From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness

Fuente: arXiv
Gespeichert in:
Bibliographische Detailangaben
Hauptverfasser: Bappy, Faisal Haque, Hossain, Tahrim, Meheraj, Sidratul Muntaher, Akhand, Annoor Sharara, Tabassum, Tasfia, Zaman, Tarannum Shaila, Hasan, Raiful, Islam, Tariqul
Format: Preprint
Veröffentlicht: 2026
Schlagworte:
Online-Zugang:
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
_version_ 1866916038104317952
author Bappy, Faisal Haque
Hossain, Tahrim
Meheraj, Sidratul Muntaher
Akhand, Annoor Sharara
Tabassum, Tasfia
Zaman, Tarannum Shaila
Hasan, Raiful
Islam, Tariqul
author_facet Bappy, Faisal Haque
Hossain, Tahrim
Meheraj, Sidratul Muntaher
Akhand, Annoor Sharara
Tabassum, Tasfia
Zaman, Tarannum Shaila
Hasan, Raiful
Islam, Tariqul
contents AI coding assistants are now central to professional software development, yet their impact on how developers think about and practice security remains poorly understood. While prior work has documented vulnerability rates in AI-generated code, a more fundamental question persists: how do these tools transform security awareness in authentic, ongoing development practice? We conducted semi-structured interviews with 15 professional software engineers and observed them completing security-relevant coding tasks with AI assistance, spanning 3 experience cohorts defined by their relationship to AI tools during professional formation. We find that AI coding assistants reorganize rather than eliminate security thinking, shifting it from the act of writing code to the act of reviewing it. This transition from preventive to reactive security is structurally encouraged by interaction models that frame code generation as a functional task, leaving security as an afterthought. Notably, none of our coding session participants specified security requirements in their initial prompts, even when they possessed the relevant knowledge, revealing a decoupling of security awareness from security behavior. We further document informal coping strategies developers had independently invented to manage AI security risk, none of which are supported by current tools or organizations, and find that the experience cohort did not reliably predict security performance. This paper contributes a practice-grounded account of how AI-assisted development reshapes the human side of secure coding, offering empirical foundations for the design of more security-aware tools, training programs, and organizational policies.
format Preprint
id arxiv_https___arxiv_org_abs_2605_23130
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
Bappy, Faisal Haque
Hossain, Tahrim
Meheraj, Sidratul Muntaher
Akhand, Annoor Sharara
Tabassum, Tasfia
Zaman, Tarannum Shaila
Hasan, Raiful
Islam, Tariqul
Human-Computer Interaction
Cryptography and Security
AI coding assistants are now central to professional software development, yet their impact on how developers think about and practice security remains poorly understood. While prior work has documented vulnerability rates in AI-generated code, a more fundamental question persists: how do these tools transform security awareness in authentic, ongoing development practice? We conducted semi-structured interviews with 15 professional software engineers and observed them completing security-relevant coding tasks with AI assistance, spanning 3 experience cohorts defined by their relationship to AI tools during professional formation. We find that AI coding assistants reorganize rather than eliminate security thinking, shifting it from the act of writing code to the act of reviewing it. This transition from preventive to reactive security is structurally encouraged by interaction models that frame code generation as a functional task, leaving security as an afterthought. Notably, none of our coding session participants specified security requirements in their initial prompts, even when they possessed the relevant knowledge, revealing a decoupling of security awareness from security behavior. We further document informal coping strategies developers had independently invented to manage AI security risk, none of which are supported by current tools or organizations, and find that the experience cohort did not reliably predict security performance. This paper contributes a practice-grounded account of how AI-assisted development reshapes the human side of secure coding, offering empirical foundations for the design of more security-aware tools, training programs, and organizational policies.
title From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness
topic Human-Computer Interaction
Cryptography and Security
url https://arxiv.org/abs/2605.23130