Score
Designs and implements analyses, mappings, and isolation techniques that detect, trace, and classify the mechanisms by which components become part of a system. Produces component inclusion maps across the development lifecycle, identifies sources that introduce components, and exposes ambiguous or latent inclusion cases.
Current research on the security of LLM-agent systems remains fragmented, lacking a unified framework to explain the common root causes and propagation mechanisms underlying failures such as prompt injection and tool misuse. This work establishes *isolation* as a first-class principle for system security and introduces a boundary-centric taxonomy comprising five boundary types: user–agent, agent–tool, agent–execution, agent–agent, and system–environment. By systematically modeling failure pathways and defense strategies through structured review and cross-domain analysis, the study reveals that security failures predominantly originate from insufficient isolation and follow distinct cross-boundary attack propagation patterns. The paper thus provides a cohesive theoretical foundation and a construction-oriented research agenda centered on isolation for designing highly secure agent systems.
This study addresses the limitations of current AI auditing practices, which predominantly focus on individual models while overlooking integration risks arising from interactions among system components and between systems and their environments. Through a scoping review and reflexive thematic analysis of 58 studies, the work systematically codes existing literature to delineate, for the first time, three distinct domains of AI integration auditing: inter-component, system–environment, and multi-system. It further introduces domain-specific evaluation dimensions—compatibility, completeness, and oversight—that capture unique aspects of integrated AI systems. The findings reveal that current auditing practices remain fragmented and nascent, underscoring the critical role of accessible information and resource support in effective audit design. The paper calls for novel auditing frameworks capable of spanning components, environments, and systems to enable systematic exploration, identification, coordination, and standardization of integration-related risks.
Current Software Bill of Materials (SBOM) tools struggle to comprehensively identify security vulnerabilities due to the absence of a unified standard for component identification, thereby jeopardizing software supply chain security. This work introduces the Component Introduction Mechanism (CIM) analysis framework—the first of its kind—to systematically evaluate the component detection capabilities of cdxgen, syft, trivy, ORT, and Microsoft’s sbom-tool across real-world projects in six programming languages: Python, Java, Go, PHP, Rust, and C. The study reveals that existing tools commonly suffer from incomplete CIM coverage, ambiguous component definitions, and shared blind spots, leading to significant ambiguities and omissions in generated SBOMs. These findings underscore the urgent need for community-wide consensus on component identification and provide an empirical foundation and strategic guidance for developing more reliable SBOM technologies.
This work addresses the inherent limitations of individual program analysis techniques—particularly their constrained precision, coverage, and insight—which hinder comprehensive software reliability assurance. Through a systematic mapping study of 248 relevant publications, the paper presents the first taxonomy of combined program analysis approaches explicitly centered on synergistic effects and interaction patterns. The proposed multidimensional classification framework is structured around three core dimensions: collaboration objectives, workflow architectures, and types of mapping functions. This framework systematically uncovers commonalities and distinctions in the design of existing methods, offering a clear conceptual foundation for understanding, comparing, and developing novel combined analysis techniques. Furthermore, it delineates current research trends and identifies promising directions for future investigation.
This study addresses the inaccuracies inherent in Software Bill of Materials (SBOMs) when characterizing component identities and actual dependencies, particularly their inability to reliably capture code-level hidden dependencies and consistently identify component variants. These limitations lead to inconsistencies between vulnerability reports and Vulnerability Exploitability eXchange (VEX) statements. Through SBOM-driven software composition analysis, evaluation using multiple vulnerability scanners, and consistency checks of VEX assertions, the work systematically reveals significant discrepancies and shortcomings among current mainstream SBOM generation tools in handling these challenges. The findings underscore the need for enhanced mechanisms for dependency representation and component identification, offering critical directions for improving the reliability of vulnerability management practices.
This study addresses the challenge of quantifying the complexity and cost induced by external requirement changes when detailed knowledge of a system’s internal logic is unavailable. To this end, the authors propose a black-box assessment method based on a directed graph of component coupling. By analyzing component interfaces and integrating multi-view modeling—graphical, algebraic, and tabular—the approach uniquely links interface characteristics to cost factors, enabling computable bounded estimates of change-induced complexity and associated costs. The method was validated through a large-scale integration case in a retail banking platform, demonstrating its effectiveness and providing architects and operations teams with actionable, quantitative insights for system design and maintenance.
This study addresses the lack of systematic, large-scale analyses of structural properties in software feature models, which has hindered the understanding and evolution of variability models. For the first time, it systematically applies large-scale network analysis to 5,709 variability models drawn from 20 repositories. By constructing graphs capturing transitive dependencies and conflicts among features, and integrating graph modeling with network-theoretic and statistical analyses, the work uncovers cross-domain structural commonalities—such as dependency dominance, high centralization, and characteristic degree distributions—as well as domain-specific deviations. These findings provide novel empirical insights and a foundation for identifying pivotal features, guiding modular decomposition, and assessing structural fragility in variability-intensive systems.
This work addresses the inefficiency and lack of guidance faced by front-end developers when manually selecting plausible and natural attribute values for instantiating reusable UI components within a vast design space. To tackle this challenge, the paper introduces the concept of “discriminative variants,” which uniquely integrates symbolic reasoning with large language models (LLMs). Symbolic reasoning identifies visually salient attributes, while the LLM leverages real-world knowledge to generate component instances that balance fidelity to exemplars with meaningful differentiation. This approach shifts the paradigm from ad hoc manual configuration to structured exploration of the design space. A user study (n=12) demonstrates that the generated variants effectively aid developers in comprehending the design space, significantly improving both instantiation efficiency and user experience, while maintaining strong domain relevance.
This work addresses the inefficiency and steep learning curve researchers often encounter when trying to map academic papers to their corresponding implementation code. To bridge this gap, the authors propose an automated tool powered by large language models (LLMs) that achieves cross-modal semantic alignment between scholarly texts and source code for the first time. By integrating program analysis techniques, the method automatically identifies code segments that implement specific research ideas described in a paper and generates high-quality traceability mappings. This approach substantially reduces the manual effort required for alignment, enhances the comprehensibility of research software, and improves reproducibility. Preliminary experiments demonstrate the tool’s practicality and effectiveness in real-world scenarios.
This study addresses the widespread yet often insecure integration of AI components into software systems, which frequently overlooks critical security risks and can lead to malicious behaviors or data breaches. Through semi-structured interviews with 22 industry practitioners, the work systematically uncovers a pervasive neglect of security considerations during AI component selection and integration, revealing that functional performance overwhelmingly dominates decision-making while security is rarely evaluated. Drawing on established practices from traditional software supply chain security, the paper adapts and extends these principles to the AI context, proposing a set of lifecycle-spanning security-by-design guidelines. It further offers actionable recommendations tailored for developers, model providers, and researchers to foster more secure AI integration practices.
This work addresses the lack of end-to-end traceability from high-level models to generated code in Model-Driven Engineering (MDE) by proposing the ProMoTA framework. ProMoTA unifies the entire modeling and code generation process—spanning platform-independent models, platform-specific models, and final code—through megamodels and model transformation chains. The framework innovatively extends the Acceleo language to support fine-grained local traceability and, for the first time, enables comprehensive global traceability mapping and analysis across the full MDE lifecycle. Implemented on the Eclipse platform, ProMoTA’s effectiveness in facilitating end-to-end traceability analysis is empirically validated through a case study in wireless sensor network-based Internet of Things applications.