{"id":3058,"date":"2026-04-27T08:13:20","date_gmt":"2026-04-27T11:13:20","guid":{"rendered":"https:\/\/sites.usp.br\/icem\/?page_id=3058"},"modified":"2026-08-27T12:55:46","modified_gmt":"2026-08-27T15:55:46","slug":"aisecdev-cbsoft-2026","status":"publish","type":"page","link":"https:\/\/sites.usp.br\/icem\/aisecdev-cbsoft-2026\/","title":{"rendered":"AISecDev-CBSoft-2026"},"content":{"rendered":"<h1>AISecDev 2026<\/h1>\n<h2>Secure Software Development in the Age of AI<\/h2>\n<p><a href=\"https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-scaled.png\"><img fetchpriority=\"high\" decoding=\"async\" class=\"alignnone size-full wp-image-3071\" src=\"https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-scaled.png\" alt=\"\" width=\"2560\" height=\"818\" srcset=\"https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-scaled.png 2560w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-300x96.png 300w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-1024x327.png 1024w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-768x245.png 768w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-1536x491.png 1536w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-2048x654.png 2048w, https:\/\/sites.usp.br\/icem\/wp-content\/uploads\/sites\/1618\/2026\/04\/cidade-universitaria-roda-gigante-400x128.png 400w\" sizes=\"(max-width: 2560px) 100vw, 2560px\" \/><\/a><\/p>\n<p><strong>AISecDev 2026<\/strong> is a workshop co-located with <a href=\"https:\/\/cbsoft.sbc.org.br\/2026\/\"><strong>CBSoft 2026<\/strong><\/a>, dedicated to the emerging security challenges introduced by AI-assisted software development, large language models, and autonomous code generation tools.<\/p>\n<p>The workshop will take place on <strong>September 8, 2026<\/strong>, at <a href=\"https:\/\/www.ime.usp.br\/\"><strong>IME-USP, S\u00e3o Paulo, Brazil<\/strong><\/a>.<\/p>\n<hr \/>\n<h2>About<\/h2>\n<p>Software is no longer only written \u2014 it is increasingly generated. AI-based programming assistants and autonomous code generation tools are changing how software is designed, implemented, tested, and maintained.<\/p>\n<p>Development workflows are shifting from writing and maintaining stable code artifacts to producing software through specifications, prompts, and AI agents. In this new setting, each execution may generate a different program, raising new concerns for security, traceability, auditing, certification, and trustworthy deployment.<\/p>\n<p>AISecDev aims to bring together researchers and practitioners to discuss how software security is affected by AI-assisted development, including emerging industry practices, new threat models such as prompt injection and agent misuse, and the broader implications of ephemeral generated code.<\/p>\n<hr \/>\n<h2>Topics of Interest<\/h2>\n<p>Topics of interest include, but are not limited to:<\/p>\n<ul>\n<li>Security challenges introduced by AI-assisted programming and LLM-generated code.<\/li>\n<li>Secure Software Development Lifecycle (SSDLC) and DevSecOps practices with generative AI.<\/li>\n<li>Ephemeral, dynamically generated, and prompt-driven software.<\/li>\n<li>Traceability, testing, verification, and reproducibility of AI-generated code.<\/li>\n<li>Threat models and attacks involving AI agents.