{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T09:27:53Z","timestamp":1786786073970,"version":"3.56.0"},"reference-count":43,"publisher":"Springer Science and Business Media LLC","issue":"6","license":[{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T00:00:00Z","timestamp":1782086400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"name":"Guangdong Provincial Key Laboratory of Ultra High Definition Immersive Media Technology","award":["2024B1212010006"],"award-info":[{"award-number":["2024B1212010006"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Empir Software Eng"],"published-print":{"date-parts":[[2026,11]]},"DOI":"10.1007\/s10664-026-10866-8","type":"journal-article","created":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T11:25:03Z","timestamp":1782127503000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Is your prompt poisoning code? Defect induction rates and security mitigation strategies"],"prefix":"10.1007","volume":"31","author":[{"ORCID":"https:\/\/orcid.org\/0009-0005-3053-3160","authenticated-orcid":false,"given":"Bin","family":"Wang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"YiLu","family":"Zhong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"MiDi","family":"Wan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"WenJie","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"YuanBing","family":"Ouyang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"YeNan","family":"Huang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"HuiYu","family":"Wu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hui","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,22]]},"reference":[{"key":"10866_CR1","first-page":"1","volume-title":"Proceedings of the 2019 CHI conference on human factors in computing systems","author":"S Amershi","year":"2019","unstructured":"Amershi S, Weld D, Vorvoreanu M et al (2019) Guidelines for human-AI interaction. In: Proceedings of the 2019 CHI conference on human factors in computing systems, pp 1\u201313"},{"issue":"6","key":"10866_CR2","doi-asserted-by":"publisher","first-page":"673","DOI":"10.1007\/s42979-025-04241-5","volume":"6","author":"S Bistarelli","year":"2025","unstructured":"Bistarelli S, Fiore M, Mercanti I et al (2025) Usage of large language model for code generation tasks: a review. SN Comput Sci 6(6):673","journal-title":"SN Comput Sci"},{"key":"10866_CR3","first-page":"1877","volume":"33","author":"T Brown","year":"2020","unstructured":"Brown T, Mann B, Ryder N et al (2020) Language models are few-shot learners. Adv Neural Inf Process Syst 33:1877\u20131901","journal-title":"Adv Neural Inf Process Syst"},{"key":"10866_CR4","doi-asserted-by":"crossref","unstructured":"Chen J, Lu Y, Wang X et al (2025) Multi-agent-as-judge: aligning ILM-agent-based automated evaluation with multi-dimensional human evaluation. arXiv preprint arXiv:250721028","DOI":"10.18653\/v1\/2026.acl-long.790"},{"key":"10866_CR5","unstructured":"Chen M, Tworek J, Jun H et al (2021) Evaluating large language models trained on code. arXiv preprint arXiv:210703374"},{"key":"10866_CR6","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2024.112113","volume":"216","author":"D Cotroneo","year":"2024","unstructured":"Cotroneo D, Foggia A, Improta C et al (2024) Automating the correctness assessment of ai-generated code for security contexts. J Syst Softw 216:112113","journal-title":"J Syst Softw"},{"key":"10866_CR7","first-page":"1","volume-title":"Proceedings of the IEEE\/ACM 46th international conference on software engineering","author":"X Du","year":"2024","unstructured":"Du X, Liu M, Wang K et al (2024) Evaluating large language models in class-level code generation. In: Proceedings of the IEEE\/ACM 46th international conference on software engineering, pp 1\u201313"},{"key":"10866_CR8","unstructured":"Elgedawy R, Dosch P, Sadik J et al (2024) Occasionally secure: a comparative analysis of code generation assistants. arXiv preprint arXiv:240200689"},{"issue":"9","key":"10866_CR9","doi-asserted-by":"publisher","first-page":"572","DOI":"10.3390\/info15090572","volume":"15","author":"T Espinha Gasiba","year":"2024","unstructured":"Espinha Gasiba T, Iosif AC, Kessba I et al (2024) May the source be with you: on ChatGPT, cyber security, and secure coding. Information 15(9):572","journal-title":"Information"},{"key":"10866_CR10","first-page":"31","volume-title":"2023 IEEE\/ACM international conference on software engineering: future of software engineering (ICSE-FoSE)","author":"A Fan","year":"2023","unstructured":"Fan A, Gokkaya B, Harman M et al (2023) Large language models for software engineering: Survey and open problems. In: 2023 IEEE\/ACM international conference on software engineering: future of software engineering (ICSE-FoSE). IEEE, pp 31\u201353"},{"key":"10866_CR11","doi-asserted-by":"publisher","first-page":"935","DOI":"10.1145\/3540250.3549098","volume-title":"Proceedings