Fetching the paper…
Reading the bibliography…
Sonatype's 2023 report found that 97% of developers and security leads integrate generative Artificial Intelligence (AI), particularly Large Language Models (LLMs), into their development process.
CRC Press, 2014
J. Kloke and J. W. McKean, Nonparametric statistical methods using R · 2014
Earlier work this paper cites.
Y. Acar, M. Backes, S. Fahl, D. Kim, M. L. Mazurek, and C. Stransky, “You Get Where You’re Looking for: The Impact of Information Sources on Code Security,” in 2016 IEEE Symposium on Security and Privacy (SP)
2016
Earlier work this paper cites.
F. Fischer, K. Bottinger, H. Xiao, C. Stransky, Y. Acar, M. Backes, and S. Fahl, “Stack Overflow Considered Harmful? The Impact of Copy&Paste on Android Application Security,” in 2017 IEEE Symposium on Security and Privacy (SP)
2017
Earlier work this paper cites.
P. Morrison, D. Moye, R. Pandita, and L. Williams, “Mapping the field of software life cycle security metrics,” Information and Software Technology
2018
Earlier work this paper cites.
M. Chen, F. Fischer, N. Meng, X. Wang, and J. Grossklags, “How Reliable is the Crowdsourced Knowledge of Security Implementation?,” in 2019 IEEE/ACM 41st International Conference on Software Engineering (ICSE)
2019
Earlier work this paper cites.
A. Rahman, E. Farhana, and N. Imtiaz, “Snakes in paradise?: Insecure python-related coding practices in stack overflow,” in 2019 IEEE/ACM 16th International Conference on Mining Software Repositories (MSR)
2019
Earlier work this paper cites.
W. Bai, O. Akgul, and M. L. Mazurek, “A Qualitative Investigation of Insecure Code Propagation from Online Forums,” in 2019 IEEE Cybersecurity Development (SecDev)
2019
Earlier work this paper cites.
M. Ohm, H. Plate, A. Sykosch, and M. Meier, “Backstabber’s knife collection: A review of open source software supply chain attacks,” in Detection of Intrusions and Malware, and Vulnerability Assessment: 17th International Conference, DIMVA 2020, Lisbon, Portugal, June 24–26, 2020, Proceedings 17
2020
Earlier work this paper cites.
H. Hong, S. Woo, and H. Lee, “Dicos: Discovering Insecure Code Snippets from Stack Overflow Posts by Leveraging User Discussions,” in Annual Computer Security Applications Conference
2021
Earlier work this paper cites.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, “Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions,” in 2022 IEEE Symposium on Security and Privacy (SP)
2022
Earlier work this paper cites.
M. L. Siddiq, S. H. Majumder, M. R. Mim, S. Jajodia, and J. C. S. Santos, “An Empirical Study of Code Smells in Transformer-based Code Generation Techniques,” in 2022 IEEE 22nd International Working Conference on Source Code Analysis and Manipulation (SCAM)
2022
Earlier work this paper cites.
H. Zhang, S. Wang, H. Li, T.-H. Chen, and A. E. Hassan, “A Study of C/C++ Code Weaknesses on Stack Overflow,” IEEE Transactions on Software Engineering
2022
Earlier work this paper cites.
S. Baltes and P. Ralph, “Sampling in software engineering research: A critical review and guidelines,” Empirical Software Engineering
2022
Earlier work this paper cites.
S. Elder, N. Zahan, R. Shu, M. Metro, V. Kozarev, T. Menzies, and L. Williams, “Do I really need all this work to find vulnerabilities?: An empirical case study comparing vulnerability detection techniques on a Java application,” Empirical Software Engineering
2022
Earlier work this paper cites.
F. Fischer and J. Grossklags, “Nudging software developers toward secure code,” IEEE Security & Privacy
2022
Earlier work this paper cites.
N. Zahan, T. Zimmermann, P. Godefroid, B. Murphy, C. Maddila, and L. Williams, “What are weak links in the npm supply chain?,” in Proceedings of the 44th International Conference on Software Engineering: Software Engineering in Practice
2022
Earlier work this paper cites.
