发表机构
College of Computer and Information Sciences, Imam Mohammad Ibn Saud Islamic University (IMSIU)(伊玛目穆罕默德·本·沙特伊斯兰大学计算机与信息科学学院)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出安全风险评估框架SRF,结合威胁建模与定量分析,评估AI生成代码风险,发现风险因任务类型而异,实现可重复评估。
AI 中文摘要
AI驱动的开发工具现已被广泛用于生成代码并协助开发者完成日常编程任务。尽管已有研究识别出AI生成代码中的漏洞,但安全导向的工作往往侧重于漏洞检测而非风险评估。为弥补这一空白,本文提出了一种安全风险评估框架(SRF),用于评估AI生成代码的安全风险。SRF结合了威胁建模、安全分析以及基于漏洞严重性的定量风险评估方法。该框架应用于一组与安全相关的编程任务,其中由多个AI驱动的开发工具生成的代码使用Bandit和Semgrep进行分析。结果表明,AI生成的代码在所有被评估的工具中均可能引入安全漏洞。结果还显示,风险水平因任务类型而异,输入处理和文件处理任务表现出较高的风险,而较简单的任务则保持低风险。工具之间的差异存在,但小于任务类别之间的差异。总体而言,SRF能够实现对AI生成代码的可重复评估,并为评估其安全影响提供了一个实用框架。
英文摘要
AI-powered development tools are now widely used to generate code and assist developers with routine programming tasks. Although existing work has identified vulnerabilities in AI-generated code, security-oriented work is often focused on vulnerability detection rather than risk assessment. To address this gap, this paper presents a Security Risk Assessment Framework (SRF) to evaluate the security risks of AI-generated code. SRF combines threat modeling, security analysis, and a quantitative risk evaluation approach based on vulnerability criticality. The framework is applied to a set of security-relevant programming tasks, where code generated by multiple AI-powered development tools is analyzed using Bandit and Semgrep. The results show that AI-generated code can introduce security vulnerabilities across all evaluated tools. They also show that risk levels vary by task type, as input processing and file handling tasks showed higher risk, while simpler tasks remained low-risk. Differences between tools exist but are smaller than differences across task categories. Overall, SRF enables reproducible evaluation of AI-generated code and provides a practical framework for assessing its security implications.