Fetching the paper…
Reading the bibliography…
Large Language Models (LLMs) such as ChatGPT and GitHub Copilot have revolutionized automated code generation in software engineering.
D. Guo, S. Ren, S. Lu, Z. Feng, D. Tang, S. Liu, L. Zhou, N. Duan, A. Svyatkovskiy, S. Fu, M. Tufano, S. K. Deng, C. Clement, D. Drain, N. Sundaresan, J. Yin, D. Jiang, M. Zhou, Graphcodebert: Pre-training code representations with data flow (2021) · 2009
Earlier work this paper cites.
H. H. AlBreiki, Q. H. Mahmoud, Evaluation of static analysis tools for software security, in: 2014 10th International Conference on Innovations in Information Technology (IIT), IEEE, 2014, pp. 93–98
2014
Earlier work this paper cites.
M. Felderer, M. Büchler, M. Johns, A. D. Brucker, R. Breu, A. Pretschner, Security testing: A survey, in: Advances in Computers, Vol. 101, Elsevier, 2016, pp. 1–51
2016
Earlier work this paper cites.
A. Vaswani, N. Shazeer, N. Parmar, J. Uszkoreit, L. Jones, A. N. Gomez, L. u. Kaiser, I. Polosukhin, Attention is all you need, in: Advances in Neural Information Processing Systems, Vol. 30, Curran Associates, Inc., 2017
2017
Earlier work this paper cites.
doi:10.1109/TSE.2018.2880977
E. V. d. P. Sobrinho, A. De Lucia, M. d. A. Maia, A systematic literature review on bad smells–5 w’s: Which, when, what, who, where, IEEE Trans. Softw. Eng. 47 (1) (2021) 17–66 · 2018
Earlier work this paper cites.
OWASP Foundation, Owasp application security verification standard 4.0 , accessed: 2023-09-24 (2019). URL https://owasp.org/www-pdf-archive/OWASP_Application_Security_Verification_Standard_4.0-en.pdf
2019
Earlier work this paper cites.
X. Xia, Z. Wan, P. S. Kochhar, D. Lo, How practitioners perceive coding proficiency, IEEE/ACM 41st International Conference on Software Engineering (2019)
2019
Earlier work this paper cites.
doi:10.1109/TSE.2020.3023664
M. Verdi, A. Sami, J. Akhondali, F. Khomh, G. Uddin, A. K. Motlagh, An empirical study of c++ vulnerabilities in crowd-sourced code examples, IEEE Transactions on Software Engineering 48 (5) (2022) 1497–1514 · 2020
Earlier work this paper cites.
D. Votipka, K. R. Fulton, J. Parker, M. Hou, M. L. Mazurek, M. Hicks, Understanding security mistakes developers make: qualitative analysis from build it, break it, fix it, in: Proceedings of the 29th USENIX Conference on Security Symposium, SEC’20, USENIX Association, USA, 2020
2020
Earlier work this paper cites.
2020
Earlier work this paper cites.
T. Rangnau, R. v. Buijtenen, F. Fransen, F. Turkmen, Continuous security testing: A case study on integrating dynamic security testing tools in ci/cd pipelines, in: 2020 IEEE 24th International Enterprise Distributed Object Computing Conference (EDOC), IEEE, 2020, pp. 145–154
2020
Earlier work this paper cites.
2021
Earlier work this paper cites.
doi:10.1007/s10664-021-09959-3
G. A. A. Prana, A. Sharma, L. K. Shar, D. Foo, A. E. Santosa, A. Sharma, D. Lo, Out of sight, out of mind? how vulnerable dependencies affect open-source projects, Empirical Softw. Engg. 26 (4) (jul 2021) · 2021
Earlier work this paper cites.
doi:10.18653/v1/2021.findings-emnlp.232
M. R. Parvez, W. Ahmad, S. Chakraborty, B. Ray, K.-W. Chang, Retrieval augmented code generation and summarization, in: M.-F. Moens, X. Huang, L. Specia, S. W.-t. Yih (Eds.), Findings of the Association for Computational Linguistics: EMNLP 2021, Association for Computational Linguistics, Punta Cana, Dominican Republic, 2021, pp. 2719–2734 · 2021
Earlier work this paper cites.
