FSE 2026
Sun 5 - Thu 9 July 2026 Montreal, Canada
VenueConcordia SGW Campus @Downtown Montreal
Room nameMB 3.435
Floor0
Room InformationNo extra information available
Program

This program is tentative and subject to change.

You're viewing the program in a time zone which is different from your device's time zone change time zone

Sun 5 Jul

Displayed time zone: Eastern Time (US & Canada) change

09:00 - 10:30
Opening and KeynoteACM SecDev Research Papers at MB 3.435

Sunday, July 5th, 2026

Opening — 09:00–09:30

Room MB 3.435

Keynote by Dr. Rod Chapman — 09:30–10:30

Keynote Title Formal is Fast - Cryptographic code in the age of AI
Session Chair TBD
Room MB 3.435

Abstract

This talk will go over our approach to the development and verification of post-quantum cryptographic code at AWS. It will cover our approach to assembly-language verification, and how we are verifying C code within AWS LibCrypto. Proof also enables “fearless optimization” of crypto code, where proofs of correctness and/or equivalence preserve functional behaviour while allowing and inspiring non-trivial performance improvements. We’ll go on to talk about how AI agents are transforming our productivity and developer engagement without compromising our stratospheric quality bar. Our approach combines automated reasoning guardrails that constrain AI behaviour to known-good outcomes with aggressive use of agents to find proofs and optimizations of our most critical code.

Speaker Bio

Dr. Rod Chapman is a senior principal applied scientist within the Cryptography group of Amazon Web Services. He specializes in the design, development and verification of cryptographic software, and has particular experience with programming language design and automated reasoning technologies. He also coaches development teams and leadership in high-assurance software development disciplines, technologies, and processes. He is a Fellow of the IET and an honorary visiting professor at the University of York.

Coffee Break — 10:30–11:00


11:00 - 12:30
Paper Session: Program Analysis, Design, and EvaluationACM SecDev Research Papers at MB 3.435

Paper Session: Program Analysis, Design, and Evaluation — 11:00–12:30

Session Chair TBD
Room MB 3.435
# Paper
1 Reality Check: Independent Evaluation of Modern Grey-Box Fuzzing Techniques
Pavel Frolikov
2 Syntax Is Easy, Semantics Is Hard: Evaluating LLMs for LTL Translation
Priscilla Kyei Danso, Mohammad Saqib Hasan, Niranjan Balasubramanian, and Omar Chowdhury
3 CFIghter: Automated Control-Flow Integrity Enablement and Evaluation for Legacy C/C++ Systems
Sabine Houy, Bruno Kreyssig, and Alexandre Bartel
4 SoK: A Modularized Framework for Symbolic Execution and Application for Usable Tool Design
James Mattei, Andrew Lin, Jasper Geer, Jie Hu, Moritz Schloegel, Tiffany Bao, and Daniel Votipka

Lunch — 12:30–14:00

Room TBD

14:00 - 15:30
PanelACM SecDev Research Papers at MB 3.435

Panel: Trust, Autonomy, and Supply Chain Risk in Agentic Software Development — 14:00–15:00

Session Chair TBD
Room MB 3.435

Panelists

# Panelist
1 Name, Title, Organization
2 Name, Title, Organization
3 Name, Title, Organization
4 Name, Title, Organization

Poster Session and Coffee Break — 15:00–16:00

# Poster Title Presenters
1 Read the Room: LLM-Based Filesystem Intelligence for Targeted Compliance Scanning Adhithya Rajasekaran
2 Auditing MCP Servers for Over-Privileged Tool Capabilities Charoes Huang, Xin Huang, Amin Milani Fard
3 Nyx: A Distributed Performance Benchmark Framework for PSI Wout Ceulemans, Pieter Philippaerts, Dimitri Van Landuyt, Wouter Joosen
4 Are AI-assisted Development Tools Immune to Prompt Injection? Charoes Huang, Xin Huang, Amin Milani Fard
5 From Vulnerability to Resilience: Enhancing SDN-Based False Data Detection for In-Vehicle Networks Against DeepFool Long Dang, Thushari Hapuarachchi, Kaiqi Xiong, Yi Li
6 Evaluating Retrieval-Augmented Generation for Explainable Malware Analysis Jayson Ng, Amin Milani Fard
7 Automating Software Supply Chain Security: AI-Powered Threat Detection in DevSecOps Marlon Brenes Rojas, Sara Khanchi
8 Secure Local CI/CD Pipelines: Reducing Security Risk from Premature Code Integration Vinodkumar Kakarla, Sara Khanchi


