Supporting Students in Navigating LLM-Generated Insecure Code

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Park, Jaehwan, Lim, Kyungchan, Park, Seonhye, Kim, Doowon
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908676567072768
author Park, Jaehwan
Lim, Kyungchan
Park, Seonhye
Kim, Doowon
author_facet Park, Jaehwan
Lim, Kyungchan
Park, Seonhye
Kim, Doowon
contents The advent of Artificial Intelligence (AI), particularly large language models (LLMs), has revolutionized software development by enabling developers to specify tasks in natural language and receive corresponding code, boosting productivity. However, this shift also introduces security risks, as LLMs may generate insecure code that can be exploited by adversaries. Current educational approaches emphasize efficiency while overlooking these risks, leaving students underprepared to identify and mitigate security issues in AI-assisted workflows. To address this gap, we present Bifröst, an educational framework that cultivates security awareness in AI-augmented development. Bifröst integrates (1) a Visual Studio Code extension simulating realistic environments, (2) adversarially configured LLMs that generate insecure code, and (3) a feedback system highlighting vulnerabilities. By immersing students in tasks with compromised LLMs and providing targeted security analysis, Bifröst cultivates critical evaluation skills; classroom deployments (n=61) show vulnerability to insecure code, while a post-intervention survey (n=21) indicates increased skepticism toward LLM outputs.
format Preprint
id arxiv_https___arxiv_org_abs_2511_20878
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Supporting Students in Navigating LLM-Generated Insecure Code
Park, Jaehwan
Lim, Kyungchan
Park, Seonhye
Kim, Doowon
Cryptography and Security
The advent of Artificial Intelligence (AI), particularly large language models (LLMs), has revolutionized software development by enabling developers to specify tasks in natural language and receive corresponding code, boosting productivity. However, this shift also introduces security risks, as LLMs may generate insecure code that can be exploited by adversaries. Current educational approaches emphasize efficiency while overlooking these risks, leaving students underprepared to identify and mitigate security issues in AI-assisted workflows. To address this gap, we present Bifröst, an educational framework that cultivates security awareness in AI-augmented development. Bifröst integrates (1) a Visual Studio Code extension simulating realistic environments, (2) adversarially configured LLMs that generate insecure code, and (3) a feedback system highlighting vulnerabilities. By immersing students in tasks with compromised LLMs and providing targeted security analysis, Bifröst cultivates critical evaluation skills; classroom deployments (n=61) show vulnerability to insecure code, while a post-intervention survey (n=21) indicates increased skepticism toward LLM outputs.
title Supporting Students in Navigating LLM-Generated Insecure Code
topic Cryptography and Security
url https://arxiv.org/abs/2511.20878