FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Thu 9 Jul 2026 11:00 - 11:20 at MB 3.435 - Software Security Chair(s): Kevin Leach

The manual generation of software development artifacts in large organizations—particularly security requirements and threat models—demands substantial effort and is prone to inconsistencies and coverage gaps. While recent advances in generative AI show promise for supporting Requirements Engineering, their adoption in security-critical and regulated environments remains limited due to concerns related to trust, data privacy, and domain specificity.

This paper presents an empirical evaluation of an LLM-based AI assistant designed to support security requirements engineering and threat modeling under controlled and auditable conditions. The proposed approach adopts a human–AI hybrid workflow, in which AI-generated artifacts are systematically reviewed and validated by specialists to preserve contextual accuracy and regulatory compliance. Using business documents as input, the assistant generates candidate security requirements and STRIDE-based threat models.

The study compares AI-only, manual, and hybrid workflows across 20 real-world projects conducted in a Brazilian public organization. Results show an average reduction of 18.3% in artifact generation time and a 13.6% increase in STRIDE threat coverage, while maintaining 73% semantic precision. Furthermore, the hybrid human–AI approach consistently outperformed the fully manual process in terms of completeness and overall quality.

These findings provide empirical evidence that generative AI can effectively support security requirements engineering when embedded within human-centered workflows and organizational governance structures, offering practical insights for adoption in regulated software development contexts.

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
10m
Talk
FISTS: A Field-based Security Testing Tool for Updates in Software-Defined Networks
Tool Demonstrations
Jahanzaib MALIK University of Luxembourg, Fabrizio Pastore University of Luxembourg
DOI Pre-print Media Attached File Attached
10:40
20m
Talk
Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
Industry Papers
Jens Christian Opdenbusch Ruhr University Bochum, Sangavi Shanthakumar Ruhr University Bochum, Martina Angela Sasse Ruhr University Bochum, Marco Gutfleisch LMU Munich
11:00
20m
Talk
An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling
Industry Papers
Francis Martins UNB, Elaine Venson University of Brasilia
11:20
20m
Talk
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Research Papers
Sunha Park Korea University, Soojin Han Dongduk Women's University, Seunghoon Woo Korea University
Pre-print
11:40
20m
Talk
BackportBench: A Multilingual Benchmark for Automated Patch Backporting
Research Papers
Zhiqing Zhong The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Jiaming Huang The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Pinjia He Chinese University of Hong Kong, Shenzhen
Pre-print
12:00
10m
Talk
BackportCheck: An Open-Source Tool to Support Backport Decisions in Large Software Ecosystems
Tool Demonstrations
Salma Sghaier ENSI, Mannouba University, Mohamed Anas Daoud ENSI, Mannouba University, Marouene Chaieb National School of Computer Science, Moataz Chouchen Concordia University, Mohammad Hamdaqa Polytechnique Montreal, Mohamed Wiem Mkaouer University of Michigan-Flint
12:10
10m
Short-paper
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
Ideas, Visions and Reflections
Laura Baird University of Colorado Colorado Springs (UCCS), Armin Moin Purdue University
DOI