{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T08:49:05Z","timestamp":1782204545237,"version":"3.54.5"},"reference-count":65,"publisher":"Springer Science and Business Media LLC","issue":"5","license":[{"start":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T00:00:00Z","timestamp":1777507200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T00:00:00Z","timestamp":1777507200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100004410","name":"T\u00fcrkiye Bilimsel ve Teknolojik Ara\u015ft\u0131rma Kurumu","doi-asserted-by":"publisher","award":["2211-National Graduate Scholarship Program"],"award-info":[{"award-number":["2211-National Graduate Scholarship Program"]}],"id":[{"id":"10.13039\/501100004410","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1007\/s10664-026-10854-y","type":"journal-article","created":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T09:57:55Z","timestamp":1777543075000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Implicit security requirements classification with large language models using the OWASP application security verification standard: a shift-left approach"],"prefix":"10.1007","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6634-5229","authenticated-orcid":false,"given":"Yusuf","family":"G\u00fcr","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7387-8621","authenticated-orcid":false,"given":"Tu\u011fba Ta\u015fkaya","family":"Temizel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4917-192X","authenticated-orcid":false,"given":"Banu G\u00fcnel","family":"K\u0131l\u0131\u00e7","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,4,30]]},"reference":[{"key":"10854_CR1","doi-asserted-by":"publisher","unstructured":"Abbasi MA, Ihantola P, Mikkonen T, M\u00e4kitalo N (2025) Towards Human-AI synergy in requirements engineering: A framework and preliminary study. In: 2025 Sixth International Conference on Intelligent Data Science Technologies and Applications (IDSTA), pp 81\u201388. https:\/\/doi.org\/10.1109\/IDSTA66210.2025.11202850","DOI":"10.1109\/IDSTA66210.2025.11202850"},{"key":"10854_CR2","doi-asserted-by":"publisher","unstructured":"Aghaei E, Niu X, Shadid W, Al-Shaer E (2023) SecureBERT: A domain-specific language model for cybersecurity. Secur Priv Commun Netw 39\u201356. https:\/\/doi.org\/10.1007\/978-3-031-25538-0_3","DOI":"10.1007\/978-3-031-25538-0_3"},{"issue":"10","key":"10854_CR3","doi-asserted-by":"publisher","first-page":"429","DOI":"10.3390\/computers14100429","volume":"14","author":"JA Alam","year":"2025","unstructured":"Alam JA, Ayman M, Rehman GA, Sarlan AB et al (2025) Security requirements engineering: A review and analysis. Computers 14(10):429. https:\/\/doi.org\/10.3390\/computers14100429","journal-title":"Computers"},{"issue":"17","key":"10854_CR4","doi-asserted-by":"publisher","first-page":"3594","DOI":"10.3390\/electronics12173594","volume":"12","author":"R Andrade","year":"2023","unstructured":"Andrade R, Torres J, Ortiz-Garc\u00e9s I, Mi\u00f1o J, Almeida L (2023) An exploratory study gathering security requirements for the software development process. Electronics 12(17):3594. https:\/\/doi.org\/10.3390\/electronics12173594","journal-title":"Electronics"},{"issue":"11","key":"10854_CR5","doi-asserted-by":"publisher","first-page":"8963","DOI":"10.1007\/s13369-019-04067-3","volume":"44","author":"MN Anwar Mohammad","year":"2019","unstructured":"Anwar Mohammad MN, Nazir M, Mustafa K (2019) A systematic review and analytical evaluation of security requirements engineering approaches. Arab J Sci