Beyond Copy–Pasting—Contextualizing LLMs for Secure Code Generation
摘要
The transformative impact of Large Language Models (LLMs) and Co-pilots on software development is undeniable, substantially boosting developer productivity and accelerating code creation. However, amid these advancements, the critical need to scrutinize code recommendations from a security standpoint becomes increasingly apparent. This study goes beyond assessing code snippets generated by LLMs and co-pilots; it seeks to propose strategic contextualization tactics on Secure Coding Practices (SCPs) for developers. The objective is twofold: to comprehensively evaluate code snippets (qualitative analysis) for security vulnerabilities generated by LLMs or co-pilots, and to empower developers with actionable strategies and recommendations to contextualize or fine-tune their LLMs effectively. By presenting strategic contextualization as a proactive solution, this research aims to enhancing the security of code generated by LLMs and co-pilots, aligning with accelerated development with robust security practices.