Fetching the paper…
Reading the bibliography…
The increasing trend of using Large Language Models (LLMs) for code generation raises the question of their capability to generate trustworthy code.
Usability implications of requiring parameters in objects’ constructors
Jeffrey Stylos and Steven Clarke · 2007
Earlier work this paper cites.
Recommendation for key management part 3: Application-specific key management guidance
Elaine Barker, William Burr, Alicia Jones, Timothy Polk, Scott Rose, Miles Smid, Quynh Dang, et al · 2009
Earlier work this paper cites.
The most dangerous code in the world: validating ssl certificates in non-browser software
Martin Georgiev, Subodh Iyengar, Suman Jana, Rishita Anubhai, Dan Boneh, and Vitaly Shmatikov · 2012
Earlier work this paper cites.
Why eve and mallory love android: An analysis of android ssl (in) security
Sascha Fahl, Marian Harbach, Thomas Muders, Lars Baumgärtner, Bernd Freisleben, and Matthew Smith · 2012
Earlier work this paper cites.
RFC 6749: The OAuth 2.0 authorization framework, 2012
Dick Hardt · 2012
Earlier work this paper cites.
The devil is in the (implementation) details: an empirical analysis of oauth sso systems
San-Tsai Sun and Konstantin Beznosov · 2012
Earlier work this paper cites.
An empirical study of cryptographic misuse in android applications
Manuel Egele, David Brumley, Yanick Fratantonio, and Christopher Kruegel · 2013
Earlier work this paper cites.
Oauth demystified for mobile application developers
Eric Y Chen, Yutong Pei, Shuo Chen, Yuan Tian, Robert Kotcher, and Patrick Tague · 2014
Earlier work this paper cites.
Vulnerability assessment of oauth implementations in android applications
Hui Wang, Yuanyuan Zhang, Juanru Li, Hui Liu, Wenbo Yang, Bodong Li, and Dawu Gu · 2015
Earlier work this paper cites.
Proof key for code exchange by OAuth public clients
Nat Sakimura, John Bradley, and Naveen Agarwal · 2015
Earlier work this paper cites.
Helping johnny encrypt: Toward semantic interfaces for cryptographic frameworks
Soumya Indela, Mukul Kulkarni, Kartik Nayak, and Tudor Dumitraş · 2016
Earlier work this paper cites.
Cdrep: Automatic repair of cryptographic misuses in android applications
Siqi Ma, David Lo, Teng Li, and Robert H Deng · 2016
Earlier work this paper cites.
Towards the usability evaluation of security APIs
Peter Leo Gorski and Luigi Lo Iacono · 2016
Earlier work this paper cites.
You get where you’re looking for: The impact of information sources on code security
Yasemin Acar, Michael Backes, Sascha Fahl, Doowon Kim, Michelle L Mazurek, and Christian Stransky · 2016
Earlier work this paper cites.
A stitch in time: Supporting android developers in writingsecure code
Duc Cuong Nguyen, Dominik Wermke, Yasemin Acar, Michael Backes, Charles Weir, and Sascha Fahl · 2017
Earlier work this paper cites.
Comparing the usability of cryptographic APIs
Yasemin Acar, Michael Backes, Sascha Fahl, Simson Garfinkel, Doowon Kim, Michelle L Mazurek, and Christian Stransky · 2017
Earlier work this paper cites.
Security developer studies with { \{ GitHub } \} users: Exploring a convenience sample
Yasemin Acar, Christian Stransky, Dominik Wermke, Michelle L Mazurek, and Sascha Fahl · 2017
Earlier work this paper cites.
RFC 8018: PKCS# 5: Password-based cryptography specification version 2.1, 2017
Burt Kaliski and A Rusch · 2017
Earlier work this paper cites.
Yarik markov, alex petit bianco, and clement baisse. announcing the first sha1 collision
Marc Stevens, Elie Bursztein, Pierre Karpman, and Ange Albertini · 2017
Earlier work this paper cites.
Broken Fingers: On the Usage of the Fingerprint API in Android
Antonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel, Giovanni Vigna, Simon Pak Ho Chung, and Wenke Lee · 2018
Earlier work this paper cites.
Developers deserve security warnings, too: On the effect of integrated security advice on cryptographic { \{ API } \} misuse
Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian M"̈oller, Yasemin Acar, and Sascha Fahl · 2018
Earlier work this paper cites.
Why johnny can’t store passwords securely? a usability evaluation of bouncycastle password hashing
Chamila Wijayarathna and Nalin AG Arachchilage · 2018
Earlier work this paper cites.
Security in the software development lifecycle
Hala Assal and Sonia Chiasson · 2018
Earlier work this paper cites.
Inferring crypto api rules from code changes
Rumen Paletov, Petar Tsankov, Veselin Raychev, and Martin Vechev · 2018
Earlier work this paper cites.
Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized java projects
Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, and Danfeng Yao · 2019
Cited alongside, same era.
Oauthlint: An empirical study on oauth bugs in android applications
Tamjid Al Rahat, Yu Feng, and Yuan Tian · 2019
Cited alongside, same era.
