arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

理解人工智能代码助手对安全API使用的影响:一项实证研究

Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study

Zahra Mousavi, Chadni Islam, M. Ali Babar, Alsharif Abuadbba, Kristen Moore

arXiv 2607.11348首次发表:更新:

发表机构

Centre for Research on Engineering Software Technologies (CREST) & Adelaide University, Australia; Edith Cowan University, Australia; CSIRO’s Data61, Australia(工程软件研究技术中心(CREST)及阿德莱德大学,澳大利亚; 埃德温·考文大学,澳大利亚; CSIRO数据61,澳大利亚)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

该研究通过对44名开发者的实证调查,探讨人工智能代码助手对安全API使用的影响。发现GitHub Copilot虽提高功能正确性、减少不安全模式,但未显著提升安全API使用,且开发者安全意识不足,进而给出相关建议与研究方向。

AI 中文摘要

人工智能代码助手正在改变软件开发,但它们对软件安全的影响仍是主要关注点,尤其是在安全API方面。安全API对保护软件系统至关重要,但其复杂性常导致使用错误和严重漏洞。因此,基于证据理解人工智能助手如何影响开发者对这些API的使用,对制定有效缓解策略至关重要。本研究通过首次实证调查人工智能代码助手如何影响专业开发者对安全API的使用来填补这一空白。我们对44名开发者进行研究,他们在有和没有GitHub Copilot协助的情况下完成安全API编程任务。结果表明,Copilot提高了功能正确性并略微减少了某些不安全模式,但未显著改善安全API的使用。此外,开发者在使用Copilot时很少提出安全问题,许多人未意识到最终实现仍不安全。最后,我们为提高开发者的安全意识提供了建议,并提出了未来研究方向以支持更安全的人工智能辅助软件开发。

英文摘要

AI code assistants are transforming software development, but their implications for software security remain a major concern, particularly in the context of security APIs. These APIs are critical for safeguarding software systems, yet their complexity often leads to incorrect use and serious vulnerabilities. Developing an evidence-based understanding of how AI assistants influence developers' use of these APIs is therefore essential for informing effective mitigation strategies. While a few user studies have examined the broader impact of AI assistants on software vulnerabilities, the use of security APIs remains unexplored from a developer-centered perspective. This study addresses this gap by presenting the first empirical investigation into how AI code assistants affect professional developers' use of security APIs. We conducted a study with 44 developers who completed security API programming tasks with and without GitHub Copilot assistance. Our findings show that, while Copilot improves functional correctness and marginally reduces certain insecure patterns, it does not significantly improve secure API usage. We also found that developers rarely raised security concerns when engaging with Copilot, and many did not recognize that their final implementations remained insecure. Finally, we offer recommendations for enhancing security awareness among developers and propose future research directions to support safer AI-assisted software development.

CommentsAccepted for publication at the 29th International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2026)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