FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
Thu 9 Jul 2026 11:40 - 12:00 at MB 3.435 - Software Security Chair(s): Kevin Leach

Many modern software projects evolve rapidly to incorporate new features and security patches. It is important for users to update their dependencies to safer versions, but many still use older, vulnerable package versions because upgrading can be difficult and may break their existing codebase. Software developers can mitigate this problem by backporting security patches to older releases. However, manually backporting is time-consuming and error-prone. The effectiveness of existing automated backporting techniques on general software remains unclear since they typically target only code-hunk or function-level patch porting scenarios and are evaluated with imperfect metrics.

To facilitate the development and evaluation of automated backporting techniques, we introduce BackportBench, the first comprehensive benchmark suite for patch backporting problem. BackportBench is a multilingual benchmark that contains 202 patch backporting problems from PyPI, Maven, and npm, each with executable Docker environments and relevant test cases. We evaluated existing patch porting methods and LLM-based techniques that have the potential to adapt to this task using BackportBench. The results show that the agentic method has outperformed traditional patch porting methods, especially on cases that require logical and structural changes. However, the performance varies across different programming languages. Based on the findings, we draw several implications for researchers and software practitioners in future work on automated backporting.

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
10m
Talk
FISTS: A Field-based Security Testing Tool for Updates in Software-Defined Networks
Tool Demonstrations
Jahanzaib MALIK University of Luxembourg, Fabrizio Pastore University of Luxembourg
DOI Pre-print Media Attached File Attached
10:40
20m
Talk
Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
Industry Papers
Jens Christian Opdenbusch Ruhr University Bochum, Sangavi Shanthakumar Ruhr University Bochum, Martina Angela Sasse Ruhr University Bochum, Marco Gutfleisch LMU Munich
11:00
20m
Talk
An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling
Industry Papers
Francis Martins UNB, Elaine Venson University of Brasilia
11:20
20m
Talk
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Research Papers
Sunha Park Korea University, Soojin Han Dongduk Women's University, Seunghoon Woo Korea University
Pre-print
11:40
20m
Talk
BackportBench: A Multilingual Benchmark for Automated Patch Backporting
Research Papers
Zhiqing Zhong The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Jiaming Huang The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Pinjia He Chinese University of Hong Kong, Shenzhen
Pre-print
12:00
10m
Talk
BackportCheck: An Open-Source Tool to Support Backport Decisions in Large Software Ecosystems
Tool Demonstrations
Salma Sghaier ENSI, Mannouba University, Mohamed Anas Daoud ENSI, Mannouba University, Marouene Chaieb National School of Computer Science, Moataz Chouchen Concordia University, Mohammad Hamdaqa Polytechnique Montreal, Mohamed Wiem Mkaouer University of Michigan-Flint
12:10
10m
Short-paper
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
Ideas, Visions and Reflections
Laura Baird University of Colorado Colorado Springs (UCCS), Armin Moin Purdue University
DOI