ASE 2026 (series) / Industry Showcase /
IAM Policy Autopilot: Static Analysis for Policy Generation from Application Code
Wed 14 Oct 2026 14:30 - 14:45 at Forum 6 - Security and Other Non-Functional Properties: Security and Privacy 5
Wed 14 OctDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
Wed 14 Oct
Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
14:00 - 16:00 | Security and Other Non-Functional Properties: Security and Privacy 5Journal First / Industry Showcase / Research Papers at Forum 6 | ||
14:00 15mTalk | GraphLedger: Repository-Level Vulnerability Detection via Graph-Based Compression and Assumption Validation Research Papers Thi-Hong-Cuc Le Ho Chi Minh City University of Technology, Hoang Quoc Bao Hua Ho Chi Minh City University of Technology, Xuan-Bach Le Ho Chi Minh City University of Technology | ||
14:15 15mTalk | Breaking Customized LLMs for Coding: Automated Red Teaming for Instruction Backdoor Attacks Research Papers Yuchen Chen Nanjing University, Wei Cheng Nanjing University of Aeronautics and Astronautics, Yuan Xiao Nanjing University, Weisong Sun Nanyang Technological University, Chunrong Fang Nanjing University, Yang Liu Nanyang Technological University, Zhenyu Chen Nanjing University, Baowen Xu Nanjing University | ||
14:30 15mTalk | IAM Policy Autopilot: Static Analysis for Policy Generation from Application Code Industry Showcase Antonio Filieri AWS and Imperial College London, Luke Kennedy Amazon Web Services, Kevin Luo Amazon Web Services, Matt Luttrell Amazon Web Services, Adrian Palacios Amazon Web Services, Akash Panda Amazon Web Services, Neha Rungta Amazon Web Services, Matthias Schlaipfer Amazon Web Services, Karan Jit Singh Amazon Web Services, Anvesh Tanuku Amazon Web Services, Nick Winans Amazon Web Services, Diana Yin Amazon Web Services, Weiben Zhang Amazon Web Services | ||
14:45 15mTalk | A Comprehensive Evaluation of Code Language Models for Security Patch Detection Research Papers Nils Loose University of Luebeck, Joseph Bienhüls University of Lübeck, Kristoffer Hempel University of Lübeck, Felix Mächtle University of Luebeck, Thomas Eisenbarth University of Lübeck | ||
15:00 15mTalk | LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks Journal First DOI | ||
15:15 15mTalk | “Impossible to Hide Secret ...”: Uncovering Security and Privacy Issues in LLM-Native IDEs Research Papers Mostafijur Rahman Akhond York University, Md Afif Al Mamun University of Calgary, Canada, Gias Uddin York University, Canada, Song Wang York University | ||
15:30 15mTalk | ReSEDA: Automatic and Precise Program-Level ReDoS Triage via Interprocedural Taint Analysis and Agentic Exploit Generation Research Papers Rongchen Li Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Weihao Su ISCAS, Chengyao Peng Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences, hong huang Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Haiming Chen Institute of Software, Chinese Academy of Sciences, Guiyi He Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences | ||
15:45 15mTalk | Benchmarking Automated Security Patch Backporting: How Far Are We? Research Papers Jincheng Yang Xidian University, Yulong Fu Xidian University, Chengwei Liu Nankai University, Lyuye Zhang Nanyang Technological University, Fangyuan Zhang , Bingyang Ren Xidian University, Yang Liu Nanyang Technological University, Hui Li Beijing University of Posts and Telecommunications | ||