arXiv:2506.16653cs.SEcs.AI2025-06被引 2

AI编程工具普及,但存在数据泄露与安全漏洞风险,需加强审查与防护。

LLMs in Coding and their Impact on the Commercial Software Engineering Landscape

  • 要求企业对每行AI生成代码进行标注与审查
  • 10%真实提示含私密数据,42%生成代码有安全缺陷
  • 适合关注AI编码安全的软件企业与合规团队

大型语言模型编程工具已广泛应用于软件工程。但随着人类工作向开发栈更高层转移,新风险随之出现:10%的真实提示会泄露私密数据,42%生成的代码片段隐藏安全漏洞,且模型可能表现出‘阿谀奉承’行为,即认同错误观点。我们主张企业必须对每一行AI生成的代码进行标记与审查,将提示和输出保留在私有或本地部署环境中,遵守新兴的安全法规,并添加能检测阿谀性回答的测试,以在提升效率的同时保障安全与准确性。

原文摘要 · Abstract (English)

Large-language-model coding tools are now mainstream in software engineering. But as these same tools move human effort up the development stack, they present fresh dangers: 10% of real prompts leak private data, 42% of generated snippets hide security flaws, and the models can even ``agree'' with wrong ideas, a trait called sycophancy. We argue that firms must tag and review every AI-generated line of code, keep prompts and outputs inside private or on-premises deployments, obey emerging safety regulations, and add tests that catch sycophantic answers -- so they can gain speed without losing security and accuracy.

AI编程代码安全LLM风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。