Software vulnerabilities can cause tremendous operational and financial damage to individuals and organizations in the event of cyber attacks. For example, the Log4J vulnerability can make millions of systems worldwide open to cyber attacks and potentially cause billions of dollars of damage. Software Vulnerability Management (SVM) is a critical process during software development to ensure software security and prevent these dangerous cyber attacks. SVM typically contains various phases such as detection, assessment, prioritization, fixing/patching and reporting/disclosure. In the last 10 years, there has been an unprecedented rise in the size and complexity of software systems. For instance, the codebase of Google services contains more than two billion lines of code. This in turn requires new technologies, tools, and practices for SVM to ensure the security of such systems.
The Fourth International Workshop on Software Vulnerability Management (SVM 2026) is a venue that aims to bring together academics, industry and government practitioners to present and discuss the state-of-the-art and state-of-the-practice of SVM to support both current and emerging software technologies and infrastructures.
The official website of the SVM workshop is: https://www.svmconf.org/.
The Twitter site of the workshop: https://twitter.com/svmconf.
The Linkedin site of the workshop: https://www.linkedin.com/company/svm-workshop.
Tweets by svmconfSat 18 AprDisplayed time zone: Brasilia, Distrito Federal, Brazil change
08:00 - 17:30 | Saturday RegistrationSocial, Networking and Special Rooms at Main Entrance Registration for ICSE 2026. | ||
08:00 9h30mRegistration | ICSE 2026 Registration Social, Networking and Special Rooms | ||
09:00 - 10:30 | |||
09:00 5mDay opening | Workshop Opening EnCyCriS Coralie Esnoul Institute For Energy Technology (IFE) | ||
09:05 15mFull-paper | Towards a Cognitive-Support Tool for Threat Hunters EnCyCriS Alessandra Maciel Paz Milani University of Victoria, Norman Anderson University of Victoria, Margaret-Anne Storey University of Victoria Pre-print | ||
09:20 15mFull-paper | Reflections and Factors in Applying Threat Modelling Tools for Cybersecurity Certification in Critical Infrastructure EnCyCriS Ahmed Amro Norwegian University of Science and Technology (NTNU), Vasileios Gkioulos NTNU, Claudia Lutze Hitachi Rail, Jean-Marie Lauranson Hitachi Rail, Maria I. Maslioukova Catalink, Pavlos Kosmides Catalink, Christina Michailidou Catalink, Pedro-Tito Macías-Roselló Schneider Electric, Evgeny Prokofyev Schneider Electric, Antoliano Davila Schneider Electric, Tanel Kerstna MindChip, Per Myrseth DNV, Meine Van Der Meulen DNV | ||
09:35 15mFull-paper | An Overview of Cyber Security Funding for Open Source Software EnCyCriS Jukka Ruohonen University of Southern Denmark, Gaurav Choudhary Choudhary Technical University of Denmark, Adam Alami University of Southern Denmark | ||
09:50 15mFull-paper | LLM-Assisted AHP for Explainable Cyber Range Evaluation EnCyCriS Vyron Kampourakis Norwegian University of Science and Technology NTNU, Georgios Kavallieratos Norwegian University of Science and Technology NTNU, Georgios Spathoulas Norwegian University of Science and Technology NTNU, Vasileios Gkioulos NTNU, Sokratis Katsikas Norwegian University of Science and Technology (NTNU) | ||
10:05 15mFull-paper | Behind the Quantum Curtain: A practical comparison between SVM and QSVM in OT Anomaly Detection EnCyCriS Alessio Di Santo Università degli Studi dell'Aquila, Nicola Camarda , Walter Tiberti Università degli Studi dell'Aquila, Dajana Cassioli Università degli Studi dell'Aquila | ||
10:20 10mOther | all together : picture EnCyCriS | ||
10:30 - 11:00 | Saturday Morning BreakCatering at Catering and Exhibition Hall (Europa I to IV) This break will provide an opportunity for networking and relaxation between sessions. | ||
10:30 30mCoffee break | Break Catering | ||
12:30 - 14:00 | Saturday LunchCatering at Catering and Exhibition Hall (Europa I to IV) Lunch time with a variety of meal options available for attendees, including vegetarian choices. This session will provide an opportunity for attendees to enjoy a meal while networking with colleagues and discussing the day’s events. | ||
12:30 90mLunch | Lunch Catering | ||
14:00 - 15:30 | |||
14:00 5mDay opening | SVM Opening SVM Triet Le Adelaide University | ||
14:05 20mTalk | An Automated Approach to Generate Attack Graphs with a Case Study on Siemens PCS7 Blueprint SVM Lucas Miranda UFRJ, Carlos Eduardo de Schuller Banjar UFRJ, Daniel Sadoc Menasche UFRJ, Brazil, Anton Kocheturov Siemens Technology, Gaurav Kumar Srivastava Siemens, Tobias Limmer Siemens Pre-print | ||
14:25 20mTalk | Bridging Code Property Graphs and Language Models for Program Analysis SVM Ahmed Lekssays Qatar Computing Research Institute | ||
14:45 20mTalk | Evaluating Cryptographic API Misuse Detectors for Go SVM Vivi Andersson KTH Royal Institute of Technology, Martin Monperrus KTH Royal Institute of Technology | ||
15:05 20mTalk | An Invited Talk on Trusted Vulnerability Detection SVM Zhou Yang University of Alberta, Alberta Machine Intelligence Institute | ||
15:25 5mSocial Event | Group Photo SVM | ||
