Double-Edged Sword of LLMs: Mitigating Security Risks of AI-Generated Code

被引:2
|
作者
Bharadwaj, Ramesh [1 ]
Parker, Ilya [2 ]
机构
[1] Naval Res Lab, Ctr High Assurance Comp Syst, Washington, DC 20375 USA
[2] Arcfield, 14295 Pk Meadow Dr, Chantilly, VA 20151 USA
关键词
Large Language Models; Generative AI; Symbolic AI; Automatic Code Generation; Code Defect Mitigation;
D O I
10.1117/12.2664116
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
With the increasing reliance on collaborative and cloud-based systems, there is a drastic increase in attack surfaces and code vulnerabilities. Automation is key for fielding and defending software systems at scale. Researchers in Symbolic AI have had considerable success in finding flaws in human-created code. Also, run-time testing methods such as fuzzing do uncover numerous bugs. However, the major deficiency of both approaches is the inability of the methods to fix the discovered errors. They also do not scale and defy automation. Static analysis methods also suffer from the false positive problem - an overwhelming number of reported flaws are not real bugs. This brings up an interesting conundrum: Symbolic approaches actually have a detrimental impact on programmer productivity, and therefore do not necessarily contribute to improved code quality. What is needed is a combination of automation of code generation using large language models (LLMs), with scalable defect elimination methods using symbolic AI, to create an environment for the automated generation of defect-free code.
引用
收藏
页数:6
相关论文
共 50 条
  • [41] Hypothermia: A Double-Edged Sword
    Todaro, Maria Chiara
    Oreto, Lilia
    Gupta, Anjan
    Bajwa, Tanvir
    Khandheria, Bijoy K.
    CARDIOLOGY, 2012, 122 (02) : 126 - 128
  • [42] The Blockade as a Double-Edged Sword
    Regalado, Roberto
    MONTHLY REVIEW-AN INDEPENDENT SOCIALIST MAGAZINE, 2022, 73 (08) : 11 - 22
  • [43] Herbicides - a double-edged sword?
    Kudsk, P
    Streibig, JC
    12TH EWRS (EUROPEAN WEED RESEARCH SOCIETY) SYMPOSIUM 2002, WAGENINGEN, PROCEEDINGS, 2002, : 94 - 95
  • [44] The double-edged sword of adenosine
    Plo, Isabelle
    Antony-Debre, Ileana
    HAEMATOLOGICA, 2024, 109 (01) : 13 - 15
  • [45] DOCUMENTATION - A DOUBLE-EDGED SWORD
    BALL, AE
    PERSONNEL, 1989, 66 (04) : 96 - 100
  • [46] THE DOUBLE-EDGED SWORD OF SCIENCE
    COKER, WR
    ASHRAE JOURNAL, 1989, 31 (12) : 5 - 5
  • [47] A Double-Edged Sword? Software Reuse and Potential Security Vulnerabilities
    Gkortzis, Antonios
    Feitosa, Daniel
    Spinellis, Diomidis
    REUSE IN THE BIG DATA ERA, 2019, 11602 : 187 - 203
  • [48] The double-edged sword of bivalency
    Bulut-Karslioglu, Aydan
    NATURE REVIEWS MOLECULAR CELL BIOLOGY, 2024, 25 (01) : 6 - 6
  • [49] ChatGPT: A Double-Edged Sword?
    Palal, Deepu
    Ghonge, Swati
    Jadav, Vallari
    Rathod, Hetal
    HEALTH SERVICES INSIGHTS, 2023, 16
  • [50] Taming the double-edged sword
    不详
    NATURE REVIEWS DRUG DISCOVERY, 2003, 2 (11) : 849 - 849