About Me
I am a PhD student with the Programming Group at the University of St. Gallen, working under the supervision of Prof. Dr. Guido Salvaneschi. My research focuses on software engineering and security in the age of AI, with a particular emphasis on AI agent security.
My current work investigates how AI agents can be made safer and more secure when interacting with software systems and real-world resources. I am particularly interested in mechanisms that provide agents with well-defined security boundaries, limit their capabilities and potential impact, and protect agents and their environments against threats such as prompt injection and other attacks. More broadly, my research explores how established and novel software engineering and security techniques can be applied to build trustworthy agentic systems.
I joined the Programming Group in July 2024, after nine wonderful years at smartive AG in St. Gallen, Switzerland. My passion for exploring new technologies and solving complex problems has always driven my learning and research.
Before starting my PhD in April 2026, I completed my Master's degree in Computer Science at the University of St. Gallen in spring 2026. During my Master's studies, my research focused on testing and verification of Infrastructure as Code (IaC) programs. Earlier, my Master's thesis at OST – Eastern Switzerland University of Applied Sciences (formerly HSR) focused on identity security and authentication in heterogeneous systems.
When I am not exploring new technologies or working on my research, I enjoy spending time with my wife and our kid. I also enjoy playing video games, sailing, snowboarding, and Lindy Hop dancing.
Research Interests
AI Agent Security
Security of AI agents and agentic systems from a software engineering perspective. I focus on mechanisms that constrain agent capabilities, establish secure execution boundaries, and limit the impact of compromised or misbehaving agents. This includes protecting agents and their environments against threats such as prompt injection and malicious tool interactions.
Software & System Security
Design and analysis of secure software systems, with a particular interest in access control, isolation, sandboxing, and permission mechanisms. I am interested in how established security principles can be adapted to systems in which autonomous AI agents interact with software, data, and external resources.
Software Engineering & Programming Languages
Software engineering techniques for building, analyzing, and securing complex software systems. My interests include program analysis, testing, verification, and mechanisms that make software behavior more observable and controllable.
Publications
AgentBound: Securing Execution Boundaries of AI Agents
Proceedings of the 34th ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering (FSE)
Christoph Bühler, Matteo Biagiola, Luca Di Grazia, Guido Salvaneschi
CAPE – European Open Compute Architecture for Powerful Edge
2025 28th Euromicro Conference on Digital System Design (DSD)
Martin Kaiser, Lennart Tiggges, Jens Hagemeyer, Christian Klarhorst, Björn Voß, Fred Buining, Bola Fakhoury, János Lazányi, René Griessl, Muhammad Shahzad, Yiannis Georgiou, Salim Mimouni, Pedro Velho, Michael Mercier, Eva Trungel, Julian Gajewski, Stefan Krupop, Micha vor dem Berge, Deepak M. Mathew, Skipsis Dimitrios, Arnidis Iordanis, Orestis Vantzos, David Georgantas, Gautier Rouaze, Christoph Bühler, Guido Salvaneschi, Brandon Lewis, Angela Hauber
Enhancing Early Verification and Testing for Infrastructure as Code
Christoph Bühler
TerraDS: A Dataset for Terraform HCL Programs
Proceedings of the IEEE/ACM 22nd International Conference on Mining Software Repositories (MSR)
Christoph Bühler, David Spielmann, Roland Meier, Guido Salvaneschi
Trust in a Distributed Authentication Mesh
Christoph Bühler
