Selecting Cybersecurity Requirements: Effects of LLM Use and Professional Software Development Experience

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Fujs, Damjan, Vavpotič, Damjan, Hovelja, Tomaž, Poženel, Marko
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918154695868416
author Fujs, Damjan
Vavpotič, Damjan
Hovelja, Tomaž
Poženel, Marko
author_facet Fujs, Damjan
Vavpotič, Damjan
Hovelja, Tomaž
Poženel, Marko
contents This study investigates how access to Large Language Models (LLMs) and varying levels of professional software development experience affect the prioritization of cybersecurity requirements for web applications. Twenty-three postgraduate students participated in a research study to prioritize security requirements (SRs) using the MoSCoW method and subsequently rated their proposed solutions against multiple evaluation criteria. We divided participants into two groups (one with and the other without access to LLM support during the task). Results showed no significant differences related to LLM use, suggesting that access to LLMs did not noticeably influence how participants evaluated cybersecurity solutions. However, statistically significant differences emerged between experience groups for certain criteria, such as estimated cost to develop a feature, perceived impact on user experience, and risk assessment related to non-implementation of the proposed feature. Participants with more professional experience tended to provide higher ratings for user experience impact and lower risk estimates.
format Preprint
id arxiv_https___arxiv_org_abs_2510_04274
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Selecting Cybersecurity Requirements: Effects of LLM Use and Professional Software Development Experience
Fujs, Damjan
Vavpotič, Damjan
Hovelja, Tomaž
Poženel, Marko
Software Engineering
D.2; I.2; J.6; K.3; K.7
This study investigates how access to Large Language Models (LLMs) and varying levels of professional software development experience affect the prioritization of cybersecurity requirements for web applications. Twenty-three postgraduate students participated in a research study to prioritize security requirements (SRs) using the MoSCoW method and subsequently rated their proposed solutions against multiple evaluation criteria. We divided participants into two groups (one with and the other without access to LLM support during the task). Results showed no significant differences related to LLM use, suggesting that access to LLMs did not noticeably influence how participants evaluated cybersecurity solutions. However, statistically significant differences emerged between experience groups for certain criteria, such as estimated cost to develop a feature, perceived impact on user experience, and risk assessment related to non-implementation of the proposed feature. Participants with more professional experience tended to provide higher ratings for user experience impact and lower risk estimates.
title Selecting Cybersecurity Requirements: Effects of LLM Use and Professional Software Development Experience
topic Software Engineering
D.2; I.2; J.6; K.3; K.7
url https://arxiv.org/abs/2510.04274