{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T23:07:37Z","timestamp":1782169657170,"version":"3.54.5"},"publisher-location":"New York, NY, USA","reference-count":80,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,7,1]],"date-time":"2024-07-01T00:00:00Z","timestamp":1719792000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"The work has been supported by the Cyber Security Research Centre Limited whose activities are partially funded by the Australian Government?s Cooperative Research Centres Programme."}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,7]]},"DOI":"10.1145\/3634737.3661134","type":"proceedings-article","created":{"date-parts":[[2024,6,28]],"date-time":"2024-06-28T11:51:38Z","timestamp":1719575498000},"page":"1299-1315","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":19,"title":["An Investigation into Misuse of Java Security APIs by Large Language Models"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6538-5966","authenticated-orcid":false,"given":"Zahra","family":"Mousavi","sequence":"first","affiliation":[{"name":"CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Cyber Security Cooperative Research Centre, CSIRO\/Data61, Australia, Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6349-6483","authenticated-orcid":false,"given":"Chadni","family":"Islam","sequence":"additional","affiliation":[{"name":"Queensland University of Technology, Brisbane, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9962-5080","authenticated-orcid":false,"given":"Kristen","family":"Moore","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Australia, Melbourne, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9695-7947","authenticated-orcid":false,"given":"Alsharif","family":"Abuadbba","sequence":"additional","affiliation":[{"name":"CSIRO's Data61, Australia, Sydney, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9696-3626","authenticated-orcid":false,"given":"M. Ali","family":"Babar","sequence":"additional","affiliation":[{"name":"CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Adelaide, Australia"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,7]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382204"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516693"},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"crossref","first-page":"2455","DOI":"10.1145\/3319535.3345659","volume-title":"Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"Rahaman Sazzadur","year":"2019","unstructured":"Sazzadur Rahaman, Ya Xiao, Sharmin Afrose, Fahad Shaon, Ke Tian, Miles Frantz, Murat Kantarcioglu, and Danfeng Yao. Cryptoguard: High precision detection of cryptographic vulnerabilities in massive-sized java projects. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pages 2455--2472, 2019."},{"key":"e_1_3_2_1_4_1","volume-title":"NDSS","author":"Bianchi Antonio","year":"2018","unstructured":"Antonio Bianchi, Yanick Fratantonio, Aravind Machiry, Christopher Kruegel, Giovanni Vigna, Simon Pak Ho Chung, and Wenke Lee. Broken Fingers: On the Usage of the Fingerprint API in Android. In NDSS, 2018."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"crossref","first-page":"293","DOI":"10.1109\/ASE.2019.00036","volume-title":"2019 34th IEEE\/ACM International Conference on Automated Software Engineering (ASE)","author":"Rahat Tamjid Al","year":"2019","unstructured":"Tamjid Al Rahat, Yu Feng, and Yuan Tian. Oauthlint: An empirical study on oauth bugs in android applications. In 2019 34th IEEE\/ACM International Conference on Automated Software Engineering (ASE), pages 293--304. IEEE, 2019."},{"issue":"11","key":"e_1_3_2_1_6_1","doi-asserted-by":"crossref","first-page":"2382","DOI":"10.1109\/TSE.2019.2948910","article-title":"An extensible approach to validating the correct usage of cryptographic APIs","volume":"47","author":"Kr\u00fcger Stefan","year":"2019","unstructured":"Stefan Kr\u00fcger, Johannes Sp\u00e4th, Karim Ali, Eric Bodden, and Mira Mezini. CrySL: An extensible approach to validating the correct usage of cryptographic APIs. IEEE Transactions on Software Engineering, 47(11):2382--2400, 2019.