{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T12:21:29Z","timestamp":1783513289058,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":49,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786582.3786832","type":"proceedings-article","created":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:52:47Z","timestamp":1783511567000},"page":"166-170","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["TraceCaps: Inline Provenance and Risk Enforcement for Agentic Software Engineering"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-7772-6002","authenticated-orcid":false,"given":"Andre","family":"Catarino","sequence":"first","affiliation":[{"name":"Faculty of Engineering, University of Porto, Porto, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3283-4360","authenticated-orcid":false,"given":"Claudia","family":"Mamede","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University &amp; FEUP, Pittsburgh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0009-0463","authenticated-orcid":false,"given":"Rui","family":"Melo","sequence":"additional","affiliation":[{"name":"Carnegie Mellon University &amp; FEUP, Pittsburgh, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3734-3157","authenticated-orcid":false,"given":"Rui","family":"Abreu","sequence":"additional","affiliation":[{"name":"Faculty of Engineering, University of Porto, Porto, Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,7,8]]},"reference":[{"key":"e_1_3_3_2_2_2","unstructured":"Khalid Belhajjame Reza B\u2019Far James Cheney Sam Coppens Stephen Cresswell Yolanda Gil Paul Groth Graham Klyne Timothy Lebo Jim McCusker et\u00a0al. 2013. Prov-dm: The prov data model. W3C Recommendation 14 (2013) 15\u201316."},{"key":"e_1_3_3_2_3_2","unstructured":"Islem Bouzenia Premkumar Devanbu and Michael Pradel. 2024. Repairagent: An autonomous llm-based agent for program repair. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2403.17134 (2024)."},{"key":"e_1_3_3_2_4_2","unstructured":"Sahana Chennabasappa Cyrus Nikolaidis Daniel Song David Molnar Stephanie Ding Shengye Wan Spencer Whitman Lauren Deason Nicholas Doucette Abraham Montilla et\u00a0al. 2025. Llamafirewall: An open source guardrail system for building secure ai agents. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2505.03574 (2025)."},{"key":"e_1_3_3_2_5_2","volume-title":"Elements of information theory","author":"Cover Thomas\u00a0M","year":"1999","unstructured":"Thomas\u00a0M Cover. 1999. Elements of information theory. John Wiley & Sons."},{"key":"e_1_3_3_2_6_2","unstructured":"Cursor AI Inc.2024. Cursor. https:\/\/www.cursor.sh. AI-powered code editor."},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"crossref","unstructured":"Zehang Deng Yongjian Guo Changzhou Han Wanlun Ma Junwu Xiong Sheng Wen and Yang Xiang. 2025. Ai agents under threat: A survey of key security challenges and future pathways. Comput. Surveys 57 7 (2025) 1\u201336.","DOI":"10.1145\/3716628"},{"key":"e_1_3_3_2_8_2","unstructured":"Shen Dong Shaochen Xu Pengfei He Yige Li Jiliang Tang Tianming Liu Hui Liu and Zhen Xiang. 2025. A practical memory injection attack against llm agents. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2503.03704 (2025)."},{"key":"e_1_3_3_2_9_2","volume-title":"Google\u2019s Approach for Secure AI Agents","author":"D\u00edaz Santiago\u00a0(Sal)","year":"2025","unstructured":"Santiago\u00a0(Sal) D\u00edaz, Christoph Kern, and Kara Olive. 2025. Google\u2019s Approach for Secure AI Agents. Technical Report."},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"crossref","unstructured":"Shouki\u00a0A Ebad Abdulbasit\u00a0A Darem and Jemal\u00a0H Abawajy. 