CrySL: An extensible approach to validating the correct usage of cryptographic APIs
Stefan Krüger, Johannes Späth, Karim Ali, Eric Bodden, and Mira Mezini · 2019
Cited alongside, same era.
The impact of developer experience in using Java cryptography
Mohammadreza Hazhirpasand, Mohammad Ghafari, Stefan Krüger, Eric Bodden, and Oscar Nierstrasz · 2019
Cited alongside, same era.
Big code!= big vocabulary: Open-vocabulary models for source code
Rafael-Michael Karampatsis, Hlib Babii, Romain Robbes, Charles Sutton, and Andrea Janes · 2020
Cited alongside, same era.
Statistics of chatgpt & generative ai in business: 2023 report, 2023
master of code · 2023
Later among the works it cites.
Security weaknesses of copilot generated code in github
Yujia Fu, Peng Liang, Amjed Tahir, Zengyang Li, Mojtaba Shahin, and Jiaxin Yu · 2023
Later among the works it cites.
Is github’s copilot as bad as humans at introducing vulnerabilities in code?
Owura Asare, Meiyappan Nagappan, and N Asokan · 2023
Later among the works it cites.
Lost at c: A user study on the security implications of large language model code assistants
Gustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri, Siddharth Garg, and Brendan Dolan-Gavitt · 2023
Later among the works it cites.
Do users write more insecure code with ai assistants?
Neil Perry, Megha Srivastava, Deepak Kumar, and Dan Boneh · 2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
On conducting security developer studies with cs students: Examining a password-storage study with cs students, freelancers, and company developers
Alena Naiakshina, Anastasia Danilova, Eva Gerlitz, and Matthew Smith · 2020
Cited alongside, same era.
Identifying vulnerabilities of ssl/tls certificate verification in android apps with static and dynamic analysis
Yingjie Wang, Guangquan Xu, Xing Liu, Weixuan Mao, Chengxiang Si, Witold Pedrycz, and Wei Wang · 2020
Cited alongside, same era.
Fluentcrypto: Cryptography in easy mode
Simon Kafader and Mohammad Ghafari · 2021
Cited alongside, same era.
Firebugs: Finding and repairing cryptography api misuses in mobile applications
Larry Singleton, Rui Zhao, Harvey Siy, and Myoungkyu Song · 2021
Cited alongside, same era.
Python crypto misuses in the wild
Anna-Katharina Wickert, Lars Baumgärtner, Florian Breitfelder, and Mira Mezini · 2021
Cited alongside, same era.
Asleep at the keyboard? assessing the security of github copilot’s code contributions
Hammond Pearce, Baleegh Ahmad, Benjamin Tan, Brendan Dolan-Gavitt, and Ramesh Karri · 2022
Cited alongside, same era.
An empirical study of code smells in transformer-based code generation techniques
Mohammed Latif Siddiq, Shafayat H Majumder, Maisha R Mim, Sourov Jajodia, and Joanna CS Santos · 2022
Cited alongside, same era.
Zahra Mousavi, Chadni Islam, M Ali Babar, Alsharif Abuadbba, and Kristen Moore · 2023
Later among the works it cites.
Fingerprint api, a
Google · 2023
Later among the works it cites.
Safetynet attestation, b
Google · 2023
Later among the works it cites.
Biometrics api, c
Google · 2023
Later among the works it cites.
Play integrity, d
Google · 2023
Later among the works it cites.
Don’t call it a comeback: Why java is still champ, 2022
MIKE MELANSON · 2023
Later among the works it cites.
Pypl popularity of programming language, 2023
Pierre Carbonnelle · 2023
Later among the works it cites.
Oauth api, 2023
Google · 2023
Later among the works it cites.
A prompt pattern catalog to enhance prompt engineering with chatgpt
Jules White, Quchen Fu, Sam Hays, Michael Sandborn, Carlos Olea, Henry Gilbert, Ashraf Elnashar, Jesse Spencer-Smith, and Douglas C Schmidt · 2023
Later among the works it cites.
URL https://github.com/CryptoGuardOSS/cryptoapi-bench
CryptoAPI-Bench, 2019 · 2023
Later among the works it cites.
URL https://github.com/CryptoAPI-Bench/ApacheCryptoAPI-Bench
ApacheCryptoAPI-Bench, 2020 · 2023
Later among the works it cites.
URL https://GitHub.com/stg-tud/MUBench
MUBench, 2016 · 2023
Later among the works it cites.
Googlenethttptransport, e
Google · 2023
Later among the works it cites.
Nethttptransport, f
Google · 2023
Later among the works it cites.
Cryptography for biometric authentication, g
Google · 2023
Later among the works it cites.
Android local authentication
OWASP · 2023
Later among the works it cites.
URL https://github.com/LLM-security-study/ChatGPT
Resources for the research on "Evaluating the Trustworthiness of Large Language Models in Generating Secure Security API Code", 2023 · 2023
Later among the works it cites.
OAuth 2.0 for Mobile & Desktop Apps, h
Google · 2023
Later among the works it cites.
Breaking the silence: the threats of using llms in software engineering
J. Sallou, T. Durieux, and A. Panichella · 2024
Closest in time.