{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T10:18:35Z","timestamp":1778667515615,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":31,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"name":"Federal Ministry of Research, Technology and Space","award":["16IS22091"],"award-info":[{"award-number":["16IS22091"]}]},{"name":"Hessian Ministry for Digital Strategy and Innovation","award":["S-DIW04\/0013\/003"],"award-info":[{"award-number":["S-DIW04\/0013\/003"]}]},{"name":"Federal Ministry of Research, Technology and Space","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]},{"name":"Hessian Ministry of Science and Research, Arts and Culture","award":["ATHENE"],"award-info":[{"award-number":["ATHENE"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786165.3788437","type":"proceedings-article","created":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:49:18Z","timestamp":1778665758000},"page":"1-8","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Q&amp;AEval: Benchmarking Secure Coding Ability of LLMs on Real-World Tasks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0803-9458","authenticated-orcid":false,"given":"Markus","family":"Toran","sequence":"first","affiliation":[{"name":"Fraunhofer SIT | ATHENE, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-9915-3804","authenticated-orcid":false,"given":"Bettina","family":"Ballin","sequence":"additional","affiliation":[{"name":"Independent Researcher, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3806-0522","authenticated-orcid":false,"given":"Marc","family":"Miltenberger","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT | ATHENE, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5807-9431","authenticated-orcid":false,"given":"Steven","family":"Arzt","sequence":"additional","affiliation":[{"name":"Fraunhofer SIT | ATHENE, Darmstadt, Germany"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"e_1_3_3_2_2_2","doi-asserted-by":"publisher","DOI":"10.1109\/csr61664.2024.10679468"},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1145\/3460946.3464315"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549091"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2594291.2594299"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","unstructured":"Owura Asare Meiyappan Nagappan and N. Asokan. 2023. Is GitHub\u2019s Copilot as bad as humans at introducing vulnerabilities in code? Empirical Software Engineering 28 6 (2023). 10.1007\/s10664-023-10380-1","DOI":"10.1007\/s10664-023-10380-1"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1145\/2259051.2259056"},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","unstructured":"Gavin\u00a0S. Black Bhaskar\u00a0P. Rimal and Varghese\u00a0Mathew Vaidyan. 2025. Balancing Security and Correctness in Code Generation: An Empirical Study on Commercial Large Language Models. IEEE Transactions on Emerging Topics in Computational Intelligence 9 1 (Feb. 2025) 419\u2013430. 10.1109\/tetci.2024.3446695","DOI":"10.1109\/tetci.2024.3446695"},{"key":"e_1_3_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/forge66646.2025.00018"},{"key":"e_1_3_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/icse.2019.00065"},{"key":"e_1_3_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.31"},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1109\/spw63631.2024.00014"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1109\/esem.2019.8870184"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/3643787.3648036"},{"key":"e_1_3_3_2_15_2","volume-title":"Cetus Users and Compiler Infastructure Workshop","author":"Lam Patrick","year":"2011","unstructured":"Patrick Lam, Eric Bodden, Ondvrej Lhot\u00e1k, and Laurie Hendren. 2011. The Soot framework for Java program analysis: a retrospective. In Cetus Users and Compiler Infastructure Workshop."},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","DOI":"10.1109\/saner60148.2024.00051"},{"key":"e_1_3_3_2_17_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690298"},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/sp46214.2022.9833571"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1109\/llm4code66737.2025.00009"},{"key":"e_1_3_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-76934-4_7"},{"key":"e_1_3_3_2_22_2","doi-asserted-by":"publisher","unstructured":"Amirali Sajadi Binh Le Anh Nguyen Kostadin Damevski and Preetha Chatterjee. 2025. Do LLMs consider security? an empirical study on responses to programming questions. Empirical Software Engineering 30 3 (April 2025) 101. 10.1007\/s10664-025-10658-6","DOI":"10.1007\/s10664-025-10658-6"},{"key":"e_1_3_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1145\/3691621.3694934"},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/3549035.3561184"},{"key":"e_1_3_3_2_25_2","doi-asserted-by":"publisher","unstructured":"Norbert Tihanyi Tamas Bisztray Mohamed\u00a0Amine Ferrag Ridhi Jain and Lucas\u00a0C. Cordeiro. 2024. How secure is AI-generated code: a large-scale comparison of large language models. Empirical Software Engineering 30 2 (Dec. 2024). 10.1007\/s10664-024-10590-1","DOI":"10.1007\/s10664-024-10590-1"},{"key":"e_1_3_3_2_26_2","doi-asserted-by":"publisher","unstructured":"Catherine Tony Nicol\u00e1s\u00a0E. D\u00edaz\u00a0Ferreyra Markus Mutas Salem Dhif and Riccardo Scandariato. 2025. Prompting Techniques for Secure Code Generation: A Systematic Investigation. ACM Transactions on Software Engineering and Methodology 34 8 (Oct. 2025) 1\u201353. 10.1145\/3722108","DOI":"10.1145\/3722108"},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSR59073.2023.00084"},{"key":"e_1_3_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/sp54263.2024.00210"},{"key":"e_1_3_3_2_29_2","volume-title":"Jimple: Simplifying Java Bytecode for Analyses and Transformations","author":"Vallee-rai Raja","year":"1998","unstructured":"Raja Vallee-rai and Laurie Hendren. 1998. Jimple: Simplifying Java Bytecode for Analyses and Transformations. Technical Report. McGill University."},{"key":"e_1_3_3_2_30_2","volume-title":"ICLR","author":"White Colin","year":"2025","unstructured":"Colin White, Samuel Dooley, Manley Roberts, Arka Pal, Benjamin Feuer, Siddhartha Jain, Ravid Shwartz-Ziv, Neel Jain, Khalid Saifullah, Sreemanti Dey, Shubh-Agrawal, Sandeep\u00a0Singh Sandha, Siddartha\u00a0Venkat Naidu, Chinmay Hegde, Yann LeCun, Tom Goldstein, Willie Neiswanger, and Micah Goldblum. 2025. LiveBench: A Challenging, Contamination-Limited LLM Benchmark. In ICLR. https:\/\/openreview.net\/forum?id=sKYHBTAxVa"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","unstructured":"Xin Xia Lingfeng Bao David Lo Pavneet\u00a0Singh Kochhar Ahmed\u00a0E Hassan and Zhenchang Xing. 2017. What do developers search for on the web? Empirical Software Engineering 22 6 (April 2017) 3149\u20133185. 10.1007\/s10664-017-9514-4","DOI":"10.1007\/s10664-017-9514-4"},{"key":"e_1_3_3_2_32_2","doi-asserted-by":"publisher","DOI":"10.1145\/2901739.2901767"}],"event":{"name":"SVM '26: 4th International Workshop on Software Vulnerability Management","location":"Rio de Janeiro Brazil","acronym":"SVM '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 2026 IEEE\/ACM 4th International Workshop on Software Vulnerability Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786165.3788437","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:49:19Z","timestamp":1778665759000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786165.3788437"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":31,"alternative-id":["10.1145\/3786165.3788437","10.1145\/3786165"],"URL":"https:\/\/doi.org\/10.1145\/3786165.3788437","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}