A Security Risk Assessment Framework for AI-Powered Development Tools

📅 2026-09-16
📈 Citations: 0
Influential: 0
📄 PDF
🤖 AI Summary
本文提出了一种安全风险评估框架(SRF),通过结合威胁建模、安全分析和基于漏洞关键性的定量风险评估方法,来解决AI生成代码的安全风险评估问题。
📝 Abstract
AI-powered development tools are now widely used to generate code and assist developers with routine programming tasks. Although existing work has identified vulnerabilities in AI-generated code, security-oriented work is often focused on vulnerability detection rather than risk assessment. To address this gap, this paper presents a Security Risk Assessment Framework (SRF) to evaluate the security risks of AI-generated code. SRF combines threat modeling, security analysis, and a quantitative risk evaluation approach based on vulnerability criticality. The framework is applied to a set of security-relevant programming tasks, where code generated by multiple AI-powered development tools is analyzed using Bandit and Semgrep. The results show that AI-generated code can introduce security vulnerabilities across all evaluated tools. They also show that risk levels vary by task type, as input processing and file handling tasks showed higher risk, while simpler tasks remained low-risk. Differences between tools exist but are smaller than differences across task categories. Overall, SRF enables reproducible evaluation of AI-generated code and provides a practical framework for assessing its security implications.
Problem

Research questions and friction points this paper is trying to address.

Security Risk Assessment
AI-generated Code
Vulnerability
Innovation

Methods, ideas, or system contributions that make the work stand out.

Security Risk Assessment Framework
threat modeling
vulnerability criticality
AI-generated code
💼 Related Jobs
No related jobs found.
S
Salem AlJanah
College of Computer and Information Sciences, Imam Mohammad Ibn Saud Islamic University (IMSIU), Saudi Arabia