arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2609.21020cs.CRcs.SE

(不要)信任,但(不要)验证:开发者对AI生成代码安全性的关注

(Don't) Trust, but (Don't) Verify: Developers' Attention to Security in AI-Generated Code

  • Tufts University(塔夫茨大学)
  • Philips(飞利浦)
  • Colorado School of Mines(科罗拉多矿业学院)

机构由 AI 辅助整理,请以论文原文为准。

Hamza Khalid, Ronald E. Thompson, Alejandra Sabater, Perucy Mussiba, Kelsey R. Fulton, Daniel Votipka

AI总结:

本研究通过远程观察100名开发者评估AI生成代码的过程,发现开发者对安全性的关注不足,信任影响决策,且难以识别漏洞,为AI辅助安全开发提供基础见解。

AI中文摘要:

AI编程助手正迅速改变软件开发,但已知会产生不安全的代码。先前的研究衡量了AI辅助开发者是否生成安全代码,但对开发者如何评估AI生成的代码知之甚少:他们能否识别漏洞,使用哪些线索,以及信任如何影响他们的决策。这一评估步骤是使用AI进行安全开发的基础,无论是使用自动补全、聊天工具还是AI代理。作为第一步,我们进行了一项远程观察研究,有100名参与者参与,隔离了这一评估阶段。参与者的任务是为四个C语言链表任务生成安全和功能正确的代码。对于每个任务,参与者能够循环浏览五个AI生成的建议,这些建议在安全性和功能性上各不相同,选择一个,并将其编辑为最终提交。参与者还完成了一项关于其决策过程和对AI生成代码安全性看法的研究后调查,其中23人完成了更深入的访谈。

英文摘要:

AI coding assistants are rapidly transforming software development, but are known to produce insecure code. Prior work has measured whether AI-assisted developers produce secure code, but less is known about how they evaluate AI-generated code: whether they can identify vulnerabilities, what cues they use, and how trust shapes their decisions. This evaluation step is foundational to secure development with AI, whether using auto-complete, chat tools, or AI agents. As a first step, we conducted a remote observational study with 100 participants isolating this evaluation stage. Participants were tasked with producing secure and functional code for four C linked-list tasks. For each, participants were able to cycle through five AI-generated suggestions varying in security and functionality, select one, and edit their choice into a final submission. Participants also completed a post-study survey about their decision-making and perception of AI-generated code's security and 23 completed a more in-depth interview.

补充信息

↑