Trustworthy AI-enhanced DevSecOps framework: bridging XAI and RAG for interpretable anomaly detection and context-aware root cause analysis
| dc.contributor.advisor | Hossain, Muhammad Iqbal | |
| dc.contributor.author | Reza, Nowshin | |
| dc.contributor.author | Parvez, Md. Adnan | |
| dc.contributor.author | Mottakee, Md Sayem | |
| dc.contributor.author | Islam, Ariful | |
| dc.contributor.department | Department of Computer Science and Engineering | |
| dc.date.accessioned | 2026-04-12T06:37:23Z | |
| dc.date.available | 2026-04-12T06:37:23Z | |
| dc.date.copyright | 2026 | |
| dc.date.issued | 2026-01 | |
| dc.description | Cataloged from PDF version of thesis. | |
| dc.description | Includes bibliographical references (pages 77-78). | |
| dc.description | This thesis is submitted in partial fulfillment of the requirements for the degree of Bachelor of Science in Computer Science, 2026. | en_US |
| dc.description.abstract | Modern software development faces many challenges in balancing rapid delivery with robust security. The challenges are bugs,vulnerabilities and inefficiencies. The AI-based DevSecOps tools that are being used today are effective at detecting abnormalities and vulnerabilities but they act as a black box that provides little to no transparency or context that leaves the security team a little skeptical and makes it hard for them to trust the tools and act on them. An AI-driven DevSecOps system that employs Explainable Artificial Intelligence (XAI), which offers insights into the choices made by the transformer model LogBert, is presented as a solution to this problem. The proposed framework also uses Retrieval-Augmented Generation (RAG) that dynamically retrieves contextual data(i.e. Historical fixes, security protocols and optimization patterns). LogBert is trained to model normal system behaviour, detect anomalies while SHAP boosts interpretability and RAG produces historical context which fosters trust from developers and collaborative debugging to eliminate any doubt which is induced by the black box dilemma. In this framework security is actively strengthened through real-time vulnerability scanning, threat prediction and automated compliance check. Moreover, LLM is combined with SHAP to describe what the output of SHAP means, making it more human interpretable. Also it is applied to RAG which transforms retrieved contextual information into simple human readable texts and proposes fixes. This proposed framework does not only improve performance but it also provides a clear path for using AI in a way that is both sustainable and transparent within DevSecOps test phase. | en_US |
| dc.description.degree | Bachelor of Science in Computer Science | |
| dc.description.statementofresponsibility | Nowshin Reza | |
| dc.description.statementofresponsibility | Md. Adnan Parvez | |
| dc.description.statementofresponsibility | Md Sayem Mottakee | |
| dc.description.statementofresponsibility | Ariful Islam | |
| dc.format.extent | 78 pages | |
| dc.identifier.other | ID 21301042 | |
| dc.identifier.other | ID 21301017 | |
| dc.identifier.other | ID 21301080 | |
| dc.identifier.other | ID 21301016 | |
| dc.identifier.uri | http://hdl.handle.net/10361/27857 | |
| dc.language.iso | en | en_US |
| dc.publisher | BRAC University | en_US |
| dc.rights | BRAC University theses are protected by copyright. They may be viewed from this source for any purpose, but reproduction or distribution in any format is prohibited without written permission. | |
| dc.subject | Trustworthy AI | en_US |
| dc.subject | DevSecOps | en_US |
| dc.subject | Retrieval-augmented generation | en_US |
| dc.subject | Large language model | en_US |
| dc.subject | Adaptive pipeline optimization | en_US |
| dc.subject | Security automation | en_US |
| dc.subject.lcsh | Artificial intelligence--Moral and ethical aspects. | |
| dc.subject.lcsh | Linguistic analysis (Linguistics)--Data processing. | |
| dc.subject.lcsh | Data encryption (Computer science). | |
| dc.subject.lcsh | Computer security. | |
| dc.title | Trustworthy AI-enhanced DevSecOps framework: bridging XAI and RAG for interpretable anomaly detection and context-aware root cause analysis | en_US |
| dc.type | Thesis | en_US |