SANER 2026
Tue 17 - Fri 20 March 2026 Limassol, Cyprus
Tue 17 Mar 2026 15:00 - 15:15 at Atrium A - SQA4AI - Session 1

The integration of Large Language Models (LLMs) into Software Engineering offers efficiency but may also introduce significant risks. In Security Requirements Engineering (SRE), generic LLMs frequently exhibit omission errors — failing to identify necessary security constraints — and hallucinations. While Retrieval-Augmented Generation (RAG) mitigates factual errors, standard implementations rely on semantic similarity, creating a bottleneck that overlooks structurally necessary but semantically distinct security categories.

To address this, we propose a specialized RAG framework designed as an automated Quality Assurance mechanism. Our approach integrates a curated OWASP Knowledge Base with a novel two-stage generation pipeline. Unlike single-shot RAG, our system incorporates a deterministic threshold-based feedback loop: it statically analyzes the initial output’s coverage against the security taxonomy and triggers an adaptive compensatory generation to populate under-represented categories.

We evaluated the framework on UniClass, a web application case study, across repeated executions. Empirical results demonstrate that the pipeline achieves a stable Mean Coverage of 72% across relevant security categories with a high Applicability of 81%, as verified by one project developer. By enforcing structural completeness before implementation, our approach serves as a critical QA guardrail for secure AI-driven development.

Tue 17 Mar

Displayed time zone: Athens change

14:00 - 15:30
SQA4AI - Session 1Workshops & Tutorials at Atrium A

14:00–14:15: Workshop Introduction

14:15
15m
Talk
CVE-Poisoning: Towards Human-Guided and Cost-Effective Detection of a Novel AI Data Poisoning Attack
Workshops & Tutorials
Norbert Szolnoki Sándor Department of Software Engineering, University of Szeged, Gergő Balogh Department of Software Engineering, University of Szeged, Szabina Herman University of Szeged, Gabor Antal Department of Software Engineering, University of Szeged
14:30
15m
Talk
An LLM-based Approach for Automatic ML Prototype Review
Workshops & Tutorials
Selin Coban Research Group Software Construction RWTH Aachen University, Miguel Perez Research Group Software Construction RWTH Aachen University, Cagatay Akpinar Research Group Software Construction RWTH Aachen University, Baran Tanriverdi Research Group Software Construction RWTH Aachen University, Horst Lichter RWTH Aachen University
14:45
15m
Talk
From Threat Reports to Security Knowledge: Building an LLM-based Pipeline for AI Systems
Workshops & Tutorials
Takuma Tsuchida Waseda University, Yuya Fujiwara Waseda University, Hironori Washizaki Waseda University, Naoyasu Ubayashi Waseda University
15:00
15m
Talk
Enhancing Security Requirements Coverage via RAG and Automated Feedback Loops
Workshops & Tutorials
Giuseppe Sabetta University of Salerno, Alfonso Cannavale University of Salerno, Fabio Palomba University of Salerno, Andrea De Lucia University of Salerno
15:15
15m
Talk
Empirical Evaluation of Open Source Large Language Models for Paper Selection: Are LLMs Trustworthy Tools for Scoping Reviews?
Workshops & Tutorials
Homayoun Safarpour University of Szeged, Gergő Balogh Department of Software Engineering, University of Szeged, Aondowase James Orban