<\/li>\n<li>Prompt injection, data exfiltration, agent misuse, and supply-chain risks.<\/li>\n<li>Analysis, auditing, and certification of AI-generated software.<\/li>\n<li>Vulnerability detection and formal verification.<\/li>\n<li>Privacy, governance, compliance, and industrial experience reports.<\/li>\n<\/ul>\n<hr \/>\n<h2>Submission<\/h2>\n<p>AISecDev welcomes submissions that promote interaction, discussion, and community building between researchers and practitioners working on the security implications of AI-assisted software development.<\/p>\n<p>We invite the following types of contributions:<\/p>\n<ul>\n<li>Research papers<\/li>\n<li>Position papers<\/li>\n<li>Experience reports<\/li>\n<li>Tool demonstrations<\/li>\n<li>Work-in-progress papers<\/li>\n<li>Extended abstracts<\/li>\n<li>Short summaries of recently published results relevant to the workshop theme<\/li>\n<\/ul>\n<p>Submissions should clearly explain their implications for secure software development in the context of AI-generated or AI-assisted software.<\/p>\n<p class=\"justified\">The works should be submited as <strong>Short Papers (max 4 pages including references)<\/strong>.\u00a0 Papers may be submitted in Portuguese or English and must be uploaded in PDF format via the <a href=\"https:\/\/jems3.sbc.org.br\/events\/655\">JEMS<\/a>\u00a0system. The conference template is available on Overleaf and also as a ZIP package (please see below). Authors may use either version, but all submissions must strictly follow the official CBSoft 2026 template. Although this template is adapted from the ACM conference format, authors must not use the original ACM_SigConf template. The same adapted template is used across all symposia and workshops co-located with CBSoft 2026.<\/p>\n<ul>\n<li>Overleaf template:\u00a0<a href=\"https:\/\/www.overleaf.com\/read\/cyhpwwkngcwk#baf5f5\">https:\/\/www.overleaf.com\/read\/cyhpwwkngcwk#baf5f5<\/a><\/li>\n<li>ZIP Package:\u00a0<a href=\"https:\/\/cbsoft.sbc.org.br\/2026\/Template_para_eventos_do_CBSoft.zip\">https:\/\/cbsoft.sbc.org.br\/2026\/Template_para_eventos_do_CBSoft.zip<\/a><\/li>\n<\/ul>\n<hr \/>\n<h2>Reviewing Process<\/h2>\n<p>Submissions will be evaluated by the Program Committee, which may also invite external reviewers when appropriate. Rather than focusing solely on novelty, the review process will consider:<\/p>\n<ul>\n<li>Relevance to the workshop theme<\/li>\n<li>Clarity of presentation<\/li>\n<li>Potential to stimulate discussion and exchange of ideas<\/li>\n<li>Interest to the research and practitioner community<\/li>\n<\/ul>\n<p>The workshop aims to promote interaction and community building rather than serve primarily as a competitive publication venue.<\/p>\n<hr \/>\n<h2>Important Dates<\/h2>\n<ul>\n<li><strong>Paper registration:<\/strong> July 3, 2026<\/li>\n<li><strong>Paper submission:<\/strong> <strong>July 13, 2026 (UPDATED!)<\/strong><\/li>\n<li><strong>Author notification:<\/strong> August 3, 2026<\/li>\n<li><strong>Camera-ready:<\/strong> August 10, 2026<\/li>\n<li><strong>Workshop date:<\/strong> September 8, 2026<\/li>\n<\/ul>\n<hr \/>\n<h2 id=\"program\">Program<\/h2>\n<table>\n<thead>\n<tr>\n<th>Time<\/th>\n<th>Session<\/th>\n<th>Description<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>11h-12h30<\/td>\n<td><strong>Paper Session 1<\/strong><\/td>\n<td>Short presentations followed by group interaction.