SafeCoder vs. Closed-source Code Assistants
Related stories
Introducing CodeMender: an AI agent for code security
Using advanced AI to fix critical software vulnerabilities
SecureVibeBench: Benchmarking Secure Vibe Coding of AI Agents via Reconstructing Vulnerability-Introducing Scenarios
arXiv:2509. 22097v5 Announce Type: replace-cross Abstract: Large language model-powered code agents are rapidly transforming software engineering, yet the security risks of their generated code have become a critical concern.
Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study
arXiv:2607. 11348v1 Announce Type: cross Abstract: AI code assistants are transforming software development, but their implications for software security remain a major concern, particularly in the context of security APIs.
Workspace Topology as an Attack Vector in Agentic Coding Assistants
arXiv:2608. 14876v1 Announce Type: cross Abstract: Agentic coding assistants are finding widespread use, not just in new code development but in quickly ingesting and leveraging third-party code.
Personal Copilot: Train Your Own Coding Assistant
Beware What You Autocomplete: Forensic Attribution of Backdoored Code Completions
arXiv:2607. 08011v1 Announce Type: cross Abstract: Large language models have enabled powerful code completion systems that assist developers by predicting subsequent lines of code.
IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests
arXiv:2607. 20759v1 Announce Type: cross Abstract: AI coding agents powered by LLMs are increasingly integrated into real-world software development, where they generate, edit, and execute code with autonomous access to local files and tools.
Securing AI-Generated Code: A Just-in-Time Vulnerability Detection and Remediation Pipeline
arXiv:2608. 16187v1 Announce Type: cross Abstract: AI-assisted development tools generate vulnerable code at significant rates, yet few automated mechanisms exist to detect, enrich, fix, and verify security issues at development velocity, particularly ones that ground remediation in real-world threat context.
Coding with "Enemy": Can Human Developers Detect AI Agent Sabotage?
arXiv:2606. 05647v1 Announce Type: new Abstract: AI coding agents are increasingly embedded in real-world software development, collaborating with human developers while gaining broader access to codebases and tools.
Creating a Coding Assistant with StarCoder
Code-Poisoning Property Inference Attacks
arXiv:2607. 15970v1 Announce Type: cross Abstract: The flourishing code hosting platforms and coding agents enable even beginners with private data to build tailored Machine Learning (ML) models using available code quickly.