AI for Interactive Security-by-Design Assistance: Automatic Vulnerable Asset Extraction and Integration into a ReqSecDes Framework
D-27
Doctorate Full Doctorate
- Disciplines
- Other (Computer Sciences)
- Laboratory
- TOULOUSE INSTITUTE FOR INFORMATICS RESEARCH (IRIT) - UMR 5505
- Host institution
- UNIVERSITY OF TOULOUSE
Description
ContextIn modern software development, pressure for rapid delivery often pushes security to the background. Yet, design-level flaws account for more than half of reported vulnerabilities, leading to costly fixes and major breaches. The Security-by-Design paradigm seeks to address this by embedding security early, during requirements and design. However, this ambition faces several challenges: lack of specialized expertise, absence of systematic methods to refine abstract goals (confidentiality, integrity, availability) into actionable design, and limited tools for engineers without cybersecurity training. Advances in AI, especially NLP and machine learning, open new opportunities to automatically extract and structure security knowledge, and to provide intelligent, interactive support to practitioners.
Research questions
The key issue is integrating security systematically at the requirements and design phases, while ensuring accessibility for non-expert engineers. This raises several questions:
How can AI extract and organize vulnerable assets from heterogeneous sources (CAPEC, CWE, ATT&CK)?
How to refine high-level security objectives into formal, verifiable design patterns?
How to embed this knowledge in an assistant that offers real-time feedback and recommendations without disrupting agile development?
Objectives
The PhD will develop the ReqSecDes framework by combining AI-driven extraction and formalization of vulnerable assets with tool-supported assistance bridging requirements and secure design. Expected results:
Automated Vulnerable Asset Library: NLP/ML methods to extract vulnerabilities, threats, mitigations, and structure them in an ontology.
Formal Taxonomy of Security Properties: refinement of security goals into verifiable design patterns, checked with formal methods.
Interactive Security Assistance: algorithms linking system specifications with the asset library, providing real-time, context-aware recommendations in modeling tools.
Validation: industrial case studies to assess vulnerability reduction and usability by non-experts.
Expected contributions
The candidate will:
Survey the state of the art in security requirements engineering, asset-based approaches, and AI/NLP in cybersecurity.
Design and train NLP/ML models to extract and link vulnerable assets.
Develop a formal taxonomy of security properties, verify it, and integrate it into modeling environments.
Implement a prototype of an interactive assistant with real-time reasoning and feedback.
Validate the approach via case studies with industrial partners, measuring effectiveness and adoption.
Skills required
The call is open to master-degree students or professionals ; Masters students seeking a 6-month internship, with the intention of continuing into a PhD, are also welcome to apply.Bibliography
[1] D. Gonzalez, F. Alhenaki, and M. Mirakhorli, Architectural Security Weaknesses in Industrial Control Systems (ICS) an Empirical Study Based on Disclosed Software Vulnerabilities, in 2019 IEEE International Conference on Software Architecture (ICSA), Hamburg, Germany: IEEE, Mar. 2019, pp. 3140. doi: 10.1109/ICSA.2019.00012.[2] N. Messe, Security by Design : An asset-based approach to bridge the gap between architects and security experts, phdthesis, Université de Bretagne Sud, 2021. Accessed: Feb. 15, 2022. [Online]. Available: https://tel.archives-ouvertes.fr/tel-03407189
[3] N. Messe, V. Chiprianov, N. Belloir, J. El-Hachem, R. Fleurquin, and S. Sadou, Asset-Oriented Threat Modeling, in 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), Dec. 2020, pp. 491501. doi: 10.1109/TrustCom50675.2020.00073.
[4] N. Messe, N. Belloir, V. Chiprianov, J. El-Hachem, R. Fleurquin, and S. Sadou, An Asset-Based Assistance for Secure by Design, in 2020 27th Asia-Pacific Software Engineering Conference (APSEC), Dec. 2020, pp. 178187. doi: 10.1109/APSEC51365.2020.00026.
[5] Nigmatullin, I., Sadovykh, A., Messe, N., Ebersold, S., & Bruel, J. M. (2022, April). RQCODETowards Object-Oriented Requirements in the Software Security Domain. In IEEE International Conference on Software Testing, Verification and Validation Workshops (ICSTW 2022) (pp. 2-6). IEEE.
[6] Hachem, J. E., Chiprianov, V., Babar, M. A., Khalil, T. A., & Aniorte, P. (2020). Modeling, analyzing and predicting security cascading attacks in smart buildings systems-of-systems. Journal of Systems and Software, 162, 110484.
[7] Zhioua, Z., Ameur-Boulifa, R., & Roudier, Y. (2018). Framework for the formal specification and verification of security guidelines. Advances in Science, Technology and Engineering Systems Journal, 3(1), 38-48.
[8] Teixeira De Castro, H., Hussain, A., Blanc, G., El Hachem, J., Blouin, D., Leneutre, J., & Papadimitratos, P. (2024, July). A model-based approach for assessing the security of cyber-physical systems. In Proceedings of the 19th International Conference on Availability, Reliability and Security (pp. 1-10).
[9] Sadovykh, A., & Ivanov, V. V. (2024). Enhancing DevSecOps with continuous security requirements analysis and testing. Компьютерные исследования и моделирование, 16(7), 1687-1702.
Keywords
machine learning, software engineering, cybersecurity, formal methodsFunded offer
Dates
Application deadline 21/09/26
Duration36 months
Start date01/10/26
Creation date22/09/25
Languages
Level of french requiredB2 (upper-intermediate)
Level of English requiredB2 (upper-intermediate)
Miscellaneous
Annual tuition fee400 € / year
Contacts
You must connect to be able to display the contacts.