16:00 - 18:00
Paper Session: Software Security and Vulnerability AnalysisACM SecDev Research Papers at MB 3.435

Paper Session: Software Security and Vulnerability Analysis — 16:00–18:00

Session Chair TBD
Room MB 3.435
# Paper
1 Origin Story: A Comprehensive Lifecycle Analysis of Same-Origin Policy Bugs
Jakub Szymsza, Gertjan Franken, Vik Vanderlinden, Tom Van Goethem, Mathy Vanhoef, and Lieven Desmet
2 ASN1spect: Uncovering ASN.1 Compiler-Generated Vulnerabilities in Critical Infrastructure
Seaver Thorn, Nathaniel Bennett, Kevin Butler, Patrick Traynor, and William Enck
3 On the Variability of Source Code in Maven Package Rebuilds
Jens Dietrich and Behnaz Hassanshahi
4 RepliGuard: Policy-Driven Replica Management Framework for Protecting against Acoustic Attacks
Jennifer Sheldon, Yungwoo Ko, Sri Hrushikesh Varma Bhupathiraju, Sara Osmanovic, Weidong Zhu, Md Jahidul Islam, and Sara Rampazzi
5 At the Precipice of Integrity Protection using Pointer Authentication
Viorel Preoteasa, Carlos Chinea Pérez, Hans Liljestrand, and Jan-Erik Ekberg
6 Cloud Safety: A Hardware Perspective
Raghudeep Kannavara, Matthew Dickinson, and Monty Wiseman

Mon 6 Jul

Displayed time zone: Eastern Time (US & Canada) change

09:00 - 10:30
Opening and KeynoteACM SecDev Research Papers at MB 3.435

Monday, July 6th, 2026

Keynote by Dr. Sergey L. Bratus — 09:30–10:30

Keynote Title Mapping and Bridging the Software Understanding Gap
Session Chair TBD
Room MB 3.435

Abstract

The gap between our capabilities to build software and to understand what we’ve built, reason about it, and anticipate its emergent behaviors, is tremendous. The joint “Closing the Software Understanding Gap” memorandum by US Government agencies recognized addressing this gap as a national priority. I will argue that the keys to bridging this gap lie in rethinking ostensibly mere-engineering tasks as truly first-class computer science challenges; changing the formats in which code and data are delivered based on this new understanding; and applying strong predictive theories of software’s emergent behaviors (typically witnessed via ‘hacking’ or exploitation) to all stages of software construction, delivery, and operation.

Speaker Bio

Dr. Sergey L. Bratus is the Dartmouth College Distinguished Professor in Cyber Security, Technology, and Society and an Associate Professor of Computer Science. In 2018–2024 he served as a Program Manager at DARPA’s Information Innovation Office (I2O), where he created multiple fundamental research programs in cybersecurity, resilience, and sustainment of critical software.

Coffee Break — 10:30–11:00


11:00 - 12:30
Paper Session: Security Analysis and DesignACM SecDev Research Papers at MB 3.435

Paper Session: Security Analysis and Design — 11:00–12:30

Session Chair TBD
Room MB 3.435
# Paper
1 OpenClaw RedTeam Recon: A Local OSS-LLM-Powered Autonomous Reconnaissance Agent
Marcelo Garcia and Robson de Oliveira Albuquerque
2 SafeAIMerge: A Tool for Integrating DAST and LLM-Generated Security Feedback into GitHub Actions Workflows
Arpit Thool, Justin Smith, and Chris Brown
3 A CNN-LSTM Security Model for SCADA Network
Olga Dye and Brian Dye
4 SoK: A Comprehensive Analysis of the Current Status of Neural Tangent Generalization Attacks with Research Directions
Thushari Hapuarachchi and Kaiqi Xiong

