AISecDev 2026

Secure Software Development in the Age of AI

AISecDev 2026 is a workshop co-located with CBSoft 2026, dedicated to the emerging security challenges introduced by AI-assisted software development, large language models, and autonomous code generation tools.

The workshop will take place on September 8, 2026, at IME-USP, São Paulo, Brazil.


About

Software is no longer only written — it is increasingly generated. AI-based programming assistants and autonomous code generation tools are changing how software is designed, implemented, tested, and maintained.

Development workflows are shifting from writing and maintaining stable code artifacts to producing software through specifications, prompts, and AI agents. In this new setting, each execution may generate a different program, raising new concerns for security, traceability, auditing, certification, and trustworthy deployment.

AISecDev aims to bring together researchers and practitioners to discuss how software security is affected by AI-assisted development, including emerging industry practices, new threat models such as prompt injection and agent misuse, and the broader implications of ephemeral generated code.


Topics of Interest

Topics of interest include, but are not limited to:

  • Security challenges introduced by AI-assisted programming and LLM-generated code.
  • Secure Software Development Lifecycle (SSDLC) and DevSecOps practices with generative AI.
  • Ephemeral, dynamically generated, and prompt-driven software.
  • Traceability, testing, verification, and reproducibility of AI-generated code.
  • Threat models and attacks involving AI agents.
  • Prompt injection, data exfiltration, agent misuse, and supply-chain risks.
  • Analysis, auditing, and certification of AI-generated software.
  • Vulnerability detection and formal verification.
  • Privacy, governance, compliance, and industrial experience reports.

Submission

AISecDev welcomes submissions that promote interaction, discussion, and community building between researchers and practitioners working on the security implications of AI-assisted software development.

We invite the following types of contributions:

  • Research papers
  • Position papers
  • Experience reports
  • Tool demonstrations
  • Work-in-progress papers
  • Extended abstracts
  • Short summaries of recently published results relevant to the workshop theme

Submissions should clearly explain their implications for secure software development in the context of AI-generated or AI-assisted software.

The works should be submited as Short Papers (max 4 pages including references).  Papers may be submitted in Portuguese or English and must be uploaded in PDF format via the JEMS system. The conference template is available on Overleaf and also as a ZIP package (please see below). Authors may use either version, but all submissions must strictly follow the official CBSoft 2026 template. Although this template is adapted from the ACM conference format, authors must not use the original ACM_SigConf template. The same adapted template is used across all symposia and workshops co-located with CBSoft 2026.


Reviewing Process

Submissions will be evaluated by the Program Committee, which may also invite external reviewers when appropriate. Rather than focusing solely on novelty, the review process will consider:

  • Relevance to the workshop theme
  • Clarity of presentation
  • Potential to stimulate discussion and exchange of ideas
  • Interest to the research and practitioner community

The workshop aims to promote interaction and community building rather than serve primarily as a competitive publication venue.


Important Dates

  • Paper registration: July 3, 2026
  • Paper submission: July 13, 2026 (UPDATED!)
  • Author notification: August 3, 2026
  • Camera-ready: August 10, 2026
  • Workshop date: September 8, 2026

Program

Time Session Description
11h-12h30 Paper Session 1 Short presentations followed by group interaction.

Exploring security requirements specification supported by LLM: Results of an exploratory study with entry-level software engineers Amália Melo (USP, Brazil)
Marcelo Conti (USP, Brazil)
Lina Garcés  (ICMC/USP, Brazil)
Lineage-Aware Security for AI-Assisted Software Development Rafael Araújo Rodrigues  (PUCRS, Brazil)
Avelino Francisco Zorzo  (PUCRS, Brazil)
Élder Rodrigues  (UNIPAMPA, Brazil)
Lauren Silva Rolan Sampaio  (HP, Brazil)
Investigating the use of LLMs for Addressing Injection Vulnerabilities. Pedro Pinto  (USP, Brazil)
Lina Garcés (ICMC /USP, Brazil)
Carolina Gomes Guerreiro  (USP, Brazil)
Trojans in Financial Code Generated by LLMs: Empirical Evaluation with PAIR Ygor Maria  (POLI/USP, Brazil)
Victor Takashi Hayashi  (USP, Brazil)
Marcos Antonio Simplicio Jr (USP, Brazil)
12:30-14h Lunch
14:00–16h Panel Discussion Broad discussion on AI, security, and software development, with invited
speakers from industry and academia.

  • Benício Goulart (Motorola)
  • Lucas Boscaini (Google)
  • Ricardo Ribani (HP)
  • Rodolfo Azevedo (UNICAMP)
16:30–18:00 Paper Session 2 Short presentations followed by group interaction.

Using Concept Drift Detection as an Operational Indicator of Compromise for Continuous Security Monitoring Jane Piantoni (UNICAMP, Brazil)
A Multi-Layered Architecture for Microservices with Self-Protection Properties Vinícius Santos (USP, Brazil)
Lina Garcés  (ICMC/USP, Brazil)
SecContext-Fin: Structuring LLM-Based Red/Blue Security Tools for the Secure Software Development Lifecycle Juka Gonçalves (UFLA, Brazil)
Maria Júlia Pedroso Pimenta  (UFLA, Brazil)
Bento Rafael Siqueira  (UFLA, Brazil)
Samira Santos da Silva  (UFLA, Brazil)
Diego Saqui  (UFLA, Brazil)
Alysson Naves Silva  (UFLA, Brazil)
Security architectural pattern recommendation in a RAG-based assistant: Results of an LLM-as-a-judge evaluation Rebeca Pontes  (ICMC/USP, Brazil)
Lina Garcés (ICMC/USP, Brazil)

 


Organizing Committee

  • Avelino Francisco Zorzo, PUCRS
  • Cassio Berra, HP
  • Lucas Boscaini, Google
  • Roberto Marcondes Cesar Junior, IME-USP

Program Committee

  • Avelino Francisco Zorzo, PUCRS
  • Cassio Berra, HP
  • Elder Macedo Rodrigues, Unipampa
  • Lucas Boscaini, Google
  • Michele Nogueira, UFMG
  • Rafael C. Cardoso, University of Aberdeen, UK
  • Ricardo Iramar dos Santos, HP
  • Roberto Marcondes Cesar Junior, IME-USP
  • Regio Michelin, InDebted, Australia

Workshop Coordinators

Avelino Francisco Zorzo
PUCRS
avelino.zorzo@pucrs.br

Roberto Marcondes Cesar Junior
IME-USP
mcesar@usp.br


Venue

AISecDev 2026 will be held at the Institute of Mathematics, Statistics and Computer Science, University of São Paulo, in São Paulo, Brazil.

This Workshop is an initiative promoted by INCT SiMAI (CNPq), SYNESTEC.AI (Softex/MCTI/Motorola), GARA Google and CCD IAMAI (FAPESP / SEDUC SP). More information about the venue and the conference will be available on the official CBSoft 2026 website.