ASE 2026
Mon 12 - Fri 16 October 2026 Munich, Germany

At Amazon Prime Video, we face the critical operational challenge of managing code deployments during live events and rapid feature releases without causing service outages. Current change control approaches use blanket deployment freezes that block all changes regardless of risk, creating significant developer toil. While prior research has explored risky change predictors, these rely on developer-specific metadata or extensive historical data, raising privacy concerns and limiting applicability to new projects. We introduce a framework centered on diff-aware features-characteristics derived directly from code modifications. Our key contribution is the systematic identification of which quantitative metrics (code-level and change-level metrics) and qualitative indicators (coding style violations, change type classification) are necessary for risk prediction. We employ LLMs as multi-language feature extractors, demonstrating their effectiveness for code analysis beyond generation tasks and eliminating the need for language-specific tooling. We evaluated our framework on two datasets: Prime Video’s production environment and the public ApacheJIT dataset. Our best-performing model achieves an average recall of 0.83 and F1 score of 0.81 across both datasets for detecting risky code changes. Notably, ablation analysis reveals that change-level volume metrics (e.g., lines added/deleted) are noisy predictors, while structural code complexity provides a substantially stronger risk signal. These results demonstrate that thoughtful feature curation enables effective change risk assessment across different programming languages and organizational contexts while avoiding privacy concerns.

Thu 15 Oct

Displayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change

16:30 - 17:30
Security and Other Non-Functional Properties: Dependability and Safety 2Industry Showcase / Research Papers / Tools and Datasets at Forum 6
16:30
15m
Talk
Understanding Real-World Ordering-Related Concurrency Bugs under Weak-Memory and Cross-Architecture Settings
Industry Showcase
Shaohao Wang Xidian University, Cheng Wen Xidian University, Yuandao Cai Hong Kong University of Science and Technology, Shengchao Qin Xidian University, Jie Su Xidian University, Mengda He Huawei Technologies Co., Ltd., Xiaoxue Ma City University of Hong Kong, Cong Tian Xidian University
16:45
15m
Talk
Context-Aware Trust Verification for Identity-Based Software Signing
Research Papers
Chinenye Okafor Purdue University, James C. Davis Purdue University, Santiago Torres-Arias Purdue University
17:00
10m
Talk
Deployment Risk Assessment using Diff-Aware Features: A Case Study at Prime Video
Industry Showcase
Mayur Premkumar Kurup Amazon.com, Hyunjae Suh University of California, Irvine, Swathi Vaidyanathan Amazon Prime Video, Pranesh Vyas Amazon Prime Video, Srinidhi Madabhushi Amazon Prime Video, Yegor Silyutin Amazon Prime Video
17:10
10m
Talk
ThreatCraft: Automated Attack Scenario Generation via Hybrid Rule-Based and LLM-Driven Reasoning
Tools and Datasets
Dohee Kang Korea University, Jiwon Kwak Korea University, Geunwoo Baek Korea University, Seungjoo Kim Korea University
DOI
17:20
10m
Talk
The EVerest Dataset for Secure Software Engineering
Tools and Datasets
Sophie Corallo Karlsruhe Institute of Technology, Debora Grupp KIT, Dominik Fuchß Karlsruhe Institute of Technology (KIT), Jan Keim Karlsruhe Institute of Technology (KIT), Frederik Reiche Karlsruhe Institute of Technology, Tobias Hey Karlsruhe Institute of Technology (KIT), Anne Koziolek Karlsruhe Institute of Technology
DOI Pre-print