Lunch — 12:30–14:00

Room TBD

14:00 - 15:30
Award Session and Paper Session: Security Analysis and DesignACM SecDev Research Papers at MB 3.435

Award Session — 14:00–14:10

Room MB 3.435

Distinguished Reviewer & Paper Awards

Chair Dr. Dimitri Van Landuyt

Paper Session: Security Analysis and Design — 14:10–15:30

Session Chair TBD
Room MB 3.435
# Paper
1 SGX-MB: A Secure Framework for Middleboxes Leveraging Intel SGX
Mahmoud Hofny, Lianying Zhao, and Amr Youssef
2 A Technology-Readiness Evaluation of Private Set Intersection
Wout Ceulemans, Pieter Philippaerts, Dimitri Van Landuyt, and Wouter Joosen
3 Augment Mutual TLS Authentication with HW Rooted Identity: Simplified Device Lifecycle and Interoperability
Dhananjay Phadke and Xiling Sun
4 Adversarially Mixed Secret Key Generation for Side-Channel Defense for the Cloud
Venkat Sai Suman Lamba Karanam, Zahmeeth Sayed Sakkaff, and Pasindu Balasooriya

Coffee Break — 15:30–16:00


16:00 - 18:00

Tue 7 Jul

Displayed time zone: Eastern Time (US & Canada) change

11:00 - 12:30
11:00
20m
Research paper
Carbon-Taxed Transformers: A Green Compression Pipeline for Overgrown Language Models
Research Papers
Ajmain Inqiad Alam University of Saskatchewan, Palash Ranjan Roy University of Saskatchewan, Chanchal K. Roy University of Saskatchewan, Banani Roy University of Saskatchewan, Kevin Schneider University of Saskatchewan
Pre-print
11:20
10m
Talk
Advancing Evidence-Based Social Sustainability in Software Engineering: A Research Roadmap
Ideas, Visions and Reflections
Bimpe Ayoola Dalhousie University, Anielle Andrade Federal University of Pampa, Paul Ralph Dalhousie University, Ronnie de Souza Santos University of Calgary
11:30
20m
Talk
Practical Feasibility of Sustainable Software Engineering Tools and Techniques
Industry Papers
Satwik Ghanta University of Glasgow, Peggy Gregory University of Glasgow, UK, Gül Calikli University of Glasgow
11:50
20m
Talk
Adopting Concepts for Sustainable Improvement of the Developer Experience within a Medium-sized Corporation
Industry Papers
Jannik Lange Munich University of Applied Sciences, Axel Böttcher Munich University of Applied Sciences
12:10
20m
Talk
Fairness Testing of Large Language Models in Role-Playing
Research Papers
Xinyue Li Peking University, Zhenpeng Chen Tsinghua University, Jie M. Zhang Mistral AI and King's College London, Ying Xiao , Li Tianlin , Weisong Sun Nanyang Technological University, Yang Liu Nanyang Technological University, Yiling Lou University of Illinois at Urbana-Champaign, Xuanzhe Liu Peking University
14:00 - 15:30
14:00
10m
Talk
TestAgent: A Multi-Agent LLM Framework for Repository-Level Unit Test Generation
Tool Demonstrations
ye shang Nanjing University, Quanjun Zhang Nanjing University of Science and Technology, Zhengyu Zhan Nanjing University, Ke Huang Nanjing University, Chunrong Fang Nanjing University, Zhenyu Chen Nanjing University
14:10
20m
Talk
Just-in-Time Catching Test Generation at Meta
Industry Papers