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_1_7_1","first-page":"1","volume-title":"2019 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)","author":"Hazhirpasand Mohammadreza","year":"2019","unstructured":"Mohammadreza Hazhirpasand, Mohammad Ghafari, Stefan Kr\u00fcger, Eric Bodden, and Oscar Nierstrasz. The impact of developer experience in using Java cryptography. In 2019 ACM\/IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM), pages 1--6. IEEE, 2019."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/2986012.2986024"},{"key":"e_1_3_2_1_9_1","first-page":"265","volume-title":"Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018","author":"Gorski Peter Leo","year":"2018","unstructured":"Peter Leo Gorski, Luigi Lo Iacono, Dominik Wermke, Christian Stransky, Sebastian M\u00f6ller, Yasemin Acar, and Sascha Fahl. Developers deserve security warnings, too: On the effect of integrated security advice on cryptographic {API} misuse. In Fourteenth Symposium on Usable Privacy and Security (SOUPS 2018), pages 265--281, 2018."},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"crossref","first-page":"402","DOI":"10.1109\/ICSME52107.2021.00042","volume-title":"2021 IEEE International Conference on Software Maintenance and Evolution (ICSME)","author":"Kafader Simon","year":"2021","unstructured":"Simon Kafader and Mohammad Ghafari. Fluentcrypto: Cryptography in easy mode. In 2021 IEEE International Conference on Software Maintenance and Evolution (ICSME), pages 402--412. IEEE, 2021."},{"key":"e_1_3_2_1_11_1","first-page":"711","volume-title":"Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security","author":"Ma Siqi","year":"2016","unstructured":"Siqi Ma, David Lo, Teng Li, and Robert H Deng. Cdrep: Automatic repair of cryptographic misuses in android applications. In Proceedings of the 11th ACM on Asia Conference on Computer and Communications Security, pages 711--722, 2016."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133977"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/3524610.3527895"},{"key":"e_1_3_2_1_14_1","first-page":"1194","volume-title":"Firebugs: Finding and repairing cryptography api misuses in mobile applications. In 2021 IEEE 45th Annual Computers, Software, and Applications Conference (COMPSAC)","author":"Singleton Larry","year":"2021","unstructured":"Larry Singleton, Rui Zhao, Harvey Siy, and Myoungkyu Song. Firebugs: Finding and repairing cryptography api misuses in mobile applications. In 2021 IEEE 45th Annual Computers, Software, and Applications Conference (COMPSAC), pages 1194--1201. IEEE, 2021."},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"crossref","first-page":"1073","DOI":"10.1145\/3377811.3380342","volume-title":"Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering","author":"Karampatsis Rafael-Michael","year":"2020","unstructured":"Rafael-Michael Karampatsis, Hlib Babii, Romain Robbes, Charles Sutton, and Andrea Janes. Big code!= big vocabulary: Open-vocabulary models for source code. In Proceedings of the ACM\/IEEE 42nd International Conference on Software Engineering, pages 1073--1085, 2020."},{"key":"e_1_3_2_1_16_1","volume-title":"Openai devday, opening keynote","author":"AI.","year":"2023","unstructured":"OpenAI. Openai devday, opening keynote, 2023. URL https:\/\/www.youtube.com\/watch?v=U9mJuUkhUzk. Accessed December 3, 2023."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833571"},{"key":"e_1_3_2_1_18_1","volume-title":"How secure is code generated by chatgpt? arXiv preprint arXiv:2304.09655","author":"Khoury Rapha\u00ebl","year":"2023","unstructured":"Rapha\u00ebl Khoury, Anderson R Avila, Jacob Brunelle, and Baba Mamadou Camara. How secure is code generated by chatgpt? arXiv preprint arXiv:2304.09655, 2023."},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.infsof.2019.07.007"},{"key":"e_1_3_2_1_20_1","first-page":"252","volume-title":"Frankfurt","author":"Gorski Peter Leo","year":"2016","unstructured":"Peter Leo Gorski and Luigi Lo Iacono. Towards the usability evaluation of security APIs. In Clarke, Furnell (Eds.): Tenth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2016), Frankfurt, Germany, July 19-21, 2016, pages 252--265. CSCAN, 2016."},{"key":"e_1_3_2_1_21_1","volume-title":"TechRxiv","author":"Hadi Muhammad Usman","year":"2023","unstructured":"Muhammad Usman Hadi, Rizwan Qureshi, Abbas Shah, Muhammad Irfan, Anas Zafar, Muhammad Bilal Shaikh, Naveed Akhtar, Jia Wu, Seyedali Mirjalili, et al. Large language models: a comprehensive survey of its applications, challenges, limitations, and future prospects. TechRxiv, 2023."