Static Analysis of Vulnerabilities That AI-Based Code Assistants May Introduce

dc.contributor.authorMengüllüoǧlu, Mehmet Ali
dc.contributor.authorTatar, Zeynep Nisanur
dc.contributor.authorMaral, Yusuf
dc.contributor.authorUlaş, Harun
dc.contributor.authorBaykara, Muhammet
dc.date.accessioned2026-09-08T07:08:32Z
dc.date.issued2026
dc.departmentFırat Üniveristesi
dc.description2nd International Symposium on AI-Driven Engineering Systems, ISADES 2026 -- 19 June 2026 through 20 June 2026 -- Hybrid, Mbale -- 226193
dc.description.abstractWith the rapid development of Large Language Models (LLMs) today, they are beginning to be seen as an alternative to working with software experts for individuals without software expertise when developing web environments. In previous studies on this 'vibe coding' method, which appears low-cost and practical in theory, the individuals' knowledge base and the method itself have been overshadowed by the template databases used. In this study, by mimicking the methods of vibe coders, project files generated by various language models using a single prompt without any intervention are identified and compared using two different Static Application Security Testing (SAST) tools within an AI-powered coding agent-based (Agent-first) autonomous development environment. © 2026 IEEE.
dc.identifier.doi10.1109/ISADES69945.2026.11608062
dc.identifier.isbn979-831953447-7
dc.identifier.scopus2-s2.0-105046103822
dc.identifier.scopusqualityN/A
dc.identifier.urihttps://doi.org/10.1109/ISADES69945.2026.11608062
dc.identifier.urihttps://hdl.handle.net/11508/64942
dc.indekslendigikaynakScopus
dc.language.isoen
dc.publisherInstitute of Electrical and Electronics Engineers Inc.
dc.relation.ispartofISADES 2026 - 2nd International Symposium on AI-Driven Engineering Systems, Proceedings
dc.relation.publicationcategoryKonferans Öğesi - Uluslararası - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.snmzKA_Scopus_20250903
dc.subjectAgent-First
dc.subjectAntigravity
dc.subjectArtificial Intelligence
dc.subjectClaude Opus
dc.subjectClaude Sonnet
dc.subjectGemini
dc.subjectLinux
dc.subjectLlms
dc.subjectOwasp
dc.subjectSast
dc.subjectSecurity
dc.subjectSemgrep
dc.subjectSnyk
dc.subjectVibe Coding
dc.subjectVulnerability
dc.titleStatic Analysis of Vulnerabilities That AI-Based Code Assistants May Introduce
dc.typeConference Object

Dosyalar