SANER 2026
Tue 17 - Fri 20 March 2026 Limassol, Cyprus
Tue 17 Mar 2026 16:50 - 17:10 at Megaron Gamma - MSR4P&S - Session 2

We investigated the capabilities of GPT-4o and Gemini 2.0 Flash for secure Infrastructure as Code (IaC) development. On the Stack Overflow dataset, which primarily contains small, simplified code snippets, the models detected at least 71% of security smells when prompted to analyze code from a security perspective (general prompt). With a guided prompt (adding clear, step-by-step instructions), this increased to 78%. In GitHub repositories, which contain complete, real-world project scripts, a general prompt was less effective, leaving more than half of the smells undetected. However, with the guided prompt, the models uncovered at least 67% of security smells and achieved promising F1 scores of 74% or higher. To assess how cautious LLMs are about security risks, we then asked the models to generate code for synthetic scenarios based on 89 insecure patterns identified from GitHub IaC scripts. For both models, only 7% of the generated scripts were secure. Adding an explicit instruction to generate secure code increased GPT-4o’s secure output rate to 17%, while Gemini 2.0 Flash changed little (8%); however, the number of warnings increased. This study highlights the need for further research to improve LLMs’ capabilities in assisting developers with secure IaC development.

Tue 17 Mar

Displayed time zone: Athens change

16:00 - 17:30
MSR4P&S - Session 2Workshops & Tutorials at Megaron Gamma
16:00
20m
Talk
Evaluating Large Language Models for Security Bug Report Prediction
Workshops & Tutorials
Farnaz Soltaniani Technische Universität Clausthal, Shoaib Razzaq Technical University of Clausthal, Mohammad Ghafari TU Clausthal
16:20
20m
Talk
Towards Project-Aware Actionability Detection for Coding Rule Violations
Workshops & Tutorials
Széles Csoma Lázár University of Szeged, Department of Software Engineering, Gergő Balogh Department of Software Engineering, University of Szeged
16:40
10m
Talk
Don’t Mind the Mesh: An Empirical Study of Istio Service Mesh Security in GitHub
Workshops & Tutorials
Kohsuke Sonoda Aalto university, Jose Luis Martin-Navarro Aalto University, Tuomas Aura Aalto University
16:50
20m
Talk
Can Developers rely on LLMs for Secure IaC Development?
Workshops & Tutorials
Ehsan Firouzi TU Clausthal, Shardul Bhatt TU Clausthal, Mohammad Ghafari TU Clausthal
17:10
20m
Talk
Persistent Human Feedback, LLMs, and Static Analyzers for Secure Code Generation and Vulnerability Detection
Workshops & Tutorials
Ehsan Firouzi TU Clausthal, Mohammad Ghafari TU Clausthal