2021
Earlier work this paper cites.
doi:10.1109/ICMT52455.2021.9502768
A. Coufalíková, I. Klaban, T. Šlajs, Complex strategy against supply chain attacks, in: 2021 International Conference on Military Technologies (ICMT), 2021, pp. 1–5 · 2021
Earlier work this paper cites.
National Institute of Standards and Technology (NIST), Secure software development framework (ssdf), https://csrc.nist.gov/projects/ssdf , accessed: 2024-02-24 (2021)
2021
Earlier work this paper cites.
O. B. Tauqeer, S. Jan, A. O. Khadidos, A. O. Khadidos, F. Q. Khan, S. Khattak, Analysis of security testing techniques, Intelligent Automation & Soft Computing 29 (1) (2021) 291–306
2021
Earlier work this paper cites.
Microsoft, Security development lifecycle , accessed: 2023-09-24 (2021). URL https://www.microsoft.com/en-us/securityengineering/sdl/
2021
Earlier work this paper cites.
A. Nguyen-Duc, M. V. Do, Q. L. Hong, K. N. Khac, A. N. Quang, On the adoption of static analysis for software security assessment–a case study of an open-source e-government project, computers & security 111 (2021) 102470
2021
Earlier work this paper cites.
2022
Earlier work this paper cites.
Y. Wang, H. Le, A. Gotmare, J. Li, S. Hoi, Codet5mix: A pretrained mixture of encoder-decoder transformers for code understanding and generation (2022). URL https://openreview.net/forum?id=VPCi3STZcaO
2022
Earlier work this paper cites.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, R. Karri, Asleep at the keyboard? assessing the security of github copilot’s code contributions, in: 2022 IEEE Symposium on Security and Privacy (SP), IEEE, 2022, pp. 754–768
2022
Earlier work this paper cites.
doi:10.1145/3520312.3534862
F. F. Xu, U. Alon, G. Neubig, V. J. Hellendoorn, A systematic evaluation of large language models of code, in: Proceedings of the 6th ACM SIGPLAN International Symposium on Machine Programming, MAPS 2022, Association for Computing Machinery, New York, NY, USA, 2022, p. 1–10 · 2022
Earlier work this paper cites.
Y. Li, S. Qi, C. Gao, Y. Peng, D. Lo, Z. Xu, M. R. Lyu, A closer look into transformer-based code intelligence through code transformation: Challenges and opportunities (2022) · 2022
Earlier work this paper cites.
J. Finnie-Ansley, P. Denny, B. A. Becker, A. Luxton-Reilly, J. Prather, The robots are coming: Exploring the implications of openai codex on introductory programming, in: Proceedings of the 24th Australasian Computing Education Conference, 2022, pp. 10–19
2022
Cited alongside, same era.
S. Cordey, Software supply chain attacks: An illustrated typological review, CSS Cyberdefense Reports (2022)
2022
Cited alongside, same era.
doi:10.1145/3511861.3511863
J. Finnie-Ansley, P. Denny, B. A. Becker, A. Luxton-Reilly, J. Prather, The robots are coming: Exploring the implications of openai codex on introductory programming, in: Proceedings of the 24th Australasian Computing Education Conference, ACE ’22, Association for Computing Machinery, New York, NY, USA, 2022, p. 10–19 · 2022
Cited alongside, same era.
R. Sun, Q. Wang, L. Guo, Research towards key issues of api security, in: W. Lu, Y. Zhang, W. Wen, H. Yan, C. Li (Eds.), Cyber Security, Springer Nature Singapore, Singapore, 2022, pp. 179–192
2022
Cited alongside, same era.
