Securing the AI Supply Chain: What Can We Learn From Developer-Reported Security Issues and Solutions of AI Projects?
Fuente:
arXiv
Saved in:
| Main Authors: | Nguyen, The Anh, Le, Triet Huynh Minh, Babar, M. Ali |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
Similar Items
Automated Code-centric Software Vulnerability Assessment: How Far Are We? An Empirical Study in C/C++
by: Nguyen, Anh The, et al.
Published: (2024)
by: Nguyen, Anh The, et al.
Published: (2024)
Automatic Data Labeling for Software Vulnerability Prediction Models: How Far Are We?
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
LLMSecConfig: An LLM-Based Approach for Fixing Software Container Misconfigurations
by: Ye, Ziyang, et al.
Published: (2025)
by: Ye, Ziyang, et al.
Published: (2025)
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023)
by: Tran, Nguyen Khoi, et al.
Published: (2023)
Qualitative Coding Analysis through Open-Source Large Language Models: A User Study and Design Recommendations
by: Ngo, Tung T., et al.
Published: (2026)
by: Ngo, Tung T., et al.
Published: (2026)
Bugdar: AI-Augmented Secure Code Review for GitHub Pull Requests
by: Naulty, John, et al.
Published: (2025)
by: Naulty, John, et al.
Published: (2025)
SecDOAR: A Software Reference Architecture for Security Data Orchestration, Analysis and Reporting
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
by: Chauhan, Muhammad Aufeef, et al.
Published: (2024)
Security Concerns in Generative AI Coding Assistants: Insights from Online Discussions on GitHub Copilot
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
Mitigating Data Imbalance for Software Vulnerability Assessment: Does Data Augmentation Help?
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
Operationalizing Research Software for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2026)
by: Kalu, Kelechi G., et al.
Published: (2026)
Software Supply Chain Security of Web3
by: Monperrus, Martin
Published: (2025)
by: Monperrus, Martin
Published: (2025)
Evaluating Software Supply Chain Security in Research Software
by: Hegewald, Richard, et al.
Published: (2025)
by: Hegewald, Richard, et al.
Published: (2025)
Securing the Software Package Supply Chain for Critical Systems
by: Murali, Ritwik, et al.
Published: (2025)
by: Murali, Ritwik, et al.
Published: (2025)
SoK: Analysis of Software Supply Chain Security by Establishing Secure Design Properties
by: Okafor, Chinenye, et al.
Published: (2024)
by: Okafor, Chinenye, et al.
Published: (2024)
How Can ChatGPT Support Human Security Testers to Help Mitigate Supply Chain Attacks?
by: Zhang, Ying, et al.
Published: (2023)
by: Zhang, Ying, et al.
Published: (2023)
Civil Servants as Builders: Enabling Non-IT Staff to Develop Secure Python and R Tools
by: Sharma, Prashant
Published: (2025)
by: Sharma, Prashant
Published: (2025)
An Industry Interview Study of Software Signing for Supply Chain Security
by: Kalu, Kelechi G., et al.
Published: (2024)
by: Kalu, Kelechi G., et al.
Published: (2024)
Secure Coding with AI -- From Detection to Repair
by: Belozerov, Vladislav, et al.
Published: (2025)
by: Belozerov, Vladislav, et al.
Published: (2025)
Are Latent Vulnerabilities Hidden Gems for Software Vulnerability Prediction? An Empirical Study
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
MVD: A Multi-Lingual Software Vulnerability Detection Framework
by: Zhang, Boyu, et al.
Published: (2024)
by: Zhang, Boyu, et al.
Published: (2024)
Software Supply Chain Smells: Lightweight Analysis for Secure Dependency Management
by: Schmid, Larissa, et al.
Published: (2026)
by: Schmid, Larissa, et al.
Published: (2026)
Detecting Misuse of Security APIs: A Systematic Review
by: Mousavi, Zahra, et al.
Published: (2023)
by: Mousavi, Zahra, et al.
Published: (2023)
No Silver Bullet: Towards Demonstrating Secure Software Development for Danish Small and Medium Enterprises in a Business-to-Business Model
by: Asadi, Raha, et al.
