AI正被广泛用于软件漏洞管理,但误报和信任问题仍制约其落地。
Software Vulnerability Management in the Era of Artificial Intelligence: An Industry Perspective
- 通过60位从业者调研,分析AI工具在漏洞管理中的实际应用
- 69%用户满意当前使用,但误报和上下文缺失是主要痛点
- 建议提升可解释性与人机协同机制,适合开发者与安全工具设计者参考
人工智能(AI)已深刻改变软件开发,尤其在自动化重复任务、提升开发效率方面成效显著。然而,针对软件漏洞管理(SVM)的AI工具——如漏洞检测与修复——在产业实践中的应用仍缺乏深入研究。为填补这一空白,本研究调查了来自27个国家、不同行业的60名从业者,旨在了解AI工具在SVM中的采用程度、障碍与促进因素,并收集改进建议。结果显示,AI工具已被广泛应用于整个漏洞管理生命周期,69%的使用者表示满意。从业者认可其速度、覆盖范围和易用性,但普遍担忧误报、上下文缺失及信任问题。实际应用呈现社会技术融合特征:AI输出需经人工审核与组织治理。为此,我们建议增强可解释性、上下文感知能力、集成流程优化及验证机制。这些发现可为从业者、工具开发者与研究者提供实用指导,助力安全软件开发中AI的有效落地。
原文摘要 · Abstract (English)
Artificial Intelligence (AI) has revolutionized software development, particularly by automating repetitive tasks and improving developer productivity. While these advancements are well-documented, the use of AI-powered tools for Software Vulnerability Management (SVM), such as vulnerability detection and repair, remains underexplored in industry settings. To bridge this gap, our study aims to determine the extent of the adoption of AI-powered tools for SVM, identify barriers and facilitators to the use, and gather insights to help improve the tools to meet industry needs better. We conducted a survey study involving 60 practitioners from diverse industry sectors across 27 countries. The survey incorporates both quantitative and qualitative questions to analyze the adoption trends, assess tool strengths, identify practical challenges, and uncover opportunities for improvement. Our findings indicate that AI-powered tools are used throughout the SVM life cycle, with 69% of users reporting satisfaction with their current use. Practitioners value these tools for their speed, coverage, and accessibility. However, concerns about false positives, missing context, and trust issues remain prevalent. We observe a socio-technical adoption pattern in which AI outputs are filtered through human oversight and organizational governance. To support safe and effective use of AI for SVM, we recommend improvements in explainability, contextual awareness, integration workflows, and validation practices. We assert that these findings can offer practical guidance for practitioners, tool developers, and researchers seeking to enhance secure software development through the use of AI.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。