七款主流大模型生成代码均含高危漏洞,安全风险不容忽视。
Security of LLM-generated Code: A Comparative Analysis
- 对比测试七款主流LLM生成代码的漏洞情况。
- 所有模型生成代码均含漏洞,多数为高危或严重级别。
- 适合关注AI编程安全的开发者与安全研究人员参考。
目前,大多数软件开发者正在使用或计划使用人工智能(AI)工具辅助开发,主要出于提升效率和加速学习的目的。事实上,大型语言模型(LLM)生成的代码已进入生产环境,包括在多家科技公司中应用。然而,使用AI生成代码带来的安全风险引发关注。本文聚焦于软件安全问题,对七款主流大模型生成代码的安全性进行了实证评估。我们基于前人工作,模拟开发者使用LLM生成代码的实际行为。结果表明,所有被评估的七款大模型生成的代码均存在漏洞,其中多数漏洞属于高危或严重级别。
原文摘要 · Abstract (English)
The majority of software developers use or are planning to use Artificial Intelligence (AI) tools in their development processes. Their top reasons include improving productivity and faster learning. In fact, Large Language Model (LLM)-generated code is currently in production, including in major tech companies. However, concerns were raised about the risks associated with the use of AI tools to generate code. In this paper, we focus our attention on the risks to software security. We empirically evaluate the security of code generated by seven popular LLMs. We build upon previous work to mimic the behaviours of developers when using LLMs to generate code. Our results show that all seven LLMs that we have evaluated generate code that contains vulnerabilities, the majority of which are of critical or high severity.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。