For the most recent list of papers and patents, visit my Google Scholar page.
Refereed Papers & Articles
"Trustworthy and Confidential SBOM Exchange" (paper)
E. Abu Ishgair, C. Okafor, M. S. Melara, S. Torres-Arias. USENIX Security Symposium. August 2026.
"IDEAS: C-to-Rust Translation Using Improved Large Language Model Decoding and Automated Equivalence Testing" (paper)
C. Cornelius, M. S. Melara, W. Xu, M. Arvinte, M. Momeu, J. He, K. Sen, D. Song. IEEE Security & Privacy, Early Access. July 2026.
"SourceFabric: Consistent and Scalable Security Policies for Git Repositories" (paper)
A. Sirish A Yelgundhalli, P. Zielinski, M. S. Melara, D. Roellke, R. Curtmola, J. Cappos. IEEE European Symposium on Security and Privacy (EuroS&P). July 2026.
"SoK: A Defense-Oriented Evaluation of Software Supply Chain Security" (paper)
E. Abu Ishgair, J. Gomez, M. S. Melara, A. Cardenas, S. Torres-Arias. IEEE European Symposium on Security and Privacy (EuroS&P)*. July 2026.
"Proving Attributes about Confidential Compute Services with Validation and Endorsement Services" (pdf)
A. Vahldiek-Oberwagner, M. S. Melara. IEEE Workshop on System Software for Trusted Execution (SysTEX). July 2025.
"Atlas: A Framework for ML Lifecycle Provenance & Transparency" (pdf)
M. Spoczynski, M. S. Melara, S. Szyller. IEEE Workshop on System Software for Trusted Execution (SysTEX). July 2025.
"A Viewpoint on Software Supply Chain Security: Are We Getting Lost in Translation?" (article)
M. S. Melara and S. Torres-Arias. IEEE Security & Privacy, Vol. 21, Issue 6. November 2023.
"Hardware-Enforced Integrity and Provenance for Distributed Code Deployments" (pdf)
M. S. Melara and M. Bowman. NIST Workshop on Enhancing Software Supply Chain Security. June 2021.
"CONIKS: Bringing Key Transparency to End Users" (pdf) (slides)
M. S. Melara, A. Blankstein, J. Bonneau, E. Felten, M. Freedman. USENIX Security Symposium. August 2015.
Caspar Bowden PET Award, 2017.
"Shining the Floodlights on Mobile Web Tracking — A Privacy Survey" (pdf)
C. Eubank, M. Melara, D. Perez Botero, A. Narayanan. W2SP, 2013.
"Vireos: an Integrated, Bottom-Up Educational Operating Systems Project with FPGA support" (pdf)
M. Corliss, M. Melara. ACM SIGCSE, 2011.
Invited Talks
"Keynote: BEAR-ing Fruit: A Year of Learning, Mentorship, and Community Building in Open Source Security" (video)
M. Melara and Y. Yser. OpenSSF Community Day NA. May 2026.
"Securing the AI Lifecycle: Trust, Transparency & Tooling in Open Source" (video)
S. Evans, M. Maruseac and M. Melara. OpenSSF Tech Talk. September 2025.
"Understanding the Software Supply Chain Trust Landscape" (slides)
M. Melara. C2PA Conformance Working Group. July 2024.
"Securing the Software Supply Chain: An In-Depth Exploration of SLSA" (video)
M. Lieberman, M. Melara, J. Lock, L. Capadan. OpenSSF Tech Talk. October 2023.
"Building Trust with Attestation" (podcast)
M. Melara, V. Scarlata. Open at Intel Podcast. May 2023.
"Software Supply Chains" (podcast)
M. Melara, B. Domingues. Open at Intel Podcast. March 2023.
"EnclaveDom: Privilege Separation for Large-TCB Applications in Trusted Execution Environments" (slides)
M. Melara. Microsoft Research Cryptography & Privacy Colloqium. September 2020.
Conference Talks
"Petra: SBOMs Without Oversharing for Confidential Supply Chain Transparency" (video)
E. Abu Ishgair and M. Melara. OpenSSF Community Day NA. May 2026.
"BEAR-ing Fruit: How OpenSSF’s Working Group Is Diversifying Open Source Security" (slides)
M. Melara and Y. Yser. Open Source Summit NA. May 2026.
"Panel Discussion: Securing the AI Supply Chain: Critical Infrastructure for Model Integrity and Trust" (video)
C. Robinson, A. Chin, M. Maruseac, M Melara. Open Source Summit NA. May 2026.
"The Whole Is Greater Than the Sum of Its Parts: A Case for Interoperable Supply Chain Tooling" (video)
Hayden Blauzvern and M. Melara. Open Source SecurityCon. November 2025.
"Harnessing in-toto Attestations for Security and Compliance With Next-gen Policies" (slides) (video)
M. Melara and T. Karthik Kuppusamy. OpenSSF Community Day NA. June 2025.
"Building Trust in ML: Mapping the Model Lifecycle for ML Integrity and Transparency" (slides) (video)
M. S. Melara. Open Source Summit NA. June 2025.
"Auditing the CI/CD Platform: Reproducible Builds vs. Hardware-Attested Build Environments, Which is Right for You?" (slides)
M. S. Melara, C. Kimes. ACM Workshop on Software Supply Chain Offensive Research and Ecosystem Defenses (SCORED). October 2024.