N. Nguyen and S. Nadi, “An empirical evaluation of GitHub copilot’s code suggestions,” in Proceedings of the 19th International Conference on Mining Software Repositories
2022
Earlier work this paper cites.
N. Al Madi, “How Readable is Model-generated Code? Examining Readability and Visual Inspection of GitHub Copilot,” in Proceedings of the 37th IEEE/ACM International Conference on Automated Software Engineering
2022
Earlier work this paper cites.
P. Vaithilingam, T. Zhang, and E. L. Glassman, “Expectation vs. Experience: Evaluating the Usability of Code Generation Tools Powered by Large Language Models,” in Extended Abstracts of the 2022 CHI Conference on Human Factors in Computing Systems
2022
Earlier work this paper cites.
M. L. Siddiq and J. C. S. Santos, “SecurityEval dataset: Mining vulnerability examples to evaluate machine learning-based code generation techniques,” in Proceedings of the 1st International Workshop on Mining Software Repositories Applications for Privacy and Security
2022
Cited alongside, same era.
Sonatype, “Annual State of the Software Supply Chain,” 2023
2023
Cited alongside, same era.
GitHub, “The state of open source software.” https://octoverse.github.com/ , 2023
2023
Cited alongside, same era.
2023
Cited alongside, same era.
M. D. Purba, A. Ghosh, B. J. Radford, and B. Chu, “Software vulnerability detection using large language models,” in 2023 IEEE 34th International Symposium on Software Reliability Engineering Workshops (ISSREW)
2023
Later among the works it cites.
A. Happe and J. Cito, “Getting pwn’d by ai: Penetration testing with large language models,” in Proceedings of the 31st ACM Joint European Software Engineering Conference and Symposium on the Foundations of Software Engineering
2023
Later among the works it cites.
2023
Later among the works it cites.
2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2023
Cited alongside, same era.
2023
Cited alongside, same era.
2023
Cited alongside, same era.
Sonatype, “The Risks and Rewards of Generative AI in Software Development,” 2023
2023
Cited alongside, same era.
2023
Cited alongside, same era.
B. Xu, T.-D. Nguyen, T. Le-Cong, T. Hoang, J. Liu, K. Kim, C. Gong, C. Niu, C. Wang, B. Le, et al
2023
Cited alongside, same era.
“Stack Exchange.” https://stackexchange.com/sites , 2023
2023
Cited alongside, same era.
StackOverflow, “2023 Developer Survey.” https://survey.stackoverflow.co/2023 , 2023
2023
Cited alongside, same era.
2023
Later among the works it cites.
A. Moradi Dakhel, V. Majdinasab, A. Nikanjam, F. Khomh, M. C. Desmarais, and Z. M. J. Jiang, “GitHub Copilot AI pair programmer: Asset or Liability?,” Journal of Systems and Software
2023
Later among the works it cites.
2023
Later among the works it cites.
N. Perry, M. Srivastava, D. Kumar, and D. Boneh, “Do users write more insecure code with AI assistants?,” in Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security
2023
Later among the works it cites.
G. Sandoval, H. Pearce, T. Nys, R. Karri, S. Garg, and B. Dolan-Gavitt, “Lost at c: A user study on the security implications of large language model code assistants,” in 32nd USENIX Security Symposium (USENIX Security 23)
2023
Later among the works it cites.
O. Asare, M. Nagappan, and N. Asokan, “Is GitHub’s Copilot as Bad as Humans at Introducing Vulnerabilities in Code?,” Empirical Software Engineering
2023
Later among the works it cites.
OpenAI, “ChatGPT.” https://chat.openai.com/ , 2024
2024
Closest in time.
StackOverflow, “StackOverflow.” https://stackoverflow.com/ , 2024
2024
Closest in time.
GitHub, “CodeQL.” https://codeql.github.com/ , 2024
2024
Closest in time.
StackExchange, “StackExchange API.” https://api.stackexchange.com/ , 2024
2024
Closest in time.
B. Soup, “Beautiful Soup Documentation.” https://beautiful-soup-4.readthedocs.io/ , 2024
2024
Closest in time.
javalang, “javalang.” https://github.com/c2nes/javalang , 2024
2024
Closest in time.
OpenAI, “OpenAI Python API library.” https://github.com/openai/openai-python , 2024
2024
Closest in time.