Gil Luria

dblp:154/9515 · DBLP profile ↗
← Back
6ranked-venue papers
0as first author
5since 2021 · last 2026
0000-0002-7983-2517ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 6 · 5 since 2021
YearPublicationVenuePosition
2026 Decoupling in AI ethics: Learning how to walk the talk
abstract
In recent years, AI ethics declarations, commitments, and frameworks for AI systems development have proliferated. Yet, implementation remains persistently low. This phenomenon, often termed “AI ethics washing,” has been widely criticized but lacks empirical investigation. Our paper examines these gaps between declarations and operations in AI ethics through the organizational psychology concept of “decoupling”—the disconnect between what organizations say and what they do. Using data collected through in-depth interviews with 32 practitioners across diverse companies, from early-stage startups to large corporations, we present a systematic analysis of decoupling between declarations and operations in AI ethics, producing the first analysis of decoupling not only in AI ethics but in any technology development field. Our findings identify and characterize (i) common types of AI ethics declarations, such as policies and internal communications, (ii) common types of AI ethics operations, such as reviews and testing, (iii) common rationales behind companies’ approaches to AI ethics, and (iv) distinct decoupling profiles, i.e., common ways in which AI ethics declarations come apart from operations. Our discussion includes recommendations for increasing AI ethics adoption tailored to each profile. These recommendations differ from traditional AI ethics frameworks. While traditional frameworks prescribe ideal practices based on regulatory or industry expectations, this paper offers recommendations grounded in an empirical analysis of how AI ethics efforts succeed or fail in practice. Our decoupling-informed perspective fundamentally reshapes how practitioners and scholars can approach the challenge of AI ethics implementation.
Ravit Dotan, Tomer Gershoni, Irit Hadar, Gil Luria
Empir. Softw. Eng.4
2024 Exploring the Role of Team Security Climate in the Implementation of Security by Design: A Case Study in the Defense Sector
abstract
The rapid diffusion of software systems into all aspects of human life has exacerbated security threats and thus amplified the requirement for proactive approaches for designing security as a default. Following evidence from previous studies, indicating or ganizational climate as a key influencer on developers’ security mindsets and behaviors, this study was focused on examining the relations hip between team security climate level and developers’ actual practices when addressing security threats during software development. The empirical study was conducted in a defense software development organization and included a survey questionnaire completed by 212 developers from 50 software teams. The results were compared to managers’ evaluations regarding the implementation level of security mechanisms in the teams’ development. The findings indicate a positive relationship between team security climate level and the implementation level of security mechanisms in the teams' software development and that team productivity climate moderates this relationship. The results also reveal that team security climate mediates the association between manager developer relationships and the implementation level of security mechanisms in software development. The study provides support to organizational climate theory and to the specific scale of organizational security climate, demonstrating the predictive validity of this scale, and sheds light on the influence of leadership and competitive facets on security engineering.
Micha Prudjinski, Irit Hadar, Gil Luria
IEEE Trans. Software Eng.3
2022 The Importance of Security Is in the Eye of the Beholder: Cultural, Organizational, and Personal Factors Affecting the Implementation of Security by Design
abstract
Security by design is a recommended approach, addressing end-to-end security and privacy in the design of software systems. To realize this approach, proactive security behavior is required from software developers. This research follows results from previous studies that suggest that personal and organizational characteristics influence security-related behaviors during the software design process. The research is aimed at gaining an in-depth understanding of proactive security behavior and the factors affecting it. Leveraging organization climate theory from organizational psychology, we propose a theoretical model, detailing different factors and their relations with proactive security behavior and test it in empirical settings. The empirical study was conducted in collaboration with an internationally distributed information technology enterprise and included a survey questionnaire completed by 499 software developers working in seven countries. The results of the survey confirm the moderation-mediation relations in the proposed model, revealing that organizational security climate and security self-efficacy are both positively associated with proactive security behavior, organizational security climate is positively associated with security self-efficacy, and cultures promoting individualism moderate the relationship between organizational security climate and security self-efficacy, thus impeding proactive security behavior. The body of knowledge of organizational psychology points to directions that can effectively be activated for improvement.
Renana Arizon-Peretz, Irit Hadar, Gil Luria
IEEE Trans. Software Eng.3
2021 Privacy as first-class requirements in software development: A socio-technical approach
abstract
Privacy requirements have become increasingly important as information about us is continuously accumulated and digitally stored. However, despite the many proposed methodologies and tools to address these requirements, privacy engineering is often underperformed in most domains of the software industry. Two of the major reasons underlying this under-performance are (1) the low expertise and understanding of privacy by the two main actors in requirements engineering: users and analysts, and (2) the fact that software developers often do not perceive privacy requirements as a priority for their companies, thus neglecting to meet these requirements even when they do have the required knowledge, skills, and supporting tools to do so. To address these two problems, we propose to integrate knowledge from software engineering and organizational psychology in an iterative, customizable, socio-technical environment. Such environment has the potential to support the design of systems by providing technical tools for eliciting, modeling, and designing privacy aspects, thus addressing the knowledge gap of both data subjects and analysts, and social mechanisms for achieving a supportive and sustainable organizational privacy climate within a company, thus reorienting the organizational attention and engagement toward addressing privacy requirements.
Yizhaq Benbenisty, Irit Hadar, Gil Luria, Paola Spoletini
ASE3
2021 Understanding developers' privacy and security mindsets via climate theory
Renana Arizon-Peretz, Irit Hadar, Gil Luria, Sofia Sherman
Empir. Softw. Eng.3
2018 Leveraging organizational climate theory for understanding industry-academia collaboration
Sofia Sherman, Irit Hadar, Gil Luria
Inf. Softw. Technol.3