{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T06:04:21Z","timestamp":1784268261539,"version":"3.55.0"},"reference-count":73,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/icst69053.2026.00075","type":"proceedings-article","created":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:48:20Z","timestamp":1784238500000},"page":"519-530","source":"Crossref","is-referenced-by-count":0,"title":["Do Language Models Prefer Vulnerable Code? A Probabilistic Study of Insecure Code Preference"],"prefix":"10.1109","author":[{"given":"Rui","family":"Melo","sequence":"first","affiliation":[{"name":"Carnegie Mellon University,Pittsburgh,PA,USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sofia","family":"Reis","sequence":"additional","affiliation":[{"name":"University of Porto,Faculty of Engineering,Porto,Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Andre","family":"Catarino","sequence":"additional","affiliation":[{"name":"University of Porto,Faculty of Engineering,Porto,Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Rui","family":"Abreu","sequence":"additional","affiliation":[{"name":"University of Porto,Faculty of Engineering,Porto,Portugal"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1145\/3520312.3534864"},{"key":"ref2","article-title":"Github copilot ai pair programmer: Asset or liability?","author":"Dakhel","year":"2023"},{"key":"ref3","first-page":"2205","article-title":"Lost at c: A user study on the security implications of large language model code assistants","volume-title":"32nd USENIX Security Symposium (USENIX Security 23).","author":"Sandoval"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/SMC53992.2023.10394237"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2023.3300381"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-023-10380-1"},{"key":"ref7","doi-asserted-by":"crossref","DOI":"10.1109\/TSE.2024.3392499","article-title":"No need to lift a finger anymore? assessing the quality of code generation by chatgpt","author":"Liu","year":"2024"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623157"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833571"},{"key":"ref10","article-title":"Helping l l ms improve code generation using feedback from testing and static analysis","author":"Dolcetti","year":"2025"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690298"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3691367"},{"key":"ref13","doi-asserted-by":"crossref","DOI":"10.1109\/SCAM63643.2024.00020","article-title":"Franc: A lightweight framework for high-quality code generation","author":"Siddiq","year":"2024"},{"key":"ref14","article-title":"Llm-powered code vulnerability repair with reinforcement learning and semantic reward","author":"Islam","year":"2024"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/LLM4Code66737.2025.00009"},{"key":"ref16","article-title":"Measuring coding challenge competence with apps","author":"Hendrycks","year":"2021","journal-title":"arXiv preprint arXiv:2105.09938"},{"key":"ref17","article-title":"Program synthesis with large language models","author":"Austin","year":"2021"},{"key":"ref18","article-title":"Codegen: An open large language model for code with multi-turn program synthesis","volume-title":"arXiv preprint arXiv:2203.13474","author":"Nijkamp","year":"2022"},{"key":"ref19","article-title":"Evaluating language models for efficient code generation","author":"Liu","year":"2024","journal-title":"arXiv preprint arXiv:2408.06450"},{"key":"ref20","article-title":"Livecodebench: Holistic and contamination free evaluation of large language models for code","author":"Jain","year":"2024","journal-title":"arXiv preprint arXiv:2403.07974"},{"key":"ref21","article-title":"Swe-bench: Can language models resolve real-world github issues?","author":"Jimenez","year":"2023","journal-title":"arXiv preprint arXiv:2310.06770"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0943"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2023.acl-long.773"},{"key":"ref24","article-title":"Evaluating large language models trained on code","author":"Chen","year":"2021"},{"key":"ref25","article-title":"Codexglue: A machine learning benchmark dataset for code understanding and generation","author":"Lu","year":"2021"},{"key":"ref26","article-title":"Attention is all you need","author":"Vaswani","year":"2017","journal-title":"Advances in Neural Information Processing Systems"},{"issue":"Feb","key":"ref27","first-page":"1137","article-title":"A neural probabilistic language model","volume":"3","author":"Bengio","year":"2003","journal-title":"Journal of machine learning research"},{"key":"ref28","article-title":"What is wrong with perplexity for long-context language modeling?","author":"Fang","year":"2025"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2022.findings-emnlp.198"},{"key":"ref30","article-title":"Fine-tuning language models from human p","author":"Ziegler","year":"2019","journal-title":"arXiv preprint arXiv:1909.08593"},{"key":"ref31","first-page":"3008","article-title":"Learning to summarize with human feedback","volume":"33","author":"Stiennon","year":"2020","journal-title":"Advances in neural information processing systems"},{"key":"ref32","article-title":"Purple llama cyberseceval: A secure coding benchmark for language models","author":"Bhatt","year":"2023","journal-title":"arXiv preprint arXiv:2312.04724"},{"key":"ref33","article-title":"Cyberseceval 