Exploring the Impact of Intervention Methods on Developers' Security Behavior in a Manipulated ChatGPT Study
Raphael Serafini, Asli Yardim, Alena Naiakshina
Abstract
Increased AI use in software development raises concerns about AI-generated code security. We investigated the impact of security prompts, insecure AI suggestion warnings, and the use of password storage guidelines (OWASP, NIST) on the security behavior of software developers when presented with insecure AI assistance. In an online lab setting, we conducted a study with 76 freelance developers who completed a password storage task divided into four conditions. Three conditions included a manipulated ChatGPT-like AI assistant, suggesting an insecure MD5 implementation. We found a high level of trust in AI-generated code, even when insecure suggestions were presented. While security prompts, AI warnings, and guidelines improved security awareness, 32% of those notified about insecure AI recommendations still accepted weak implementation suggestions, mistakenly considering it secure and often expressing confidence in their choice. Based on our results, we discuss security implications and provide recommendations for future research.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 760dab71-228d-4579-8fde-191967c92d0dCited by top-tier papers1
Ask how each one uses itRelated papers
- "The AI tool can't make it any worse." Investigating Developers' Security Behavior with AI Assistants in a Password Storage StudyAsli Yardim, Raphael Serafini, Nadine Jost, Anna-Marie Ortloff et al.CHI 2026 · 1 citation
- Using AI Assistants in Software Development: A Qualitative Study on Security Practices and ConcernsJan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden et al.CCS 2024 · 14 citations
- Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI ModelsSanghak Oh, Kiho Lee, Seonhye Park, Doowon Kim et al.S&P 2024 · 42 citations
- Trust Dynamics in AI-Assisted Development: Definitions, Factors, and ImplicationsSadra Sabouri, Philipp Eibl, Xinyi Zhou, Morteza Ziyadi et al.ICSE 2025 · 2 citations
- Lost at C: A User Study on the Security Implications of Large Language Model Code AssistantsGustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri et al.USENIX Security 2023
