美国安全与新兴技术中心:2024人工智能生成代码的网络安全风险研究报告(英文版)(41页).pdf

编号:180440 PDF  中文版  DOCX 41页 1.37MB 下载积分:VIP专享
下载报告请您先登录!

美国安全与新兴技术中心:2024人工智能生成代码的网络安全风险研究报告(英文版)(41页).pdf

1、Issue BriefNovember 2024Cybersecurity Risks of AI-Generated CodeAuthorsJessica JiJenny JunMaggie WuRebecca GellesCybersecurity Risks of AI-Generated CodeAuthorsJessica JiJenny JunMaggie WuRebecca GellesCenter for Security and Emerging Technology|1 Executive Summary Recent developments have improved

2、the ability of large language models(LLMs)and other AI systems to generate computer code.While this is promising for the field of software development,these models can also pose direct and indirect cybersecurity risks.In this paper,we identify three broad categories of risk associated with AI code g

3、eneration models:1)models generating insecure code,2)models themselves being vulnerable to attack and manipulation,and 3)downstream cybersecurity impacts such as feedback loops in training future AI systems.Existing research has shown that,under experimental conditions,AI code generation models freq

4、uently output insecure code.However,the process of evaluating the security of AI-generated code is highly complex and contains many interdependent variables.To further explore the risk of insecure AI-written code,we evaluated generated code from five LLMs.Each model was given the same set of prompts

5、,which were designed to test likely scenarios where buggy or insecure code might be produced.Our evaluation results show that almost half of the code snippets produced by these five different models contain bugs that are often impactful and could potentially lead to malicious exploitation.These resu

6、lts are limited to the narrow scope of our evaluation,but we hope they can contribute to the larger body of research surrounding the impacts of AI code generation models.Given both code generation models current utility and the likelihood that their capabilities will continue to improve,it is import

友情提示

1、下载报告失败解决办法
2、PDF文件下载后,可能会被浏览器默认打开,此种情况可以点击浏览器菜单,保存网页到桌面,就可以正常下载了。
3、本站不支持迅雷下载,请使用电脑自带的IE浏览器,或者360浏览器、谷歌浏览器下载即可。
4、本站报告下载后的文档和图纸-无水印,预览文档经过压缩,下载后原文更清晰。

本文(美国安全与新兴技术中心:2024人工智能生成代码的网络安全风险研究报告(英文版)(41页).pdf)为本站 (Kelly Street) 主动上传,三个皮匠报告文库仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对上载内容本身不做任何修改或编辑。 若此文所含内容侵犯了您的版权或隐私,请立即通知三个皮匠报告文库(点击联系客服),我们立即给予删除!

温馨提示:如果因为网速或其他原因下载失败请重新下载,重复下载不扣分。
客服
商务合作
小程序
服务号
折叠