of the 30th ACM joint European software engineering conference and symposium on the foundations of software engineering","author":"M Fu","year":"2022","unstructured":"Fu M, Tantithamthavorn C, Le T et al (2022) VulRepair: a T5-based automated software vulnerability repair. In: Proceedings of the 30th ACM joint European software engineering conference and symposium on the foundations of software engineering, pp 935\u2013947"},{"issue":"8","key":"10866_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3716848","volume":"34","author":"Y Fu","year":"2025","unstructured":"Fu Y, Liang P, Tahir A et al (2025) Security weaknesses of copilot-generated code in GitHub projects: an empirical study. ACM Trans Softw Eng Methodol 34(8):1\u201334","journal-title":"ACM Trans Softw Eng Methodol"},{"issue":"11","key":"10866_CR13","doi-asserted-by":"publisher","first-page":"665","DOI":"10.1038\/s42256-020-00257-z","volume":"2","author":"R Geirhos","year":"2020","unstructured":"Geirhos R, Jacobsen JH, Michaelis C et al (2020) Shortcut learning in deep neural networks. Nat Mach Intell 2(11):665\u2013673","journal-title":"Nat Mach Intell"},{"key":"10866_CR14","unstructured":"Gendron G, Bao Q, Witbrock M et al (2023) Large language models are not strong abstract reasoners. arXiv preprint arXiv:230519555"},{"key":"10866_CR15","unstructured":"Generation C (2024) CodeRAG-Bench: can retrieval augment code generation"},{"key":"10866_CR16","doi-asserted-by":"publisher","first-page":"1004","DOI":"10.1145\/3756681.3756984","volume-title":"Proceedings of the 29th international conference on evaluation and assessment in software engineering","author":"J Gong","year":"2025","unstructured":"Gong J, Duan N, Tao Z et al (2025) How well do large language models serve as end-to-end secure code agents for python? In: Proceedings of the 29th international conference on evaluation and assessment in software engineering, pp 1004\u20131013"},{"key":"10866_CR17","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1145\/3605764.3623985","volume-title":"Proceedings of the 16th ACM workshop on artificial intelligence and security","author":"K Greshake","year":"2023","unstructured":"Greshake K, Abdelnabi S, Mishra S et al (2023) Not what you've signed up for: compromising real-world lm-integrated applications with indirect prompt injection. In: Proceedings of the 16th ACM workshop on artificial intelligence and security, pp 79\u201390"},{"key":"10866_CR18","doi-asserted-by":"publisher","first-page":"684","DOI":"10.1109\/SaTML59370.2024.00040","volume-title":"2024 IEEE conference on secure and trustworthy machine learning (SaTML)","author":"H Hajipour","year":"2024","unstructured":"Hajipour H, Hassler K, Holz T et al (2024) CodeLMSec benchmark: systematically evaluating and finding security vulnerabilities in black-box code language models. In: 2024 IEEE conference on secure and trustworthy machine learning (SaTML). IEEE, pp 684\u2013709"},{"issue":"8","key":"10866_CR19","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3695988","volume":"33","author":"X Hou","year":"2024","unstructured":"Hou X, Zhao Y, Liu Y et al (2024) Large language models for software engineering: a systematic literature review. ACM Trans Softw Eng Methodol 33(8):1\u201379","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"10866_CR20","doi-asserted-by":"publisher","DOI":"10.1016\/j.csi.2024.103917","volume":"92","author":"RA Husein","year":"2025","unstructured":"Husein RA, Aburajouh H, Catal C (2025) Large language models for code completion: a systematic literature review. Comput Stand Interfaces 92:103917","journal-title":"Comput Stand Interfaces"},{"key":"10866_CR21","doi-asserted-by":"publisher","first-page":"229","DOI":"10.1145\/3603287.3651194","volume-title":"Proceedings of the 2024 ACM southeast conference","author":"M Jamdade","year":"2024","unstructured":"Jamdade M, Liu Y (2024) A pilot study on secure code generation with ChatGPT for web applications. In: Proceedings of the 2024 ACM southeast conference, pp 229\u2013234"},{"issue":"12","key":"10866_CR22","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3571730","volume":"55","author":"Z Ji","year":"2023","unstructured":"Ji Z, Lee N, Frieske R et al (2023) Survey of hallucination in natural language generation. ACM Comput Surv 55(12):1\u201338","journal-title":"ACM Comput Surv"},{"key":"10866_CR23","doi-asserted-by":"publisher","first-page":"159","DOI":"10.1145\/3779211.3795738","volume-title":"Proceedings of the nineteenth ACM international conference on web search and data mining","author":"H Joshi","year":"2026","unstructured":"Joshi H (2026) Joint evaluation: a human+ ILM+ multi-agents collaborative frame- work for comprehensive AI safety (Jo.E). In: Proceedings of the nineteenth ACM international conference on web search and data