pipette
ENEnglish

(Don't) Trust, but (Don't) Verify: Developers' Attention to Security in AI-Generated Code

Hamza Khalid, Ronald E. Thompson III, Alejandra Sabater, Perucy Mussiba, Kelsey R. Fulton, Daniel Votipka

Preprint

En palabras de los autores

AI coding assistants are rapidly transforming software development, but are known to produce insecure code. Prior work has measured whether AI-assisted developers produce secure code, but less is known about how they evaluate AI-generated code: whether they can identify vulnerabilities, what cues they use, and how trust shapes their decisions. This evaluation step is foundational to secure development with AI, whether using auto-complete, chat tools, or AI agents. As a first step, we conducted a remote observational study with 100 participants isolating this evaluation stage. Participants were tasked with producing secure and functional code for four C linked-list tasks. For each, participants were able to cycle through five AI-generated suggestions varying in security and functionality, select one, and edit their choice into a final submission. Participants also completed a post-study survey about their decision-making and perception of AI-generated code's security and 23 completed a more in-depth interview.

Resultado principalEl resumen no menciona limitaciones.

Apareció: lunes, 21 de septiembre. arXiv. Preprint, todavía sin revisión por pares.

Comentario de los autores: To appear at IEEE Security and Privacy (S&P) '27