},{"key":"e_1_3_2_1_22_1","volume-title":"Large language models for software engineering: A systematic literature review. arXiv preprint arXiv:2308.10620","author":"Hou Xinyi","year":"2023","unstructured":"Xinyi Hou, Yanjie Zhao, Yue Liu, Zhou Yang, Kailong Wang, Li Li, Xiapu Luo, David Lo, John Grundy, and Haoyu Wang. Large language models for software engineering: A systematic literature review. arXiv preprint arXiv:2308.10620, 2023."},{"key":"e_1_3_2_1_23_1","volume-title":"Generating secure hardware using chatgpt resistant to cwes. Cryptology ePrint Archive","author":"Nair Madhav","year":"2023","unstructured":"Madhav Nair, Rajat Sadhukhan, and Debdeep Mukhopadhyay. Generating secure hardware using chatgpt resistant to cwes. Cryptology ePrint Archive, 2023."},{"key":"e_1_3_2_1_24_1","first-page":"1","volume-title":"Proceedings of the 47th IEEE Computer Software and Applications Conference","author":"Feng Yunhe","year":"2023","unstructured":"Yunhe Feng, Sreecharan Vanam, Manasa Cherukupally, Weijian Zheng, Meikang Qiu, and Haihua Chen. Investigating code generation performance of chat-gpt with crowdsourcing social data. In Proceedings of the 47th IEEE Computer Software and Applications Conference, pages 1--10, 2023."},{"key":"e_1_3_2_1_25_1","volume-title":"Xunzhu Tang, Shing-Chi Cheung, Jacques Klein, and Tegawend\u00e9 F Bissyand\u00e9. Is chatgpt the ultimate programming assistant-how far is it? arXiv preprint arXiv:2304.11938","author":"Tian Haoye","year":"2023","unstructured":"Haoye Tian, Weiqi Lu, Tsz On Li, Xunzhu Tang, Shing-Chi Cheung, Jacques Klein, and Tegawend\u00e9 F Bissyand\u00e9. Is chatgpt the ultimate programming assistant-how far is it? arXiv preprint arXiv:2304.11938, 2023."},{"key":"e_1_3_2_1_26_1","volume-title":"Yuyao Wang, and Lingming Zhang. Is your code generated by chatgpt really correct? rigorous evaluation of large language models for code generation. arXiv preprint arXiv:2305.01210","author":"Liu Jiawei","year":"2023","unstructured":"Jiawei Liu, Chunqiu Steven Xia, Yuyao Wang, and Lingming Zhang. Is your code generated by chatgpt really correct? rigorous evaluation of large language models for code generation. arXiv preprint arXiv:2305.01210, 2023."},{"key":"e_1_3_2_1_27_1","volume-title":"No need to lift a finger anymore? assessing the quality of code generation by chatgpt. arXiv preprint arXiv:2308.04838","author":"Liu Zhijie","year":"2023","unstructured":"Zhijie Liu, Yutian Tang, Xiapu Luo, Yuming Zhou, and Liang Feng Zhang. No need to lift a finger anymore? assessing the quality of code generation by chatgpt. arXiv preprint arXiv:2308.04838, 2023."},{"key":"e_1_3_2_1_28_1","volume-title":"Improving chatgpt prompt for code generation. arXiv preprint arXiv:2305.08360","author":"Liu Chao","year":"2023","unstructured":"Chao Liu, Xuanlin Bao, Hongyu Zhang, Neng Zhang, Haibo Hu, Xiaohong Zhang, and Meng Yan. Improving chatgpt prompt for code generation. arXiv preprint arXiv:2305.08360, 2023."},{"key":"e_1_3_2_1_29_1","volume-title":"Self-collaboration code generation via chatgpt. arXiv preprint arXiv:2304.07590","author":"Dong Yihong","year":"2023","unstructured":"Yihong Dong, Xue Jiang, Zhi Jin, and Ge Li. Self-collaboration code generation via chatgpt. arXiv preprint arXiv:2304.07590, 2023."},{"key":"e_1_3_2_1_30_1","volume-title":"Statistics of chatgpt & generative ai in business: 2023 report","year":"2023","unstructured":"master of code. Statistics of chatgpt & generative ai in business: 2023 report, 2023. URL https:\/\/masterofcode.com\/blog\/statistics-of-chatgpt-generative-ai-in-business-2023-report. Accessed November 9, 2023."},{"key":"e_1_3_2_1_31_1","first-page":"2303","volume-title":"Gpt-4 technical report. arXiv","author":"R","year":"2023","unstructured":"R OpenAI. Gpt-4 technical report. arXiv, pages 2303--08774, 2023."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/SCAM55253.2022.00014"},{"key":"e_1_3_2_1_33_1","volume-title":"Security weaknesses of copilot generated code in github. arXiv preprint arXiv:2310.02059","author":"Fu Yujia","year":"2023","unstructured":"Yujia Fu, Peng Liang, Amjed Tahir, Zengyang Li, Mojtaba Shahin, and Jiaxin Yu. Security weaknesses of copilot generated code in github. arXiv preprint arXiv:2310.02059, 2023."