Gianluca Filippone, Sara Pettinari, Patrizio Pelliccione
{"title":"Formalisms for Robotic Mission Specification and Execution: A Comparative Analysis","authors":"Gianluca Filippone, Sara Pettinari, Patrizio Pelliccione","doi":"10.1109/tse.2026.3725356","DOIUrl":"https://doi.org/10.1109/tse.2026.3725356","url":null,"abstract":"","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"67 1","pages":""},"PeriodicalIF":7.4,"publicationDate":"2026-08-21","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148806420","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Guodong Fan, Cuiyun Gao, Chun Yong Chong, Lu Zhang, Jing Li, Jinglin Zhang, Shizha Chen
{"title":"When Model Editing Meets Service Evolution: A Knowledge-Update Perspective for Service Recommendation","authors":"Guodong Fan, Cuiyun Gao, Chun Yong Chong, Lu Zhang, Jing Li, Jinglin Zhang, Shizha Chen","doi":"10.1109/tse.2026.3724627","DOIUrl":"https://doi.org/10.1109/tse.2026.3724627","url":null,"abstract":"","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"2 1 1","pages":"1-17"},"PeriodicalIF":7.4,"publicationDate":"2026-08-17","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148755975","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Antonio Della Porta, Stefano Lambiase, Valeria Pontillo, Joao F. Ferreira, Akond A. Rahman, Chaiyong Ragkhitwetsagul, Fabio Palomba
{"title":"Understanding Prompt Quality and Its Relation to LLM-based Code Generation","authors":"Antonio Della Porta, Stefano Lambiase, Valeria Pontillo, Joao F. Ferreira, Akond A. Rahman, Chaiyong Ragkhitwetsagul, Fabio Palomba","doi":"10.1109/tse.2026.3719766","DOIUrl":"https://doi.org/10.1109/tse.2026.3719766","url":null,"abstract":"","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"275 1","pages":""},"PeriodicalIF":7.4,"publicationDate":"2026-08-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148682216","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
Qiong Feng, Xiaotian Ma, Jiayi Sheng, Huan Ji, Peng Liang
{"title":"An Empirical Study of Kotlin-Java Cross-Dependency Issues and Their Detection","authors":"Qiong Feng, Xiaotian Ma, Jiayi Sheng, Huan Ji, Peng Liang","doi":"10.1109/tse.2026.3719845","DOIUrl":"https://doi.org/10.1109/tse.2026.3719845","url":null,"abstract":"","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"31 5 1","pages":""},"PeriodicalIF":7.4,"publicationDate":"2026-08-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148682230","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"EffiReasonTrans: RL-Optimized Reasoning for Code Translation","authors":"Yanlin Wang;Rongyi Ou;Yanli Wang;Mingwei Liu;Jiachi Chen;Ensheng Shi;Xilin Liu;Yuchi Ma;Zibin Zheng","doi":"10.1109/TSE.2026.3693795","DOIUrl":"10.1109/TSE.2026.3693795","url":null,"abstract":"Code translation is a crucial task in software development and maintenance. While recent advancements in Large Language Models (LLMs) have improved automated code translation accuracy, these gains often come at the cost of increased inference latency—hindering real-world development workflows that involve human-in-the-loop inspection. To address this trade-off, we propose EffiReasonTrans, a training framework designed to improve translation accuracy while balancing inference latency. We first construct a high-quality reasoning-augmented dataset by prompting a stronger language model DeepSeek-R1 to generate intermediate reasoning and target translations. Each (source code, reasoning, target code) triplet undergoes automated syntax and functionality checks to ensure reliability. Based on this dataset, we employ a two-stage training strategy: supervised fine-tuning on reasoning-augmented samples, followed by reinforcement learning to further enhance accuracy, which also helps balance inference latency. We evaluate EffiReasonTrans on six translation pairs. Experimental results show that EffiReasonTrans consistently improves translation accuracy (up to +49.2% CA and +27.8% CodeBLEU compared to the base model), while reducing the number of generated tokens (up to -19.3%) and lowering inference latency in most cases (up to -29.0%). Ablation studies further confirm the complementary benefits of the two-stage training framework. Additionally, EffiReasonTrans shows improvements of translation accuracy when integrated into agent-based frameworks. Our code and data are available at <uri>https://github.com/DeepSoftwareAnalytics/EffiReasonTrans</uri>.","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"52 8","pages":"2354-2366"},"PeriodicalIF":6.0,"publicationDate":"2026-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148291572","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"RuleDroid: LLM-Augmented Synthesis of Static Security Detection Rules for Android Apps","authors":"Zhentao Xie;Mingyang Chen;Yaqi Gao;Shishuai Yang;Wenrui Diao;Xiangyu Liu;Kehuan Zhang","doi":"10.1109/TSE.2026.3700217","DOIUrl":"10.1109/TSE.2026.3700217","url":null,"abstract":"Android’s vast ecosystem and expansive API surfaces pose a serious challenge to static application security testing (SAST) tools. Mainstream tools such as MobSF, APKHunt, and AUSERA mainly rely on manually crafted rules. Crafting these rules demands considerable effort, yet they still cannot cover every security issue. When Android introduces new APIs, changes its permission model, or revises other security policies, the rules soon fall behind. Without constant maintenance, false positives grow, and true vulnerabilities slip through. Recently released LLM-based detectors are easy to use and potentially support a wide range of vulnerability types, but their findings often lack clear explanations and suffer from high false-positive rates. In this paper, we present <sc>RuleDroid</small>, a new framework that leverages LLMs to automatically generate Semgrep-compatible static detection rules from up-to-date official Android security documentation. <sc>RuleDroid</small> tackles the limits of pure LLM detection by combining (i) <bold>Retrieval-Augmented Generation (RAG)</b>, which grounds model outputs in trusted documents, and (ii) a modular <bold>workflow</b> that decomposes rule synthesis into well-defined stages. The resulting rules are then applied with proven static-analysis techniques, ensuring consistent and explainable results. We evaluated <sc>RuleDroid</small> on three public benchmark datasets. Based on its large and precise rule set, <sc>RuleDroid</small> achieved higher coverage and accuracy than traditional SAST tools, and sharply reduced false positives compared with direct LLM scanning. When applied to real-world apps, <sc>RuleDroid</small> discovered multiple new vulnerabilities, resulting in 57 CVE IDs being assigned. These results show that <sc>RuleDroid</small> combines the broad vulnerability coverage of LLMs with the precision of static analysis, delivering a fully automated docs-to-rules solution for Android security testing.","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"52 8","pages":"2488-2506"},"PeriodicalIF":6.0,"publicationDate":"2026-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148288706","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}
{"title":"TIF: Learning Temporal Invariance in Android Malware Detectors","authors":"Xinran Zheng;Shuo Yang;Edith C.-H. Ngai;Suman Jana;Lorenzo Cavallaro","doi":"10.1109/TSE.2026.3698484","DOIUrl":"10.1109/TSE.2026.3698484","url":null,"abstract":"Learning-based Android malware detectors degrade over time due to natural distribution drift caused by malware variants and new families. This paper systematically investigates the challenges classifiers trained with empirical risk minimization (ERM) face against such distribution shifts and attributes their shortcomings to their inability to learn <italic>stable</i> discriminative features. Invariant learning theory offers a promising solution by encouraging models to generate stable representations across environments that expose the instability of the training set. However, the lack of prior environment labels, the diversity of drift factors, and low-quality representations caused by diverse families make this task challenging. To address these issues, we propose TIF, the first temporal invariant training framework for malware detection, which aims to enhance the ability of detectors to learn stable representations across time. TIF organizes environments based on application observation dates to reveal temporal drift, integrating specialized multi-proxy contrastive learning and invariant gradient alignment to generate and align environments with high-quality, stable representations. TIF can be seamlessly integrated into any learning-based detector. Experiments on a decade-long dataset show that TIF excels, particularly in early deployment stages, addressing real-world needs and outperforming state-of-the-art methods.","PeriodicalId":13324,"journal":{"name":"IEEE Transactions on Software Engineering","volume":"52 8","pages":"2463-2474"},"PeriodicalIF":6.0,"publicationDate":"2026-08-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":null,"resultStr":null,"platform":"Semanticscholar","paperid":"148288734","PeriodicalName":null,"FirstCategoryId":null,"ListUrlMain":null,"RegionNum":1,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":"","EPubDate":null,"PubModel":null,"JCR":null,"JCRName":null,"Score":null,"Total":0}