Unsafe Code Still a Hurdle Copilot Must Clear.

This paper investigates the security implications of code generated by large language models (LLMs) like GitHub Copilot, which is trained on public repositories to assist developers with code completion. A systematic analysis of 89 programming scenarios revealed that around 40% of Copilot's outputs...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 68; no. 2; pp. 95 - 96
Autor principal: Holz, Thorsten
Formato: Artículo
Publicado: Association for Computing Machinery Feb2025
Materias:
Acceso en línea:Ver este registro en EBSCOhost
fields @attributes:
  recordID: 1
pdfLink:
plink: https://search.ebscohost.com/login.aspx?direct=true&db=hlh&AN=182365556&site=ehost-live
header:
  @attributes:
    shortDbName: hlh
    uiTerm: 182365556
    longDbName: Humanities International Complete
    uiTag: AN
  controlInfo:
    bkinfo:
    jinfo:
      jid:
        00010782
        ACM
      jtl: Communications of the ACM
      issn: 00010782
      maglogo: N
    pubinfo:
      dt: Feb2025
      vid: 68
      iid: 2
      pid: 68
      pub: Association for Computing Machinery
    artinfo:
      ui:
        182365556
        10.1145/3660529
      ppf: 95
      ppct: 1
      formats:
      tig:
        atl: Unsafe Code Still a Hurdle Copilot Must Clear.
      aug:
        au: Holz, Thorsten
        affil: CISPA Helmholtz Center for Information Security, Saarbrücken, Germany
      su:
        Language models
        Computer software development
        Generative artificial intelligence
        Computer programming
        Computer software quality control
      sug:
        subj:
          Language models
          Computer software development
          Generative artificial intelligence
          Computer programming
          Computer software quality control
      ab: This paper investigates the security implications of code generated by large language models (LLMs) like GitHub Copilot, which is trained on public repositories to assist developers with code completion. A systematic analysis of 89 programming scenarios revealed that around 40% of Copilot's outputs contained vulnerabilities, often reflecting insecure coding practices present in its training data. The study highlights the need for prompt engineering, manual oversight, and secure coding standards to mitigate risks, emphasizing the importance of combining LLMs with traditional security practices for reliable and safe software development.
      pubtype: Periodical
      doctype: Article
      src: R
    language: English
    refInfo:
    copyright:
      @attributes:
        flag: Y
      dt:
        @attributes:
          year: 2025
    holdings:
      @attributes:
        islocal: N