The Language of Security: How Prompt Syntax Shapes Secure Code Generation in Open LLMs
This program is tentative and subject to change.
Large Language Models (LLMs) are increasingly used for source code generation despite their outputs often exhibiting security vulnerabilities. Prior work shows that prompt engineering can mitigate such risks, yet (1) they focused on high-level prompting strategies, neglecting recent evidence that fine-grained syntactic variations can substantially alter model behavior; and (2) predominantly evaluate proprietary LLMs, limiting the applicability of their findings in industrial settings where self-hosted, open models are preferred for privacy, compliance, and deployment control. In this paper, we study how fine-grained syntactic constituents of prompts influence the security of open LLM-generated code. Using a parser-driven approach, we systematically generate syntactic variants of security-relevant code generation prompts and evaluate their impact on code security across multiple open LLMs and programming languages. Our results show that specific syntactic elements, such as constraints, guards, conditions, and concept bindings, and their position within the prompt consistently affect the likelihood of generating insecure code. These findings identify prompt syntax as a concrete security control surface and provide actionable guidance for reducing vulnerability risk in LLM-assisted development.
This program is tentative and subject to change.
Wed 16 SepDisplayed time zone: Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna change
11:00 - 12:30 | Session 4 - Intelligent Frontiers: AI Meets Security and DataTool Demonstration and Data Showcase Track / Industry Track / Research Papers Track / Replication and Negative Results at A59S Chair(s): Yuanjun Gong University of Trento, Esteban Parra Rodriguez Belmont University Theme: AI-Driven Software Development | ||
11:00 20mPaper | Supporting Maintenance and Evolution in Cyber-Physical Production Systems through Semi-automatic Variability Extraction Industry Track Oleksandr Kudriavcheniko CDL VaSiCS, LIT CPS Lab, Johannes Kepler University Linz, Philipp Bauer CDL VaSiCS, LIT CPS Lab, Johannes Kepler University Linz, Benjamin Muttenthaler Primetals Technologies Austria GmbH, Rick Rabiser LIT CPS, Johannes Kepler University Linz, Lisa Sonnleithner CDL VaSiCS, LIT CPS Lab, Johannes Kepler University Linz | ||
11:20 20mPaper | What Fails in Empirical SE and AI4SE? A Study of Evaluation Fragility Replication and Negative Results Radoslaw Klimek AGH University of Krakow | ||
11:40 20mPaper | Arithmetic-aware Targeted Fuzzing for Integer Overflow Vulnerability Detection in Virtual Devices Research Papers Track Zhenghao Li Key Laboratory of System Software (Chinese Academy of Sciences), Xiangkun Jia Key Laboratory of System Software (Chinese Academy of Sciences), Jia Yan Key Laboratory of System Software (Chinese Academy of Sciences), Purui Su Key Laboratory of System Software (Chinese Academy of Sciences) | ||
12:00 20mPaper | The Language of Security: How Prompt Syntax Shapes Secure Code Generation in Open LLMs Research Papers Track Matteo Cicalese University of Salerno, Antonio Della Porta University of Salerno, Stefano Lambiase Department of Computer Science, Aalborg University, Denmark, Emanuele Iannone Technische Universität Hamburg, Torge Hinrichs Technische Universität Hamburg, Riccardo Scandariato Hamburg University of Technology, Fabio Palomba University of Salerno Pre-print | ||
12:20 10mShort-paper | GHAgentFiles: A dataset of coding agent file histories in GitHub repositories Tool Demonstration and Data Showcase Track Guillaume Cardoen University of Mons, Tom Mens University of Mons, Alexandre Decan University of Mons; F.R.S.-FNRS Pre-print Media Attached | ||