PROMISE 2026
Sun 5 Jul 2026 Montreal, Canada
co-located with FSE 2026

Although Large Language Models (LLMs) show promising solutions to automated code generation, they often produce insecure code that threatens software security. Current approaches (e.g., SafeCoder) to improve secure code generation suffer from limited and imbalanced datasets, reducing their effectiveness and generalizability. In this work, we present Secure-Instruct, a novel framework that automatically synthesizes high-quality vulnerable and secure code examples, generates fine- tuning instructions, and instruction- tunes LLMs to align task description and secure code generation abilities. We evaluate Secure-Instruct on four representative LLMs using two benchmarks: our own CWEBench and the existing CWEval. CWEBench comprises 93 scenarios on 44 CWEs, all without overlap with Secure-Instruct’s synthetic instruction- tuning dataset, while CWEval covers 31 CWEs with 119 manually verified security-critical tasks. We find that Secure-Instruct improves not only the security but also the functional correctness of the generated code. On CWEBench, Secure-Instruct substantially improves secure code generation, giving a 14.3% average increase in secure ratio over the pretrained models and outperforms SafeCoder by 7.6%. On CWEval, Secure-Instruct achieves a 14% increase for CodeLlama-7B and 5.8% for Mistral-7B in Func-Sec@1 over pretrained models, and surpasses SafeCoder by 15.8% and 6.8% respectively.

Sun 5 Jul

Displayed time zone: Eastern Time (US & Canada) change

09:00 - 10:30
Session 1: Keynote and Research Papers on LLM Code Generation FoundationsPROMISE 2026 at MB 3.430
Chair(s): Lili Wei McGill University
09:00
5m
Day opening
Opening
PROMISE 2026
Lili Wei McGill University, Xiaoyu Sun Australian National University, Australia, Csaba Nagy PONTUM Software GmbH
09:05
55m
Talk
Keynote 1 - The Limits of “Cute” CI/CD Pipelines
PROMISE 2026
Shane McIntosh University of Waterloo
10:00
15m
Talk
An Empirical Study of Waterfall-style Multi-Agent Workflows for Class-Level Code Generation
PROMISE 2026
Wasique Islam Shafin Concordia University, Md Naklha Rafi Concordia University, Zhenhao Li York University, Tse-Hsun (Peter) Chen Concordia University
10:15
15m
Talk
Secure-Instruct: Prompt, Synthesize, and Fine-Tune for Secure Code Generation
PROMISE 2026
Junjie Li Concordia University, Fazle Rabbi Concordia University, Bo Yang Concordia University, Song Wang York University, Jinqiu Yang Concordia University