Eng 44(11):8963\u20138987. https:\/\/doi.org\/10.1007\/s13369-019-04067-3","journal-title":"Arab J Sci Eng"},{"key":"10854_CR6","doi-asserted-by":"publisher","unstructured":"Batool R, Naseer A, Maqbool A, Kayani M (2025) Automated categorization of software security requirements: An NLP and ML based approach. Requirements Eng 1\u201313. https:\/\/doi.org\/10.1007\/s00766-025-00443-8","DOI":"10.1007\/s00766-025-00443-8"},{"issue":"4","key":"10854_CR7","doi-asserted-by":"publisher","first-page":"699","DOI":"10.1162\/COLIa00074","volume":"37","author":"PS Bayerl","year":"2011","unstructured":"Bayerl PS, Paul KI (2011) What determines inter-coder agreement in manual annotations? a meta-analytic investigation. Comput Linguist 37(4):699\u2013725. https:\/\/doi.org\/10.1162\/COLIa00074","journal-title":"Comput Linguist"},{"issue":"10","key":"10854_CR8","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/s10462-024-10902-3","volume":"57","author":"F Bolanos","year":"2024","unstructured":"Bolanos F, Salatino A, Osborne F, Motta E (2024) Artificial intelligence for literature reviews: Opportunities and challenges. Artif Intell Rev 57(10):259. https:\/\/doi.org\/10.1007\/s10462-024-10902-3","journal-title":"Artif Intell Rev"},{"key":"10854_CR9","unstructured":"Brown TB, Mann B, Ryder N, Subbiah M, Kaplan J, Dhariwal P, Amodei D (2020) Language models are few-shot learners. arXiv: 2005.14165 [cs.CL]"},{"key":"10854_CR10","unstructured":"Christodoulopoulos C, Chakraborty T, Rose C, Peng V (Eds) (2025) In: Proceedings of the 2025 conference on empirical methods in natural language processing. Association for Computational Linguistics"},{"key":"10854_CR11","doi-asserted-by":"crossref","unstructured":"Cohen KB, Fox L, Ogren P, Hunter L (2005) Corpus design for biomedical natural language processing. In: Proceedings of the ACL-ISMB workshop on linking biological literature, ontologies and databases: mining biological semantics, pp 38\u201345","DOI":"10.3115\/1641484.1641490"},{"key":"10854_CR12","unstructured":"Comanici G et al (2025) Gemini 2.5: Pushing the frontier with advanced reasoning, multimodality, long context, and next generation agentic capabilities. arXiv: 2507. 06261 [cs.CL]"},{"key":"10854_CR13","doi-asserted-by":"publisher","unstructured":"Dalpiaz F, Dell\u2019Anna D, Aydemir FB, \u00c7evikol S (2019) Requirements classification with interpretable machine learning and dependency parsing. In: 2019 IEEE 27th international requirements engineering conference (RE), pp 142\u2013152. https:\/\/doi.org\/10.1109\/RE.2019.00025","DOI":"10.1109\/RE.2019.00025"},{"key":"10854_CR14","unstructured":"DeepSeek-AI, Liu A, Feng B, Wang B, Wang B, Liu B, Xie Z (2024) Deepseek-v2: A strong, economical, and efficient mixture-of-experts language model. arXiv: 2405.04434 [cs.CL]"},{"key":"10854_CR15","doi-asserted-by":"publisher","unstructured":"Dekhtyar A, Fong V (2017) Re data challenge: Requirements identification with word2vec and tensorflow. In: 2017 IEEE 25th International Requirements Engineering Conference (RE), pp 484\u2013489. https:\/\/doi.org\/10.1109\/RE.2017.26","DOI":"10.1109\/RE.2017.26"},{"key":"10854_CR16","first-page":"1","volume":"7","author":"J Dem\u0161ar","year":"2006","unstructured":"Dem\u0161ar J (2006) Statistical comparisons of classifiers over multiple data sets. J Mach Learn Res 7:1\u201330","journal-title":"J Mach Learn Res"},{"key":"10854_CR17","doi-asserted-by":"publisher","unstructured":"Devlin J, Chang M-W, Lee K, Toutanova K (2019) BERT: Pretraining of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers), pp 4171\u20134186. https:\/\/doi.org\/10.18653\/v1\/N19-1423","DOI":"10.18653\/v1\/N19-1423"},{"key":"10854_CR18","unstructured":"DGSSI (2024) Application security verification framework. Retrieved from https:\/\/www.dgssi.gov.ma\/en\/publications\/application-security-verification-framework. Accessed 08 Dec 2025"},{"key":"10854_CR19","unstructured":"Grattafiori A, Dubey A, Jauhri A, Pandey A, Kadian A, Al-Dahle A, Ma Z (2024) The llama 3 herd of models. arXiv: 2407.21783 [cs.AI]"},{"key":"10854_CR20","doi-asserted-by":"publisher","unstructured":"Hey T, Keim J, Koziolek A, Tichy WF (2020) NoRBERT: Transfer learning for requirements classification. In: 2020 IEEE 28th international requirements engineering conference (RE), pp 169\u2013179. https:\/\/doi.org\/10.1109\/RE48521.2020.00028","DOI":"10.1109\/RE48521.2020.00028"},{"issue":"1","key":"10854_CR21","doi-asserted-by":"publisher","first-page":"93","DOI":"10.13088\/jiis.2024.30.1.093","volume":"30","author":"C Jeong","year":"2024","unstructured":"Jeong C (2024) Domain-specialized LLM: Financial fine-tuning and utilization method using mistral 7b. J Intell Inf Syst 30(1):93\u2013120. https:\/\/doi.org\/10.13088\/jiis.2024.30.1.093","journal-title":"J Intell Inf Syst"},{"key":"10854_CR22","unstructured":"JIT.io (2024) How to use OWASP ASVS to protect web applications. Retrieved from https:\/\/www.jit.io\/resources\/securitystandards\/owasp-asvs-to-protect-web-applications. Accessed 08 Dec 2025"},{"key":"10854_CR23","doi-asserted-by":"publisher","unstructured":"Jindal R, Malhotra R, Jain A (2016) Automated classification of security requirements. In: 2016 International conference on advances in computing, communications and informatics (ICACCI), pp 2027\u20132033. https:\/\/doi.org\/10.1109\/ICACCI.2016.7732349","DOI":"10.1109\/ICACCI.2016.7732349"},{"key":"10854_CR24","doi-asserted-by":"publisher","first-page":"e01496","DOI":"10.1016\/j.sciaf.2022.e01496","volume":"19","author":"P Kadebu","year":"2023","unstructured":"Kadebu P, Sikka S, Tyagi RK, Chiurunge P (2023) A classification approach for software requirements towards maintainable security. Sci African 19:e01496. https:\/\/doi.org\/10.1016\/j.sciaf.2022.e01496","journal-title":"Sci African"},{"key":"10854_CR25","unstructured":"Karhu K, Kasurinen J, Smolander K (2025) Expectations vs ereality\u2013a secondary study on AI adoption in software testing. arXiv preprint arXiv:2504.04921"},{"issue":"6","key":"10854_CR26","doi-asserted-by":"publisher","first-page":"97","DOI":"10.1109\/MS.2025.3572561","volume":"42","author":"F Karlsson","year":"2025","unstructured":"Karlsson F, Chatzipetrou P, Gao S, Havstorm TE (2025) How reliable are GPT-4o and LLAMA3.3-70B in classifying natural language requirements?: The impact of the temperature setting. IEEE Softw 42(6):97\u2013104. https:\/\/doi.org\/10.1109\/MS.2025.3572561","journal-title":"IEEE Softw"},{"key":"10854_CR27","doi-asserted-by":"publisher","unstructured":"Khan R, McLaughlin K, Laverty D, Sezer S (2017) Stride-based threat modeling for cyber-physical systems. In: 2017 IEEE PES innovative smart grid technologies conference Europe (ISGT-Europe), pp 1\u20136. https:\/\/doi.org\/10.1109\/ISGTEurope.2017.8260283","DOI":"10.1109\/ISGTEurope.2017.8260283"},{"issue":"5","key":"10854_CR28","doi-asserted-by":"publisher","first-page":"e2594","DOI":"10.1002\/smr.2594","volume":"36","author":"RA Khan","year":"2024","unstructured":"Khan RA, Akbar MA, Rafi S, Almagrabi AO, Alzahrani M (2024) Evaluation of requirement engineering best practices for secure software development in GSD: An ISM analysis. J Softw Evol Process 36(5):e2594. https:\/\/doi.org\/10.1002\/smr.2594","journal-title":"J Softw Evol Process"},{"key":"10854_CR29","doi-asserted-by":"publisher","unstructured":"Knauss E, Houmb S, Schneider K, Islam S, J\u00fcrjens J (2011) Supporting requirements engineers in recognising security issues. Int Working Conf Requirements Eng Found Softw Qual 4\u201318. https:\/\/doi.org\/10.1007\/978-3-642-19858-8_2","DOI":"10.1007\/978-3-642-19858-8_2"},{"key":"10854_CR30","doi-asserted-by":"crossref","unstructured":"Labrak Y, Rouvier M, Dufour R (2024) A zero-shot and few-shot study of instruction-finetuned large language models applied to clinical and biomedical tasks. In: Calzolari N, Kan M-Y, Hoste V, Lenci A, Sakti S, Xue N (eds) Proceedings of the 2024 joint international conference on computational linguistics, language resources and evaluation (lrec-coling 2024) pp 2049\u20132066. Torino, Italia: ELRA and ICCL. Retrieved from https:\/\/aclanthology.org\/2024.lrec-main.185\/","DOI":"10.63317\/2fcovvb4zao3"},{"key":"10854_CR31","doi-asserted-by":"publisher","unstructured":"Lima M, Valle V, Costa E, Lira F, Gadelha B (2019) Software engineering repositories: Expanding the promise database. In: Proceedings of the XXXIII Brazilian symposium on software engineering, pp 427\u2013436. https:\/\/doi.org\/10.1145\/3350768.33507","DOI":"10.1145\/3350768.33507"},{"issue":"9","key":"10854_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3560815","volume":"55","author":"P Liu","year":"2023","unstructured":"Liu P, Yuan W, Fu J, Jiang Z, Hayashi H, Neubig G (2023) Pretrain, prompt, and predict: A systematic survey of prompting methods in natural language processing. ACM Comput Surv 55(9):1\u201335. https:\/\/doi.org\/10.1145\/3560815","journal-title":"ACM Comput Surv"},{"issue":"3","key":"10854_CR33","doi-asserted-by":"publisher","first-page":"105","DOI":"10.1007\/s10664-025-10641-1","volume":"30","author":"Z Liu","year":"2025","unstructured":"Liu Z, Wang H, Xu T, Wang B (2025) RAG-driven multiple assertions generation with large language models. Empir Softw Eng 30(3):105. https:\/\/doi.org\/10.1007\/s10664-025-10641-1","journal-title":"Empir Softw Eng"},{"key":"10854_CR34","unstructured":"Loshchilov I, Hutter F (2019) Decoupled weight decay regularization. International Conference on Learning Representations. Retrieved from https:\/\/openreview.net\/forum?id=Bkg6RiCqY7"},{"key":"10854_CR35","doi-asserted-by":"publisher","unstructured":"\u0141ukasiewicz K, Cyga\u0144ska S (2019) Security-oriented agile approach with AgileSafe and OWASP ASVS. In: 2019 Federated conference on computer science and information systems (FedCSIS) pp 875\u2013878. https:\/\/doi.org\/10.15439\/2019F213","DOI":"10.15439\/2019F213"},{"key":"10854_CR36","doi-asserted-by":"publisher","unstructured":"Masoudifard A, Sorond MM, Madadi M, Sabokrou M, Habibi E (2024) Leveraging Graph-RAG and prompt engineering to enhance LLMbased automated requirement traceability and compliance checks. https:\/\/doi.org\/10.48550\/arXiv.2412.08593","DOI":"10.48550\/arXiv.2412.08593"},{"key":"10854_CR37","doi-asserted-by":"publisher","unstructured":"Maturi MH, Cruz EDL, Addula SR, Yadulla AR, Ravindran RK, Nadella GS, Meduri K (2025) Enhancing smart contract security with explainable AI: A framework for re-entrancy vulnerability detection and explanation. In: 2025 Systems and Information Engineering Design Symposium (SIEDS), pp 386\u2013391. https:\/\/doi.org\/10.1109\/SIEDS65500.2025.11021147","DOI":"10.1109\/SIEDS65500.2025.11021147"},{"key":"10854_CR38","unstructured":"National Security Agency (2002) Common criteria for information technology security evaluation. National Security Agency"},{"issue":"18","key":"10854_CR39","doi-asserted-by":"publisher","first-page":"3758","DOI":"10.3390\/electronics13183758","volume":"13","author":"S-C Necula","year":"2024","unstructured":"Necula S-C, Fotache D, Rieder E (2024) Assessing the impact of artificial intelligence tools on employee productivity: Insights from a comprehensive survey analysis. Electronics 13(18):3758. https:\/\/doi.org\/10.3390\/electronics13183758","journal-title":"Electronics"},{"key":"10854_CR40","unstructured":"OpenAI (2025) GPT-4o mini: Advancing cost-effective intelligence. Retrieved from https:\/\/openai.com\/index\/gpt-4o-mini-advancing-costeffective-intelligence\/"},{"key":"10854_CR41","unstructured":"Pustejovsky J, Stubbs A (2012) Natural language annotation for machine learning: A guide to corpus-building for applications. \u201cO\u2019Reilly Media, Inc.\u201d"},{"key":"10854_CR42","doi-asserted-by":"publisher","unstructured":"Rajbhoj A, Somase A, Kulkarni P, Kulkarni V (2024) Accelerating software development using generative AI: ChatGPT case study. In: Proceedings of the 17th innovations in software engineering conference, pp 1\u201311. https:\/\/doi.org\/10.1145\/3641399.3641403","DOI":"10.1145\/3641399.3641403"},{"key":"10854_CR43","unstructured":"Reqview (2016) OWASP application security verification standard (ASVS) template. Retrieved from https:\/\/www.reqview.com\/doc\/asvs-template\/. Accessed 08 Dec 2025"},{"key":"10854_CR44","doi-asserted-by":"publisher","unstructured":"Riaz M, Williams L (2012) Security requirements patterns: Understanding the science behind the art of pattern writing. 2012 Second IEEE international workshop on requirements patterns (RePa), pp 29\u201334. https:\/\/doi.org\/10.1109\/RePa.2012.6359977","DOI":"10.1109\/RePa.2012.6359977"},{"key":"10854_CR45","doi-asserted-by":"publisher","unstructured":"Riaz M, King J, Slankas J, Williams L (2014) Hidden in plain sight: Automatically identifying security requirements from natural language artifacts. In: 2014 IEEE 22nd international requirements engineering conference (RE), pp 183\u2013192. https:\/\/doi.org\/10.1109\/RE.2014.6912260","DOI":"10.1109\/RE.2014.6912260"},{"key":"10854_CR46","doi-asserted-by":"publisher","unstructured":"Ronanki K, Cabrero-Daniel B, Horkoff J, Berger C (2024) Requirements engineering using generative AI: Prompts and prompting patterns. In: Generative AI for effective software development, pp 109\u2013127. https:\/\/doi.org\/10.1007\/978-3-031-55642-55","DOI":"10.1007\/978-3-031-55642-55"},{"issue":"1","key":"10854_CR47","doi-asserted-by":"publisher","first-page":"22","DOI":"10.30564\/jcsr.v4i1.4271","volume":"4","author":"S Schmeelk","year":"2022","unstructured":"Schmeelk S, Tao L (2022) A case study of mobile health applications: The OWASP risk of insufficient cryptography. J Comput Sci Res 4(1):22\u201331","journal-title":"J Comput Sci Res"},{"key":"10854_CR48","doi-asserted-by":"publisher","unstructured":"Schweter S (2020) BERTurk - BERT models for Turkish (Version v2). https:\/\/doi.org\/10.5281\/zenodo.3770924","DOI":"10.5281\/zenodo.3770924"},{"key":"10854_CR49","doi-asserted-by":"publisher","first-page":"159439","DOI":"10.1109\/ACCESS.2025.3607813","volume":"13","author":"M Shafikuzzaman","year":"2025","unstructured":"Shafikuzzaman M, Islam MR, Zaman S, Ma A, Islam Sifat A (2025) On the effectiveness of zero-shot and few-shot pretrained language models for software requirement classification. IEEE Access 13:159439\u2013159453. https:\/\/doi.org\/10.1109\/ACCESS.2025.3607813","journal-title":"IEEE Access"},{"key":"10854_CR50","unstructured":"Sommerville I, Sawyer P (1997) Requirements engineering: A good practice guide. John Wiley & Sons, Inc"},{"key":"10854_CR51","doi-asserted-by":"publisher","unstructured":"Souppaya M, Scarfone K, Dodson D (2022) Secure software development framework (ssdf) version 1.1. NIST Spec Publ 800(218):800\u2013218. https:\/\/doi.org\/10.6028\/NIST.SP.800-218","DOI":"10.6028\/NIST.SP.800-218"},{"key":"10854_CR52","doi-asserted-by":"publisher","first-page":"103001","DOI":"10.1109\/ACCESS.2023.3317798","volume":"11","author":"AF Subahi","year":"2023","unstructured":"Subahi AF (2023) BERT-based approach for greening software requirements engineering through non-functional requirements. IEEE Access 11:103001\u2013103013. https:\/\/doi.org\/10.1109\/ACCESS.2023.3317798","journal-title":"IEEE Access"},{"key":"10854_CR53","doi-asserted-by":"publisher","unstructured":"Tan V, Cheh C, Chen B (2021) From application security verification standard (asvs) to regulation compliance: A case study in financial services sector. In: 2021 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW), pp 69\u201376. https:\/\/doi.org\/10.1109\/ISSREW53611.2021.00046","DOI":"10.1109\/ISSREW53611.2021.00046"},{"key":"10854_CR54","unstructured":"Team G, Anil R, Borgeaud S, Alayrac J-B, Yu J, Soricut R, Millican K, et al (2023). Gemini: A family of highly capable multimodal models. arXiv preprint arXiv:2312.11805"},{"key":"10854_CR55","unstructured":"Team G, Kamath A, Ferret J, Pathak S, Vieillard N, Merhej R, Hussenot L (2025) Gemma 3 technical report. arXiv:2503.19786 [cs.CL]"},{"key":"10854_CR56","doi-asserted-by":"publisher","unstructured":"Villamizar H, Kalinowski M, Viana M, Fern\u00e1ndez DM (2018) A systematic mapping study on security in agile requirements engineering. In: 2018 44th Euromicro conference on software engineering and advanced applications (SEAA), pp 454\u2013461. https:\/\/doi.org\/10.1109\/SEAA.2018.00080","DOI":"10.1109\/SEAA.2018.00080"},{"issue":"7","key":"10854_CR57","doi-asserted-by":"publisher","first-page":"2300798","DOI":"10.1002\/aisy.202300798","volume":"6","author":"F Wang","year":"2024","unstructured":"Wang F, Harker A, Edirisinghe M, Parhizkar M (2024) Tackling data scarcity challenge through active learning in materials processing with electrospray. Adv Intell Syst 6(7):2300798. https:\/\/doi.org\/10.1002\/aisy.202300798","journal-title":"Adv Intell Syst"},{"key":"10854_CR58","doi-asserted-by":"publisher","unstructured":"Wei J, Tay Y, Bommasani R, Raffel C, Zoph B, Borgeaud S, Fedus W (2022). Emergent abilities of large language models. https:\/\/doi.org\/10.48550\/arXiv.2206.07682","DOI":"10.48550\/arXiv.2206.07682"},{"key":"10854_CR59","doi-asserted-by":"publisher","first-page":"103532","DOI":"10.1016\/j.cose.2023.103532","volume":"135","author":"S-F Wen","year":"2023","unstructured":"Wen S-F, Katt B (2023) A quantitative security evaluation and analysis model for web applications based on OWASP application security verification standard. Comput Secur 135:103532. https:\/\/doi.org\/10.1016\/j.cose.2023.103532","journal-title":"Comput Secur"},{"key":"10854_CR60","doi-asserted-by":"publisher","unstructured":"White J, Hays S, Fu Q, Spencer-Smith J, Schmidt DC (2024) ChatGPT prompt patterns for improving code quality, refactoring, requirements elicitation, and software design. In: Generative AI for effective software development, pp 71\u2013108. https:\/\/doi.org\/10.1007\/978-3-031-55642-54","DOI":"10.1007\/978-3-031-55642-54"},{"key":"10854_CR61","doi-asserted-by":"publisher","unstructured":"Wu T, Wang Y, Quach N (2025) Advancements in natural language processing: Exploring transformer-based architectures for text understanding. In: 2025 5th International Conference on Artificial Intelligence and Industrial Technology Applications (AIITA), pp 1384\u20131388. https:\/\/doi.org\/10.1109\/AIITA65135.2025.11048063","DOI":"10.1109\/AIITA65135.2025.11048063"},{"key":"10854_CR62","doi-asserted-by":"publisher","unstructured":"Ye J, Yao Z, Huang Z, Pan L, Liu J, Bai Y, Hou L et al (2025) How do transformers learn implicit reasoning? https:\/\/doi.org\/10.48550\/arXiv.2505.23653","DOI":"10.48550\/arXiv.2505.23653"},{"key":"10854_CR63","unstructured":"Zadenoori MA, Dabrowski J, Alhoshan W, Zhao L, Ferrari A (2025) Large language models for requirements engineering: A systematic literature review. arXiv preprint arXiv:2509.11446"},{"issue":"1","key":"10854_CR64","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1109\/JAS.2024.124983","volume":"12","author":"W Zhou","year":"2025","unstructured":"Zhou W, Zhu X, Han Q-L, Li L, Chen X, Wen S, Xiang Y (2025) The security of using large language models: A survey with emphasis on ChatGPT. IEEE\/CAA J Autom Sinica 12(1):1\u201326. https:\/\/doi.org\/10.1109\/JAS.2024.124983","journal-title":"IEEE\/CAA J Autom Sinica"},{"issue":"2","key":"10854_CR65","doi-asserted-by":"publisher","first-page":"317","DOI":"10.1109\/JAS.2024.124971","volume":"12","author":"X Zhu","year":"2025","unstructured":"Zhu X, Zhou W, Han Q-L, Ma W, Wen S, Xiang Y (2025) When software security meets large language nodels: A survey. IEEE\/CAA J Autom Sinica 12(2):317\u2013334. https:\/\/doi.org\/10.1109\/JAS.2024.124971","journal-title":"IEEE\/CAA J Autom Sinica"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10854-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-026-10854-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10854-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,23]],"date-time":"2026-06-23T08:08:57Z","timestamp":1782202137000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-026-10854-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,30]]},"references-count":65,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2026,9]]}},"alternative-id":["10854"],"URL":"https:\/\/doi.org\/10.1007\/s10664-026-10854-y","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,4,30]]},"assertion":[{"value":"18 August 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 March 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 April 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This study did not involve human participants, clinical trials, or personal data, and therefore did not require formal approval from an institutional ethics committee. The subject matter experts contributed solely in their professional capacity to the annotation process.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}},{"value":"Informed consent was not applicable as no human participants were involved. The subject matter experts participated in their professional capacity and provided voluntary contributions.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Informed Consent"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest\/Competing Interests"}},{"value":"Not applicable.","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Clinical Trial Number"}}],"article-number":"130"}}