Reading Between the Code Lines: On the Use of Self-Admitted Technical Debt for Security Analysis

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Ferreyra, Nicolás E. Díaz, Mock, Moritz, Kretschmann, Max, Russo, Barbara, Shahin, Mojtaba, Zahedi, Mansooreh, Scandariato, Riccardo
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866911418551369728
author Ferreyra, Nicolás E. Díaz
Mock, Moritz
Kretschmann, Max
Russo, Barbara
Shahin, Mojtaba
Zahedi, Mansooreh
Scandariato, Riccardo
author_facet Ferreyra, Nicolás E. Díaz
Mock, Moritz
Kretschmann, Max
Russo, Barbara
Shahin, Mojtaba
Zahedi, Mansooreh
Scandariato, Riccardo
contents Static Analysis Tools (SATs) are central to security engineering activities, as they enable early identification of code weaknesses without requiring execution. However, their effectiveness is often limited by high false-positive rates and incomplete coverage of vulnerability classes. At the same time, developers frequently document security-related shortcuts and compromises as Self-Admitted Technical Debt (SATD) in software artifacts, such as code comments. While prior work has recognized SATD as a rich source of security information, it remains unclear whether -and in what ways- it is utilized during SAT-aided security analysis. OBJECTIVE: This work investigates the extent to which security-related SATD complements the output produced by SATs and helps bridge some of their well-known limitations. METHOD: We followed a mixed-methods approach consisting of (i) the analysis of a SATD-annotated vulnerability dataset using three state-of-the-art SATs and (ii) an online survey with 72 security practitioners. RESULTS: The combined use of all SATs flagged 114 of the 135 security-related SATD instances, spanning 24 distinct Common Weakness Enumeration (CWE) identifiers. A manual mapping of the SATD comments revealed 33 unique CWE types, 6 of which correspond to categories that SATs commonly overlook or struggle to detect (e.g., race conditions). Survey responses further suggest that developers frequently pair SAT outputs with SATD insights to better understand the impact and root causes of security weaknesses and to identify suitable fixes. IMPLICATIONS: Our findings show that such SATD-encoded information can be a meaningful complement to SAT-driven security analysis, while helping to overcome some of SATs' practical shortcomings.
format Preprint
id arxiv_https___arxiv_org_abs_2602_03470
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Reading Between the Code Lines: On the Use of Self-Admitted Technical Debt for Security Analysis
Ferreyra, Nicolás E. Díaz
Mock, Moritz
Kretschmann, Max
Russo, Barbara
Shahin, Mojtaba
Zahedi, Mansooreh
Scandariato, Riccardo
Cryptography and Security
Human-Computer Interaction
Software Engineering
Static Analysis Tools (SATs) are central to security engineering activities, as they enable early identification of code weaknesses without requiring execution. However, their effectiveness is often limited by high false-positive rates and incomplete coverage of vulnerability classes. At the same time, developers frequently document security-related shortcuts and compromises as Self-Admitted Technical Debt (SATD) in software artifacts, such as code comments. While prior work has recognized SATD as a rich source of security information, it remains unclear whether -and in what ways- it is utilized during SAT-aided security analysis. OBJECTIVE: This work investigates the extent to which security-related SATD complements the output produced by SATs and helps bridge some of their well-known limitations. METHOD: We followed a mixed-methods approach consisting of (i) the analysis of a SATD-annotated vulnerability dataset using three state-of-the-art SATs and (ii) an online survey with 72 security practitioners. RESULTS: The combined use of all SATs flagged 114 of the 135 security-related SATD instances, spanning 24 distinct Common Weakness Enumeration (CWE) identifiers. A manual mapping of the SATD comments revealed 33 unique CWE types, 6 of which correspond to categories that SATs commonly overlook or struggle to detect (e.g., race conditions). Survey responses further suggest that developers frequently pair SAT outputs with SATD insights to better understand the impact and root causes of security weaknesses and to identify suitable fixes. IMPLICATIONS: Our findings show that such SATD-encoded information can be a meaningful complement to SAT-driven security analysis, while helping to overcome some of SATs' practical shortcomings.
title Reading Between the Code Lines: On the Use of Self-Admitted Technical Debt for Security Analysis
topic Cryptography and Security
Human-Computer Interaction
Software Engineering
url https://arxiv.org/abs/2602.03470