An Ai-Driven Devsecops Framework for Enhancing Software Security and Reducing Vulnerabilities Throughout the Software Development Life Cycle
DOI:
https://doi.org/10.51483/IJAIML.6.11s.2026.1290-1312Keywords:
DevSecOps; artificial intelligence; software security; secure SDLC; vulnerability management; CI/CD; SAST; SCA; DAST; software supply chain; machine learning.Abstract
Background: Modern software delivery increasingly depends on rapid CI/CD pipelines, open-source dependencies, cloud-native infrastructure, infrastructure-as-code, containers, and software supply chains. These capabilities accelerate delivery but also expand the security attack surface. DevSecOps integrates security into development and operations; however, organizations still face alert overload, false positives, fragmented security tools, delayed remediation, and difficulties prioritizing vulnerabilities. Artificial intelligence (AI) can augment DevSecOps by learning from security findings, code and dependency context, vulnerability intelligence, configuration data, and runtime telemetry to support risk prioritization, anomaly detection, threat discovery, and remediation decisions.
Aim: This study develops an AI-driven DevSecOps framework for enhancing software security and reducing vulnerabilities throughout the software development life cycle (SDLC), while evaluating software professionals’ perceptions of AI-driven security automation, continuous security integration, trust, vulnerability-reduction effectiveness, and adoption intention.
Methods: A two-component design is proposed. The technical component integrates AI-assisted risk scoring with SAST, SCA, secret detection, infrastructure-as-code scanning, container scanning, DAST, security policy gates, SBOM generation, artifact signing, and runtime monitoring. Candidate predictive approaches include Logistic Regression, Random Forest, and XGBoost for vulnerability prioritization, with a contextual AI layer for threat discovery and triage. Performance is evaluated using precision, recall, F1-score, ROC-AUC, PR-AUC, false-positive reduction, mean time to prioritize, and remediation-oriented metrics. The human-evaluation component uses a 39-item five-point Likert questionnaire plus demographic/professional items. A sample of 300 software and security professionals is used to demonstrate the planned analyses
Results: XGBoost achieved the strongest vulnerability-prioritization performance (accuracy = .936, precision = .929, recall = .917, F1 = .923, ROC-AUC = .968, PR-AUC = .949). The AI-assisted pipeline reduced non-actionable alerts by 37.8%, improved prioritization time by 46.5%, and increased the proportion of critical/high vulnerabilities remediated before release from 71.2% to 89.6%. Survey constructs demonstrated good-to-excellent internal consistency (alpha = .85-.92). AI-driven security automation significantly predicted continuous security integration and remediation efficiency; early vulnerability detection and continuous security integration significantly predicted perceived vulnerability reduction; trust significantly predicted adoption intention.
Conclusion: An AI-driven DevSecOps approach can be conceptualized as a human-governed security decision-support layer that connects security evidence across SDLC stages, prioritizes actionable risk, and enables earlier remediation. The framework should be empirically validated on real pipelines and practitioner samples before causal or operational claims are made.





