ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil

This program is tentative and subject to change.

Wed 15 Apr 2026 12:15 - 12:30 at Oceania X - Dependability and Security 1

Software Composition Analysis (SCA) identifies third-party components in applications for vulnerability management and license compliance. C and C++ applications often rely on copy-based code reuse without maintaining origin information, rendering precise SCA generation challenging. We present Foiegras, a production SCA system addressing this challenge through advanced code clone detection. The system segments source files into functions, types and licenses maintaining cryptographic signatures for exact matching and embeddings for similarity-based detection. Uniquely, we curate and index of 1,700 authoritative open-source projects, constructed through manual annotation by 13 domain experts. This curation addresses the fundamental challenge of distinguishing original sources from copies. We evaluate Foiegras on a file-based synthetic dataset and 28 high-profile open-source C/C++ applications with manually verified ground truth. At the file level, Foiegras identifies exact file versions with 78% average precision. In real-world applications, it achieves mean precision of 0.7 and recall of 0.5 for exact version matching (0.79/0.71 for library name matching), approaching state of the art performance and significantly outperforming a commercial SCA platform. Foiegras is deployed at Endor Labs, processing thousands of SCA requests daily, demonstrating both feasibility and necessity of combining automated analysis with expert curation for accurate software composition analysis in ecosystems lacking modern dependency management.

This program is tentative and subject to change.

Wed 15 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Dependability and Security 1Research Track / SE In Practice (SEIP) at Oceania X
11:00
15m
Talk
Towards Global Matches for Third-Party Library Detection in Android
Research Track
Lige Zhan Wuhan University, Jiang Ming Tulane University, USA, Chenke Luo Tulane University, Guojun Peng Wuhan University, Jianming Fu Wuhan University
DOI
11:15
15m
Talk
ViTAL: LLM-Powered Taint Analysis for GUI Field Visualization Auditing in Android
SE In Practice (SEIP)
Liuyang Jiang Beijing University of Posts and Telecommunications, Shenghan Liu Douyin, Qiuping Yi Beijing University of Posts and Telecommunications, Hongliang Liang beijing university of posts and telecommunication, xiangxingqian Douyin, Qingyun Kong Douyin, Yixiu Chen Douyin, XiaoQiang Fan Douyin, LiangXu Zou Douyin
11:30
15m
Talk
Out of Distribution, Out of Luck: How Well Can LLMs Trained on Vulnerability Datasets Detect Top 25 CWE Weaknesses?
Research Track
Yikun Li Singapore Management University, Ngoc Tan Bui Singapore Management University, Ting Zhang Monash University, Chengran Yang Singapore Management University, Singapore, Xin Zhou Singapore Management University, Singapore, Martin Weyssow Singapore Management University, Jinfeng Jiang Singapore Management University, Junkai Chen Singapore Management University, Singapore, Huihui Huang Singapore Management University, Singapore, Huu Hung Nguyen Singapore Management University, Chiok Yew Ho Chinese University of Hong Kong, Jie Tan University of Groningen, Ruiyin Li Wuhan University, China; University of Groningen, The Netherlands, Yide Yin GovTech, Han Wei Ang GovTech, Frank Liauw Government Technology Agency Singapore, Eng Lieh Ouh Singapore Management University, Singapore, Lwin Khin Shar Singapore Management University, David Lo Singapore Management University
Pre-print
11:45
15m
Talk
OctopusGuard: K-Line Enhanced Token Scam Detector Powered by Multimodal LLMs
Research Track
Litong Sun SUN YAT-SEN UNIVERSITY, YangTian Mi Sun Yat-Sen University, Xiapu Luo Hong Kong Polytechnic University, Weigang Wu Sun Yat-sen University
12:00
15m
Talk
UnPII: Unlearning Personally Identifiable Information with Quantifiable Exposure Risk
SE In Practice (SEIP)
Intae Jeon Samsung Research, Yujeong Kwon Sungkyunkwan University, Hyungjoon Koo Sungkyunkwan University
12:15
15m
Talk
Foiegras: Source Code Based Software Composition Analysis For C/C++ Applications
SE In Practice (SEIP)
Georgios Gousios Endor Labs, Philip Hamer Endor Labs, Camilla Odlund Endor Labs, Leandro Melo Endor Labs, Joseph Hejderup Endor Labs & Delft University of Technology, Sridhara Muniraju Endor Labs, Thomas Durieux Endor Labs