},{"issue":"6","key":"e_1_3_2_1_34_1","first-page":"1","article-title":"copilot as bad as humans at introducing vulnerabilities in code?","volume":"28","author":"Asare Owura","year":"2023","unstructured":"Owura Asare, Meiyappan Nagappan, and N Asokan. Is github's copilot as bad as humans at introducing vulnerabilities in code? Empirical Software Engineering, 28(6):1--24, 2023.","journal-title":"Empirical Software Engineering"},{"key":"e_1_3_2_1_35_1","first-page":"2205","volume-title":"32nd USENIX Security Symposium (USENIX Security 23)","author":"Sandoval Gustavo","year":"2023","unstructured":"Gustavo Sandoval, Hammond Pearce, Teo Nys, Ramesh Karri, Siddharth Garg, and Brendan Dolan-Gavitt. Lost at c: A user study on the security implications of large language model code assistants. In 32nd USENIX Security Symposium (USENIX Security 23), pages 2205--2222, 2023."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623157"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICSE.2007.92"},{"key":"e_1_3_2_1_38_1","volume-title":"Detecting misuses of security apis: A systematic review. arXiv preprint arXiv:2306.08869","author":"Mousavi Zahra","year":"2023","unstructured":"Zahra Mousavi, Chadni Islam, M Ali Babar, Alsharif Abuadbba, and Kristen Moore. Detecting misuses of security apis: A systematic review. arXiv preprint arXiv:2306.08869, 2023."},{"key":"e_1_3_2_1_39_1","volume-title":"Fingerprint api,. URL https:\/\/developer.android.com\/reference\/android\/hardware\/fingerprint\/package-summary. Accessed","year":"2023","unstructured":"Google. Fingerprint api,. URL https:\/\/developer.android.com\/reference\/android\/hardware\/fingerprint\/package-summary. Accessed October 29, 2023."},{"key":"e_1_3_2_1_40_1","volume-title":"Safetynet attestation,. URL https:\/\/developer.android.com\/privacy-and-security\/safetynet\/attestation. Accessed","year":"2023","unstructured":"Google. Safetynet attestation,. URL https:\/\/developer.android.com\/privacy-and-security\/safetynet\/attestation. Accessed October 29, 2023."},{"key":"e_1_3_2_1_41_1","volume-title":"Biometrics api,. URL https:\/\/developer.android.com\/reference\/android\/hardware\/biometrics\/package-summary. Accessed","year":"2023","unstructured":"Google. Biometrics api,. URL https:\/\/developer.android.com\/reference\/android\/hardware\/biometrics\/package-summary. Accessed October 29, 2023."},{"key":"e_1_3_2_1_42_1","volume-title":"Play integrity,. URL https:\/\/developer.android.com\/google\/play\/integrity. Accessed","year":"2023","unstructured":"Google. Play integrity,. URL https:\/\/developer.android.com\/google\/play\/integrity. Accessed October 29, 2023."},{"key":"e_1_3_2_1_43_1","volume-title":"Accessed","author":"Don't MIKE MELANSON.","year":"2023","unstructured":"MIKE MELANSON. Don't call it a comeback: Why java is still champ, 2022. URL https:\/\/github.com\/readme\/featured\/java-programming-language?utm_source=github&utm_medium=referral&utm_campaign=&scid=&utm_content=octoverse. Accessed October 26, 2023."},{"key":"e_1_3_2_1_44_1","volume-title":"Accessed","author":"Carbonnelle Pierre","year":"2023","unstructured":"Pierre Carbonnelle. Pypl popularity of programming language, 2023. URL https:\/\/pypl.github.io\/PYPL.html. Accessed October 29, 2023."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.52"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1145\/3210459.3210483"},{"key":"e_1_3_2_1_47_1","first-page":"503","volume-title":"Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022","author":"Geierhaas Lisa","year":"2022","unstructured":"Lisa Geierhaas, Anna-Marie Ortloff, Matthew Smith, and Alena Naiakshina. {Let's} hash: Helping developers with password security. In Eighteenth Symposium on Usable Privacy and Security (SOUPS 2022), pages 503--522, 2022."},{"key":"e_1_3_2_1_48_1","first-page":"81","volume-title":"Thirteenth Symposium on Usable Privacy and Security (SOUPS 2017","author":"Acar Yasemin","year":"2017","unstructured":"Yasemin Acar, Christian Stransky, Dominik Wermke, Michelle L Mazurek, and Sascha Fahl. Security developer studies with {GitHub} users: Exploring a convenience sample. In Thirteenth Symposium on Usable Privacy and Security (SOUPS 2017), pages 81--95, 2017."