3: Advancing the evaluation of cybersecurity risks and capabilities in large language models","author":"Wan","year":"2024","journal-title":"arXiv preprint arXiv:2408.01605"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML59370.2024.00040"},{"key":"ref35","article-title":"Enhancing large language models for secure code generation: A dataset-driven study on vulnerability mitigation","author":"Wang","year":"2023","journal-title":"arXiv preprint arXiv:2310.16263"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-76934-4_7"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3691621.3694934"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-024-10590-1"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227135"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.52202\/075280-2338"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.findings-acl.1101"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1038\/s41586-024-07421-0"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1646353.1646374"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/MSR66628.2025.11513373"},{"key":"ref45","article-title":"A ground-truth dataset of real security patches","author":"Reis","year":"2021","journal-title":"arXiv preprint arXiv:2110.09635"},{"key":"ref46","article-title":"Large language models for test-free fault localization","author":"Yang","year":"2023"},{"key":"ref47","article-title":"Repairllama: Efficient representations and fine-tuned adapters for program repair","author":"Silva","year":"2024"},{"key":"ref48","doi-asserted-by":"crossref","DOI":"10.1145\/3639476.3639762","article-title":"Large language model for vulnerability detection: Emerging results and future directions","author":"Zhou","year":"2024"},{"key":"ref49","article-title":"Code llama: Open foundation models for code","author":"Rozi\u00e8re","year":"2023"},{"key":"ref50","article-title":"Mellum-4b-base","author":"Pavlichenko","year":"2025"},{"key":"ref51","article-title":"Starcoder 2 and the stack v2: The next generation","author":"Lozhkov","year":"2024"},{"key":"ref52","article-title":"Deepseek-coder: When the large language model meets programming \u2013 the rise of code intelligence","author":"Guo","year":"2024"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2012.6227135"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884848"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.2307\/2334029"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1002\/j.1538-7305.1948.tb01338.x"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-04898-2_616"},{"key":"ref58","article-title":"Emergent abilities of large language models","author":"Wei","year":"2022"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1145\/3706599.3706670"},{"key":"ref60","article-title":"Github copilot: Your ai pair programmer","year":"2023"},{"key":"ref61","article-title":"Ai code assistant","year":"2025"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1145\/3603287.3651194"},{"key":"ref63","article-title":"Can chatgpt fix your code? evaluating zero-shot code repair with llms","volume-title":"Proceedings of the 2023 Conference on Neural Information Processing Systems (NeurIPS).","author":"Zhang"},{"key":"ref64","doi-asserted-by":"publisher","DOI":"10.1145\/3643991.3645074"},{"key":"ref65","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623175"},{"key":"ref66","first-page":"1277","volume-title":"Securing Language Models Against Vulnerability Encoding.","author":"Melo","year":"2025"},{"key":"ref67","article-title":"Sparse autoencoders find highly interpretable features in language models","author":"Cunningham","year":"2023","journal-title":"arXiv preprint arXiv:2309.08600"},{"key":"ref68","article-title":"Towards monosemanticity: Decomposing language models with dictionary learning","author":"Bricken","year":"2023","journal-title":"Transformer Circuits Thread"},{"key":"ref69","article-title":"Scaling and evaluating sparse autoencoders","author":"Gao","year":"2024","journal-title":"arXiv preprint"},{"key":"ref70","article-title":"Are sparse autoencoders useful for java function bug detection?","author":"Melo","year":"2025"},{"key":"ref71","article-title":"Representation engineering: A top-down approach to ai transparency","author":"Zou","year":"2025"},{"key":"ref72","article-title":"A mixture of linear corrections generates secure code","author":"Yu","year":"2025","journal-title":"arXiv preprint arXiv:2507.09508"},{"key":"ref73","article-title":"Understanding intermediate layers using linear classifier probes","author":"Alain","year":"2016","journal-title":"arXiv preprint arXiv:1610.01644"}],"event":{"name":"2026 IEEE International Conference on Software Testing, Verification and Validation (ICST)","location":"Daejeon, Korea, Republic of","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,22]]}},"container-title":["2026 IEEE International Conference on Software Testing, Verification and Validation (ICST)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11600401\/11600462\/11600473.pdf?arnumber=11600473","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,17]],"date-time":"2026-07-17T05:22:11Z","timestamp":1784265731000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11600473\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":73,"URL":"https:\/\/doi.org\/10.1109\/icst69053.2026.00075","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}