2021. Measuring software obfuscation quality\u2013a systematic literature review. IEEE Access 9 (2021) 99024\u201399038.","DOI":"10.1109\/ACCESS.2021.3094517"},{"key":"e_1_3_3_2_11_2","unstructured":"GitHub Inc. and Microsoft Corporation. 2024. GitHub Copilot. https:\/\/github.com\/features\/copilot. AI-powered code completion tool."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/3605764.3623985"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","unstructured":"Stuart Haber and W.\u00a0Scott Stornetta. 1991. How to time-stamp a digital document. Journal of Cryptology 3 2 (01 Jan 1991) 99\u2013111. 10.1007\/BF00196791","DOI":"10.1007\/BF00196791"},{"key":"e_1_3_3_2_14_2","unstructured":"William Hackett Lewis Birch Stefan Trawicki Neeraj Suri and Peter Garraghan. 2025. Bypassing Prompt Injection and Jailbreak Detection in LLM Guardrails. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2504.11168 (2025)."},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"crossref","unstructured":"Ragib Hasan Radu Sion and Marianne Winslett. 2009. The Case of the Fake Picasso: Preventing History Forgery with Secure Provenance. 1\u201314.","DOI":"10.1145\/1629080.1629082"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"crossref","unstructured":"Ragib Hasan Radu Sion and Marianne Winslett. 2009. Preventing history forgery with secure provenance. ACM Transactions on Storage (TOS) 5 4 (2009) 1\u201343.","DOI":"10.1145\/1629080.1629082"},{"key":"e_1_3_3_2_17_2","unstructured":"Wenyue Hua Xianjun Yang Mingyu Jin Zelong Li Wei Cheng Ruixiang Tang and Yongfeng Zhang. 2024. Trustagent: Towards safe and trustworthy llm-based agents. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2402.01586 (2024)."},{"key":"e_1_3_3_2_18_2","unstructured":"Kush Jain Gabriel Synnaeve and Baptiste Roziere. 2024. Testgeneval: A real world unit test generation and test completion benchmark. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2410.00752 (2024)."},{"key":"e_1_3_3_2_19_2","unstructured":"Changyue Jiang Xudong Pan and Min Yang. 2025. Think Twice Before You Act: Enhancing Agent Behavioral Safety with Thought Correction. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2505.11063 (2025)."},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613892"},{"key":"e_1_3_3_2_21_2","unstructured":"Daniel Jones Giorgio Severi Martin Pouliot Gary Lopez Joris de Gruyter Santiago Zanella-Beguelin Justin Song Blake Bullwinkel Pamela Cortez and Amanda Minnich. 2025. A Systematization of Security Vulnerabilities in Computer Use Agents. arxiv:https:\/\/arXiv.org\/abs\/2507.05445\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/2507.05445"},{"key":"e_1_3_3_2_22_2","unstructured":"Yi Liu Gelei Deng Yuekang Li Kailong Wang Zihao Wang Xiaofeng Wang Tianwei Zhang Yepang Liu Haoyu Wang Yan Zheng et\u00a0al. 2023. Prompt injection attack against llm-integrated applications. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2306.05499 (2023)."},{"key":"e_1_3_3_2_23_2","unstructured":"Dan Lorenc et\u00a0al. 2021. Sigstore: Software signing for everybody. https:\/\/www.sigstore.dev."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"crossref","unstructured":"Pratyusa\u00a0K Manadhata and Jeannette\u00a0M Wing. 2010. An attack surface metric. IEEE Transactions on Software Engineering 37 3 (2010) 371\u2013386.","DOI":"10.1109\/TSE.2010.60"},{"key":"e_1_3_3_2_25_2","first-page":"80","volume-title":"Proceedings of the First International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security","author":"Meg\u00edas Alberto Jos\u00e9\u00a0Guti\u00e9rrez","year":"2024","unstructured":"Alberto Jos\u00e9\u00a0Guti\u00e9rrez Meg\u00edas, L\u00a0Alfonso\u00a0Urena Lopez, and Eugenio Mart\u00ednez-C\u00e1mara. 2024. The influence of the perplexity score in the detection of machine-generated texts. In Proceedings of the First International Conference on Natural Language Processing and Artificial Intelligence for Cyber Security. 80\u201385."},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.5555\/2994437"},{"key":"e_1_3_3_2_27_2","unstructured":"Van Nguyen Trung Le Chakkrit Tantithamthavorn Michael Fu John Grundy Hung Nguyen Seyit Camtepe Paul Quirk and Dinh Phung. 2022. Statement-Level Vulnerability Detection: Learning Vulnerability Patterns Through Information Theory and Contrastive Learning. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2209.10414 (2022)."},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"crossref","unstructured":"Bofeng Pan Natalia Stakhanova and Suprio Ray. 2023. Data provenance in security and privacy. Comput. Surveys 55 14s (2023) 1\u201335.","DOI":"10.1145\/3593294"},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3127479.3129249"},{"key":"e_1_3_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243776"},{"key":"e_1_3_3_2_31_2","unstructured":"Atharv\u00a0Singh Patlan Ashwin Hebbar Pramod Viswanath and Prateek Mittal. 2025. Context manipulation attacks : Web agents are susceptible to corrupted memory. arxiv:https:\/\/arXiv.org\/abs\/2506.17318\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/2506.17318"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991122"},{"key":"e_1_3_3_2_33_2","unstructured":"Melissa\u00a0Kazemi Rad Huy Nghiem Andy Luo Sahil Wadhwa Mohammad Sorower and Stephen Rawls. 2025. Refining input guardrails: Enhancing llm-as-a-judge efficiency through chain-of-thought fine-tuning and alignment. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2501.13080 (2025)."},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"crossref","unstructured":"Tomer Raitsis Yossi Elgazari Guy\u00a0E Toibin Yotam Lurie Shlomo Mark and Oded Margalit. 2025. Code obfuscation: A comprehensive approach to detection classification and ethical challenges. Algorithms 18 2 (2025) 54.","DOI":"10.3390\/a18020054"},{"key":"e_1_3_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/LLM4Code66737.2025.00005"},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884848"},{"key":"e_1_3_3_2_37_2","unstructured":"Baptiste Roziere Jonas Gehring Fabian Gloeckle Sten Sootla Itai Gat Xiaoqing\u00a0Ellen Tan Yossi Adi Jingyu Liu Romain Sauvestre Tal Remez et\u00a0al. 2023. Code llama: Open foundation models for code. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2308.12950 (2023)."},{"key":"e_1_3_3_2_38_2","doi-asserted-by":"crossref","unstructured":"Fred\u00a0B Schneider. 2000. Enforceable security policies. ACM Transactions on Information and System Security (TISSEC) 3 1 (2000) 30\u201350.","DOI":"10.1145\/353323.353382"},{"key":"e_1_3_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3549034.3561175"},{"key":"e_1_3_3_2_40_2","doi-asserted-by":"crossref","unstructured":"Claude\u00a0E Shannon. 2001. A mathematical theory of communication. ACM SIGMOBILE mobile computing and communications review 5 1 (2001) 3\u201355.","DOI":"10.1145\/584091.584093"},{"key":"e_1_3_3_2_41_2","volume-title":"The mathematical theory of communication","author":"Shannon Claude\u00a0E","year":"1998","unstructured":"Claude\u00a0E Shannon and Warren Weaver. 1998. The mathematical theory of communication. University of Illinois press."},{"key":"e_1_3_3_2_42_2","doi-asserted-by":"publisher","unstructured":"Robin Sommer and Vern Paxson. 2010. Outside the Closed World: On Using Machine Learning for Network Intrusion Detection. Proceedings - IEEE Symposium on Security and Privacy 305\u2013316. 