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"crossref","first-page":"486","DOI":"10.1109\/EuroSPW55150.2022.00058","volume-title":"2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW)","author":"McGregor L\u00e9on","year":"2022","unstructured":"L\u00e9on McGregor, Sheung Chi Chan, Szymon Wlodarczyk, and Manuel Maarek. Aligning a serious game, secure programming and cybok-linked learning outcomes. In 2022 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), pages 486--495. IEEE, 2022."},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.25"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3313831.3376791"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.09.007"},{"key":"e_1_3_2_1_53_1","volume-title":"Accessed","author":"Oauth","year":"2023","unstructured":"Google. Oauth api, 2023. URL https:\/\/developers.google.com\/identity\/protocols\/oauth2\/native-app. Accessed September 28, 2023."},{"key":"e_1_3_2_1_54_1","volume-title":"A prompt pattern catalog to enhance prompt engineering with chatgpt. arXiv preprint arXiv:2302.11382","author":"White Jules","year":"2023","unstructured":"Jules White, Quchen Fu, Sam Hays, Michael Sandborn, Carlos Olea, Henry Gilbert, Ashraf Elnashar, Jesse Spencer-Smith, and Douglas C Schmidt. A prompt pattern catalog to enhance prompt engineering with chatgpt. arXiv preprint arXiv:2302.11382, 2023."},{"key":"e_1_3_2_1_55_1","first-page":"281","volume-title":"SOUPS@ USENIX Security Symposium","author":"Assal Hala","year":"2018","unstructured":"Hala Assal and Sonia Chiasson. Security in the software development lifecycle. In SOUPS@ USENIX Security Symposium, pages 281--296, 2018."},{"key":"e_1_3_2_1_56_1","volume-title":"Accessed","year":"2019","unstructured":"CryptoAPI-Bench, 2019. URL https:\/\/github.com\/CryptoGuardOSS\/cryptoapi-bench. Accessed June 10, 2023."},{"key":"e_1_3_2_1_57_1","volume-title":"Accessed","year":"2020","unstructured":"ApacheCryptoAPI-Bench, 2020. URL https:\/\/github.com\/CryptoAPI-Bench\/ApacheCryptoAPI-Bench. Accessed June 10, 2023."},{"key":"e_1_3_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3154717"},{"issue":"1","key":"e_1_3_2_1_59_1","doi-asserted-by":"crossref","first-page":"288","DOI":"10.1109\/TSE.2022.3150302","article-title":"Automatic detection of Java cryptographic API misuses: Are we there yet?","volume":"49","author":"Zhang Ying","year":"2022","unstructured":"Ying Zhang, Md Mahir Asef Kabir, Ya Xiao, Danfeng Yao, and Na Meng. Automatic detection of Java cryptographic API misuses: Are we there yet? IEEE Transactions on Software Engineering, 49(1):288--303, 2022.","journal-title":"IEEE Transactions on Software Engineering"},{"key":"e_1_3_2_1_60_1","volume-title":"Accessed","year":"2016","unstructured":"MUBench, 2016. URL https:\/\/GitHub.com\/stg-tud\/MUBench. Accessed June 10, 2023."},{"key":"e_1_3_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3484195"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"crossref","DOI":"10.6028\/NIST.SP.800-57p3","volume-title":"Recommendation for key management part 3: Application-specific key management guidance. NIST special publication, 800:57","author":"Barker Elaine","year":"2009","unstructured":"Elaine Barker, William Burr, Alicia Jones, Timothy Polk, Scott Rose, Miles Smid, Quynh Dang, et al. Recommendation for key management part 3: Application-specific key management guidance. NIST special publication, 800:57, 2009."},{"key":"e_1_3_2_1_63_1","doi-asserted-by":"publisher","DOI":"10.1145\/3296979.3192403"},{"key":"e_1_3_2_1_64_1","volume-title":"PKCS# 5: Password-based cryptography specification version 2.1","author":"Kaliski Burt","year":"2017","unstructured":"Burt Kaliski and A Rusch. RFC 8018: PKCS# 5: Password-based cryptography specification version 2.1, 2017."},{"key":"e_1_3_2_1_65_1","volume-title":"Yarik markov, alex petit bianco, and clement baisse. announcing the first sha1 collision. Google Security Blog, https:\/\/security.googleblog.com\/2017\/02\/announcing-first-sha1-collision.html","author":"Stevens Marc","year":"2017","unstructured":"Marc Stevens, Elie Bursztein, Pierre Karpman, and Ange Albertini. Yarik markov, alex petit bianco, and clement baisse. announcing the first sha1 collision. Google Security Blog, https:\/\/security.googleblog.com\/2017\/02\/announcing-first-sha1-collision.html, 2017."