arXiv AI

Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study

arXiv:2607. 11348v1 Announce Type: cross Abstract: AI code assistants are transforming software development, but their implications for software security remain a major concern, particularly in the context of security APIs.

arXiv AI
Aug 19

From Adoption to Deployment: A Qualitative Study on AI Integration in Software Development Practice

The study investigates how software developers, architects, and AI practitioners select and integrate Large Language Models (LLMs) into modern software systems. Interviews with 22 professionals reveal that functional criteria—such as performance, accuracy, cost, and specific features—dominate model choice, while security concerns are rarely considered. The research highlights a pervasive neglect of established software supply‑chain security lessons, leading to vulnerabilities like malicious components, data leakage, and unintended behavior, and offers actionable recommendations for a proactive, security‑by‑design approach.

By Mahzabin Tamanna, Elizabeth Lin, Sparsha Gowda, Laurie Williams, Dominik Wermke
arXiv AI
Aug 5

AgenticSCR: An Autonomous Agentic Secure Code Review for Immature Vulnerabilities Detection

arXiv:2601. 19138v2 Announce Type: replace-cross Abstract: Secure code review is critical during pre-integration, where Atlassian developers rely on lightweight analysis tools, while deep security assessment is deferred to later stages, delaying feedback and increasing remediation costs.

By Wachiraphan Charoenwet, Kla Tantithamthavorn, Patanamon Thongtanunam, Hong Yi Lin, Minwoo Jeong, Ming Wu
arXiv AI
Aug 18

Workspace Topology as an Attack Vector in Agentic Coding Assistants

arXiv:2608. 14876v1 Announce Type: cross Abstract: Agentic coding assistants are finding widespread use, not just in new code development but in quickly ingesting and leveraging third-party code.

By Alexandre G. R. Day, Pradeep Yadlapalli, Sriram Venkatapathy, Thomas Paniagua, Nick Raines, Sahil Wadhwa, Himanshu Kumar, Andy Luo, Sudeep Panyam, Rikhiya Ghosh, Pranab Mohanty, Giri Iyengar
arXiv AI
Aug 24

Vibe Coding and Web Application Security: A Twin-Prompt Study

The study examines how adding a security-requirements section to prompts affects web applications generated by a large language model. Six distinct applications were produced twice—once with a baseline prompt and once with a security-aware prompt—yielding 12 programs. Analysis of these programs revealed 75 confirmed security findings, with the security-aware variants showing fewer issues (24 vs. 51) and no Critical or High severity problems.

By Darko Andro\v{c}ec