SafeCoder vs. Closed-source Code Assistants
Related stories
Introducing CodeMender: an AI agent for code security
Using advanced AI to fix critical software vulnerabilities
Interpreting and Steering for Safe and Correct Code Generation
arXiv:2608.30025v1 Announce Type: new Abstract: Large language models (LLMs) frequently generate source code containing vulnerabilities, yet little work studies the internal mechanisms that distingui...
SecureVibeBench: Benchmarking Secure Vibe Coding of AI Agents via Reconstructing Vulnerability-Introducing Scenarios
arXiv:2509. 22097v5 Announce Type: replace-cross Abstract: Large language model-powered code agents are rapidly transforming software engineering, yet the security risks of their generated code have become a critical concern.
Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study
arXiv:2607. 11348v1 Announce Type: cross Abstract: AI code assistants are transforming software development, but their implications for software security remain a major concern, particularly in the context of security APIs.
Workspace Topology as an Attack Vector in Agentic Coding Assistants
arXiv:2608. 14876v1 Announce Type: cross Abstract: Agentic coding assistants are finding widespread use, not just in new code development but in quickly ingesting and leveraging third-party code.
Personal Copilot: Train Your Own Coding Assistant
Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks
The paper introduces SUSVIBES, a benchmark of 186 real‑world software engineering tasks where human programmers have committed vulnerable code. It evaluates 12 popular coding‑agent settings on these tasks and finds that all agents perform poorly in terms of security, with only 11.8% of solutions from SWE‑Agent with Claude 4 Sonnet being secure despite 57% being functionally correct. Attempts to mitigate security issues by adding vulnerability hints to the prompts do not improve results.
What is the Difference Between Me and You? Benchmarking the Quality Gap Between Human-Written and AI-Generated Code
arXiv:2609.12708v2 Announce Type: replace-cross Abstract: AI coding assistants are becoming co-authors of production software, yet their evaluation centers on functional correctness, leaving open whe...
Beware What You Autocomplete: Forensic Attribution of Backdoored Code Completions
arXiv:2607. 08011v1 Announce Type: cross Abstract: Large language models have enabled powerful code completion systems that assist developers by predicting subsequent lines of code.
IssueTrojanBench: Benchmarking AI Coding Agents Against Malicious Issue Requests
arXiv:2607. 20759v1 Announce Type: cross Abstract: AI coding agents powered by LLMs are increasingly integrated into real-world software development, where they generate, edit, and execute code with autonomous access to local files and tools.
Securing AI-Generated Code: A Just-in-Time Vulnerability Detection and Remediation Pipeline
arXiv:2608. 16187v1 Announce Type: cross Abstract: AI-assisted development tools generate vulnerable code at significant rates, yet few automated mechanisms exist to detect, enrich, fix, and verify security issues at development velocity, particularly ones that ground remediation in real-world threat context.