MAS-SRE: A Multi-Agent System for Security Requirements Engineering
Translating high-level business requirements into standards-grounded security requirements remains a persistent challenge in software engineering. Traditional Security Requirements Engineering (SRE) is often manual, error-prone, and too slow for modern development, creating a translation gap that can leave software vulnerable. This paper presents MAS-SRE, a multi-agent framework that automates the transformation of business requirements into traceable security requirements grounded in OWASP ASVS, NIST SP 800-53, and ISO 27001. MAS-SRE orchestrates 10 specialized agents across 4 workflow stages and combines STRIDE-based threat modeling with Retrieval-Augmented Generation (RAG) to produce standards-aligned outputs. Following the Design Science Research Process, the framework was evaluated on 14 industrial use cases through expert assessment by 15 software engineering practitioners and deterministic coverage and traceability metrics. MAS-SRE achieved 100% verification test coverage, 98.6% threat mapping coverage, 87.6% control mapping coverage, and about 40% lower processing time than sequential execution, while also receiving positive practitioner feedback on usefulness and adoption intent. These results indicate that MAS-SRE is a feasible approach for drafting standards-grounded, traceable security requirements, although comparative evaluation against alternative methods and deeper integration into development workflows remain future work.
Sun 5 JulDisplayed time zone: Eastern Time (US & Canada) change
16:00 - 18:00 | Session 4: Security, Trust, and Verification of LLM-Generated CodePROMISE 2026 at MB 3.430 Chair(s): Zhijie Wang Concordia University | ||
16:00 15mTalk | Model-Driven Automation of Cyber-Physical Systems via AADL and LLMs PROMISE 2026 | ||
16:15 15mTalk | MAS-SRE: A Multi-Agent System for Security Requirements Engineering PROMISE 2026 Savvas Mantzouranidis Blekinge Institute of Technology, Ricardo Britto Ericsson / Blekinge Institute of Technology | ||
16:30 15mTalk | Detecting Malicious Intents in Smart Contracts with Pre-trained Programming Language Models PROMISE 2026 Youwei Huang Independent Researcher, Jianwen Li Carnegie Mellon University, Silicon Valley, Sen Fang North Carolina State University, Yao Li Macau University of Science and Technology, Peng Yang Institute of Intelligent Computing Technology, Suzhou, CAS, Bin Hu Institute of Computing Technology, Chinese Academy of Sciences | ||
16:45 10mTalk | Probabilistic Evidence Aggregation for Source Code Authorship Verification: An Ongoing Set-Based Approach PROMISE 2026 | ||
16:55 5mDay closing | Closing PROMISE 2026 Lili Wei McGill University, Xiaoyu Sun Australian National University, Australia, Csaba Nagy PONTUM Software GmbH | ||