15:30 - 16:00 | Saturday Afternoon BreakCatering at Catering and Exhibition Hall (Europa I to IV) Afternoon Break with a variety of beverages and snacks available for attendees. This break will provide an opportunity for networking and relaxation between sessions. | ||
15:30 30mCoffee break | Break Catering | ||
16:00 - 17:30 | |||
16:00 20mTalk | LLMs in Code Vulnerability Analysis: A Proof of Concept SVM Shaznin Sultana Ohio University, Sadia Afreen University of Cincinnati, Nasir Eisty University of Tennessee-Knoxville | ||
16:20 20mTalk | Q&AEval: Benchmarking Secure Coding Ability of LLMs on Real-World Tasks SVM Markus Toran Fraunhofer SIT; ATHENE, Bettina Ballin , Marc Miltenberger Fraunhofer SIT; ATHENE, Steven Arzt Fraunhofer SIT; ATHENE | ||
16:40 20mTalk | Process-based Indicators of Vulnerability Re-Introducing Code Changes: An Exploratory Case Study SVM Samiha Shimmi Northern Illinois University, Nicholas Synovic Loyola University Chicago, Mona Rahimi Northern Illinois University, George K. Thiruvathukal Loyola University Chicago | ||
17:00 5mDay closing | SVM Closure SVM Triet Le Adelaide University | ||
Accepted Papers
Call for Papers
The International Workshop on Software Vulnerability Management (SVM) invites academia, industry, and governmental entities to submit original research papers and demos (hands-on or videos) concerning the advances and practices of software vulnerability management from both technical and socio-technical perspectives.
The suggested topics include but not limited to:
- Requirements engineering for SVM
- Techniques and practices of threat modeling (including mixed-methods)
- Methodology and processes for SVM
- Static/dynamic analysis tools for SVM
- AI-driven techniques, including Large Language Models for SVM (AI4SVM / LLM4SVM)
- SVM for AI/LLM-based systems (SVM4AI / SVM4LLM)
- Socio-technical aspects of SVM
- Human-AI collaboration for SVM
- Empirical study of SVM tools and/or practices (including mixed-methods)
- SVM in software development lifecycle
- SVM in software supply chain security, including SBOMs/AIBOMs
- Mining software repositories for SVM
- Datasets for SVM
- Data quality for SVM analytics
- Software infrastructures for SVM
- SVM for infrastructure-as-code and/or virtualised infrastructures
- SVM for DevOps
- SVM for emerging software systems (e.g., blockchain, virtual, augmented, mixed reality, and quantum systems)
Please note that the contributions can target any task/phase within an SVM process.
Submission Types
The SVM workshop welcomes two types of submissions:
- Research or Industry Papers: up to eight pages, including references. These papers are expected to describe original contributions to research and/or industry practices for SVM. We also welcome short papers of up to five pages on tool demos, models, and datasets for SVM with clear usage and implications. Although these papers can include work-in-progress work, authors must outline a clear plan moving forward. The accepted papers will be allocated 15 to 20 minutes for presentation during the workshop, depending on the number of accepted papers.
- Extended Abstracts: up to five pages, including references, which will be featured as lightning talks of 10-15 minutes each. These abstracts will include visions, emerging ideas, preliminary results that have yet to be fully developed for SVM in academia and/or industry. Important note: These abstracts are free of APC charges. The “extended abstract” term should be explicit in the call (and papers should be marked as such by the proceedings chairs). Please note that “short papers” are charged, but “extended abstracts” are not (see https://libraries.acm.org/acmopen/article-types).
How to Submit
We adopt the guidelines of ICSE 2026 paper submission for the SVM workshop. Specifically, all submissions must conform, at time of submission, to the official “ACM Primary Article Template”, which can be obtained from the ACM Proceedings Template page.
When submitting to the workshop, authors acknowledge that they conform to the authorship policy of the ACM, and the authorship policy of the IEEE.
Authors are strongly encouraged to share the artifacts (e.g., data, code, and models) in the submissions, whenever possible, as per the Open Science Policy of ICSE 2026. The submissions need to be made to HotCRP at https://icse2026-svm.hotcrp.com/.
Conflicts of Interest
We seriously consider Conflicts of Interest during the paper review. Both authors and program committee members are encouraged to cooperate to prevent submissions from being evaluated by reviewers having a conflict of interest with any of the authors. The authors and reviewers can refer to the ACM Conflict of Interest Policy for identifying a conflict of interest.
Ethics Policies
If the research involves human participants/subjects, the authors must adhere to the ACM Publications Policy on Research Involving Human Participants and Subjects. Upon submitting, authors will declare their compliance to such a policy.
If the submission describes, or otherwise takes advantage of, newly discovered software vulnerabilities or cyber attacks, the authors should disclose these vulnerabilities to the vendors/maintainers of affected systems prior to the submission deadline. When disclosure is necessary, authors are expected to include a statement within their submission and/or final paper about steps taken to fulfill the goal of responsible disclosure.