research
What the Software Languages Lab works on.
Software is built in layers of abstraction — the software stack — from the system software that runs directly on the hardware up to the applications that people use. SOFT studies the theories, technologies, and methods that underpin the construction of software at every layer of this stack.
SOFT aims to be a leading research group in the foundational domains of Programming Languages, Software Engineering, System Software, and Databases — and in their application to Cybersecurity, AI for Software Engineering, and Cyber-Physical Systems.
Research clusters
The research of SOFT’s professors clusters along three broad themes. Each cluster brings together the research teams of two professors. Themes overlap and evolve over time, and many researchers are active in more than one of them.
Program Construction and Manipulation
Software as a linguistic artefact: the languages in which programs are written, and the tools that reason about programs and change them.
Program analysis, software quality, and the interplay between AI and software engineering: finding bugs and vulnerabilities, engineering AI-enabled software (SE4AI), and applying AI to software engineering tasks (AI4SE).
The design and implementation of programming languages: reactive and actor-based programming, distributed stream processing, domain-specific languages, and language support for AI-enabled software.
Systems and Distribution
The software that runs close to the hardware and across many machines, and the guarantees it offers on correctness and performance.
Programming languages and tools for concurrent and distributed systems: replicated data types, debuggers for distributed and embedded software, and dynamic analysis of WebAssembly and web applications.
The performance and safety of system software: structured performance reasoning, reproducible evaluation, and the migration of C/C++ code to Rust, for operating systems, compilers, and real-time, robotic, and embedded software.
Databases and Applications
Data and the applications built on top of it, from the formal foundations of data management to the engineering of dependable applications.
The foundations of data management at scale: transaction processing and concurrency control, optimal query evaluation in distributed systems, and coordination in asynchronous systems.
Applied software engineering: secure web and cloud applications, distributed ledger technology, domain-specific and neurosymbolic programming environments, and security-event detection for small organisations.
Application domains
- Cybersecurity: The lab develops static and dynamic application security testing, for instance of WebAssembly binaries and Infrastructure as Code. It works on software composition analysis and software supply chain security, from detecting vulnerable dependencies to building more precise software bills of materials. It also designs secure programming languages that rule out vulnerabilities by construction. SOFT is a member of the Cybersecurity Research Program Flanders. Projects include DART, BUGATTI, and CRACY.
- AI for Software Engineering and Software Engineering for AI: Machine learning and large language models can support developers in many tasks, such as predicting design smells, detecting sensitive parameters in Infrastructure as Code, and mining change patterns from commits and library usage from Stack Overflow. The lab also studies how developers can use AI code assistants securely. Conversely, it works on the engineering, verification, and testing of software that integrates AI components. Projects include CodeGuard, SECO-ASSIST, and INTiMALS.
- Cyber-Physical Systems: The lab builds safe, secure, and predictable system software for embedded, real-time, and robotic systems. Its work ranges from scheduling theory and real-time operating systems to the evaluation of new languages and platforms, such as GPUs, for time-sensitive workloads. It migrates legacy C/C++ code to safer languages such as Rust, and develops software frameworks for safe collaborative robots. Projects include Speedup Stacks, Multifaceted Performance, and FORCES.
- Cloud and Decentralised Systems: The lab develops programming languages, verification techniques, and testing tools for software that runs across many machines. It designs replicated data types and languages for replicated state whose consistency is verified automatically, and techniques to test cloud-native applications for flaky behaviour and resilience. It also builds tools and execution layers that make decentralised applications safer and more scalable. Projects include SODISA, EVEREST, and BaseCamp Zero.
See the projects page for all of the lab’s projects.