FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada

This program is tentative and subject to change.

Thu 9 Jul 2026 12:00 - 12:10 at MB 3.435 - Software Security

Backporting changes to stable releases is a critical yet high-stakes maintenance task. In practice, large-scale ecosystems like OpenStack rely on explicit governance rules for stable branches, where many repositories enforce that changes cannot be merged or released without an explicit backport-related vote (e.g., Backport-Candidate). However, identifying changes that are safe to backport remains largely manual, leading to significant decision latency and inconsistency. To alleviate this challenge, we present BackportCheck, a decision-support tool implemented as a Chrome extension for the Gerrit code review interface. BackportCheck is based on a Gradient Boosting model (XGBoost), trained on historical process data, combined with a Large Language Model (LLM) that generates concise, human-readable justifications for predicted backport decisions. We evaluate BackportCheck for both usefulness and usability across 3,422 OpenStack changes, achieving 81.31% accuracy while maintaining a mean end-to-end response time of 1.39 seconds, outperforming CodeBERT-based classifiers and standalone LLMs. BackportCheck is available via GitHub . A video demonstrating the tool usage is available on YouTube.

This program is tentative and subject to change.

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
10m
Talk
FISTS: A Field-based Security Testing Tool for Updates in Software-Defined Networks
Tool Demonstrations
Jahanzaib MALIK University of Luxembourg, Fabrizio Pastore University of Luxembourg
10:40
20m
Talk
Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
Industry Papers
Jens Christian Opdenbusch Ruhr University Bochum, Sangavi Shanthakumar Ruhr University Bochum, Martina Angela Sasse Ruhr University Bochum, Marco Gutfleisch LMU Munich
11:00
20m
Talk
An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling
Industry Papers
Francis Martins UNB, Elaine Venson University of Brasilia
11:20
20m
Talk
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Research Papers
Sunha Park Korea University, Soojin Han Dongduk Women's University, Seunghoon Woo Korea University
11:40
20m
Talk
Reducing the TCB of SGX-oriented LibOSes at Runtime
Research Papers
Donghui Yu Shanghai Jiao Tong University, Dahan Pan Shanghai Jiao Tong University, Fengwei Zhang Shanghai Jiao Tong University, Haoran Fang Shanghai Jiao Tong University, Ya Fang Shanghai Jiao Tong University, Yuanyuan Zhang Shanghai Jiao Tong University
12:00
10m
Talk
BackportCheck: An Open-Source Tool to Support Backport Decisions in Large Software Ecosystems
Tool Demonstrations
Salma Sghaier ENSI, Mannouba University, Mohamed Anas Daoud ENSI, Mannouba University, Marouene Chaieb National School of Computer Science, Moataz Chouchen Concordia University, Mohammad Hamdaqa Polytechnique Montreal, Mohamed Wiem Mkaouer University of Michigan-Flint
12:10
10m
Short-paper
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
Ideas, Visions and Reflections
Laura Baird University of Colorado Colorado Springs (UCCS), Armin Moin University of Colorado Colorado Springs
DOI