Publications

(2025). LLM Company Policies and Policy Implications in Software Organizations. arXiv.

(2025). Leveraging Large Language Models for Cybersecurity Risk Assessment: A Case from Forestry Cyber-Physical Systems. arXiv.

(2025). Challenges of Virtual Validation and Verification for Automotive Functions. SEAA 2025.

DOI

(2025). The Impact of Prompt Programming on Function-Level Code Generation. IEEE TSE.

DOI

(2025). The Impact of Prompt Programming on Function-Level Code Generation. IEEE Trans. Software Eng..

Cite DOI URL

(2025). LLM Company Policies and Policy Implications in Software Organizations.

Cite arXiv URL

(2025). Leveraging Large Language Models for Cybersecurity Risk Assessment -- A Case from Forestry Cyber-Physical Systems.

Cite arXiv URL

(2025). Challenges of Virtual Validation and Verification for Automotive Functions. Software Engineering and Advanced Applications, SEAA 2025.

Cite DOI URL

(2024). Guidelines for Supporting Software Engineers in Developing Secure Web Applications. PROFES 2024.

DOI

(2024). Evaluating the Role of Security Assurance Cases in Agile Medical Device Development. SEAA 2024.

DOI

(2024). Increasing the Confidence in Security Assurance Cases using Game Theory. ARES 2024.

DOI

(2024). Beyond Code Generation: An Observational Study of ChatGPT Usage in Software Engineering Practice. PACMSE / FSE 2024.

DOI

(2024). Cybersecurity Pathways Towards CE-Certified Autonomous Forestry Machines. DSN-W 2024.

DOI

(2024). Managing security evidence in safety-critical organizations. In JSS.

Cite

(2024). Managing security evidence in safety-critical organizations. Journal of Systems and Software.

Cite DOI URL

(2024). Increasing the Confidence in Security Assurance Cases using Game Theory. Proceedings of the 19th International Conference on Availability, Reliability and Security, ARES 2024.

Cite DOI URL

(2024). Guidelines for Supporting Software Engineers in Developing Secure Web Applications. Product-Focused Software Process Improvement, PROFES 2024.

Cite DOI URL

(2024). Evaluating the Role of Security Assurance Cases in Agile Medical Device Development. 50th Euromicro Conference on Software Engineering and Advanced Applications, SEAA 2024, Paris, France, August 28-30, 2024.

Cite DOI URL

(2024). Cybersecurity Pathways Towards CE-Certified Autonomous Forestry Machines. 54th Annual IEEE/IFIP International Conference on Dependable Systems and Networks, DSN 2024 - Workshops, Brisbane, Australia, June 24-27, 2024.

Cite DOI URL

(2024). Beyond Code Generation: An Observational Study of ChatGPT Usage in Software Engineering Practice. Proc. ACM Softw. Eng..

Cite DOI URL

(2023). CASCADE: An Asset-driven Approach to Build Security Assurance Cases for Automotive Systems. ACM Trans. Cyber Phys. Syst..

Cite DOI URL

(2023). CASCADE: An Asset-driven Approach to Build Security Assurance Cases for Automotive Systems. ACM TCPS.

DOI

(2022). Identifying security-related requirements in regulatory documents based on cross-project classification. PROMISE 2022.

DOI

(2022). Identifying security-related requirements in regulatory documents based on cross-project classification. Proceedings of the 18th International Conference on Predictive Models and Data Analytics in Software Engineering, PROMISE 2022, co-located with ESEC/FSE 2022.

Cite DOI URL

(2021). Security assurance cases - state of the art of an emerging approach. EMSE.

DOI

(2021). Asset-Driven Security Assurance Cases with Built-in Quality Assurance. EnCyCriS 2021.

DOI

(2021). Security assurance cases - state of the art of an emerging approach. Empir. Softw. Eng..

Cite DOI URL

(2021). Asset-Driven Security Assurance Cases with Built-in Quality Assurance. 2021 IEEE/ACM 2nd International Workshop on Engineering and Cybersecurity of Critical Systems, EnCyCriS 2021.

Cite DOI URL

(2020). Security assurance cases for road vehicles: an industry perspective. ARES 2020.

DOI

(2020). Security assurance cases for road vehicles: an industry perspective. ARES 2020: The 15th International Conference on Availability, Reliability and Security, Virtual Event, Ireland, August 25-28, 2020.

Cite DOI URL