mining, pp 159\u2013173"},{"key":"10866_CR24","doi-asserted-by":"crossref","unstructured":"Khoury R, Avila AR, Brunelle J et al (2023) How secure is code generated by ChatGPT? arXiv preprint arXiv:230409655","DOI":"10.1109\/SMC53992.2023.10394237"},{"key":"10866_CR25","first-page":"9459","volume":"33","author":"P Lewis","year":"2020","unstructured":"Lewis P, Perez E, Piktus A et al (2020) Retrieval-augmented generation for knowledge-intensive NLP tasks. Adv Neural Inf Proc Syst 33:9459\u20139474","journal-title":"Adv Neural Inf Proc Syst"},{"key":"10866_CR26","first-page":"35735","volume-title":"International conference on learning representations","author":"Z Li","year":"2025","unstructured":"Li Z, Dutta S, Naik M (2025) Iris: LLM-assisted static analysis for detecting security vulnerabilities. In: International conference on learning representations, pp 35735\u201335758"},{"key":"10866_CR27","unstructured":"Lian K, Wang B, Zhang L et al (2025) ASE: a repository-level benchmark for evaluating security in AI-generated code. arXiv preprint arXiv:250818106"},{"issue":"5","key":"10866_CR28","first-page":"1","volume":"33","author":"Y Liu","year":"2024","unstructured":"Liu Y, Le-Cong T, Widyasari R et al (2024) Refining ChatGPT-generated code: characterizing and mitigating code quality issues. ACM Trans Softw Eng Methodol 33(5):1\u201326","journal-title":"ACM Trans Softw Eng Methodol"},{"key":"10866_CR29","doi-asserted-by":"publisher","first-page":"46534","DOI":"10.52202\/075280-2019","volume":"36","author":"A Madaan","year":"2023","unstructured":"Madaan A, Tandon N, Gupta P et al (2023) Self-refine: iterative refinement with self-feedback. Adv Neural Inf Process Syst 36:46534\u201346594","journal-title":"Adv Neural Inf Process Syst"},{"key":"10866_CR30","doi-asserted-by":"publisher","first-page":"435","DOI":"10.1109\/SANER60148.2024.00051","volume-title":"2024 IEEE international conference on software analysis, evolution and reengineering (SANER)","author":"V Majdinasab","year":"2024","unstructured":"Majdinasab V, Bishop MJ, Rasheed S et al (2024) Assessing the security of GitHub copilot's generated code-a targeted replication study. In: 2024 IEEE international conference on software analysis, evolution and reengineering (SANER). IEEE, pp 435\u2013444"},{"key":"10866_CR31","doi-asserted-by":"publisher","first-page":"1299","DOI":"10.1145\/3634737.3661134","volume-title":"Proceedings of the 19th ACM Asia conference on computer and communications security","author":"Z Mousavi","year":"2024","unstructured":"Mousavi Z, Islam C, Moore K et al (2024) An investigation into misuse of java security APIs by large language models. In: Proceedings of the 19th ACM Asia conference on computer and communications security, pp 1299\u20131315"},{"key":"10866_CR32","doi-asserted-by":"publisher","first-page":"1386720","DOI":"10.3389\/fdata.2024.1386720","volume":"7","author":"C Negri-Ribalta","year":"2024","unstructured":"Negri-Ribalta C, Geraud-Stewart R, Sergeeva A et al (2024) A systematic literature review on the impact of AI models on the security of code generation. Front Big Data 7:1386720","journal-title":"Front Big Data"},{"key":"10866_CR33","doi-asserted-by":"publisher","first-page":"2339","DOI":"10.1109\/SP46215.2023.10179324","volume-title":"2023 IEEE symposium on security and privacy (SP)","author":"H Pearce","year":"2023","unstructured":"Pearce H, Tan B, Ahmad B et al (2023) Examining zero-shot vulnerability repair with large language models. In: 2023 IEEE symposium on security and privacy (SP). IEEE, pp 2339\u20132356"},{"issue":"2","key":"10866_CR34","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1145\/3610721","volume":"68","author":"H Pearce","year":"2025","unstructured":"Pearce H, Ahmad B, Tan B et al (2025) Asleep at the keyboard? Assessing the security of GitHub copilot's code contributions. Commun ACM 68(2):96\u2013105","journal-title":"Commun ACM"},{"key":"10866_CR35","doi-asserted-by":"publisher","first-page":"2785","DOI":"10.1145\/3576915.3623157","volume-title":"Proceedings of the 2023 ACM SIGSAC conference on computer and communications security","author":"N Perry","year":"2023","unstructured":"Perry N, Srivastava M, Kumar D et al (2023) Do users write more insecure code with AI assistants? In: Proceedings of the 2023 ACM SIGSAC conference on computer and communications security, pp 2785\u20132799"},{"key":"10866_CR36","doi-asserted-by":"publisher","first-page":"660","DOI":"10.1145\/3658644.3690291","volume-title":"Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security","author":"J Shi","year":"2024","unstructured":"Shi J, Yuan Z, Liu Y et al (2024) Optimization-based prompt injection attack to ILM-as-a-judge. In: Proceedings of the 2024 on ACM SIGSAC conference on computer and communications security, pp 660\u2013674"},{"key":"10866_CR37","first-page":"29","volume-title":"Proceedings