Enhancing Regulation-Adherent Requirement Engineering with Contextual AI: An industrial study
Wed 3 Dec 2025 14:00 - 14:30 at Sala Espositiva (Exhibition Hall) - Poster Session 2
Software projects in the medical device domain specify requirements at different abstraction levels (layers) to ensure traceability, compliance, and clarity. However, writing detailed lower-level requirements is time-consuming. Privacy and regulatory constraints often prohibit the use of external or public cloud services for processing sensitive requirement data. This study investigates whether privacy-preserving, on-premise large language models (LLMs) can automate the decomposition of high-level requirements into system and software-level specifications while complying with data-protection regulations. Five open-weights instruction-tuned models ranging from 3 billion to 70 billion parameters are evaluated locally using the Ollama runtime. Four prompt strategies are tested: minimal, regulatory-context, example-driven, and retrieval-augmented generation (RAG), across two decomposition levels: user-to-system and system-to-software on real-world medical device requirements. The results indicate that (i) all on-premise models generate syntactically valid and structured requirements when prompted appropriately, (ii) example-driven prompts achieve the highest semantic similarity scores to the ground truth, (iii) larger models (R1 Distill Qwen 32B and LLaMA 3.3 70B) outperform smaller models, and (iv) RAG, which is used to fetch examples for few-shot prompting, shows no measurable benefit due to limited retrieval corpus. These findings demonstrate that local LLMs can effectively automate requirements decomposition while maintaining regulatory compliance. Proposed approach has the potential to reduce the time used in requirements engineering while maintaining regulatory compliance.
Tue 2 DecDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
Wed 3 DecDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
14:00 - 14:30 | |||
14:00 30mTalk | Enhancing Regulation-Adherent Requirement Engineering with Contextual AI: An industrial study Industry Papers Orhan Sirin Solita Oy, Malik Sami Tampere University, Tuomas Granlund Solita Oy, Jussi Rasku Tampere University, Zheying Zhang Tampere University, Pekka Abrahamsson Tampere University | ||
14:00 30mTalk | An Empirical Study of Security-Policy Related Issues in Open Source Projects Short Papers and Posters Rintaro Kanaji Nara Institute of Science and Technology, Brittany Reid Nara Institute of Science and Technology, Yutaro Kashiwa Nara Institute of Science and Technology, Raula Gaikovina Kula The University of Osaka, Hajimu Iida Nara Institute of Science and Technology File Attached | ||
14:00 30mTalk | Towards Understanding the Developer Experience in Quantum Software Development Short Papers and Posters Ronja Heikkinen University of Jyväskylä, Majid Haghparast University of Jyväskylä, Tommi Mikkonen University of Jyvaskyla | ||