Published: (2025)
by: Asadi, Raha, et al.
Published: (2025)
SBOMproof: Beyond Alleged SBOM Compliance for Supply Chain Security of Container Images
by: Bufalino, Jacopo, et al.
Published: (2025)
by: Bufalino, Jacopo, et al.
Published: (2025)
Software Vulnerability Prediction in Low-Resource Languages: An Empirical Study of CodeBERT and ChatGPT
by: Le, Triet H. M., et al.
Published: (2024)
by: Le, Triet H. M., et al.
Published: (2024)
Large Language Model Supply Chain: Open Problems From the Security Perspective
by: Hu, Qiang, et al.
Published: (2024)
by: Hu, Qiang, et al.
Published: (2024)
Software Bill of Materials in Software Supply Chain Security A Systematic Literature Review
by: O'Donoghue, Eric, et al.
Published: (2025)
by: O'Donoghue, Eric, et al.
Published: (2025)
Enabling Cyber Security Education through Digital Twins and Generative AI
by: Barletta, Vita Santa, et al.
Published: (2025)
by: Barletta, Vita Santa, et al.
Published: (2025)
The Kubernetes Security Landscape: AI-Driven Insights from Developer Discussions
by: Curtis, J. Alexander, et al.
Published: (2024)
by: Curtis, J. Alexander, et al.
Published: (2024)
LightSC: The Making of a Usable Security Classification Tool for DevSecOps
by: Shrestha, Manish, et al.
Published: (2024)
by: Shrestha, Manish, et al.
Published: (2024)
Reading Between the Code Lines: On the Use of Self-Admitted Technical Debt for Security Analysis
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
by: Ferreyra, Nicolás E. Díaz, et al.
Published: (2026)
From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
by: Bappy, Faisal Haque, et al.
Published: (2026)
by: Bappy, Faisal Haque, et al.
Published: (2026)
Fixing Security Vulnerabilities with AI in OSS-Fuzz
by: Zhang, Yuntong, et al.
Published: (2024)
by: Zhang, Yuntong, et al.
Published: (2024)
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
by: Klemmer, Jan H., et al.
Published: (2024)
by: Klemmer, Jan H., et al.
Published: (2024)
A Qualitative Study on Using ChatGPT for Software Security: Perception vs. Practicality
by: Kholoosi, M. Mehdi, et al.
Published: (2024)
by: Kholoosi, M. Mehdi, et al.
Published: (2024)
Towards Secure Management of Edge-Cloud IoT Microservices using Policy as Code
by: Pallewatta, Samodha, et al.
Published: (2024)
by: Pallewatta, Samodha, et al.
Published: (2024)
Metaverse Security and Privacy Research: A Systematic Review
by: Rahartomo, Argianto, et al.
Published: (2025)
by: Rahartomo, Argianto, et al.
Published: (2025)
Can I Check What I Designed? Mapping Security Design DSLs to Code Analyzers
by: Peldszus, Sven, et al.
Published: (2026)
by: Peldszus, Sven, et al.
Published: (2026)
Beyond Security-by-design: Securing a compromised system
by: Rashid, Awais, et al.
Published: (2025)
by: Rashid, Awais, et al.
Published: (2025)
Using LLMs for Security Advisory Investigations: How Far Are We?
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
by: Abdullah, Bayu Fedra, et al.
Published: (2025)
Similar Items
-
Automated Code-centric Software Vulnerability Assessment: How Far Are We? An Empirical Study in C/C++
by: Nguyen, Anh The, et al.
Published: (2024) -
Automatic Data Labeling for Software Vulnerability Prediction Models: How Far Are We?
by: Le, Triet H. M., et al.
Published: (2024) -
LLMSecConfig: An LLM-Based Approach for Fixing Software Container Misconfigurations
by: Ye, Ziyang, et al.
Published: (2025) -
An Empirically Grounded Reference Architecture for Software Supply Chain Metadata Management
by: Tran, Nguyen Khoi, et al.
Published: (2023) -
Qualitative Coding Analysis through Open-Source Large Language Models: A User Study and Design Recommendations
by: Ngo, Tung T., et al.
Published: (2026)