{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T15:54:43Z","timestamp":1784044483496,"version":"3.55.0"},"reference-count":78,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"12","license":[{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,12,1]],"date-time":"2025-12-01T00:00:00Z","timestamp":1764547200000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Key Research and Development Program of China","award":["2023YFB3106600"],"award-info":[{"award-number":["2023YFB3106600"]}]},{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["62472296"],"award-info":[{"award-number":["62472296"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IIEEE Trans. Software Eng."],"published-print":{"date-parts":[[2025,12]]},"DOI":"10.1109\/tse.2025.3619281","type":"journal-article","created":{"date-parts":[[2025,10,9]],"date-time":"2025-10-09T17:53:23Z","timestamp":1760032403000},"page":"3507-3523","source":"Crossref","is-referenced-by-count":6,"title":["Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration"],"prefix":"10.1109","volume":"51","author":[{"given":"Jianguo","family":"Zhao","sequence":"first","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4340-3371","authenticated-orcid":false,"given":"Yuqiang","family":"Sun","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5871-946X","authenticated-orcid":false,"given":"Cheng","family":"Huang","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1175-2753","authenticated-orcid":false,"given":"Chengwei","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"YaoHui","family":"Guan","sequence":"additional","affiliation":[{"name":"Beijing Language and Culture University, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yutong","family":"Zeng","sequence":"additional","affiliation":[{"name":"School of Cyber Science and Engineering, Sichuan University, Chengdu, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7300-9215","authenticated-orcid":false,"given":"Yang","family":"Liu","sequence":"additional","affiliation":[{"name":"Nanyang Technological University, Singapore"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","article-title":"Training language models to follow instructions with human feedback","author":"Ouyang","year":"2022"},{"key":"ref2","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023"},{"key":"ref3","article-title":"GitHub copilot your AI pair programmer."},{"key":"ref5","first-page":"754","article-title":"Asleep at the keyboard? Assessing the security of GitHub copilot\u2019s code contributions","volume-title":"Proc. IEEE Symp. Secur. Privacy (SP)","author":"Pearce","year":"2022"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623157"},{"key":"ref7","first-page":"21558","article-title":"Is your code generated by ChatGPT really correct? Rigorous evaluation of large language models for code generation","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"36","author":"Liu","year":"2023"},{"key":"ref8","article-title":"Copyrights, professional perspective - IP issues with AI code generators."},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3597503.3639117"},{"key":"ref10","article-title":"LLM4Vuln: A unified evaluation framework for decoupling and enhancing LLMS\u2019 vulnerability reasoning","author":"Sun","year":"2024"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1145\/3649828"},{"key":"ref12","article-title":"Large language models are edge-case fuzzers: Testing deep learning libraries via FuzzGPT","author":"Deng","year":"2023"},{"key":"ref13","first-page":"1","article-title":"Large language model guided protocol fuzzing","volume-title":"Proc. Netw. Distrib. Syst. Secur. Symp.","author":"Meng","year":"2024"},{"key":"ref14","article-title":"PentestGPt: An LLM-empowered automatic penetration testing tool","author":"Deng","year":"2023"},{"key":"ref15","article-title":"ACFIX: Guiding LLMs with mined common RBAC practices for context-aware repair of access control vulnerabilities in smart contracts","author":"Zhang","year":"2024"},{"key":"ref16","article-title":"Keep the conversation going: Fixing 162 out of 337 bugs for $0.42 each using ChatGPT","author":"Xia"},{"key":"ref17","article-title":"Why can GPT learn in-context? Language models implicitly perform gradient descent as meta-optimizers","author":"Dai","year":"2023"},{"key":"ref18","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume-title":"Proc. NeurIPS","author":"Wei","year":"2022"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v38i16.29720"},{"key":"ref20","first-page":"9459","article-title":"Retrieval-augmented generation for knowledge-intensive NLP tasks","volume-title":"Proc. NeurIPS","author":"Lewis","year":"2020"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2024.3392499"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2023.111734"},{"key":"ref23","first-page":"2205","article-title":"Lost at C: A user study on the security implications of large language model code assistants","volume-title":"Proc. 32nd USENIX Security Symp. (USENIX Security)","author":"Sandoval","year":"2023"},{"key":"ref24","article-title":"In ChatGPT we trust? Measuring and characterizing the reliability of ChatGPT","author":"Shen","year":"2023"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1145\/3558489.3559072"},{"key":"ref26","article-title":"Can ChatGPT replace StackOverflow? A study on robustness and reliability of large language model code generation","author":"Zhong","year":"2024"},{"key":"ref27","article-title":"Stack overflow - Where developers learn, share, & build careers"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v37i4.25642"},{"key":"ref30","first-page":"2339","article-title":"Examining zero-shot vulnerability repair with large language models","volume-title":"Proc. IEEE Symp. Secur. Privacy (SP)","author":"Pearce","year":"2023"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616256"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549101"},{"key":"ref33","article-title":"Repairing bugs in Python assignments using large language models","author":"Zhang","year":"2022"},{"key":"ref34","article-title":"Codexity: Secure AI-assisted code generation","author":"Kim","year":"2024"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/icse48619.2023.00061"},{"key":"ref36","article-title":"CWE - Common weakness enumeration","year":"2024"},{"key":"ref37","article-title":"ChatGPT \u2014 OpenAI."