Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
Jan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik, Cordelia Ludden, Cordell Burton Jr., Carson Powers, Fabio Massacci, Akond Rahman, Daniel Votipka, Heather Richter Lipford, Awais Rashid, Alena Naiakshina, Sascha Fahl
摘要
Following the recent release of AI assistants, such as OpenAI's ChatGPT and GitHub Copilot, the software industry quickly utilized these tools for software development tasks, e.g., generating code or consulting AI for advice. While recent research has demonstrated that AI-generated code can contain security issues, how software professionals balance AI assistant usage and security remains unclear. This paper investigates how software professionals use AI assistants in secure software development, what security implications and considerations arise, and what impact they foresee on secure software development. We conducted 27 semi-structured interviews with software professionals, including software engineers, team leads, and security testers. We also reviewed 190 relevant Reddit posts and comments to gain insights into the current discourse surrounding AI assistants for software development. Our analysis of the interviews and Reddit posts finds that despite many security and quality concerns, participants widely use AI assistants for security-critical tasks, e.g., code generation, threat modeling, and vulnerability detection. Their overall mistrust leads to checking AI suggestions in similar ways to human code, although they expect improvements and, therefore, a heavier use for security tasks in the future. We conclude with recommendations for software professionals to critically check AI suggestions, AI creators to improve suggestion security and capabilities for ethical security tasks, and academic researchers to consider general-purpose AI in software development.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper13
- LLM Hallucinations in Practical Code Generation: Phenomena, Mechanism, and MitigationZiyao Zhang, Chong Wang, Yanlin Wang, Ensheng Shi 等ISSTA 2025 · 被引用 53 次
- An Investigation of Interaction and Information Needs for Protocol Reverse Engineering AutomationSamantha Katcher, James Mattei, Jared Chandler, Daniel VotipkaCHI 2025 · 被引用 7 次
- "That's another doom I haven't thought about": A User Study on AI Labels as a Safeguard Against Image-Based MisinformationSandra Höltervennhoff, Jonas Ricker, Maike M. Raphael, Charlotte Schwedes 等CHI 2026 · 被引用 2 次
- "Impressively Scary: ' Exploring User Perceptions and Reactions to Unraveling Machine Learning Models in Social Media ApplicationsJack West, Bengisu Cagiltay, Shirley Zhang, Jingjie Li 等CHI 2025 · 被引用 2 次
- 'Tab, Tab, Bug': Security Pitfalls of Next Edit Suggestions in AI-Integrated IDEsYunlong Lyu, Yixuan Tang, Peng Chen, Tian Dong 等CCS 2026 · 被引用 1 次
它引用的顶会 Paper22
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt 等S&P 2022 · 被引用 725 次
- You Get Where You're Looking for: The Impact of Information Sources on Code SecurityYasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim 等S&P 2016 · 被引用 325 次
- Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application SecurityFelix Fischer, Konstantin Böttinger, Huang Xiao, Christian Stransky 等S&P 2017 · 被引用 293 次
- Do Users Write More Insecure Code with AI Assistants?Neil Perry, Megha Srivastava, Deepak Kumar, Dan BonehCCS 2023 · 被引用 150 次
- Is Stack Overflow Obsolete? An Empirical Study of the Characteristics of ChatGPT Answers to Stack Overflow QuestionsSamia Kabir, David N. Udo-Imeh, Bonan Kou, Tianyi ZhangCHI 2024 · 被引用 149 次
相关 Paper
- Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI ModelsSanghak Oh, Kiho Lee, Seonhye Park, Doowon Kim 等S&P 2024 · 被引用 42 次
- Exploring the Impact of Intervention Methods on Developers' Security Behavior in a Manipulated ChatGPT StudyRaphael Serafini, Asli Yardim, Alena NaiakshinaCHI 2025 · 被引用 5 次
- A User-centered Security Evaluation of CopilotOwura Asare, Meiyappan Nagappan, N. AsokanICSE 2024 · 被引用 11 次
- "The AI tool can't make it any worse." Investigating Developers' Security Behavior with AI Assistants in a Password Storage StudyAsli Yardim, Raphael Serafini, Nadine Jost, Anna-Marie Ortloff 等CHI 2026 · 被引用 1 次
- 'Always Nice and Confident, Sometimes Wrong': Developer's Experiences Engaging Generative AI Chatbots Versus Human-Powered Q&A PlatformsJiachen Li, Elizabeth D. Mynatt, Varun Mishra, Jonathan BellCSCW 2025 · 被引用 8 次
