(Don't) Trust, but (Don't) Verify: Developers' Attention to Security in AI-Generated Code

📅 2026-09-17
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
研究通过观察100名参与者如何评估和选择AI生成的C语言代码的安全性和功能性,探讨了开发者在使用AI辅助编程时对安全性的关注程度及信任影响。
📝 Abstract
AI coding assistants are rapidly transforming software development, but are known to produce insecure code. Prior work has measured whether AI-assisted developers produce secure code, but less is known about how they evaluate AI-generated code: whether they can identify vulnerabilities, what cues they use, and how trust shapes their decisions. This evaluation step is foundational to secure development with AI, whether using auto-complete, chat tools, or AI agents. As a first step, we conducted a remote observational study with 100 participants isolating this evaluation stage. Participants were tasked with producing secure and functional code for four C linked-list tasks. For each, participants were able to cycle through five AI-generated suggestions varying in security and functionality, select one, and edit their choice into a final submission. Participants also completed a post-study survey about their decision-making and perception of AI-generated code's security and 23 completed a more in-depth interview.
Problem

Research questions and friction points this paper is trying to address.

AI-generated code
security evaluation
developers' decision-making
vulnerability identification
Innovation

Methods, ideas, or system contributions that make the work stand out.

security evaluation
AI-generated code
developer trust
remote observational study
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
H
Hamza Khalid
Tufts University
R
Ronald E. Thompson III
Philips
A
Alejandra Sabater
Tufts University
P
Perucy Mussiba
Tufts University
Kelsey R. Fulton
Kelsey R. Fulton
Assistant Professor, Colorado School of Mines
Daniel Votipka
Daniel Votipka
Tufts University
Usable SecuritySecurity ProfessionalsMobile SecurityVulnerability DiscoverySecure Development