Akamai Technologies, Sans survey on api security , Tech. rep., Akamai Technologies (2023). URL https://www.akamai.com/site/en/documents/research-paper/2023/sans-survey-api-security.pdf
2023
Later among the works it cites.
MITRE Corporation, CWE - Top 25 Most Dangerous Software Weaknesses, https://cwe.mitre.org/top25/ , accessed: 2024-03-02 (2023)
2023
Later among the works it cites.
Open Web Application Security Project (OWASP), OWASP Top Ten Web Application Security Risks, https://owasp.org/www-project-top-ten/ , accessed: 2024-03-02 (2023)
2023
Later among the works it cites.
K. Greenberg, Akamai survey: Api-specific controls are lacking , Tech. rep., Akamai Technologies (Jul 2023). URL https://www.techrepublic.com/article/akamai-survey-api-security/
2023
Later among the works it cites.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
E. B. Fernandez, N. Yoshioka, H. Washizaki, J. Yoder, Abstract security patterns and the design of secure systems, Cybersecurity 5 (1) (2022) 7
2022
Cited alongside, same era.
R. Croft, Y. Xie, M. Zahedi, M. A. Babar, An empirical study of developers’ discussions about security challenges of different programming languages , Empirical Software Engineering (2022). URL https://link.springer.com/article/10.1007/s10664-021-10054-w
2022
Cited alongside, same era.
doi:10.1007/s10664-023-10380-1
O. Asare, M. Nagappan, N. Asokan, Is github’s copilot as bad as humans at introducing vulnerabilities in code?, Empirical Softw. Engg. 28 (6) (sep 2023) · 2023
Cited alongside, same era.
G. Sandoval, H. Pearce, T. Nys, R. Karri, S. Garg, B. Dolan-Gavitt, Lost at c: A user study on the security implications of large language model code assistants, in: 32nd USENIX Security Symposium (USENIX Security 23), USENIX Association, Anaheim, CA, 2023, pp. 2205–2222
2023
Cited alongside, same era.
doi:https://doi.org/10.4218/etrij.2023-0357
S. Yeo, Y.-S. Ma, S. C. Kim, H. Jun, T. Kim, Framework for evaluating code generation ability of large language models, ETRI Journal 46 (1) (2024) 106–117 · 2023
Cited alongside, same era.
Google AI, PALM 2 Technical Report , Tech. rep., Google AI Research (2023). URL {https://ai.google/static/documents/palm2techreport.pdf}
2023
Cited alongside, same era.
Google, An overview of bard: an early experiment with generative ai , accessed: 2023-11-30 (2023). URL https://ai.google/static/documents/google-about-bard.pdf
2023
Cited alongside, same era.
Y. Chang, X. Wang, J. Wang, Y. Wu, L. Yang, K. Zhu, H. Chen, X. Yi, C. Wang, Y. Wang, et al., A survey on evaluation of large language models, ACM Transactions on Intelligent Systems and Technology (2023)
2023
Cited alongside, same era.
G. Team, Gemini: A family of highly capable multimodal models (2023) · 2023
Later among the works it cites.
Infosys, Amazone codewhisperer: Early adoption of emerging technologies, https://www.infosys.com/services/incubating-emerging-technologies/documents/early-adoption-infosys.pdf , accessed: 2023-09-30 (2023)
2023
Later among the works it cites.
G. Sandoval, H. Pearce, T. Nys, R. Karri, S. Garg, B. Dolan-Gavitt, Lost at c: A user study on the security implications of large language model code assistants (2023) · 2023
Later among the works it cites.
MITRE Corporation, CWE-699: Software Development Weaknesses, https://cwe.mitre.org/data/definitions/699.html , accessed: 2024-03-02 (2023)
2023
Later among the works it cites.
Amazon Web Services, AWS CodeWhisperer User Guide for Security Scanning , Amazon Web Services, accessed: 2024-03-29 (2023). URL https://docs.aws.amazon.com/pdfs/codewhisperer/latest/userguide/user-guide.pdf#security-scans
2023
Later among the works it cites.