<\/p>\n<table width=\"1264\">\n<tbody>\n<tr>\n<td width=\"832\">Exploring security requirements specification supported by LLM: Results of an exploratory study with entry-level software engineers<\/td>\n<td width=\"432\">Am\u00e1lia Melo\u00a0(USP,\u00a0Brazil)<br \/>\nMarcelo Conti\u00a0(USP, Brazil)<br \/>\nLina Garc\u00e9s\u00a0\u00a0(ICMC\/USP,\u00a0Brazil)<\/td>\n<\/tr>\n<tr>\n<td>Lineage-Aware Security for AI-Assisted Software Development<\/td>\n<td width=\"432\">Rafael Ara\u00fajo Rodrigues\u00a0\u00a0(PUCRS,\u00a0Brazil)<br \/>\nAvelino Francisco Zorzo\u00a0\u00a0(PUCRS,\u00a0Brazil)<br \/>\n\u00c9lder Rodrigues\u00a0\u00a0(UNIPAMPA,\u00a0Brazil)<br \/>\nLauren Silva Rolan Sampaio\u00a0\u00a0(HP,\u00a0Brazil)<\/td>\n<\/tr>\n<tr>\n<td>Investigating the use of LLMs for Addressing Injection Vulnerabilities.<\/td>\n<td width=\"432\">Pedro Pinto\u00a0\u00a0(USP,\u00a0Brazil)<br \/>\nLina Garc\u00e9s\u00a0(ICMC \/USP,\u00a0Brazil)<br \/>\nCarolina Gomes Guerreiro\u00a0\u00a0(USP,\u00a0Brazil)<\/td>\n<\/tr>\n<tr>\n<td>Trojans in Financial Code Generated by LLMs: Empirical Evaluation with PAIR<\/td>\n<td width=\"432\">Ygor Maria\u00a0\u00a0(POLI\/USP,\u00a0Brazil)<br \/>\nVictor Takashi Hayashi\u00a0\u00a0(USP,\u00a0Brazil)<br \/>\nMarcos Antonio Simplicio Jr\u00a0(USP,\u00a0Brazil)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<tr>\n<td>12:30-14h<\/td>\n<td><strong>Lunch<\/strong><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>14:00\u201316h<\/td>\n<td><strong>Panel Discussion<\/strong><\/td>\n<td>Broad discussion on AI, security, and software development, with invited<br \/>\nspeakers from industry and academia.<\/p>\n<ul>\n<li>Ben\u00edcio Goulart (Motorola)<\/li>\n<li>Lucas Boscaini (Google)<\/li>\n<li>Ricardo Ribani (HP)<\/li>\n<li>Rodolfo Azevedo (UNICAMP)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td>16:30\u201318:00<\/td>\n<td><strong>Paper Session 2<\/strong><\/td>\n<td>Short presentations followed by group interaction.<\/p>\n<table width=\"1264\">\n<tbody>\n<tr>\n<td width=\"832\">Using Concept Drift Detection as an Operational Indicator of Compromise for Continuous Security Monitoring<\/td>\n<td width=\"432\">Jane Piantoni\u00a0(UNICAMP,\u00a0Brazil)<\/td>\n<\/tr>\n<tr>\n<td>A Multi-Layered Architecture for Microservices with Self-Protection Properties<\/td>\n<td width=\"432\">Vin\u00edcius Santos\u00a0(USP,\u00a0Brazil)<br \/>\nLina Garc\u00e9s\u00a0\u00a0(ICMC\/USP, Brazil)<\/td>\n<\/tr>\n<tr>\n<td>SecContext-Fin: Structuring LLM-Based Red\/Blue Security Tools for the Secure Software Development Lifecycle<\/td>\n<td width=\"432\">Juka Gon\u00e7alves\u00a0(UFLA,\u00a0Brazil)<br \/>\nMaria J\u00falia Pedroso Pimenta\u00a0\u00a0(UFLA,\u00a0Brazil)<br \/>\nBento Rafael Siqueira\u00a0\u00a0(UFLA,\u00a0Brazil)<br \/>\nSamira Santos da Silva\u00a0\u00a0(UFLA,\u00a0Brazil)<br \/>\nDiego Saqui\u00a0\u00a0(UFLA,\u00a0Brazil)<br \/>\nAlysson Naves Silva\u00a0\u00a0(UFLA,\u00a0Brazil)<\/td>\n<\/tr>\n<tr>\n<td>Security architectural pattern recommendation in a RAG-based assistant: Results of an LLM-as-a-judge evaluation<\/td>\n<td