"TPMs, Merkle Trees and TEEs: Enhancing SLSA with Hardware-Assisted Build Environment Verification" (slides) (video)
M. Melara, C. Kimes. Open Source Summit NA. April 2024.
"Panel Discussion: Improving Supply Chain Integrity with OpenSSF Technologies" (video)
A. Le Hors, M. Lieberman, J. White, M. Melara, I. Hepworth. Open Source Summit NA. April 2024.
"Panel Discussion: DEI for the OpenSSF Community" (video)
M. McElaney, J. Kjell, J. White, C. Voong, M. Melara. SOSS Community Day NA. April 2024.
"All things in-toto! Supply chain attestations, policies, and adoption stories, oh my!" (slides) (video)
M. Melara, S. Torres-Arias. KubeCon & CloudNativeCon NA. November 2023.
"Using FPGAs to Create a Complete Computer System for the Classroom" (slides)
M. Melara. NYCWiC 2011.
Patents
"Concept for Performing Operations on an Asset."
C. M. Bowman, P. Narayana Moorthy, B. Vavala, M. S. Melara. US Patent Application 18/343,797. 2024.
"Method and apparatus for multi-dimensional attestation for a software application."
M. S. Melara, B. Vavala, M. Steiner, V. Scarlata, A. L. Vahldiek-Oberwagner. US Patent Application 18/311,253. 2023.
"Attestation of operations by tool chains."
V. Scarlata, A. Trivedi, R. Lal, M. S. Melara, M. Steiner, A. L. Vahldiek-Oberwagner. US Patent 11650800. 2023.
"Optimizing deployment and security of microservices."
P. Saxena, A. L. Vahldiek-Oberwagner, M. Vij, K. A Doshi, C. H. Morales, C. M. Bowman, M. S. Melara, M. Steiner. US Patent Application 17/561,676. 2022.
Blog Posts
"New Atlas CLI Open Source Tool Manages Machine Learning Model Provenance and Transparency" (post)
M. Spoczynski, M. Melara, S. Szyller. Intel Community Tech Innovation Blog. June 2025.
"Building Trust in AI: An End-to-End Approach for the Machine Learning Model Lifecycle" (post)
M. Spoczynski, M. Melara, S. Szyller. Intel Community Tech Innovation Blog. December 2024.
"The Opportunity for DEI Participation in the Security Industry (And OpenSSF)" (post)
C. Voong, J. White, J. Kjell, M. Melara, M. McElaney. OpenSSF Blog. May 2024.
"Why Making Johnny's Key Management Transparent is So Challenging" (post)
M. Melara. Freedom to Tinker. March 2016.
"There's Something Wrong With This Picture..." (post)
M. Melara. Guest blogger, Grand Central Blog. November 2010.
"Busy Moms Need Energy" (post)
M. Melara. Guest blogger, Grand Central Blog. October 2010.
Posters
"Protecting the IoT Against Data Leaks through Intra-Process Access Control" (poster) (slides)
M. Melara. Stony Brook University, National Security Institute Security & Privacy Day 2017.
"Building an Automatic and Scalable Tool for Improving Environmental Recycling: ELARA" (poster)
M. Melara. HWS Summer Research Symposium 2011.
"Using FPGAs to Create a Complete Computer System for the Classroom" (poster)
M. Melara. HWS Summer Research Symposium 2010.
Public Manuscripts
"Scalable GPU-Based Integrity Verification for Large Machine Learning Models" (preprint)
M. Spoczynski and M. S. Melara. ArXiv Preprint. October 2025.
"Enabling Security-Oriented Orchestration of Microservices" (preprint)
M. S. Melara and M. Bowman. ArXiv Preprint. May 2021.
"EnclaveDom: Privilege Separation for Large-TCB Applications in Trusted Execution Environments" (preprint)
M. S. Melara, M. J. Freedman, and M. Bowman. ArXiv Preprint. July 2019.
"Pyronia: Redesigning Least Privilege and Isolation for the Age of IoT" (preprint)
M. S. Melara, D. Liu, and M. J. Freedman. ArXiv Preprint. March 2019.
Theses
"Intra-Process Least Privilege and Isolation for Emerging Applications" (pdf)
M. Melara. PhD Dissertation. Princeton University, Department of Computer Science.
Advisor: Michael J. Freedman. 2019.
"CONIKS: Preserving Secure Communication with Untrusted Identity Providers" (pdf)
M. Melara. Master's Thesis. Princeton University, Department of Computer Science.
Advisor: Edward W. Felten. 2014.
"ELARA: Environmental Liaison and Automated Recycling Assistant" (pdf)
M. Melara. Senior Honors Thesis. HWS Dept. of Math and Computer Science.
Advisor: John Vaughn. 2012.