People / Faculty / Dominik Wermke

Dominik Wermke

  • Assistant Professor
Profile photo of Dominik Wermke

Bio

Dominik Wermke is an Assistant Professor in the Department of Computer Science at North Carolina State University. His research interests center around empowering software experts to design, develop, and deploy secure, privacy-respecting, and trust-worthy software. His general areas of research are in usable security & privacy, software supply chain security & transparency, the open source ecosystem, and supporting software experts in designing secure and user-friendly systems. Prior to joining NC State, Dominik was a researcher at the CISPA Helmholtz Center for Information Security and part of the TeamUSEC research group for human-centered security. He received his Dr. rer. nat. (PhD equivalent) in computer science from Leibniz University Hannover in 2023 and both a M.Sc. and B.Sc. from Saarland University in 2016 and 2015 respectively.

Publications

  • Mahzabin Tamanna, Yash Chandrani, Matthew Burrows, Brandon Wroblewski, Laurie Williams, and and Dominik Wermke, Your Build Scripts Stink: The State of Code Smells in Build Scripts, in Proceedings of the 40th IEEE/ACM International Conference on Automated Software Engineering (ASE), Nov. 2025.
  • Elizabeth Lin, Sparsha Gowda, William Enck, and Dominik Wermke, Context Matters: Qualitative Insights into Developers’ Approaches and Challenges with Software Composition Analysis, in Proceedings of the USENIX Security Symposium, Aug. 2025.
  • Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, Michel Cukier, Christian Kästner, Alexandros Kapravelos, Dominik Wermke, and William Enck, Research Directions in Software Supply Chain Security, ACM Transactions on Software Engineering Methodology (TOSEM), pp. 1–38, May 2025.
    [PDF]
  • Jan-Ulrich Holtgrave, Kay Friedrich, Fabian Fischer, Nicolas Huaman, Niklas Busch, Jan H. Klemmer, Marcel Fourné, Oliver Wiese, Dominik Wermke, and Sascha Fahl, Attributing Open-Source Contributions is Critical but Difficult: A Systematic Analysis of GitHub Practices and Their Impact on Software Supply Chain Security, in Proceedings of the ISOC Network and Distributed System Security Symposium (NDSS), Feb. 2025.
    [PDF]
  • Rami Sammak, Anna Lena Rotthaler, Harshini Sri Ramulu, Dominik Wermke, and Yasemin Acar, Developers’ Approaches to Software Supply Chain Security: An Interview Study, in Proceedings of the ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED 2024), Oct. 2024.
  • Harshini Sri Ramulu, Helen Schmitt, Dominik Wermke, and Yasemin Acar, Security and Privacy Software Creators’ Perspectives on Unintended Consequences, in Proceedings of the 33rd USENIX Security Symposium (USENIX Sec ’24), Aug. 2024.
    [PDF]
  • Nusrat Zahan, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2023-11: Industry Secure Supply Chain Summit. Aug-2024. arXiv:2408.16529.
    [PDF]
  • Juliane Schmüser, Harshini Sri Ramulu, Noah Wöhler, Christian Stransky, Felix Bensmann, Dimitar Dimitrov, Sebastian Schellhammer, Dominik Wermke, Stefan Dietze, Yasemin Acar, and Sascha Fahl, Analyzing Security and Privacy Advice During the 2022 Russian Invasion of Ukraine on Twitter, in Proceedings of the ACM CHI Conference on Human Factors in Computing Systems (ACM CHI ’24), May 2024, pp. 1–16.
  • Greg Tystahl, Yasemin Acar, Michel Cukier, William Enck, Alexandros Kapravelos, Christian Kästner, Dominik Wermke, and Laurie Williams, S3C2 Summit 2024-03: Industry Secure Supply Chain Summit. May-2024. arXiv:2405.08762.
    [PDF]
  • Lina Boughton, Courtney Miller, Yasemin Acar, Dominik Wermke, and Christian Kästner, Decomposing and Measuring Trust in Open-Source Software Supply Chains, in Proceedings of the IEEE/ACM 46th International Conference on Software Engineering: New Ideas and Emerging Results (IEEE/ACM ICSE-NIER ’24), Apr. 2024.
  • Marcel Fourné, Dominik Wermke, William Enck, Sascha Fahl, and Yasemin Acar, It’s like flossing your teeth: On the Importance and Challenges of Reproducible Builds for Software Supply Chain Security, in Proceedings of the IEEE Symposium on Security and Privacy (S&P), May 2023.
  • Dominik Wermke, Nicolas Huaman, Yasemin Acar, Bradley Reaves, Patrick Traynor, and Sascha Fahl, A Large Scale Investigation of Obfuscation Use in Google Play, in Proceedings of the Annual Computer Security Applications Conference (ACSAC), Dec. 2018.
    (acceptance rate=20.1%)