EASE 2026
Tue 9 - Fri 12 June 2026 Glasgow, United Kingdom

Over the last decade, an increasing number of organizations have started focusing on software security because modern applications typically operate in a hostile network-based environment. Traditionally, organizations have tried to address security concerns by finding and fixing security vulnerabilities once the software development cycle is completed. Software needs to be secured against any unauthorized users, and this can be achieved by incorporating security mechanisms into different phases of the software development lifecycle. However, incorporating security practices and processes into different phases of the software development life cycle remains a challenge. The software security area is evolving due to different factors such as increasing failure rates of software projects, economic downturn, and software development without security in mind, globalization, and outsourcing. The empirical software engineering researchers need new approaches, models, and tools for addressing various emerging challenges of software security in this modern age. There is a need for using empirical evidence to support different new approaches in the software security research and practice, which will provide researchers with innovative knowledge on which to develop different software security processes and practices. This will also help in improving existing software security approaches and processes in order to effectively develop secure software. This workshop will bring together and advance the work that has been undertaken on software security. The outcome of this workshop will provide researchers and practitioners with a firm basis on which to develop different practices/ tools/ techniques that are based on an understanding of how and where they fit into secure software development and research. New practices/ tools/ techniques could then be developed targeting the secure software engineering community.

You're viewing the program in a time zone which is different from your device's time zone change time zone

Fri 12 Jun

Displayed time zone: London change

09:00 - 17:00
Software Security Engineering WorkshopSSE-26 Workshop on Software Security Engineering at JMS 707
Chair(s): Mohammad Alshayeb King Fahd University of Petroleum & Minerals, Mahmood Niazi King Fahd University of Petroleum and Minerals
09:00
15m
Day opening
Welcome by the Organizers
SSE-26 Workshop on Software Security Engineering

09:15
15m
Talk
A Multi-Agentic AI Pipeline for Iterative Vulnerability Detection and Auto-Remediation in Python
SSE-26 Workshop on Software Security Engineering
09:30
15m
Talk
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
SSE-26 Workshop on Software Security Engineering
Mohamed Elsayed , Kenneth Fulton , Jeong Yang Texas A&M University-San Antonio
09:45
15m
Talk
Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets
SSE-26 Workshop on Software Security Engineering
Zeyad Abdelrazek , Young Lee Texas A & M University - San Antonio
10:00
15m
Talk
Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners
SSE-26 Workshop on Software Security Engineering
Muhammad Azeem Akbar LUT University, Saima Rafi Edinburgh Napier University, Arif Ali Khan University of Oulu
10:15
15m
Talk
An Empirical Study of Challenges for Developing Global Cybersecurity Culture
SSE-26 Workshop on Software Security Engineering
Nisar Muhammad , Siffat Ullah Khan University of Malakand, Mahmood Niazi King Fahd University of Petroleum and Minerals, Mohammad Shameem
10:30
30m
Break
Coffee Break
SSE-26 Workshop on Software Security Engineering

11:00
15m
Talk
Pick and Sort for Graphical Authentication
SSE-26 Workshop on Software Security Engineering
Argianto Rahartomo TU Clausthal, Amirhossein Jamshidipoor , Mohammad Ghafari Tehran Institute for Advanced Studies (TEIAS)
11:15
15m
Talk
Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy
SSE-26 Workshop on Software Security Engineering
Petru-Liviu Bouruc , Ciprian Păduraru University of Bucharest, Alin Stefanescu The Institute for Logic and Data Science (ILDS), and University of Bucharest
11:30
15m
Talk
Empirical Evaluation of TLS Communication Overhead in Federated Learning Systems
SSE-26 Workshop on Software Security Engineering
11:45
15m
Talk
Understanding Security Issues in Open-Source Agentic AI Frameworks: An Empirical Analysis
SSE-26 Workshop on Software Security Engineering
Muhammad Hamza Lappeenranta-Lahti University of Technology (LUT), Muhammad Azeem Akbar LUT University, Wardah Naeem Awan LUT University, Muhammad Shoaib

Unscheduled Events

Not scheduled
Talk
Advanced Explainable AI for IoT Intrusion Detection
SSE-26 Workshop on Software Security Engineering

Accepted Papers

Title
Advanced Explainable AI for IoT Intrusion Detection
SSE-26 Workshop on Software Security Engineering
A Multi-Agentic AI Pipeline for Iterative Vulnerability Detection and Auto-Remediation in Python
SSE-26 Workshop on Software Security Engineering
An Empirical Security Evaluation of LLM-Generated Cryptographic Rust Code
SSE-26 Workshop on Software Security Engineering
An Empirical Study of Challenges for Developing Global Cybersecurity Culture
SSE-26 Workshop on Software Security Engineering
Empirical Evaluation of TLS Communication Overhead in Federated Learning Systems
SSE-26 Workshop on Software Security Engineering
Low-Code Paradox in DevOps: Security and Governance Insights from Practitioners
SSE-26 Workshop on Software Security Engineering
Pick and Sort for Graphical Authentication
SSE-26 Workshop on Software Security Engineering
Runtime Governance of Agent Actions in Agentic AI: Design and Evaluation of a Governance Proxy
SSE-26 Workshop on Software Security Engineering
Symbolic Execution Meets Multi-LLM Orchestration: Detecting Memory Vulnerabilities in Incomplete Rust CVE Snippets
SSE-26 Workshop on Software Security Engineering
Understanding Security Issues in Open-Source Agentic AI Frameworks: An Empirical Analysis
SSE-26 Workshop on Software Security Engineering

Call for Papers

https://softwareengineeringresearch.net/SSE26/CfP_SSE26.pdf

This workshop aspires to provide an opportunity for the empirical software engineering researchers and practitioners to present the state of the art, state of the practice, and the future directions on the following topics of software security:

  • Systematic literature reviews and mapping studies on software security
  • Tertiary studies on software security
  • Empirically based decision making
  • Controlled experiments and quasi-experiments on software security
  • Case studies, surveys, observational studies, Delphi studies, and field studies on software security
  • Empirical studies on software security using qualitative, quantitative, and mixed methods
  • Evaluation of software security techniques, tools, and models
  • Secure software requirements
  • Secure software design
  • Secure software coding
  • Secure software testing
  • Secure software acceptance
  • Secure software deployment, operations, and maintenance
  • Secure software acquisition
  • Project management for secure software development
  • Software security in global projects
  • Best practices and lessons learned in secure software development projects
  • Secure software metrics
  • Insider threats

Submission Guidelines

Workshop proceedings will be integrated with the EASE 2025 conference companion proceedings. Submitted papers must be written in English, contain original unpublished work, and conform to the ACM proceedings format. Please submit manuscripts via EasyChair, the link is:

https://easychair.org/conferences?conf=securesoftware26