BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//Events - ECPv6.17.2//NONSGML v1.0//EN
CALSCALE:GREGORIAN
METHOD:PUBLISH
X-ORIGINAL-URL:https://live-events-ucsc.pantheonsite.io
X-WR-CALDESC:Events for Events
REFRESH-INTERVAL;VALUE=DURATION:PT1H
X-Robots-Tag:noindex
X-PUBLISHED-TTL:PT1H
BEGIN:VTIMEZONE
TZID:America/Los_Angeles
BEGIN:DAYLIGHT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
DTSTART:20250309T100000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
TZNAME:PST
DTSTART:20251102T090000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
DTSTART:20260308T100000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
TZNAME:PST
DTSTART:20261101T090000
END:STANDARD
BEGIN:DAYLIGHT
TZOFFSETFROM:-0800
TZOFFSETTO:-0700
TZNAME:PDT
DTSTART:20270314T100000
END:DAYLIGHT
BEGIN:STANDARD
TZOFFSETFROM:-0700
TZOFFSETTO:-0800
TZNAME:PST
DTSTART:20271107T090000
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
DTSTART;TZID=America/Los_Angeles:20260825T110000
DTEND;TZID=America/Los_Angeles:20260825T130000
DTSTAMP:20260812T161153Z
CREATED:20260812T161153Z
LAST-MODIFIED:20260812T161153Z
UID:10015333-1787655600-1787662800@live-events-ucsc.pantheonsite.io
SUMMARY:Gomez\, J. (CSE) - Toward Sustainable and Secure Open Source Software: Discovery\, Measurement\, and Defense
DESCRIPTION:In March 2024\, a backdoor was discovered in xz Utils\, a widely used open source data compression library present in nearly every major Linux distribution. The attack was discovered days before merging into major distributions\, and if this had happened\, it would have allowed attackers to execute arbitrary code on millions of systems worldwide via SSH. \nThe success of this backdoor was enabled by two failures. The first was technical: weaknesses in the software supply chain allowed a malicious actor to inject code into a widely trusted release. The second was human: the project’s only maintainer\, overwhelmed and burned out after years of maintaining critical infrastructure alone\, was the target of a multi-year social engineering campaign\, in which a malicious actor built trust under a false identity and gradually obtained commit access to the project. This incident shows that software security failures and sustainability failures are not independent: an overburdened\, unsupported maintainer is itself an attack surface. \nAcademic and scientific open source software (OSS) faces both of these crises simultaneously. Projects that critical infrastructure depends on are maintained by researchers\, students\, and faculty who contribute in their spare time\, without dedicated security training or institutional support. Existing security frameworks including NIST’s SSDF\, OWASP’s SCVS\, and SLSA were not designed with these communities in mind\, and policy efforts such as the EU Cyber Resilience Act have shown that mandates developed without community input risk harming the ecosystems they are meant to protect. \nThis dissertation addresses the sustainability and security of academic open source software through two parallel empirical research tracks. The sustainability track combines GitHub’s REST API with LLM-based filtering to discover and characterize over 216\,000 institutionally affiliated repositories across 32 academic and research institutions\, finding that while 84\% include a README\, only 23.4% carry a detectable license and fewer than 2% include a Contributing Guide. Building on this dataset\, we develop a maturity-staged sustainability framework that classifies projects into four lifecycle stages and generates targeted recommendations for Open Source Program Offices (OSPOs). \nThe security track examines whether post-9/11 trade security programs offer a workable model for OSS supply-chain policy\, finding that effective frameworks require voluntary incentives and direct community engagement rather than top-down mandates. We further evaluate five large language models on the OWASP Benchmark for vulnerability