Mark Harman Meta Platforms, Inc. and UCL, Matthew Becker Meta, Yifei Chen Meta, Nicholas Cochran Meta, Pouyan Ghasemi Meta, Abhishek Gulati Meta platforms, Mehrdad Honarkhah Meta, Hervé Robert Meta platforms, Jiacheng Liu Meta, Weini Liu Meta, Sreeja Thummala Meta, Xiaoning Yang Meta, Rui Xin Meta, Sophie Zeng Meta, Zac Haluza Meta
14:30
20m
Talk
Understanding and Mitigating Hallucinations in Industrial LLM-based Unit Test Generation
Industry Papers
Yanlun Tu Ant Group, Ziyue Zhou University of Electronic Science and Technology of China, Cheng Xu Ant Group, Jingling Sun University of Electronic Science and Technology of China, Shuai Feng Ant Group, Chengyu Zhang Loughborough University
14:50
20m
Talk
Directed Grammar-Based Test Generation
Journal-First Paper
Lukas Kirschner Saarland University, Ezekiel Soremekun Singapore University of Technology and Design
15:10
20m
Talk
iCoRe: An Iterative Correlation-Aware Retriever for Bug Reproduction Test Generation
Research Papers
JunyiWang Zhejiang University, Jialun Cao Hong Kong University of Science and Technology, Zhongxin Liu Zhejiang University
16:00 - 17:20
Code similarity and searchResearch Papers at MB 3.435
16:00
20m
Talk
Understanding Code Similarity across Instruction Set Architectures: An Empirical Study
Research Papers
yuhaonan Institute of Software Chinese Academy of Sciences, Jiaxin Zhu Institute of Software at Chinese Academy of Sciences, Yingying Zheng Institute of Software at Chinese Academy of Sciences, Yuwei Zhang Institute of Software Chinese Academy of Sciences, Wei Wang Institute of Software at Chinese Academy of Sciences, Jun Wei Institute of Software at Chinese Academy of Sciences; University of Chinese Academy of Sciences, Tao Huang Institute of Software at Chinese Academy of Sciences
16:20
20m
Talk
SBridge: Identifying Source-to-Binary Function Similarity via Cross-Domain Control Block Matching
Research Papers
Heedong Yang Korea University, Jeongwoo Lee Korea University, Hajin Yun Korea University, Seunghoon Woo Korea University
16:40
20m
Talk
Understanding Binary Code Similarity for Real-World Vulnerability Detection: A Large-Scale Empirical Study
Research Papers
Jingdong Guo Institute of Information Engineering, CAS; School of Cyber Security, UCAS, Chaopeng Dong School of Cyberspace, Hangzhou Dianzi University, Yimo Ren Institute of Information Engineering Chinese Academy of Sciences & University of Chinese Academy of Sciences, China, Siyuan Li University of Chinese Academy of Sciences & Institute of Information Engineering Chinese Academy of Sciences, China, Jie Liu Institute of Software, Chinese Academy of Sciences, Hong Li Institute of Information Engineering at Chinese Academy of Sciences, Hongsong Zhu Institute of Information Engineering at Chinese Academy of Sciences; University of Chinese Academy of Sciences
17:00
20m
Talk
Project-Level C-to-Rust Translation via Pointer Knowledge Graphs
Research Papers
Zhiqiang Yuan Fudan University, Wenjun Mao Fudan University, Zhou , Xiyue Shang Fudan University, Chong Wang Nanyang Technological University, Yiling Lou University of Illinois at Urbana-Champaign, Xin Peng Fudan University

