Faculty/School

Faculty of Science

School of Computer Science

Topic status

We're looking for students to study this topic.

Research centre

Primary Supervisor

Dr Yi Lu
Position
Senior Lecturer in Cybersecurity
Division / Faculty
Faculty of Science

Other QUT supervisors

Dr Yi Lu
Position
Senior Lecturer in Cybersecurity
Division / Faculty
Faculty of Science

Overview

AI tools now help uncover thousands of software vulnerabilities every month, but most run on external, often overseas, servers. Even with data retention agreements, organisations may be reluctant to send sensitive code to a third party. Locally-hosted models avoid this by running on hardware the organisation owns or rents, keeping all data in-house, and have become more practical as smaller models grow more capable.

This project evaluates how well these smaller, locally-hosted models detect vulnerabilities in real-world software, spanning the AI/ML and software security domains. It aims to identify where these models succeed, where they fail, and whether they show promise beyond detection.

Research engagement

The project is primarily experimental: evaluating models against existing datasets.

Research activities

The student will:

  • Run language models against code samples, and build tooling to convert samples into formats suitable for larger-scale evaluation.
  • Design and tune prompts and model hyperparameters, measuring their effect on detection rates.
  • Compare performance across datasets of different program representations and vulnerability types.
  • Test whether models can patch vulnerabilities and/or write exploits.

The student will work with academics in the School of Computer Science with expertise in software security and AI/ML.

Research skills

The student will gain:

  • Practical experience with large language models and agentic tooling, including effective prompting and critical interpretation of outputs.
  • Techniques for evaluating model performance and working with labelled datasets.
  • Understanding of common vulnerability types in system software (mainly C/C++).

Outcomes

The project aims to determine:

  • How effective locally-hosted models are at detecting vulnerabilities across different program representations.
  • How prompting and hyperparameter choices, including reasoning levels, affect detection performance.
  • Whether detection generalises across a broad range of real-world vulnerability categories.
  • Common failure patterns, pointing to areas for future improvement.

Skills and experience

Ideally, the student has some awareness of:

  • Used agentic AI coding assistants (e.g. Claude Code, Codex, GitHub Copilot, OpenCode).
  • A basic understanding of how language models work (e.g. prompting, context, models vs. harnesses).
  • Experience writing and debugging C/C++ and Python.

Start date

2 November, 2026

End date

19 February, 2027

Location

QUT Gardens Point Campus

Keywords

Contact

Connor McLaughlin

0449650510

c.mclaughlin@qut.edu.au