• Home
  • Search
  • Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration
  • Cite Icon2
  • https://doi.org/10.1109/tse.2025.3619281Copy DOI Icon

Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration

Show More
  • Abstract
  • Literature Map
  • References
  • Citations
  • Similar Papers
Abstract

Automated code generation has revolutionized software development, enabling developers to accelerate project timelines and reduce manual coding errors significantly. As reliance on these technologies grows, the inherent weaknesses of generated code become increasingly apparent. Recent studies have shown that code produced by AI is not inherently safer or of higher quality than human-written code, often replicating existing vulnerabilities. <p xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink">To this end, we propose SECURECODER, which integrates Retrieval-Augmented Generation (RAG) with Common Weakness Enumeration (CWE). SECURECODER first utilizes the advanced reasoning capabilities of large language models (LLMs) to generate natural language descriptions of the code’s core business logic and functionality. Then, from a semantic perspective, it matches the requirements of the code generation task with the CWE descriptions through a multi-label classification process. Finally, based on the matched CWE, SECURECODER generates a list of security guidelines the code generation model must adhere to. Breaking down end-to-end code generation tasks into single-target tasks that LLMs excel at ensures that the generated code not only meets functional requirements but also adheres to best security practices, thereby enhancing the interpretability of the automated code generation process. After evaluating 2 programming languages and 7 LLMs on Coploit-generated code, SECURECODER has great generalization capability and could be applied to more programming languages and vulnerability types. SECURECODER could significantly decrease the security weakness in the AI-generated code and is able to mitigate more than 65% of vulnerabilities exposed to software developers. Compared to the baseline open-source LLMs, code vulnerabilities were reduced by at least 14% and the code business logic was not affected.

Similar Papers
  • PDF
  • Research Article
  • Citations7

Unit Test Generation Using Large Language Models: A Systematic Literature Review

  • May 13, 2024
  • Vilnius University Open Series
  • Dovydas Marius Zapkus +1
  • Research Article
  • Citations1

Evaluating the Test Adequacy of Benchmarks for LLMs on Code Generation

  • Jun 25, 2025
  • Journal of Software: Evolution and Process
  • Xiangyue Liu +5
  • Research Article
  • Citations1

AI-Powered Code Generation Evaluating the Effectiveness of Large Language Models (LLMs) in Automated Software Development

  • Mar 31, 2023
  • Journal of Artificial Intelligence &amp; Cloud Computing
  • Ravikanth Konda
  • Research Article
  • Citations8

Building a Coding Assistant via the Retrieval-Augmented Language Model

  • Jan 17, 2025
  • ACM Transactions on Information Systems
  • Xinze Li +8
  • Supplementary Content

Automating Code Generation for a New Ecosystem: Establishing Baselines with Large Language Model Based Code Generation for ArkTS and HarmonyOS

  • Sep 04, 2025
  • Research Square
  • Mehmet Cem Aytekin +2
  • Research Article
  • Citations4

GeoJSEval: An Automated Evaluation Framework for Large Language Models on JavaScript-Based Geospatial Computation and Visualization Code Generation

  • Sep 28, 2025
  • ISPRS International Journal of Geo-Information
  • Guanyu Chen +8
  • Research Article

TaskEval: Assessing Difficulty of Code Generation Tasks for Large Language Models

  • Oct 28, 2025
  • ACM Transactions on Software Engineering and Methodology
  • Florian Tambon +4
  • Conference Article
  • Citations1

LLASP: Fine-tuning Large Language Models for Answer Set Programming

  • Nov 01, 2024
  • Erica Coppolillo +4
  • Research Article

State of the Art of the Security of Code Generated by LLMs: A Multivocal Literature Review

  • Dec 01, 2025
  • Programming and Computer Software
  • Leonardo Criollo Ramírez +3
  • Research Article
  • Citations1

Anchor Attention, Small Cache: Code Generation With Large Language Models

  • Jun 01, 2025
  • IEEE Transactions on Software Engineering
  • Xiangyu Zhang +4
  • Research Article
  • Citations7

COFFE: A Code Efficiency Benchmark for Code Generation

  • Jun 19, 2025
  • Proceedings of the ACM on Software Engineering
  • Yun Peng +3
  • Preprint Article

Code Generation: GPT vs Llama 4

  • May 16, 2025
  • Front Matter
  • Yao Chen
  • Research Article

Research and selection of Large Learning Models for automation of ABAP-code migration

  • Sep 24, 2025
  • Management of Development of Complex Systems
  • Oleg Pozdnyakov +1
  • Research Article
  • Citations3

VISION: Robust and Interpretable Code Vulnerability Detection Leveraging Counterfactual Augmentation

  • Oct 15, 2025
  • Proceedings of the AAAI/ACM Conference on AI, Ethics, and Society
  • David Egea +2
  • Conference Article

Utilizing Chain of Thought to Generate Code from Challenging Programming Requirements

  • Feb 03, 2026
  • Emanalofi +2
Cactus Communications logo

Copyright 2026 Cactus Communications. All rights reserved.