English

Lost at C: A User Study on the Security Implications of Large Language Model Code Assistants

Cryptography and Security 2023-02-28 v4

Abstract

Large Language Models (LLMs) such as OpenAI Codex are increasingly being used as AI-based coding assistants. Understanding the impact of these tools on developers' code is paramount, especially as recent work showed that LLMs may suggest cybersecurity vulnerabilities. We conduct a security-driven user study (N=58) to assess code written by student programmers when assisted by LLMs. Given the potential severity of low-level bugs as well as their relative frequency in real-world projects, we tasked participants with implementing a singly-linked 'shopping list' structure in C. Our results indicate that the security impact in this setting (low-level C with pointer and array manipulations) is small: AI-assisted users produce critical security bugs at a rate no greater than 10% more than the control, indicating the use of LLMs does not introduce new security risks.

Keywords

Cite

@article{arxiv.2208.09727,
  title  = {Lost at C: A User Study on the Security Implications of Large Language Model Code Assistants},
  author = {Gustavo Sandoval and Hammond Pearce and Teo Nys and Ramesh Karri and Siddharth Garg and Brendan Dolan-Gavitt},
  journal= {arXiv preprint arXiv:2208.09727},
  year   = {2023}
}

Comments

Accepted for publication in USENIX'23. For associated dataset see https://doi.org/10.5281/zenodo.7187359. 18 pages, 12 figures. G. Sandoval and H. Pearce contributed equally to this work

R2 v1 2026-06-25T01:50:30.674Z