AI coding and LLM security
AI code generation security
AI code generation security means analyzing and remediating vulnerabilities in code produced by AI coding tools. It is not a formal standard; it applies existing secure-development practice to AI output. Benchmarks find a gap between functional correctness and security: in the SusVibes benchmark (Carnegie Mellon, Columbia, and Johns Hopkins, December 2025), roughly four in five functionally correct solutions from the evaluated agent were insecure. AI coding tools are therefore paired with security review and scanning rather than relied on alone.
Sources
- Zhao et al. (CMU, Columbia, Johns Hopkins), "Is Vibe Coding Safe? Benchmarking Vulnerability of Agent-Generated Code in Real-World Tasks" (SusVibes), arXiv:2512.03262
- NIST SP 800-218A, "Secure Software Development Practices for Generative AI and Dual-Use Foundation Models: An SSDF Community Profile"
- OWASP Top 10 for LLM Applications 2025, "LLM09:2025 Misinformation" (includes unsafe code generation)