vulnerabilities in real-world software, spanning the AI/ML and software security domains. It aims to identify where these models succeed, where they fail, and whether they show promise beyond detection.
Research engagement
The project is primarily experimental: evaluating models against existing datasets.
Research activities
The student will:
- Run language models against code samples, and build tooling to convert samples into formats suitable for larger-scale evaluation.
- Design and tune prompts and model hyperparameters, measuring their effect on detection rates.
- Compare performance across datasets of different program representations and vulnerability types.
- Test whether models can patch vulnerabilities and/or write exploits.
The student will work with academics in the School of Computer Science with expertise in software security and AI/ML.
Research skills
The student will gain:
- Practical experience with large language models and agentic tooling, including effective prompting and critical interpretation of outputs.
- Techniques for evaluating model performance and working with labelled datasets.
- Understanding of common vulnerability types in system software (mainly C/C++).
Outcomes
The project aims to determine:
- How effective locally-hosted models are at detecting vulnerabilities across different program representations.
- How prompting and hyperparameter choices, including reasoning levels, affect detection performance.
- Whether detection generalises across a broad range of real-world vulnerability categories.
- Common failure patterns, pointing to areas for future improvement.
Skills and experience
Ideally, the student has some awareness of:
- Used agentic AI coding assistants (e.g. Claude Code, Codex, GitHub Copilot, OpenCode).
- A basic understanding of how language models work (e.g. prompting, context, models vs. harnesses).
- Experience writing and debugging C/C++ and Python.
Start date
2 November, 2026End date
19 February, 2027Location
QUT Gardens Point Campus
Keywords
Contact
Connor McLaughlin
0449650510
c.mclaughlin@qut.edu.au