of the Ist international workshop on mining: software repositories applications for privacy and security","author":"ML Siddiq","year":"2022","unstructured":"Siddiq ML, Santos JC (2022) SecurityEval dataset: mining vulnerability examples to evaluate machine learning-based code generation techniques. In: Proceedings of the Ist international workshop on mining: software repositories applications for privacy and security, pp 29\u201333"},{"key":"10866_CR38","doi-asserted-by":"publisher","first-page":"23","DOI":"10.1109\/APR59189.2023.00012","volume-title":"2023 IEEE\/ACM international workshop on automated program repair (APR)","author":"D Sobania","year":"2023","unstructured":"Sobania D, Briesch M, Hanna C et al (2023) An analysis of the automatic bug fixing performance of ChatGPT. In: 2023 IEEE\/ACM international workshop on automated program repair (APR). IEEE, pp 23\u201330"},{"key":"10866_CR39","doi-asserted-by":"publisher","first-page":"588","DOI":"10.1109\/MSR59073.2023.00084","volume-title":"2023 IEEE\/ACM 20th international conference on mining software repositories (MSR)","author":"C Tony","year":"2023","unstructured":"Tony C, Mutas M, Ferreyra NED et al (2023) LLMSecEval: A dataset of natural language prompts for security evaluations. In: 2023 IEEE\/ACM 20th international conference on mining software repositories (MSR). IEEE, pp 588\u2013692"},{"key":"10866_CR43","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1145\/1250734.1250739","volume-title":"Proceedings of the 28th ACM SIGPLAN conference on programming language design and implementation","author":"G Wassermann","year":"2007","unstructured":"Wassermann G, Su Z (2007) Sound and precise analysis of web applications for injection vulnerabilities. In: Proceedings of the 28th ACM SIGPLAN conference on programming language design and implementation, pp 32\u201341"},{"key":"10866_CR44","doi-asserted-by":"publisher","first-page":"24824","DOI":"10.52202\/068431-1800","volume":"35","author":"J Wei","year":"2022","unstructured":"Wei J, Wang X, Schuurmans D et al (2022) Chain-of-thought prompting elicits reasoning in large language models. Adv Neural Inf Process Syst 35:24824\u201324837","journal-title":"Adv Neural Inf Process Syst"},{"key":"10866_CR45","doi-asserted-by":"crossref","unstructured":"Yu Z, Zhang X, Shang N et al (2024) WaveCoder: widespread and versatile enhancement for code large language models by instruction tuning. In: Proceedings of the 62nd annual meeting of the association for computational linguistics (Volume 1: Long Papers), pp 5140-5153","DOI":"10.18653\/v1\/2024.acl-long.280"},{"key":"10866_CR46","doi-asserted-by":"publisher","first-page":"941","DOI":"10.1109\/ICDM59182.2024.00119","volume-title":"2024 IEEE international conference on data mining (ICDM)","author":"C Zhang","year":"2024","unstructured":"Zhang C, Jin M, Yu Q et al (2024) Goal-guided generative prompt injection attack on large language models. In: 2024 IEEE international conference on data mining (ICDM). IEEE, pp 941\u2013946"}],"container-title":["Empirical Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10866-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10664-026-10866-8","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10664-026-10866-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,8,15]],"date-time":"2026-08-15T09:03:37Z","timestamp":1786784617000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10664-026-10866-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,22]]},"references-count":43,"journal-issue":{"issue":"6","published-print":{"date-parts":[[2026,11]]}},"alternative-id":["10866"],"URL":"https:\/\/doi.org\/10.1007\/s10664-026-10866-8","relation":{},"ISSN":["1382-3256","1573-7616"],"issn-type":[{"value":"1382-3256","type":"print"},{"value":"1573-7616","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,22]]},"assertion":[{"value":"5 September 2025","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 April 2026","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 June 2026","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Not applicable. This study does not involve human subjects or animal experiments. All analyses were conducted on publicly available artifacts and did not include personally identifiable information.","order":1,"name":"Ethics","label":"Ethical Approval","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":2,"name":"Ethics","label":"Conflicts of Interest","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable. The study involves no human subjects and does not include any personally identifiable information.","order":3,"name":"Ethics","label":"Informed Consent","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"Not applicable.","order":4,"name":"Ethics","label":"Clinical Trial Number","group":{"name":"EthicsHeading","label":"Declarations"}}],"article-number":"172"}}