width=\"432\">Rebeca Pontes\u00a0\u00a0(ICMC\/USP,\u00a0Brazil)<br \/>\nLina Garc\u00e9s\u00a0(ICMC\/USP,\u00a0Brazil)<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<hr \/>\n<h2>Organizing Committee<\/h2>\n<ul>\n<li>Avelino Francisco Zorzo, PUCRS<\/li>\n<li>Cassio Berra, HP<\/li>\n<li>Lucas Boscaini, Google<\/li>\n<li>Roberto Marcondes Cesar Junior, IME-USP<\/li>\n<\/ul>\n<hr \/>\n<h2>Program Committee<\/h2>\n<ul>\n<li>Avelino Francisco Zorzo, PUCRS<\/li>\n<li>Cassio Berra, HP<\/li>\n<li>Elder Macedo Rodrigues, Unipampa<\/li>\n<li>Lucas Boscaini, Google<\/li>\n<li>Michele Nogueira, UFMG<\/li>\n<li>Rafael C. Cardoso, University of Aberdeen, UK<\/li>\n<li>Ricardo Iramar dos Santos, HP<\/li>\n<li>Roberto Marcondes Cesar Junior, IME-USP<\/li>\n<li>Regio Michelin, InDebted, Australia<\/li>\n<\/ul>\n<hr \/>\n<h2>Workshop Coordinators<\/h2>\n<p><strong>Avelino Francisco Zorzo<\/strong><br \/>\nPUCRS<br \/>\n<a href=\"mailto:avelino.zorzo@pucrs.br\">avelino.zorzo@pucrs.br<\/a><\/p>\n<p><strong>Roberto Marcondes Cesar Junior<\/strong><br \/>\nIME-USP<br \/>\n<a href=\"mailto:mcesar@usp.br\">mcesar@usp.br<\/a><\/p>\n<hr \/>\n<h2>Venue<\/h2>\n<p>AISecDev 2026 will be held at the <a href=\"https:\/\/www.ime.usp.br\/\"><strong>Institute of Mathematics, Statistics and Computer Science, University of S\u00e3o Paulo<\/strong><\/a>, in S\u00e3o Paulo, Brazil.<\/p>\n<p>This Workshop is an initiative promoted by <a href=\"https:\/\/inct-simai.com.br\/\">INCT SiMAI (CNPq)<\/a>, <a href=\"https:\/\/sites.usp.br\/synestechai\/\">SYNESTEC.AI (Softex\/MCTI\/Motorola),<\/a> <a href=\"https:\/\/www.ime.usp.br\/ime-usp-e-destaque-na-america-latina-em-premiacao-do-google-academic-research-award-2025\/\">GARA Google<\/a> and <a href=\"https:\/\/sites.usp.br\/icem\/iamai-inteligencia-artificial-para-matematica-e-aprendizado-inovador\/\">CCD IAMAI (FAPESP \/ SEDUC SP)<\/a>. More information about the venue and the conference will be available on the official CBSoft 2026 website.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AISecDev 2026 Secure Software Development in the Age of AI AISecDev 2026 is a workshop co-located with CBSoft 2026, dedicated to the emerging security challenges introduced by AI-assisted software development,<a href=\"https:\/\/sites.usp.br\/icem\/aisecdev-cbsoft-2026\/\">[&#8230;]<\/a><\/p>\n","protected":false},"author":22247,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"template-fullwidth-no-title.php","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":"","_links_to":"","_links_to_target":""},"class_list":["post-3058","page","type-page","status-publish","hentry"],"_links":{"self":[{"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/pages\/3058","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/users\/22247"}],"replies":[{"embeddable":true,"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/comments?post=3058"}],"version-history":[{"count":5,"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/pages\/3058\/revisions"}],"predecessor-version":[{"id":3140,"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/pages\/3058\/revisions\/3140"}],"wp:attachment":[{"href":"https:\/\/sites.usp.br\/icem\/wp-json\/wp\/v2\/media?parent=3058"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}