EASE 2026
Tue 9 - Fri 12 June 2026 Glasgow, United Kingdom
Tue 9 Jun 2026 16:15 - 16:25 at JMS 743 - Security 1 Chair(s): Giuseppe Scanniello

Smart contract vulnerabilities have caused billions in financial losses, raising questions about whether programming language paradigms can reduce security overhead. While imperative languages like Solidity require developers to manually implement security checks, resource-oriented languages like Move encode safety guarantees in type systems. We present a preliminary mixed-methods study analyzing 12 functionally-equivalent contract pairs implemented in both Solidity and Move by the same development team, complemented by a survey of 11 developers experienced in both languages. Quantitative analysis reveals that Move reduces explicit security overhead by 60% (security check density: 6.7% vs. 16.8%, $p=0.002$, Cohen’s $d=-1.75$) at the cost of 47% larger code size ($p=0.002$, $d=1.90$), while maintaining identical cyclomatic complexity. Developer surveys show moderate learning difficulty but higher safety confidence in Move (Median=6/7, 10 of 11 above neutral), with 55% preferring Move for security-critical applications despite ecosystem maturity gaps. These preliminary findings suggest resource-oriented paradigms shift security from runtime validation to compile-time guarantees, though adoption requires investment in learning and tooling. The controlled comparison provides initial evidence for paradigm effects on smart contract development, informing language selection decisions and identifying opportunities for improved developer resources.

Tue 9 Jun

Displayed time zone: London change

15:30 - 17:00
15:30
15m
Talk
A Systematic Methodology for Ground Truth Dataset Construction: Annotating Security in Code Logs
AI Models / Data
Abanti Chakraborty Shruti University of North Carolina at Charlotte, Rrezarta Krasniqi University of North Carolina at Charlotte
15:45
15m
Paper
On the Informativeness of Security Commit Messages: A Large-scale Replication Study
Reproducibility and Negative Results
Syful Islam LTCI, Télécom Paris, Institut Polytechnique de Paris,Palaiseau, Stefano Zacchiroli LTCI, Télécom Paris, Institut Polytechnique de Paris, Palaiseau, France
Pre-print
16:00
15m
Talk
Mitigating False Positives in Static Memory Safety Analysis of Rust Programs via Reinforcement Learning
Research Papers
Akilesh P Indian Institute of Technology Tirupati, Leuson Da Silva Polytechnique Montreal, Foutse Khomh Polytechnique Montréal, Sridhar Chimalakonda Indian Institute of Technology Tirupati
Pre-print
16:15
10m
Talk
Comparing Smart Contract Paradigms: A Preliminary Study of Security and Developer Experience
Short Papers and Emerging Results
Matteo Vaccargiu University of Hohenheim, Andrea Pinna University of Cagliari, Maria Ilaria Lunesu Università degli studi di Cagliari, Giuseppe Destefanis University College London (UCL)
Pre-print