Skip to content
Book Open access

MAS-SRE: A Multi-Agent System for Security Requirements Engineering

Jul 2026 · International Conference on Predictive Models in Software Engineering · 0 citations · 12 references
Computer Science

Abstract

Translating high-level business requirements into standards-grounded security requirements remains a persistent challenge in software engineering. Traditional Security Requirements Engineering (SRE) is often manual, error-prone, and too slow for modern development, creating a translation gap that can leave software vulnerable. This paper presents MAS-SRE, a multi-agent framework that automates the transformation of business requirements into traceable security requirements grounded in OWASP ASVS, NIST SP 800–53, and ISO 27001. MAS-SRE orchestrates 10 specialized agents across 4 workflow stages and combines STRIDE-based threat modeling with Retrieval-Augmented Generation (RAG) to produce standards-aligned outputs. Following the Design Science Research Process, the framework was evaluated on 14 industrial use cases through expert assessment by 15 software engineering practitioners and deterministic coverage and traceability metrics. MAS-SRE achieved 100% verification test coverage, 98.6% threat mapping coverage, 87.6% control mapping coverage, and about 40% lower processing time than sequential execution, while also receiving positive practitioner feedback on usefulness and adoption intent. These results indicate that MAS-SRE is a feasible approach for drafting standards-grounded, traceable security requirements, although comparative evaluation against alternative methods and deeper integration into development workflows remain future work.

Read PDF

Similar papers

Book Open access Jul 2026

An Empirical Evaluation of Generative AI in Security Requirements Engineering and Threat Modeling

Empirical evidence is provided that generative AI can effectively support security requirements engineering when embedded within human-centered workflows and organizational governance structures, offering practical insights for adoption in regulated software development contexts.

F. Martins, Elaine Venson · 0 citations
Review Aug 2026

Large Language Models at the Intersection of Software Engineering and Software Security:An Evidence-Centered Structured Survey and Research Agenda

This evidence-centered structured survey synthesizes representative work available through May 31, 2026 across software engineering tasks, software security tasks, adaptation mechanisms, artifact granularity, and evaluation design and introduces an assurance framework that separates functional correctness, security, operational reliability, evidence provenance, and agent authority.

Wei Lin, Tao Zhou, Zhaofei Xie et al. · 0 citations
Review Jul 2026

Multi-Agent LLM Architecture for Systems Engineering Automation

A modular multi-agent Large Language Model pipeline that automates key steps of the systems engineering lifecycle - from requirement structuring and compliance checking to code and test generation - using specialized LLM agents orchestrated within a unified architecture.

Marcel Padubrin, A. Kulzer, Erol Guerocak · 0 citations
Book Open access Jul 2026

Industrial Deployment of an AI Multi-Agent System for Requirements-Driven Code Verification

ARC-V, a multi-agent AI system deployed at JPMorganChase that shifts quality assurance upstream by operationalising Large Language Models for automated requirement and code verification, achieves a 79% early defect discovery rate and validate a requirements-centric, AI-driven approach to scalable software quality assurance in complex environments.

Paul Baker, Blanca Manu, Rebecca Moussa et al. · 0 citations
Review Jul 2026

Multi-Agent LLM Workflow for Regulatory-Driven Requirement Generation in Automotive Software Development

A multi-agent-based large language model (LLM) workflow designed to support requirement extraction from technical specifications and regulatory documents in compliance with automotive requirement guidelines is presented.

Abdelrahman Abdalla, Lukas Schäfers, Fabian Schmidt et al. · 0 citations