MSR 2026
Mon 13 - Tue 14 April 2026 Rio de Janeiro, Brazil
co-located with ICSE 2026

This program is tentative and subject to change.

Tue 14 Apr 2026 11:20 - 11:30 at Oceania V - Session 1-A: AI & Autonomous Agents Chair(s): Filipe Cogo

Large Language Model (LLM) - based Automated Program Repair (APR) systems are increasingly integrated into modern software development workflows, offering automated patches in response to natural language bug reports. However, this reliance on untrusted user input introduces a novel and underexplored attack surface. In this paper, we investigate the security risks posed by adversarial bug reports—realistic-looking issue submissions crafted to mislead APR systems into producing insecure or harmful code changes. We develop a comprehensive threat model and conduct an empirical study to evaluate the vulnerability of state-of-the-art APR systems to such attacks. Our demonstration comprises 51 adversarial bug reports generated across a spectrum of strategies, from manual curation to fully automated pipelines. We test these against leading APR model and assess both pre-repair defenses (e.g., LlamaGuard variants, PromptGuard variants, Granite-Guardian, and custom LLM filters) and post-repair detectors (GitHub Copilot, CodeQL). Our findings show that current defenses are insufficient: 90% of crafted bug reports triggered attacker-aligned patches. The best pre-repair filter blocked only 47%, while post-repair analysis—often requiring human oversight—was effective in just 58% of cases. To support scalable security testing, we introduce a prototype framework for automating the generation of adversarial bug reports. Our analysis exposes a structural asymmetry: generating adversarial inputs is inexpensive, while detecting or mitigating them remains costly and error-prone. We conclude with practical recommendations for improving the robustness of APR systems against adversarial misuse and highlight directions for future work on trustworthy automated repair.

This program is tentative and subject to change.

Tue 14 Apr

Displayed time zone: Brasilia, Distrito Federal, Brazil change

11:00 - 12:30
Session 1-A: AI & Autonomous AgentsTechnical Papers / MSR Program at Oceania V
Chair(s): Filipe Cogo Centre for Software Excellence, Huawei Canada
11:00
10m
Talk
Speed at the Cost of Quality: How Cursor AI Increases Short-Term Velocity and Long-Term Complexity in Open-Source Projects
Technical Papers
Hao He Carnegie Mellon University, Courtney Miller Carnegie Mellon University, Shyam Agarwal Carnegie Mellon University, Christian Kästner Carnegie Mellon University, Bogdan Vasilescu Carnegie Mellon University
Pre-print Media Attached
11:10
10m
Talk
LLM-Based Detection of Tangled Code Changes for Higher-Quality Method-Level Bug Datasets
Technical Papers
Md Nahidul Islam Opu University of Manitoba, Shaowei Wang University of Manitoba, Shaiful Chowdhury University of Manitoba
Pre-print
11:20
10m
Talk
Adversarial Bug Reports as a Security Risk in Language Model-Based Automated Program Repair
Technical Papers
Piotr Przymus Nicolaus Copernicus University in Toruń, Poland, Andreas Happe TU Wien, Jürgen Cito TU Wien
Pre-print
11:30
10m
Talk
Investigating Autonomous Agent Contributions in the Wild: Activity Patterns and Code Change over Time
Technical Papers
Răzvan Mihai Popescu Delft University of Technology, David Gros University of California, Davis, Andrei Botocan Delft University of Technology, Rahul Pandita GitHub, Inc., Prem Devanbu University of California at Davis, Mali Izadi TU Delft
11:40
10m
Talk
Evaluating the Use of LLMs for Automated DOM-Level Resolution of Web Performance Issues
Technical Papers
Gideon Peters Concordia University, SayedHassan Khatoonabadi Concordia University, Emad Shihab Concordia University
11:50
10m
Talk
Are Coding Agents Generating Over-Mocked Tests? An Empirical Study
Technical Papers
Andre Hora UFMG, Romain Robbes CNRS, LaBRI, University of Bordeaux
Pre-print Media Attached
12:00
10m
Talk
Consistent or Sensitive? Automated Code Revision Tools Against Semantics-Preserving Perturbations
Technical Papers
Shirin Pirouzkhah University of Zurich, Souhaila Serbout University of Zurich, Zurich, Switzerland, Alberto Bacchelli IfI, University of Zurich
Pre-print
12:10
10m
Talk
Beyond the Prompt: An Empirical Study of Cursor Rules
Technical Papers
Shaokang Jiang University of California, Irvine, Daye Nam University of California, Irvine
Pre-print
12:20
10m
Talk
Bridging Design and Implementation: A Study of Multi-Agent LLM Architectures for Automated Front-End Generation
Technical Papers
Caren Rizk Concordia University, SayedHassan Khatoonabadi Concordia University, Emad Shihab Concordia University
Hide past events