ICSE 2026
Sun 12 - Sat 18 April 2026 Rio de Janeiro, Brazil
Tue 14 Apr 2026 17:00 - 17:10 at Oceania I - Agents (Virtual Session) Chair(s): Kexin Pei

In an increasingly digital world, the timely detection, analysis, and mitigation of software vulnerabilities are critical to maintaining secure systems. While recent research has applied Transformer-based models to automatically identify vulnerabilities from sources such as GitHub issues, these efforts do not classify the detected vulnerabilities. Without systematic classification, it becomes difficult to prioritize issues, link them to remediation strategies, or integrate them into broader security workflows, limiting their practical impact. This paper introduces a novel approach for automated vulnerability categorization using Large Language Models (LLMs) and Retrieval-Augmented Generation (RAG) within the Common Weakness Enumeration (CWE) framework. We present a RAG-based pipeline for CWE labeling and systematically evaluate multiple retrieval strategies to assess their effectiveness and efficiency. The results demonstrate that our approach achieves competitive performance compared to prior state-of-the-art methods, despite operating entirely in a zero-shot setting without any task-specific training. Moreover, the proposed method enables accurate and cost-effective vulnerability classification, helping to reduce the gap between discovery and remediation in the vulnerability lifecycle. Overall, this work highlights the potential of retrieval-driven approaches to enhance the automation, scalability, and practicality of vulnerability management across the software ecosystem.

Tue 14 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

16:40 - 17:40
Agents (Virtual Session)LLM4Code at Oceania I
Chair(s): Kexin Pei The University of Chicago

Zoom Link: https://us06web.zoom.us/j/89846180915

16:40
10m
Talk
MAsFL: Data-Secure, Efficient and Accurate Fault Localization with Multi-Agent Small Language Models
LLM4Code
PHAM DUC DUONG National Defense Academy of Japan, HIROSHI SATO National Defense Academy of Japan, MASAO KUBO National Defense Academy of Japan
16:50
10m
Talk
Natural Language Summarization Enables Multi-Repository Bug Localization by LLMs in Microservice ArchitecturesVirtual Attendance
LLM4Code
Amirkia Rafiei Oskooei Yildiz Technical University / Intellica, S. Selcan Yukcu Intellica Business Intelligence, Mehmet Cevheri Bozoglan Intellica Business Intelligence, Mehmet S. Aktas Yildiz Technical University
17:00
10m
Talk
RAG Against the Machine: Zero-Shot Software Vulnerabilities Classification using LLMs
LLM4Code
Edvin Nordqvist KTH Royal Institute of Technology, Changjie Wang KTH Royal Institute of Technology, Simone Ferlin Red Hat, Mariano Scazzariello RISE Research Institutes of Sweden, Marco Chiesa KTH Royal Institute of Technology
17:10
10m
Talk
Learning Functional Equivalence via Supervised Contrastive Code-Problem Alignment
LLM4Code
Siu Wun Cheung Lawrence Livermore National Laboratory, Harshitha Menon Lawrence Livermore National Lab
17:20
5m
Talk
Towards LLM-guided Semantic Validation of Autonomous Driving Safety Policies
LLM4Code
Qingzhao Zhang University of Arizona, Morley Mao University of Michigan
17:25
5m
Talk
ContextPilot: Code Context Engineering with Memory-Augmented Exploration Agents
LLM4Code
Shuzheng Gao Chinese University of Hong Kong, Chaozheng Wang The Chinese University of Hong Kong, Shuqing Li The Chinese University of Hong Kong, Yun Peng The Chinese University of Hong Kong, Michael Lyu The Chinese University of Hong Kong
17:30
5m
Talk
Continuous Benchmark Generation for Evaluating Enterprise-scale LLM Agents
LLM4Code
Divyanshu Saxena UT Austin, Rishikesh Maurya Microsoft, Gagan Somashekar Microsoft, Shachee Mishra Gupta Microsoft, Chetan Bansal Microsoft Research, Aditya Akella University of Texas at Austin