arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.11303cs.SE

探索安全经验与ChatGPT使用策略在安全软件工程教育中的作用

Exploring the Role of Security Experience and ChatGPT Usage Strategies on Secure Software Engineering Education

Alessio Ferrari, Minh An Nguyen, Kushal Ramkumar, Liliana Pasquale

首次发表
浏览论文内容

中文总结 AI 辅助

本研究通过实证分析26名研究生在漏洞修复作业中使用ChatGPT的日志,发现使用策略多样性而非安全经验与作业表现正相关,为安全软件工程教育中引导LLM有效使用提供了依据。

中文摘要 AI 辅助

大语言模型(LLMs)的快速普及正在重塑软件工程教育,但它们在安全软件工程教育中的作用仍未得到充分探索。我们报告了一项探索性实证研究,研究对象是兼职网络安全理学硕士项目中的26名研究生,他们在一次漏洞修复作业中使用了ChatGPT。为了刻画ChatGPT的使用情况,我们采用结构化双重编码程序分析了学生的ChatGPT交互日志,并考察了使用模式及先前网络安全专业知识是否与作业表现相关。结果表明,具有不同网络安全专业水平的学生使用了大致相似的ChatGPT策略。按成绩划分,个体使用模式显示出描述性差异,但在多重比较校正后,没有任何差异在统计上显著。相比之下,ChatGPT使用的多样性,即采用的不同使用模式的数量,与表现呈正相关,即使在控制网络安全专业知识后也是如此。这些探索性发现表明,学生与ChatGPT互动的方式可能比是否使用它更具信息量,并激励未来开展对照研究,以引导学生在安全软件工程教育中有效使用LLM。

英文摘要

The rapid adoption of Large Language Models (LLMs) is reshaping software engineering education, but their role in secure software engineering education remains underexplored. We report an exploratory empirical study of how 26 graduate students in a part-time MSc Cybersecurity programme used ChatGPT during a vulnerability-fixing assignment. To characterise ChatGPT use, we analysed students' ChatGPT interaction logs using a structured double-coding procedure and examined whether usage patterns and prior cybersecurity expertise were associated with assignment performance. The results show that students with varying levels of cybersecurity expertise used broadly similar ChatGPT strategies. Individual usage patterns showed descriptive differences by grade, but none remained statistically significant after correcting for multiple comparisons. In contrast, diversity of ChatGPT usage, i.e., the number of distinct usage patterns adopted, was positively associated with performance, even after controlling for cybersecurity expertise. These exploratory findings suggest that the way students engage with ChatGPT may be more informative than whether they use it, and motivate future controlled studies to guide students toward effective LLM use in secure software engineering education.

发表机构

  • Trinity College Dublin(都柏林三一学院)
  • University College Dublin(都柏林大学)

机构由 AI 辅助整理,请以论文原文为准。

↑