},{"key":"ref38","article-title":"Claude 2 model card","year":"2023"},{"key":"ref39","article-title":"Code Llama: Open foundation models for code","author":"Rozi\u00e8re","year":"2023"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/MSR59073.2023.00084"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1145\/3379597.3387501"},{"key":"ref42","article-title":"CodeBLEU: A method for automatic evaluation of code synthesis","author":"Ren","year":"2020"},{"key":"ref43","doi-asserted-by":"crossref","DOI":"10.1109\/TSE.2025.3619281","article-title":"Towards secure code generation with LLMs: A study common weakness enumeration","author":"Zhao","year":"2025"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2021.emnlp-main.685"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1108\/ws.2000.07949fab.004"},{"key":"ref46","first-page":"15908","article-title":"Transformer in transformer","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"34","author":"Han","year":"2021"},{"key":"ref47","article-title":"The stack: 3 tb of permissively licensed source code","author":"Kocetkov","year":"2022","journal-title":"Preprint"},{"key":"ref48","article-title":"Code Llama: Open foundation models for code","author":"Roziere","year":"2023"},{"key":"ref49","article-title":"Llama 2: Open foundation and fine-tuned chat models","author":"Touvron","year":"2023"},{"key":"ref50","article-title":"Gemini: A family of highly capable multimodal models","author":"Team","year":"2023"},{"key":"ref52","article-title":"Evaluating the code quality of AI-assisted code generation tools: An empirical study on GitHub copilot, Amazon CodeWhisperer, and ChatGPT","author":"Yeti\u015ftiren","year":"2023"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3643674"},{"key":"ref54","article-title":"AutoSafeCoder: A multi-agent framework for securing LLM code generation through static analysis and fuzz testing","author":"Nunez","year":"2024"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690298"},{"key":"ref56","article-title":"Kimi."},{"key":"ref57","article-title":"Cursor-fast model"},{"key":"ref58","article-title":"CodeQL: Powerful code analysis tool","year":"2024"},{"key":"ref59","article-title":"A comprehensive study of LLM secure code generation","author":"Dai","year":"2025"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.855"},{"key":"ref62","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE48619.2023.00088"},{"key":"ref63","doi-asserted-by":"publisher","DOI":"10.1145\/3533767.3534380"},{"key":"ref64","article-title":"Does prompt formatting have any impact on LLM performance?","author":"He","year":"2024"},{"key":"ref65","article-title":"Prompt engineering or fine tuning: An empirical assessment of large language models in automated software engineering tasks","author":"Shin","year":"2023"},{"key":"ref66","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"ref67","article-title":"Codexity: Secure AI-assisted code generation","author":"Kim","year":"2024"},{"key":"ref68","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3616271"},{"key":"ref69","first-page":"24824","article-title":"Chain-of-thought prompting elicits reasoning in large language models","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"35","author":"Wei","year":"2022"},{"key":"ref70","article-title":"Secure coding with AI, from creation to inspection","author":"Belozerov","year":"2025"},{"key":"ref71","article-title":"Text and code embeddings by contrastive pre-training","author":"Neelakantan","year":"2022"},{"key":"ref72","doi-asserted-by":"publisher","DOI":"10.1109\/tbdata.2025.3618474"},{"key":"ref73","article-title":"Instruction tuning for secure code generation","author":"He","year":"2024"},{"key":"ref74","article-title":"Evaluating large language models trained on code","author":"Mark Chen","year":"2021"},{"key":"ref75","article-title":"Tiobe index."},{"key":"ref76","article-title":"Generating secure hardware using ChatGPT resistant to CWEs","author":"Nair","year":"2023","journal-title":"Cryptology ePrint Archive"},{"key":"ref77","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613892"},{"key":"ref78","article-title":"A new era in software security: Towards self-healing software via large language models and formal verification","author":"Charalambous","year":"2023"},{"key":"ref79","doi-asserted-by":"publisher","DOI":"10.1145\/3589335.3651463"},{"key":"ref80","article-title":"Steam: Simulating the interactive behavior of programmers for automatic bug fixing","author":"Zhang","year":"2023"},{"key":"ref81","article-title":"Large language model as synthesizer: Fusing diverse inputs for better automatic vulnerability repair","author":"Zhou","year":"2024"}],"container-title":["IEEE Transactions on Software Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/32\/11298241\/11197590.pdf?arnumber=11197590","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,12,18]],"date-time":"2025-12-18T12:27:34Z","timestamp":1766060854000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11197590\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,12]]},"references-count":78,"journal-issue":{"issue":"12"},"URL":"https:\/\/doi.org\/10.1109\/tse.2025.3619281","relation":{},"ISSN":["0098-5589","1939-3520","2326-3881"],"issn-type":[{"value":"0098-5589","type":"print"},{"value":"1939-3520","type":"electronic"},{"value":"2326-3881","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,12]]}}}