SixHq, Ai realtime code scanner sixth sast, https://github.com/SixHq/ , accessed: 2024-05-04 (2023)
2023
Later among the works it cites.
doi:10.1109/SCAM59687.2023.00037
M. Esposito, S. Moreschini, V. Lenarduzzi, D. Hästbacka, D. Falessi, Can we trust the default vulnerabilities severity?, in: 2023 IEEE 23rd International Working Conference on Source Code Analysis and Manipulation (SCAM), 2023, pp. 265–270 · 2023
Later among the works it cites.
doi:10.1109/TPS-ISA58951.2023.00042
A. Mohsin, H. Janicke, S. Nepal, D. Holmes, Digital twins and the future of their use enabling shift left and shift right cybersecurity operations, in: 2023 5th IEEE International Conference on Trust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA), 2023, pp. 277–286 · 2023
Later among the works it cites.
doi:10.1145/3641289
Y. Chang, X. Wang, J. Wang, Y. Wu, L. Yang, K. Zhu, H. Chen, X. Yi, C. Wang, Y. Wang, W. Ye, Y. Zhang, Y. Chang, P. S. Yu, Q. Yang, X. Xie, A survey on evaluation of large language models, ACM Trans. Intell. Syst. Technol. 15 (3) (mar 2024) · 2024
Closest in time.
Y. Yao, J. Duan, K. Xu, Y. Cai, Z. Sun, Y. Zhang, A survey on large language model (llm) security and privacy: The good, the bad, and the ugly, High-Confidence Computing (2024)
2024
Closest in time.
I. H. Sarker, Llm potentiality and awareness: a position paper from the perspective of trustworthy and responsible ai modeling, Discover Artificial Intelligence 4 (1) (2024) 40
2024
Closest in time.
B. Rozière, J. Gehring, F. Gloeckle, S. Sootla, I. Gat, X. E. Tan, Y. Adi, J. Liu, R. Sauvestre, T. Remez, J. Rapin, A. Kozhevnikov, I. Evtimov, J. Bitton, M. Bhatt, C. C. Ferrer, A. Grattafiori, W. Xiong, A. Défossez, J. Copet, F. Azhar, H. Touvron, L. Martin, N. Usunier, T. Scialom, G. Synnaeve, Code llama: Open foundation models for code (2024) · 2024
Closest in time.
S. Kotsiantis, V. Verykios, M. Tzagarakis, Ai-assisted programming tasks using code embeddings and transformers, Electronics 13 (4) (2024) 767
2024
Closest in time.
MITRE, Cwe view: Software development, https://cwe.mitre.org/data/definitions/699.html , accessed: 2024-04-23
2024
Closest in time.
V. Ghariwala, Protecting against software supply chain attacks , InfoWorldAccessed: 2024-02-23 (2024). URL https://www.infoworld.com/article/3712543/protecting-against-software-supply-chain-attacks.html
2024
Closest in time.
Z. Bi, N. Zhang, Y. Jiang, S. Deng, G. Zheng, H. Chen, When do program-of-thought works for reasoning?, in: Proceedings of the AAAI Conference on Artificial Intelligence, Vol. 38, 2024, pp. 17691–17699
2024
Closest in time.
LeetCode Problem Set, https://leetcode.com/problemset/ , accessed: [2024-03-04]
2024
Closest in time.
OpenAI, J. A. et al., Gpt-4 technical report (2024) · 2024
Closest in time.
Snyk, Integrate with Snyk: IDE Tools, https://docs.snyk.io/integrate-with-snyk/ide-tools , accessed: 2024-03-12 (2024)
2024
Closest in time.
doi:https://doi.org/10.1016/j.icte.2024.05.007
I. H. Sarker, H. Janicke, A. Mohsin, A. Gill, L. Maglaras, Explainable ai for cybersecurity automation, intelligence and trustworthiness in digital twin: Methods, taxonomy, challenges and prospects, ICT Express (2024) · 2024
Closest in time.