10.1109\/SP.2010.25","DOI":"10.1109\/SP.2010.25"},{"key":"e_1_3_3_2_43_2","doi-asserted-by":"crossref","unstructured":"Renan Souza Amal Gueroudji Stephen DeWitt Daniel Rosendo Tirthankar Ghosal Robert Ross Prasanna Balaprakash and Rafael\u00a0Ferreira da Silva. 2025. PROV-AGENT: Unified Provenance for Tracking AI Agent Interactions in Agentic Workflows. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2508.02866 (2025).","DOI":"10.1109\/eScience65000.2025.00093"},{"key":"e_1_3_3_2_44_2","doi-asserted-by":"crossref","unstructured":"Mahzabin Tamanna Sivana Hamer Mindy Tran Sascha Fahl Yasemin Acar and Laurie Williams. 2024. Unraveling challenges with supply-chain levels for software artifacts (SLSA) for securing the software supply chain. Available at SSRN 5119626 (2024).","DOI":"10.2139\/ssrn.4979511"},{"key":"e_1_3_3_2_45_2","series-title":"(SEC\u201919)","first-page":"1393","volume-title":"Proceedings of the 28th USENIX Conference on Security Symposium","author":"Torres-Arias Santiago","year":"2019","unstructured":"Santiago Torres-Arias, Hammad Afzali, Trishank\u00a0Karthik Kuppusamy, Reza Curtmola, and Justin Cappos. 2019. In-toto: providing farm-to-table guarantees for bits and bytes. In Proceedings of the 28th USENIX Conference on Security Symposium (Santa Clara, CA, USA) (SEC\u201919). USENIX Association, USA, 1393\u20131410."},{"key":"e_1_3_3_2_46_2","unstructured":"Haoyu Wang Christopher\u00a0M Poskitt and Jun Sun. 2025. Agentspec: Customizable runtime enforcement for safe and reliable llm agents. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2503.18666 (2025)."},{"key":"e_1_3_3_2_47_2","unstructured":"Haowei Wang Rupeng Zhang Junjie Wang Mingyang Li Yuekai Huang Dandan Wang and Qing Wang. 2024. From allies to adversaries: Manipulating llm tool-calling through adversarial injection. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2412.10198 (2024)."},{"key":"e_1_3_3_2_48_2","unstructured":"Adam\u00a0Dorian Wong. 2023. Detecting Domain-Generation Algorithm (DGA) Based Fully-Qualified Domain Names (FQDNs) with Shannon Entropy. arxiv:https:\/\/arXiv.org\/abs\/2304.07943\u00a0[cs.CR] https:\/\/arxiv.org\/abs\/2304.07943"},{"key":"e_1_3_3_2_49_2","doi-asserted-by":"crossref","unstructured":"Shams Zawoad Amit\u00a0Kumar Dutta and Ragib Hasan. 2015. Towards building forensics enabled cloud through secure logging-as-a-service. IEEE Transactions on Dependable and Secure Computing 13 2 (2015) 148\u2013162.","DOI":"10.1109\/TDSC.2015.2482484"},{"key":"e_1_3_3_2_50_2","doi-asserted-by":"crossref","unstructured":"Lianmin Zheng Wei-Lin Chiang Ying Sheng Siyuan Zhuang Zhanghao Wu Yonghao Zhuang Zi Lin Zhuohan Li Dacheng Li Eric Xing et\u00a0al. 2023. Judging llm-as-a-judge with mt-bench and chatbot arena. Advances in neural information processing systems 36 (2023) 46595\u201346623.","DOI":"10.52202\/075280-2020"}],"event":{"name":"ICSE-NIER '26: 2026 IEEE\/ACM 48th International Conference on Software Engineering","location":"Rio de Janeiro Brazil","acronym":"ICSE-NIER '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the IEEE\/ACM 48th International Conference on Software Engineering"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786582.3786832","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,8]],"date-time":"2026-07-08T11:53:29Z","timestamp":1783511609000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786582.3786832"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":49,"alternative-id":["10.1145\/3786582.3786832","10.1145\/3786582"],"URL":"https:\/\/doi.org\/10.1145\/3786582.3786832","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-07-08","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}