LLM写代码致密码安全渐失,用游戏化机制修复
Secure Coding Drift in LLM-Assisted Post-Quantum Cryptography Development: A Gamified Fix

- 将LLM生成代码的潜在风险建模为长期安全行为退化
- 通过对抗评估与反馈评分,提升密码实现安全性
- 适合密码工程与AI辅助开发团队使用
向后量子密码(PQC)迁移带来显著的实现复杂性,需严格遵守常量时间执行、抗侧信道攻击及精确参数配置。与此同时,大语言模型(LLMs)深度嵌入软件开发流程,包括密码工程领域。尽管提升效率,但已有证据表明,LLMs常生成不安全或次优代码,尤其在安全关键场景中。本文提出「PQC中的安全编码漂移」概念,构建一种新型社会技术脆弱性模型,刻画持续依赖LLM生成代码所导致的渐进式安全编码实践退化。不同于以往聚焦静态漏洞的研究,本工作将安全风险视为人类与AI交互引发的长期行为现象。为缓解该问题,我们提出一种游戏化、基于LLM增强的安全编码框架,将对抗性评估、行为反馈与安全评分嵌入开发流程。该方法使LLM从被动助手转变为积极的安全协作者,助力在人工智能驱动环境中实现更安全的后量子密码实现。
原文摘要 · Abstract (English)
The transition to Post Quantum Cryptography (PQC) introduces considerable implementation complexity, requiring strict adherence to constant-time execution, side channel resistance, and precise parametrisation. Simultaneously, large language models (LLMs) are heavily embedded in software development workflows, including cryptographic engineering. While LLMs improve productivity, evidence shows that they frequently generate insecure or suboptimal code, particularly in security critical domains. This paper introduces Secure Coding Drift in PQC, a novel socio technical vulnerability model capturing the gradual degradation of secure coding practices due to sustained reliance on LLM-generated code. Unlike prior work that focuses on static vulnerabilities, we conceptualise security risk as a longitudinal behavioural phenomenon rising from human AI interaction. To mitigate this, we propose a gamified, LLM augmented secure coding framework that embeds adversarial evaluation, behavioural feedback, and security scoring into development workflows. Our approach reframes LLMs from passive assistants into active security co-pilots, contributing toward safer PQC implementation in AI mediated environments.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。