Nicolás E. Díaz Ferreyra

Senior Researcher and Lecturer

nico2jpg.jpg

Institute of Software Security

Blohmstr. 15

21079 Hamburg, Germany

I am a senior researcher and lecturer (tenured faculty member) at the Institute of Software Security of Hamburg University of Technology. My main research focus stands at the intersection of human-computer interaction and privacy engineering. Particularly, I am passionate about people’s privacy practices in networked environments, their associated risks, and developing technologies to support information disclosure. For this, I analyse empirical data extracted from software repositories, conduct studies with human participants, and elaborate on machine learning models. I am especially interested in digital nudging applications for privacy and the usability of security-enhancing technologies.

Before joining the Hamburg University of Technology, I worked as a postdoctoral fellow at the University of Duisburg-Essen. From January 2020 to October 2021 I was the coordinator of the RTG “User-Centered Social Media” funded by the German Research Foundation (DFG). I have taken part of several European projects on privacy and securiy including PDP4E, AssureMOSS and more recently Sec4AI4Sec: Cybersecurity for AI-Augmented Systems. In the past, I have worked as a software engineer in Denmark and as an undergraduate research assistant in Argentina.

Since 2023 I am an associate member of the Research Institute for Socio-Technical Cybersecurity (RISCS) at the University of Bristol. Besides conducting my research, I am involved in multi-stakeholder forums for the discussion of public policies and Internet governance issues. Particularly, in debates concerning the users’ right to privacy and control over their private information.

news

Aug 20, 2024 I am co-organizing the 3rd Workshop on Mining Software Repositories Applications for Privacy and Security at SANER '25
Aug 15, 2023 📣 I will be in Melbourne 🇦🇺 from September to mid-November 2023, working as a visiting scholar at RMIT University
Jul 15, 2023 I am co-organizing the 2nd Workshop on Mining Software Repositories Applications for Privacy and Security at SANER '24
Dec 08, 2021 IGF 2021 Town Hall #19 Paving the Road for the European Regulation on AI
Aug 16, 2021 I4ADA: Dialogues on Accountability in the Digital Age

selected publications

  1. CHASE ’25
    The Good, the Bad, and the (Un)Usable: A Rapid Literature Review on Privacy as Code
    Nicolás E. Díaz Ferreyra, Sirine Khelifi, Nalin Arachchilage, and 1 more author
    In 18th International Conference on Cooperative and Human Aspects of Software Engineering (CHASE 2025), 2025
  2. ASE ’24
    MADE-WIC: Multiple Annotated Datasets for Exploring Weaknesses In Code
    Moritz Mock, Jorge Melegati, Max Kretschmann, and 2 more authors
    In Proceedings of the 39th IEEE/ACM International Conference on Automated Software Engineering, Sacramento, CA, USA, 2024
  3. MSR ’24
    What Can Self-Admitted Technical Debt Tell Us About Security? A Mixed-Methods Study
    Nicolás E. Díaz Ferreyra, Mojtaba Shahin, Mansooreh Zahedi, and 2 more authors
    In Proceedings of the 21st International Conference on Mining Software Repositories (MSR ’24), 2024
  4. SNAM ’23
    Cybersecurity Discussions in Stack Overflow: A Developer-Centred Analysis of Engagement and Self-Disclosure Behaviour
    Nicolás E. Díaz Ferreyra, Melina Vidoni, Maritta Heisel, and 1 more author
    Social Network Analysis and Mining, Dec 2023
  5. JSS ’23
    Simple Stupid Insecure Practices and GitHub’s Code Search: A Looming Threat?
    Ken Russel Go, Sruthi Soundarapandian, Aparupa Mitra, and 2 more authors
    Journal of Systems and Software, Dec 2023
  6. MSR ’23
    LLMSecEval: A Dataset of Natural Language Prompts for Security Evaluations
    Catherine Tony, Markus Mutas, Nicolás E. Díaz Ferreyra, and 1 more author
    In Proceedings of the 20th International Conference on Mining Software Repositories (MSR ’23), Dec 2023
  7. CHASE ’23
    Developers Need Protection, Too: Perspectives and Research Challenges for Privacy in Social Coding Platforms
    Nicolás E. Díaz Ferreyra, Abdessamad Imine, Melina Vidoni, and 1 more author
    In 16th International Conference on Cooperative and Human Aspects of Software Engineering (CHASE 2023), Dec 2023
  8. QRS ’22
    GitHub Considered Harmful? Analyzing Open-Source Projects for the Automatic Generation of Cryptographic API Call Sequences
    Catherine Tony, Nicolás Díaz Ferreyra, and Riccardo Scandariato
    In 2022 IEEE 22nd International Conference on Software Quality, Reliability and Security Companion (QRS-C), Dec 2022
  9. EuroUSEC ’22
    ENAGRAM: An App to Evaluate Preventative Nudges for Instagram
    Nicolás E. Díaz Ferreyra, Sina Ostendorf, Esma Aïmeur, and 2 more authors
    In 2022 European Symposium on Usable Security (EuroUSEC 2022), Dec 2022
  10. ARES ’22
    SoK: Security of Microservice Applications: A Practitioners’ Perspective on Challenges and Best Practices
    Priyanka Billawa, Anusha Bambhore Tukaram, Nicolás E. Díaz Ferreyra, and 3 more authors
    In International Conference on Availability, Reliability and Security (ARES), Dec 2022
  11. MSR ’22
    Vul4J: A Dataset of Reproducible Java Vulnerabilities Geared Towards the Study of Program Repair Techniques
    Quang-Cuong Bui, Riccardo Scandariato, and Nicolás E. Díaz Ferreyra
    In International Conference on Mining Software Repositories (MSR), Dec 2022
  12. EASE ’22
    Conversational DevBots for Secure Programming: An Empirical Study on SKF Chatbot
    Catherine Tony, Mohana Balasubramanian, Nicolás E. Díaz Ferreyra, and 1 more author
    In Evaluation and Assessment in Software Engineering (EASE), Dec 2022