},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2020.110609"},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382205"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660323"},{"key":"e_1_3_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.17487\/RFC6749"},{"key":"e_1_3_2_1_70_1","volume-title":"URL https:\/\/cloud.google.com\/java\/docs\/reference\/google-api-client\/latest\/com.google.api.client.googleapis.javanet.GoogleNetHttpTransport. Accessed","year":"2023","unstructured":"Google. Googlenethttptransport,. URL https:\/\/cloud.google.com\/java\/docs\/reference\/google-api-client\/latest\/com.google.api.client.googleapis.javanet.GoogleNetHttpTransport. Accessed October 13, 2023."},{"key":"e_1_3_2_1_71_1","volume-title":"URL https:\/\/cloud.google.com\/java\/docs\/reference\/google-http-client\/latest\/com.google.api.client.http.javanet.NetHttpTransport. Accessed","year":"2023","unstructured":"Google. Nethttptransport,. URL https:\/\/cloud.google.com\/java\/docs\/reference\/google-http-client\/latest\/com.google.api.client.http.javanet.NetHttpTransport. Accessed October 13, 2023."},{"key":"e_1_3_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/2382196.2382238"},{"key":"e_1_3_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818024"},{"key":"e_1_3_2_1_74_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2021.103097"},{"key":"e_1_3_2_1_75_1","volume-title":"Internet Engineering Task Force (IETF)","author":"Sakimura Nat","year":"2015","unstructured":"Nat Sakimura, John Bradley, and Naveen Agarwal. Proof key for code exchange by OAuth public clients. Technical report, Internet Engineering Task Force (IETF), 2015."},{"key":"e_1_3_2_1_76_1","volume-title":"Accessed","year":"2023","unstructured":"Google. Cryptography for biometric authentication,. URL https:\/\/developer.android.com\/reference\/android\/hardware\/biometrics\/BiometricPrompt.CryptoObject. Accessed October 15, 2023."},{"key":"e_1_3_2_1_77_1","volume-title":"Accessed","author":"OWASP.","year":"2023","unstructured":"OWASP. Android local authentication. URL https:\/\/github.com\/OWASP\/owasp-mastg\/blob\/master\/Document\/0x05f-Testing-Local-Authentication. Accessed October 15, 2023."},{"key":"e_1_3_2_1_78_1","unstructured":"Resources for the research on \"Evaluating the Trustworthiness of Large Language Models in Generating Secure Security API Code\" 2023. URL https:\/\/github.com\/LLM-security-study\/ChatGPT."},{"key":"e_1_3_2_1_79_1","volume-title":"Breaking the silence: the threats of using llms in software engineering","author":"Sallou J.","year":"2024","unstructured":"J. Sallou, T. Durieux, and A. Panichella. Breaking the silence: the threats of using llms in software engineering. In ACM\/IEEE 46th International Conference on Software Engineering - New Ideas and Emerging Results. ACM\/IEEE, January 2024. URL https:\/\/conf.researchr.org\/home\/icse-2024. ACM\/IEEE 46th International Conference on Software Engineering, ICSE '24; Conference date: 14-04-2024 Through 20-04-2024."},{"key":"e_1_3_2_1_80_1","volume-title":"URL https:\/\/developers.google.com\/identity\/protocols\/oauth2\/native-app. Accessed","author":"Oauth","year":"2023","unstructured":"Google. Oauth 2.0 for mobile desktop apps,. URL https:\/\/developers.google.com\/identity\/protocols\/oauth2\/native-app. Accessed December 4, 2023."}],"event":{"name":"ASIA CCS '24: 19th ACM Asia Conference on Computer and Communications Security","location":"Singapore Singapore","acronym":"ASIA CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 19th ACM Asia Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661134","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T23:44:07Z","timestamp":1750290247000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3634737.3661134"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,7]]},"references-count":80,"alternative-id":["10.1145\/3634737.3661134","10.1145\/3634737"],"URL":"https:\/\/doi.org\/10.1145\/3634737.3661134","relation":{},"subject":[],"published":{"date-parts":[[2024,7]]},"assertion":[{"value":"2024-07-01","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}