The results indicate that language-model assistance can add value in regulated automotive requirements workflows when it is embedded in deterministic, provenance-rich, and expert-governed processes.
Abstract
Automotive software developed under ISO 26262 and ISO/SAE 21434 depends on requirements that are traceable, reviewable, and grounded in safety and cybersecurity evidence. The practical bottleneck is often not requirement writing alone, but turning fragmented project artifacts into auditable specifications at engineering speed. This paper presents CADRE, an AI-assisted requirements-engineering framework for safety- and cybersecurity-critical automotive systems. CADRE combines deterministic parsers for structured artifacts with retrieval-augmented synthesis for semi-structured and unstructured sources. It constrains this workflow through schema validation, source-grounded traceability, expert review gates, fixed decoding controls, and cryptographic provenance tracking. The evaluation covers four industrial automotive modules from ASIL-B to ASIL-D and CAL-2 to CAL-4. CADRE produced 1,022 synthesized requirements, achieved 98.6% traceability coverage, kept the fabrication rate at 0.2%, and produced byte-identical outputs across independent runs. The results indicate that language-model assistance can add value in regulated automotive requirements workflows when it is embedded in deterministic, provenance-rich, and expert-governed processes.
Translating high-level business requirements into standards-grounded security requirements remains a persistent challenge in software engineering. Traditional Security Requirements Engineering (SRE) is often manual, error-prone, and too slow for modern development, creating a translation gap that can leave software vulnerable. This paper presents MAS-SRE, a multi-agent framework that automates the transformation of business requirements into traceable security requirements grounded in OWASP ASVS, NIST SP 800–53, and ISO 27001. MAS-SRE orchestrates 10 specialized agents across 4 workflow stages and combines STRIDE-based threat modeling with Retrieval-Augmented Generation (RAG) to produce standards-aligned outputs. Following the Design Science Research Process, the framework was evaluated on 14 industrial use cases through expert assessment by 15 software engineering practitioners and deterministic coverage and traceability metrics. MAS-SRE achieved 100% verification test coverage, 98.6% threat mapping coverage, 87.6% control mapping coverage, and about 40% lower processing time than sequential execution, while also receiving positive practitioner feedback on usefulness and adoption intent. These results indicate that MAS-SRE is a feasible approach for drafting standards-grounded, traceable security requirements, although comparative evaluation against alternative methods and deeper integration into development workflows remain future work.
Savvas Mantzouranidis, Ricardo Britto· International Conference on...· 0 citations
ADATracer is presented, a software traceability tool designed to recover links between natural language requirements, Ada source files, version-control commits, and issue-tracking artifacts, and an Ada-aware parser that accounts for language features such as package specifications, bodies, and strong typing.
The deployment of a validated, low-code electronic Device History Record system on a high-mix, low-volume manufacturing line at Smith & Nephew’s Memphis site provides a practical and replicable model for regulated manufacturing environments that need to strengthen compliance while gaining flexibility for future analytics and system integration.
Pareshkumar Hotchandani, Mr. Wakhare· IEEE Access· 0 citations
Empirical evidence is provided that generative AI can effectively support security requirements engineering when embedded within human-centered workflows and organizational governance structures, offering practical insights for adoption in regulated software development contexts.
F. Martins, Elaine Venson· SIGSOFT FSE Companion· 0 citations
A multi-agent-based large language model (LLM) workflow designed to support requirement extraction from technical specifications and regulatory documents in compliance with automotive requirement guidelines is presented.
Abdelrahman Abdalla, Lukas Schäfers, Fabian Schmidt et al.· SAE technical paper series· 0 citations
Algorithm-Driven Development is introduced, a methodology developed from industrial practice to address recurring challenges in translating requirements into reliable, testable, and maintainable software behavior that provides systematic coverage of functional scenarios from the outset of development.
Philippe Jawish, Pierre Evrard, Alexandre Lemerle et al.· Journal of Systems and Softw...· 0 citations