arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.26390cs.SE

无法隐藏的秘密:揭示原生大语言模型集成开发环境(LLM-native IDEs,简称LIDEs)的安全与隐私问题

Impossible to hide secret ...: Uncovering Security and Privacy Issues in LLM-native IDEs

Mostafijur Rahman Akhond, Md Afif Al Mamun, Gias Uddin, Song Wang

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对原生大语言模型集成开发环境(LIDEs),通过分析110万条相关帖子及6000余条评论,构建其安全隐私问题分类体系,发现问题多源于系统设计,开发者依赖外部防护,为后续安全LIDEs设计提供经验。

中文摘要 AI 辅助

原生大语言模型集成开发环境(LLM-native IDEs,简称LIDEs)是从底层设计之初就适配大语言模型(LLMs)的工具,在软件工程(SE)的编码、调试、程序理解等任务中取得了显著成功。作为软件系统,LIDEs也存在漏洞。本文研究开发者使用主流LIDEs开展开发任务时报告的安全与隐私问题,从29个与LIDEs相关的热门子版块收集了110万条帖子,筛选出446条讨论几乎所有主流LIDEs(如Cursor、Copilot、Codex等)安全与隐私问题的帖子,并分析了其超过6000条评论。结合定性与定量方法,本文构建了所报告安全与隐私问题的分类体系。研究结果表明,LIDEs的多数问题源于系统级设计选择,而非底层LLMs,例如用户数据访问、未受管控的自主行动等。开发者常依赖代码沙箱、人工审核等外部防护措施解决这些问题,凸显出开发者对LIDEs普遍存在不信任。本文分享研究得出的经验教训,以支持未来安全、隐私感知型LIDEs的设计。

英文摘要

LLM-native IDEs (Integrated Development Environments), aka LIDEs, are designed from the ground up to work with Large Language Models (LLMs). LIDEs have found remarkable success in Software Engineering (SE) tasks such as coding, debugging, and program comprehension. LIDEs are software systems, and, like any system, they can exhibit vulnerabilities. In this paper, we study the security and privacy issues that developers reported while using popular LIDEs in their development tasks. We collected 1.1M posts from 29 popular subreddits related to LIDEs. We identified 446 posts and analyzed over 6K comments to the posts that discussed security and privacy issues in almost all popular LIDEs, such as Cursor, Copilot, Codex, etc. Using a mix of qualitative and quantitative methods, we constructed a taxonomy of the reported security and privacy issues. Our results show that most issues in LIDEs stem from system-level design choices, rather than the underlying LLMs, such as user data access, unchecked autonomous actions, etc. To overcome these issues, developers frequently relied on external safeguards like code sandboxing and manual reviewing, highlighting prevalent mistrust among developers about LIDEs. We share lessons from our study to support future design of secure and privacy-aware LIDEs.

↑