Program

Date Time Event
March 4, 2025
Polytechnique Montréal, Montréal
9:00 - 9:10 Welcome Message and Opening Remarks
9:10 - 10:00 Keynote
Emad Shihab | Concordia University, Montréal, Canada

Emad Shihab is an Full Professor and Concordia University Research Chair in the Department of Computer Science and Software Engineering at Concordia University. His research interests are in software engineering, mining software repositories, and software analytics. His work has been published in some of the most prestigious SE venues, including ICSE, ESEC/FSE, MSR, ICSME, EMSE, and TSE. He serves on the steering committees of PROMISE, SANER, and MSR, three of the leading conferences in areas of software analytics. His work has been done in collaboration with and adopted by some of the biggest software companies, such as Microsoft, Avaya, BlackBerry, Ericsson, and National Bank. He is a senior member of the IEEE.


On the Use of LLMs in the Presence of Software Dependencies

The use of LLMs is transforming software engineering. In many aspects of SE, using LLMs has shown tremendous improvements. One area where LLMs struggle is in the suggestion and management of software dependencies. In this talk, I will present some work that highlights the challenges of using LLMs when software dependencies are involved. I will also present some of the reasons LLMs tend to struggle with software dependencies and suggest potential solutions to address these challenges.


10:00 - 10:30 Paper Session #1 — 2 papers
  • 10:00-10:10 — "Usability of Static Application Security Testing Workflows", Bhagya Chembakottu and Martin P. Robillard
  • 10:10-10:30 — "Malicious and Unintentional Disclosure Risks in Large Language Models for Code Generation", Rafiqul Rabin, Sean McGregor and Nick Judd
10:30 - 11:00 Coffee Break
11:00 - 12:00 Paper Session #2 — 3 papers
  • 11:00-11:20 — "Impact of Identifier Normalization on Vulnerability Detection Techniques", Torge Hinrichs, Tim Diercks and Riccardo Scandariato
  • 11:20-11:40 — "SBOM Generation Tools and Formats Affect Compliance with US Standard", Redempta Manzi Muneza, Aidan Keefe, Eric O'Donoghue, Clemente Izurieta, Ann Marie Reinhold
  • 11:40-12:00 — "Links Between Package Popularity, Criticality, and Security in Software Ecosystems", Alexis Butler and Dan O'Keeffe
12:00 - 12:10 Closing