Toby Murray is a Professor in the School of Computing and Information Systems at the University of Melbourne, where he serves as Director of the Defence Science Institute and Co-Lead of the Computer Science Research Group. His work bridges formal methods, cybersecurity, and practical system security, with significant contributions to verified security and vulnerability detection. Murray's research focuses on building highly secure computing systems cost-effectively, with expertise in formal verification, information flow security, and vulnerability detection. His current research projects include Verisimilar (Verified, Secure Machine Learning), EDEFuzz (Detecting excessive data exposure in web applications), COVERN (Proving information flow security of concurrent programs), and Time Protection (Proving timing channel freedom for seL4). His work combines theoretical rigor with practical implementation, resulting in multiple open-source tools including SecC, Legion, and Underflow. Murray's recent publications demonstrate a consistent focus on verified security properties across diverse domains, from neural networks to concurrent systems. His work often bridges the gap between formal methods and practical security concerns, with increasing attention to machine learning security and policy implications of technical security measures. His publications span top venues in security, formal methods, and software engineering. Distinguished Paper Award at ICSE 2024 for EDEFuzz work on detecting excessive data exposure in web applications Extensive media commentary on cybersecurity issues including CrowdStrike outage analysis and social media regulation Regular contributions to The Conversation and Pursuit on cybersecurity policy matters Murray has advised numerous PhD students to completion, including Lianglu Pan (EDEFuzz), Zhiyuan Zhang, Mo Zhang, and Renlord Yang. He currently supervises multiple PhD students working on security verification, machine learning security, and web application security. His service includes being Program Chair for CSF'25, Associate Editor for IEEE Security & Privacy and ACM TOPS, and membership in IFIP's WG 1.7 and WG 2.3. His research group has developed multiple significant software tools including SecC (Verified Security for Concurrent C Programs), Legion (Principled Automatic Test Case Generation), and Underflow (Compositional Vulnerability Detection for C Programs), all available under open source licenses. Murray's work often involves discovering and reporting bugs in security analysis tools during his research, demonstrating the practical impact of his verification approaches.









