Skip to main content

SECASSURED at the International Summer School on LLM-Based Agents for Software Engineering

By September 15, 2026October 7th, 2026News

What role can LLM-based agents play in making software development more secure, efficient and trustworthy?

This question was at the centre of SECASSURED’s contribution to the 2nd International Summer School on LLM-Based Agents for Software Engineering (LLMA4SE 2026), held at the Universidad de Extremadura in Cáceres, Spain, from 9–11 September 2026. SECASSURED project partner SINTEF contributed both a lecture and a hands-on workshop to the programme.

Connecting LLM-based agents with security assurance

On 11 September, Phu Nguyen from SINTEF gave a lecture entitled “Assurance-driven security engineering and the roles of LLM-based agents.” The session explored how emerging LLM-based agent technologies can support security engineering activities and how they may contribute to more continuous and systematic security assurance throughout the software lifecycle.

This topic is closely aligned with the objectives of SECASSURED. The project develops assurance-driven approaches for designing, assessing and operating secure digital systems and services. As software systems become more complex and development processes increasingly integrate AI-based tools, new approaches are needed to help developers identify weaknesses, reason about security requirements and continuously assess whether systems remain compliant with their intended security properties.

LLM-based agents offer promising opportunities in this area. They can potentially assist software engineers by analysing code and design artefacts, detecting problematic patterns, supporting remediation activities and coordinating multiple specialised analysis tasks.

Hands-on experience with cooperative LLM agent workflows

The summer school also included a practical workshop entitled “Building Cooperative LLM Agent Workflows for Anti-pattern Detection, Code Smell and Technical Debt Resolution.”

The hands-on session was led by Adela N. Videsjorden and Karthik Shivashankar from SINTEF and demonstrated how multiple LLM-based agents can cooperate within software engineering workflows. Participants explored how such agent-based approaches can be applied to identify software anti-patterns, detect code smells and support the resolution of technical debt.

These challenges are important not only for software quality but also for cybersecurity. Poor architectural patterns, accumulated technical debt and weaknesses in software structure can make systems more difficult to maintain, analyse and secure. Improving these aspects can therefore contribute to stronger and more manageable security throughout the software lifecycle.

AI-assisted security engineering in SECASSURED

The contribution to LLMA4SE 2026 reflects SECASSURED’s broader work on continuous security assurance and AI-supported security services.

Rather than relying solely on security assessments at isolated stages of development, SECASSURED investigates how security evidence can be generated and evaluated continuously. AI-based techniques and autonomous or semi-autonomous agents can support this process by helping analyse complex systems, automate repetitive security engineering activities and assist experts in identifying and addressing potential weaknesses.

At the same time, the use of AI agents in security-critical processes also introduces important questions around reliability, explainability, trust and human oversight. Assurance-driven engineering can provide a framework for assessing not only the systems being protected, but also the AI-enabled tools used to support their development and operation.

Building bridges between research, education and practice

Participation in LLMA4SE 2026 provided SECASSURED with an opportunity to connect its research on security assurance with the rapidly evolving field of agentic AI for software engineering.

Through both the lecture and the practical workshop, participants could explore how LLM-based agents may become part of future software engineering workflows and how these capabilities can be combined with systematic security engineering practices.

The event also supported knowledge exchange between researchers, students and practitioners working at the intersection of artificial intelligence, software engineering and cybersecurity.

Many thanks to the organisers of LLMA4SE 2026 and to all participants for the valuable discussions, and to our colleagues at SINTEF for representing SECASSURED and sharing the project’s work with the community.

Leave a Reply