Deployment Risk Assessment using Diff-Aware Features: A Case Study at Prime Video
At Amazon Prime Video, we face the critical operational challenge of managing code deployments during live events and rapid feature releases without causing service outages. Current change control approaches use blanket deployment freezes that block all changes regardless of risk, creating significant developer toil. While prior research has explored risky change predictors, these rely on developer-specific metadata or extensive historical data, raising privacy concerns and limiting applicability to new projects. We introduce a framework centered on diff-aware features-characteristics derived directly from code modifications. Our key contribution is the systematic identification of which quantitative metrics (code-level and change-level metrics) and qualitative indicators (coding style violations, change type classification) are necessary for risk prediction. We employ LLMs as multi-language feature extractors, demonstrating their effectiveness for code analysis beyond generation tasks and eliminating the need for language-specific tooling. We evaluated our framework on two datasets: Prime Video’s production environment and the public ApacheJIT dataset. Our best-performing model achieves an average recall of 0.83 and F1 score of 0.81 across both datasets for detecting risky code changes. Notably, ablation analysis reveals that change-level volume metrics (e.g., lines added/deleted) are noisy predictors, while structural code complexity provides a substantially stronger risk signal. These results demonstrate that thoughtful feature curation enables effective change risk assessment across different programming languages and organizational contexts while avoiding privacy concerns.
Thu 15 OctDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
16:30 - 17:30 | Security and Other Non-Functional Properties: Dependability and Safety 2Industry Showcase / Research Papers / Tools and Datasets at Forum 6 | ||
16:30 15mTalk | Understanding Real-World Ordering-Related Concurrency Bugs under Weak-Memory and Cross-Architecture Settings Industry Showcase Shaohao Wang Xidian University, Cheng Wen Xidian University, Yuandao Cai Hong Kong University of Science and Technology, Shengchao Qin Xidian University, Jie Su Xidian University, Mengda He Huawei Technologies Co., Ltd., Xiaoxue Ma City University of Hong Kong, Cong Tian Xidian University | ||
16:45 15mTalk | Context-Aware Trust Verification for Identity-Based Software Signing Research Papers Chinenye Okafor Purdue University, James C. Davis Purdue University, Santiago Torres-Arias Purdue University | ||
17:00 10mTalk | Deployment Risk Assessment using Diff-Aware Features: A Case Study at Prime Video Industry Showcase Mayur Premkumar Kurup Amazon.com, Hyunjae Suh University of California, Irvine, Swathi Vaidyanathan Amazon Prime Video, Pranesh Vyas Amazon Prime Video, Srinidhi Madabhushi Amazon Prime Video, Yegor Silyutin Amazon Prime Video | ||
17:10 10mTalk | ThreatCraft: Automated Attack Scenario Generation via Hybrid Rule-Based and LLM-Driven Reasoning Tools and Datasets Dohee Kang Korea University, Jiwon Kwak Korea University, Geunwoo Baek Korea University, Seungjoo Kim Korea University DOI | ||
17:20 10mTalk | The EVerest Dataset for Secure Software Engineering Tools and Datasets Sophie Corallo Karlsruhe Institute of Technology, Debora Grupp KIT, Dominik Fuchß Karlsruhe Institute of Technology (KIT), Jan Keim Karlsruhe Institute of Technology (KIT), Frederik Reiche Karlsruhe Institute of Technology, Tobias Hey Karlsruhe Institute of Technology (KIT), Anne Koziolek Karlsruhe Institute of Technology DOI Pre-print | ||