arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

提示结构是重新分布而非减少:对大语言模型生成Python代码中安全漏洞的实证分析

Prompt Structure Redistributes, Not Reduces: An Empirical Analysis of Security-Weaknesses in LLM-Generated Python Code

Maitreyee Das Urmi, Jessica Pourleyli, Fabio Santos, Glaucia Melo

arXiv 2608.24857首次发表:更新:

AI 中文总结

该研究通过424个安全敏感Python任务,对比GPT-4o与LLaMA 3.1-8B在5种提示变体下的代码生成效果,发现结构化提示可提升合规性但会重新分布安全风险,无法替代稳健安全控制。

AI 中文摘要

大语言模型(LLM)越来越多地根据自然语言提示生成代码,使得提示工程成为塑造生成软件安全性的关键机制。结构化且面向安全的提示被广泛用于鼓励生成更安全的代码,然而它们的影响远不止于是否存在被检测到的漏洞。本研究使用424个安全敏感型Python任务,在5种逐步添加结构化和安全指导的提示变体下,用GPT-4o和LLaMA 3.1-8B生成解决方案,并通过Bandit和CodeQL从两个维度评估:生成合规性以及安全漏洞的流行度、严重程度和CWE分布。结构化提示大幅减少了拒绝情况(例如,GPT-4o的无效输出从424个中的338个降至37-52个),支持大规模分析,但面向安全的优化并未持续降低整体漏洞流行度。对于GPT-4o,更强的提示主要重新分布风险:高严重程度发现占比从20.8%降至13.6%,而低严重程度发现占比从32%升至43.5%;LLaMA则表现出更弱、更不一致的变化。研究还观察到安全驱动的语义漂移,即更严格的提示会悄悄删除或重写明确要求的不安全构造。总体而言,提示结构可提升合规性,但在大语言模型辅助开发中,它无法可靠替代稳健的安全控制措施。

英文摘要

Large Language Models (LLMs) increasingly generate code from natural-language prompts, making prompt engineering a key mechanism for shaping the security of generated software. Structured and security-oriented prompts are widely used to encourage safer code, yet their effects extend beyond whether detected weaknesses are simply present or absent. Using 424 security-sensitive Python tasks, we generate solutions with GPT-4o and LLaMA 3.1-8B under five prompt variants that progressively add structural and security guidance, and evaluate them with Bandit and CodeQL along two axes: generation compliance and security weakness prevalence, severity, and CWE distributions. Structured prompting substantially reduces refusals (e.g., GPT-4o invalid outputs drop from 338 of 424 to 37-52), enabling large-scale analysis, but security-oriented refinements do not consistently reduce overall weakness prevalence. For GPT-4o, stronger prompts primarily redistribute risk: high-severity findings fall (20.8% to 13.6%) while low-severity findings rise (32% to 43.5%); LLaMA shows weaker, less consistent shifts. We also observe security-driven semantic drift, where stricter prompts silently remove or rewrite explicitly requested unsafe constructs. Overall, prompt structure improves compliance but is an unreliable substitute for robust security controls in LLM-assisted development.

CommentsAccepted at CASCON 2026

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