Wed 8 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
20m
Talk
YASA: Scalable Multi-Language Taint Analysis on the Unified AST at Ant Group
Industry Papers
Yayi Wang Ant Group, Shenao Wang Huazhong University of Science and Technology, Jian Zhao Huazhong University of Science and Technology, Shaosen Shi Ant Group, Ting Li Ant Group, Yan Cheng Ant Group, Lizhong Bian Ant Group, Kan Yu Ant Group, Yanjie Zhao Huazhong University of Science and Technology, Haoyu Wang Huazhong University of Science and Technology
10:50
20m
Talk
InDe-LLM: Defending Against Jailbreak Attacks in LLM-Powered Systems via Intention Disentangling
Research Papers
YujueWang Tsinghua University, Quan Zhang East China Normal University, Chijin Zhou East China Normal University, Gwihwan Go Tsinghua University, Dalong Shi AVIC International Digital Network Technology Co., Ltd., Yu Jiang Tsinghua University
11:10
20m
Talk
Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical Study
Research Papers
Weijie Liu Nankai University, Hongbo Chen Indiana University Bloomington, Shuo Huai Nankai University, Zhen Xu Nanyang Technological University, Wenhao Wang Institute of Information Engineering, CAS, XiaoFeng Wang Nanyang Technological University, Danfeng Zhang Duke University, Zhi Li Huazhong University of Science and Technology, Haixu Tang Indiana University Bloomington, Zheli Liu Nankai University
11:30
20m
Talk
GadgetHunter: Region-Based Neuro-Symbolic Detection of Java Deserialization Vulnerabilities
Research Papers
Kaixuan Li Nanyang Technological University, Jian Zhang Beihang University, Chong Wang Nanyang Technological University, Sen Chen Nankai University, Zong Cao Imperial Global Singapore, Min Zhang East China Normal University, Yang Liu Nanyang Technological University
Pre-print
11:50
20m
Talk
ReGA: Model-based Safeguard for LLMs via Representation-Guided Abstraction
Research Papers
Zeming Wei Peking University, Chengcan Wu Peking University, Meng Sun Peking University
14:00 - 15:30
14:00
20m
Talk
Impact of extensions on browser performance: An empirical study on google chrome
Journal-First Paper
Bihui Jin University of Waterloo, Heng Li Polytechnique Montréal, Ying Zou Queen's University, Kingston, Ontario
14:20
20m
Talk
Evaluating Risk and Confidence in Performance Bounds of Configuration Sampling Strategies
Research Papers
Kallistos Weis Saarland University, Martina Maggio Saarland University, Germany / Lund University, Sweden, Norbert Siegmund Leipzig University, Sven Apel Saarland University
Pre-print
14:40
20m
Talk
Unleashing HPC Application Performance through Software Deployment: A Joint Model of Software Parallelism and Co-location
Research Papers
Yuxin Ren Huawei Technologies, li zhou Huawei Technologies, Chumin Sun Huawei Technologies, Rui Fan Huawei Technologies, Jie Sun Huawei Technologies, Ning Jia Huawei Technologies, Xinwei Hu Huawei Technologies
15:00
10m
Talk
Rethinking Performance Debugging: From Optimization to Collaborative Reasoning
Ideas, Visions and Reflections
Mahsa Panahandeh Postdoctoral Fellow, School of Electrical Engineering and Computer Science, University of Ottawa, Naser Ezzati-Jivan Brock University, Abdelwahab Hamou-Lhadj Concordia University, Montreal, Canada
15:10
10m
Talk
Energy Flow Graph: Modeling Software Energy Consumption
Ideas, Visions and Reflections
Saurabhsingh Rajput Dalhousie University, Tushar Sharma Dalhousie University
15:20
10m
Talk
CodeGreen: Towards Improving Precision and Portability in Software Energy Measurement
Tool Demonstrations
Saurabhsingh Rajput Dalhousie University, Tushar Sharma Dalhousie University
16:00 - 16:50
16:00
20m
Talk
Cost-Effective Testing of MPC Compilers
Research Papers
Pre-print
16:20
10m
Talk
Compilomorphic Fuzzing: Turning a Compiler Against Itself
Ideas, Visions and Reflections
Vasileios Klimis Queen Mary University of London
16:30
10m
Talk
PYURIFY: Purifying Python Tests for Precise Fault Localization
Tool Demonstrations
Marius Smytzek CISPA Helmholtz Center for Information Security, Andreas Zeller CISPA Helmholtz Center for Information Security
16:40
20m
Talk
Detecting Bugs in Rust Compiler Fix Suggestions via Constraint-Violation-Guided Mutation
Research Papers
Zixi Liu Nanjing University, Yang Feng Nanjing University, Jialiang Jiang Nanjing University, Baowen Xu Nanjing University

