6 papers
The Cathedral and the Bazaar of Software Vulnerabilities: From the NVD to the CNAs
Siqi Zhang, Fabio Massacci, Mengyuan Zhang
For decades, the National Vulnerability Database (NVD), the "Cathedral", has been the reference source for vulnerability information for downstream research and industry tasks, e.g…
Helpful or Harmful? Evaluating LLM-Assisted Vulnerability Patching via a Human Study
Giulian Biolo, Michael Tezza, Yuanjun Gong +1
Software vulnerability remediation is a cognitively demanding task that requires specialized security expertise often lacking in general developers. In the meantime, Large Language…
LLMs for Qualitative Data Analysis Fail on Security-specificComments in Human Experiments
Maria Camporese, Fabio Massacci, Yuanjun Gong
[Background:] Thematic analysis of free-text justifications in human experiments provides significant qualitative insights. Yet, it is costly because reliable annotations require m…
Large Language Models Are Unreliable for Cyber Threat Intelligence
Emanuele Mezzi, Fabio Massacci, Katja Tuma
Several recent works have argued that Large Language Models (LLMs) can be used to tame the data deluge in the cybersecurity field, by improving the automation of Cyber Threat Intel…
Risks of ignoring uncertainty propagation in AI-augmented security pipelines
Emanuele Mezzi, Aurora Papotti, Fabio Massacci +1
The use of AI technologies is being integrated into the secure development of software-based systems, with an increasing trend of composing AI-based subsystems (with uncertain leve…
Using AI Assistants in Software Development: A Qualitative Study on Security Practices and Concerns
Jan H. Klemmer, Stefan Albert Horstmann, Nikhil Patnaik +10
Following the recent release of AI assistants, such as OpenAI's ChatGPT and GitHub Copilot, the software industry quickly utilized these tools for software development tasks, e.g.,…