Department of Mathematics and Statistics, Georgia State University, Atlanta, Georgia, USA.
International Journal of Science and Research Archive, 2023, 10(01), 1298-1306
Article DOI: 10.30574/ijsra.2023.10.1.0818
Received on 19 September 2023; revised on 24 October 2023; accepted on 28 October 2023
Software development using artificial intelligence (AI) is gaining momentum, and with it a new set of security risks, including vulnerabilities in AI-generated code. This research explores the security risks associated with AI-generated code in several languages, such as Python, Java, C++, and JavaScript. Through the automated generation of code fragments for a range of common programming tasks, the study examined the incidence, nature, and criticality of security vulnerabilities in the code generated by AI-based software development tools. This study examined the incidence of common types of vulnerabilities including injection, buffer overflow, insecure input validation, insecure cryptography, and resource management issues. However, findings demonstrate that the code generated by AI has a tendency towards security vulnerabilities, that varies based on language, and program complexity. It was also found that Python and JavaScript code were more vulnerable to input validation and injection attacks, while C++ code was more vulnerable to memory-related issues. The research further reveals AI tendencies that lead to the generation of insecure code such as excessive reliance on code templates, insufficient error management and lack of consideration for context. Nevertheless, the study concludes by highlighting the need for incorporating automated security testing and human review into AI-powered software development processes. Apart from offering guidance to AI model developers, highlighting the need for training data and code generation algorithms that promote secure coding techniques, this research also quantifies AI-induced security vulnerabilities, shedding light on potential vulnerabilities in contemporary software development and the need for pre-emptive measures to ensure security and integrity throughout software development practices. Based on the findings and conclusion of the study, it recommends a holistic assessment of AI-induced vulnerabilities, aiming to drive ethical deployment of AI in software engineering and reducing risks of vulnerabilities in software.
AI-Generated Code; Security Vulnerabilities; Programming Languages; Empirical Study; Software Security; Code Analysis
Preview Article PDF
Ayobami Adebesin. An empirical study of security vulnerabilities introduced by AI-generated code across programming languages. International Journal of Science and Research Archive, 2023, 10(01), 1298-1306. Article DOI: https://doi.org/10.30574/ijsra.2023.10.1.0818.






