TCSE logo 
 Sigsoft logo
Sustainability badge
Tue 29 Apr 2025 09:05 - 09:11 at 212 - Session 1: Security & Miscellaneous (talks and panel) Chair(s): Tayana Conte

The rise of ChatGPT and GitHub Copilot has sparked a surge in developers leveraging large language models (LLMs) for code generation, aiming to automate software development processes. However, these tools can generate substandard and vulnerable code. Notably, a significant portion of developers in the US embrace LLMs due to productivity boost. However, research indicates that LLM-generated code may compromise security, with users often overestimating its reliability. To address these challenges, this proposal aims to enhance the quality and security of generated code in outputs. The proposal includes an empirical study of code generation models’ training sets and benchmarks for code and security smells. It also consists of a framework, SALLM, to automatically benchmark code generation models from the security perspective. This proposal is a work in progress in creating quality datasets to reinforce the code generation model and generate standard and secure code. By establishing trust in LLM-based tools and generating secure and standard code, developers can confidently integrate them into their workflows and rely on them.

I am a Ph.D. candidate working as a Graduate Research Assistant at the University of Notre Dame, IN, USA. I mainly focus on Code Generation Models and their applications in software testing and security.

Tue 29 Apr

Displayed time zone: Eastern Time (US & Canada) change

09:00 - 10:05
Session 1: Security & Miscellaneous (talks and panel)Doctoral Symposium at 212
Chair(s): Tayana Conte Universidade Federal do Amazonas
09:00
5m
Day opening
Opening of the Doctoral Symposium
Doctoral Symposium
Tayana Conte Universidade Federal do Amazonas, Alexander Serebrenik Eindhoven University of Technology
09:05
6m
Talk
Advancing Secure and Standard Source Code Generation Techniques
Doctoral Symposium
Mohammed Latif Siddiq University of Notre Dame
Pre-print
09:11
6m
Talk
Towards Secure and Interactive Smart Contract Code from Formal SYMBOLEO Specifications
Doctoral Symposium
Sofana Alfuhaid University of Ottawa
Link to publication
09:17
6m
Talk
Empirically-Informed Approaches to Shift Vulnerability Detection to the Left
Doctoral Symposium
Paschal Amusuo Purdue University
09:23
6m
Talk
A BizDevOps-Aligned Framework for Integrating Security Practices in Agile Software Development
Doctoral Symposium
Alejandra Selva-Mora Universidad de Costa Rica
09:29
6m
Talk
Towards Configuration-Aware Performance Modeling
Doctoral Symposium
Yuanjie Xia University of Waterloo
09:35
30m
Panel
Panel: Security
Doctoral Symposium
Marsha Chechik University of Toronto, Laurie Williams North Carolina State University, Mohammed Latif Siddiq University of Notre Dame, Yuanjie Xia University of Waterloo, Paschal Amusuo Purdue University, Alejandra Selva-Mora Universidad de Costa Rica, Sofana Alfuhaid University of Ottawa
:
:
:
: