AI-generated Сode Security

dc.contributor.authorBodnar, Mykola
dc.contributor.authorRodionov, Andrii
dc.contributor.authorDegtiarenko, Maryna
dc.date.accessioned2026-06-01T12:36:34Z
dc.date.available2026-06-01T12:36:34Z
dc.date.issued2025
dc.description.abstractThe integration of Generative AI (GenAI) and Large Language Models (LLMs) into software development workflows represents a paradigm shift, driven by significant productivity gains (Asare, Nagappan, & Asokan, 2023). However, this rapid adoption obscures a critical security deficit. Empirical studies demonstrate that AI-generated code frequently introduces known security flaws; comprehensive analyses reveal that nearly half of all generated code is insecure (Sabra, Schmitt, & Tyler, 2025), and iterative refinement can counterintuitively increase critical vulnerabilities. While common vulnerabilities (e.g., injection) are prevalent, the most systemic and dangerous failures lie in the logical domain of security roles and privileges. This research posits that the fundamental flaw of current models is “contextblindness” – an inherent inability to comprehend or model an application's specific risk model, security architecture, or implicit authorization invariants. This gap leads to the generation of code with catastrophic Broken Access Control (BAC) and Insecure Direct Object Reference (IDOR) vulnerabilities, rendering traditional static analysis ineffective.
dc.format.pagerangeP. 18-20
dc.identifier.citationBodnar, M. AI-generated Сode Security / Mykola Bodnar, Andrii Rodionov, Maryna Degtiarenko // Advances in Science and Technology : proceedings of the II International Final R&D Online Conference of the II International Student Research Paper Competition, [Kyiv], 2025, Part I / Ukraine National Technical University of Ukraine “Igor Sikorsky Kyiv Polytechnic Institute”. - Kyiv, 2025. - P. 18-20.
dc.identifier.orcid0000-0002-9877-8106
dc.identifier.urihttps://ela.kpi.ua/handle/123456789/81399
dc.language.isoen
dc.publisherNational Technical University of Ukraine ‘Igor Sikorsky Kyiv Polytechnic Institute’
dc.publisher.placeKyiv
dc.relation.ispartofAdvances in Science and Technology : proceedings of the II International Final R&D Online Conference of the II International Student Research Paper Competition, 2025, Part I, Kyiv, Ukraine
dc.subjectGenerative AI (GenAI)
dc.subjectcode security
dc.subjectlarge language models (LLMs)
dc.subjectcontext-aware generation (RAG)
dc.subjectformal verification (FV)
dc.subjectStatic Application Security Testing (SAST)
dc.subjectDynamic Application Security Testing (DAST)
dc.subjectInsecure Direct Object Reference (IDOR)
dc.titleAI-generated Сode Security
dc.typeArticle

Файли

Контейнер файлів
Зараз показуємо 1 - 1 з 1
Вантажиться...
Ескіз
Назва:
Bodnar_Radionov_Degtiarenko_AI-generated_Сode_Security.pdf
Розмір:
312.8 KB
Формат:
Adobe Portable Document Format
Ліцензійна угода
Зараз показуємо 1 - 1 з 1
Ескіз недоступний
Назва:
license.txt
Розмір:
8.98 KB
Формат:
Item-specific license agreed upon to submission
Опис: