Do Users Write More Insecure Code with AI Assistants?
2022/11/07 by Neil Perry, Megha Srivastava, Deepak Kumar +1 · 23 voices · 53 citations
Computer Science · Social Sciences · #Software Engineering Research #Ethics and Social Impacts of AI #Mobile Crowdsensing and Crowdsourcing
paper · pdf · doi:10.1145/3576915.3623157
Abstract
AI code assistants have emerged as powerful tools that can aid in the software development life-cycle and can improve developer productivity. Unfortunately, such assistants have also been found to produce insecure code in lab environments, raising significant concerns about their usage in practice. In this paper, we conduct a user study to examine how users interact with AI code assistants to solve a variety of security related tasks. Overall, we find that participants who had access to an AI assistant wrote significantly less secure code than those without access to an assistant. Participants with access to an AI assistant were also more likely to believe they wrote secure code, suggesting that such tools may lead users to be overconfident about security flaws in their code. To better inform the design of future AI-based code assistants, we release our user-study apparatus to researchers seeking to build on our work.
Cited by
Discussions
- Do Users Write More Insecure Code with AI Assistants? [lemmy, 75 points, 26 comments]
- Apparently yes [bsky, 29 points, 5 comments]
- Do Users Write More Insecure Code with AI Assistants? [lobsters, 20 points, 10 comments]
- - AI generated code is insecure between 39% and 50% of the time (dependent on language) arxiv.org/abs/2211.03622 [bsky, 7 points, 1 comments]
- The article links to this study, showing that code written with an AI assistant is more buggy and less secure. Pichai is bragging that a quarter of all new Google code is of lower quality than normal [bsky, 5 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 5 points, 4 comments]
- Study: Do Users Write More Insecure Code with AI Assistants? [hn, 4 points, 2 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 4 points, 1 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 3 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 3 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 3 points, 1 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 2 points, 1 comments]
- AI-assistenter gör så att folk skriver fler säkerhetsbuggar i sin kod "Overall, we find that participants who had access to an AI assistant based [...] wrote significantly less secure code than those [bsky, 2 points, 1 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 2 points, 2 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 2 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 2 points, 0 comments]
- "[P]articipants who had access to an #AI assistant ... wrote significantly less secure code than those without access. Additionally, participants with access to an AI assistant were more likely to bel [bsky, 1 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? [hn, 1 points, 0 comments]
- Do Users Write More Insecure Code with AI Assistants? - arxiv.org/abs/2211.0... [bsky, 0 points, 0 comments]
- Ref for the data: www.gitclear.com/ai_assistant... dora.dev/research/202... arxiv.org/abs/2211.03622 [bsky, 0 points, 1 comments]
- Do Users Write More Insecure Code with AI Assistants? [yes] https://arxiv.org/abs/2211.03622 [bsky, 0 points, 0 comments]
- Pretty much: arxiv.org/abs/2211.03622 [bsky, 0 points, 0 comments]
- Surprising: no one, actually arxiv.org/abs/2211.03622 [bsky, 0 points, 0 comments]
Related