Comment Traps: How Defective Commented-Out Code Augment Defects in AI-Assisted Code Generation
Yuan Huang, Yukang Zhou, Xiangping Chen, Zibin Zheng
摘要
With the rapid development of large language models in code generation, AI-powered editors such as GitHub Copilot and Cursor are revolutionizing software development practices. At the same time, studies have identified potential defects in the generated code. Previous research has predominantly examined how code context influences the generation of defective code, often overlooking the impact of defects within commentedout code (CO code). AI coding assistants' interpretation of CO code in prompts affects the code they generate.
This study evaluates how AI coding assistants, GitHub Copilot and Cursor, are influenced by defective CO code. The experimental results show that defective CO code in the context causes AI coding assistants to generate more defective code, reaching up to 58.17 percent. Our findings further demonstrate that the tools do not simply copy the defective code from the context. Instead, they actively reason to complete incomplete defect patterns and continue to produce defective code despite distractions such as incorrect indentation or tags. Even with explicit instructions to ignore the defective CO code, the reduction in defects does not exceed 21.84 percent. These findings underscore the need for improved robustness and security measures in AI coding assistants.
CCS Concepts: • Software and its engineering → Automatic programming; Software defect analysis.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper3
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code ContributionsHammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt 等S&P 2022 · 被引用 725 次
- JIT-Smart: A Multi-task Learning Framework for Just-in-Time Defect Prediction and LocalizationXiangping Chen, Furen Xu, Yuan Huang, Neng Zhang 等FSE 2024 · 被引用 11 次
- Are Prompt Engineering and TODO Comments Friends or Foes? An Evaluation on GitHub CopilotDavid O'Brien, Sumon Biswas, Sayem Mohammad Imtiaz, Rabe Abdalkareem 等ICSE 2024 · 被引用 7 次
相关 Paper
- Poisoned ChatGPT Finds Work for Idle Hands: Exploring Developers' Coding Practices with Insecure Suggestions from Poisoned AI ModelsSanghak Oh, Kiho Lee, Seonhye Park, Doowon Kim 等S&P 2024 · 被引用 42 次
- A User-centered Security Evaluation of CopilotOwura Asare, Meiyappan Nagappan, N. AsokanICSE 2024 · 被引用 11 次
- Impeding LLM-assisted Cheating in Introductory Programming Assignments via Adversarial PerturbationSaiful Islam Salim, Rubin Yuchan Yang, Alexander Cooper, Suryashree Ray 等EMNLP 2024 · 被引用 4 次
- Lost at C: A User Study on the Security Implications of Large Language Model Code AssistantsGustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri 等USENIX Security 2023
- Do Users Write More Insecure Code with AI Assistants?Neil Perry, Megha Srivastava, Deepak Kumar, Dan BonehCCS 2023 · 被引用 150 次