triage\, finding that o1-mini reduces false positives by 20% over the Semgrep baseline\, demonstrating the potential for automation to reduce the security burden on individual maintainers. \nTogether\, these contributions treat sustainability and security as interconnected problems. A project that cannot sustain itself cannot secure its code\, and this dissertation takes steps toward closing both gaps. \n  \nEvent Host: Juanita Gomez\, Ph.D. Candidate\, Computer Science & Engineering \nAdvisor: Alvaro Cardenas  \nZoom: https://ucsc.zoom.us/j/91057980344?pwd=XMMjHZVgbbLXfwxKehrTEbat18066o.1 \nPasscode: 292091
URL:https://live-events-ucsc.pantheonsite.io/event/gomez-j-cse-toward-sustainable-and-secure-open-source-software-discovery-measurement-and-defense/
LOCATION:Engineering 2\, Engineering 2 1156 High Street\, Santa Cruz\, CA\, 95064
CATEGORIES:Ph.D. Presentations
ATTACH;FMTTYPE=image/jpeg:https://live-events-ucsc.pantheonsite.io/wp-content/uploads/2026/04/ph.d.-presentation-graphic-option2.jpg
GEO:37.0009723;-122.0632371
X-APPLE-STRUCTURED-LOCATION;VALUE=URI;X-ADDRESS=Engineering 2 Engineering 2 1156 High Street Santa Cruz CA 95064;X-APPLE-RADIUS=500;X-TITLE=Engineering 2 1156 High Street:geo:-122.0632371,37.0009723
END:VEVENT
BEGIN:VEVENT
DTSTART;TZID=America/Los_Angeles:20260901T090000
DTEND;TZID=America/Los_Angeles:20260901T110000
DTSTAMP:20260812T161813Z
CREATED:20260812T161813Z
LAST-MODIFIED:20260812T161813Z
UID:10015334-1788253200-1788260400@live-events-ucsc.pantheonsite.io
SUMMARY:Shen\, J. (STAT) - Bayesian Modeling and Uncertainty Quantification for Verbal Autopsy Data
DESCRIPTION:Verbal autopsy (VA) is a well developed tool to collect information describing deaths outside of hospitals by conducting surveys to the relatives and caregivers of the deceased person. It is routinely-implemented in low and middle income countries\, where it often lacks sufficient resources to conduct the autopsy. The main task is to estimate both individual level cause-of-death probabilities and population level cause-specific mortality fractions. In this document\, we present three projects dealing with challenges current VA modeling faces. In the first project\, we build a shared latent class model for verbal autopsy\, which allows causes to share common symptom patterns. A truncated Bayesian nonparametric prior allows the number of latent classes to adapt to data\, while retaining a computationally tractable representation. We provide a general framework for few-shot learning of the VA data\, where limited labels can be combined in analysis with a potentially much larger collection of unlabeled symptom profile. Two complementary factorizations are considered to account for different types of distribution shift between source and target. In the second project\, we develop a conformal prediction procedure for verbal autposy. For each death\, we generate a conformal prediction set from existing VA model outputs\, which guarantees a marginal coverage of true cause from a fequentist perspective. We also investigate conformal Bayesian procedures that more directly incorporate posterior uncertainty from Bayesian VA models. In the third project\, we consider situations where source and target do not share a common cause list. We propose methods using repulsive priors to identify deaths in the target domain whose symptom profiles are not adequately represented by the known causes in the source domain. \nEvent Host: Jibo Shen\, Ph.D. Student\, Statistical Science \nAdvisor: Zehang Richard Li \nZoom: https://ucsc.zoom.us/j/94158273558?pwd=VZORHL8P5O9bfb5JpSMZAL1DOM44uC.1&jst=2 \nPasscode:  294401
URL:https://live-events-ucsc.pantheonsite.io/event/shen-j-stat-bayesian-modeling-and-uncertainty-quantification-for-verbal-autopsy-data/
CATEGORIES:Ph.D. Presentations
ATTACH;FMTTYPE=image/png:https://live-events-ucsc.pantheonsite.io/wp-content/uploads/2026/04/ph.d.-presentation-graphic-option-3.png
LOCATION:
END:VEVENT
END:VCALENDAR