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change

10:30 - 12:30
10:30
10m
Talk
FISTS: A Field-based Security Testing Tool for Updates in Software-Defined Networks
Tool Demonstrations
Jahanzaib MALIK University of Luxembourg, Fabrizio Pastore University of Luxembourg
10:40
20m
Talk
Enabling Security Champions With Breakout Action Groups (BAGs) – A Longitudinal Case Study
Industry Papers
Jens Christian Opdenbusch Ruhr University Bochum, Sangavi Shanthakumar Ruhr University Bochum, Martina Angela Sasse Ruhr University Bochum, Marco Gutfleisch LMU Munich
11:00
20m
Talk
An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling
Industry Papers
Francis Martins UNB, Elaine Venson University of Brasilia
11:20
20m
Talk
Uncovering Similar but Different Packages in PyPI and Potential Security Threats
Research Papers
Sunha Park Korea University, Soojin Han Dongduk Women's University, Seunghoon Woo Korea University
11:40
20m
Talk
BackportBench: A Multilingual Benchmark for Automated Patch Backporting
Research Papers
Zhiqing Zhong The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Jiaming Huang The Chinese University of Hong Kong, Shenzhen (CUHK-Shenzhen), Pinjia He Chinese University of Hong Kong, Shenzhen
12:00
10m
Talk
BackportCheck: An Open-Source Tool to Support Backport Decisions in Large Software Ecosystems
Tool Demonstrations
Salma Sghaier ENSI, Mannouba University, Mohamed Anas Daoud ENSI, Mannouba University, Marouene Chaieb National School of Computer Science, Moataz Chouchen Concordia University, Mohammad Hamdaqa Polytechnique Montreal, Mohamed Wiem Mkaouer University of Michigan-Flint
12:10
10m
Short-paper
Towards Predicting Multi-Vulnerability Attack Chains in Software Supply Chains from Software Bill of Materials Graphs
Ideas, Visions and Reflections
Laura Baird University of Colorado Colorado Springs (UCCS), Armin Moin University of Colorado Colorado Springs
DOI
14:00 - 15:30
14:00
20m
Talk
Agentic Verification of Software Systems
Research Papers
Haoxin Tu Singapore Management University, Singapore, Huan Zhao National University of Singapore, Yahui Song Standard Chartered Bank, Mehtab Zafar National University of Singapore, Ruijie Meng CISPA Helmholtz Center for Information Security, Abhik Roychoudhury National University of Singapore
14:20
20m
Talk
DiverFPS: Generating Diverse Solutions for Floating-Point SMT Formulas
Research Papers
Shuangyu Lyu Beihang University, Chuan Luo Beihang University, Ruizhi Shi Beihang University, Zhuo Su Beihang University, Chunming Hu Beihang University
14:40
10m
Talk
The Watermark Paradox: How Provenance Verification Paves the Road to Camouflaged Backdoors
Ideas, Visions and Reflections
Haoyi Zhang Xi’an Jiaotong-Liverpool University, Huaijin Ran Xi’an Jiaotong-Liverpool University, Kisub Kim DGIST, Xunzhu Tang University of Luxembourg
DOI
14:50
10m
Talk
HarnessForge: Automated Extraction of Verification Tasks from Industry-Scale Software Projects
Tool Demonstrations
Dirk Beyer LMU Munich, Po-Chun Chien LMU Munich, Bo-Yuan Huang Intel, USA, Nian-Ze Lee National Taiwan University, Taiwan, Thomas Lemberger LMU Munich
Pre-print Media Attached
15:00
10m
Talk
PyMOP: A Runtime Verification Tool for Python
Tool Demonstrations
Zhuohang Shen Cornell University, Mohammed S. Yaseen Independent Researcher, Kevin Guan Cornell University, Denini Silva Federal University of Pernambuco, Marcelo d'Amorim North Carolina State University, Owolabi Legunsen Cornell University
15:10
20m
Talk
Property Refinement in Linear Temporal Logic: Formal Semantics and Algorithms for Software Verification
Research Papers
Luca Brodo Hochschule Hamm-Lippstadt, Giuseppe Scalora Hamm-Lippstadt University of Applied Sciences, Stefan Henkler Hochschule Hamm-Lippstadt
File Attached

Tue 7 Jul

Displayed time zone: Eastern Time (US & Canada) change

Room11:0015304512:0015304513:0015304514:0015304515:0015304516:0015304517:00153045
MB 3.435

Wed 8 Jul

Displayed time zone: Eastern Time (US & Canada) change

Room10:0015304511:0015304512:0015304513:0015304514:0015304515:0015304516:00153045
MB 3.435

Thu 9 Jul

Displayed time zone: Eastern Time (US & Canada) change