SUPR
Impact of security guidelines on LLM generated code refactoring
Dnr:

NAISS 2025/22-641

Type:

NAISS Small Compute

Principal Investigator:

Raffaela Groner

Affiliation:

Chalmers tekniska högskola

Start Date:

2025-04-23

End Date:

2026-05-01

Primary Classification:

10205: Software Engineering

Webpage:

Allocation

Abstract

Web applications are an easy target because they are publicly exposed, and their input fields are easy targets for attacks such as SQL injection. Svensson et al. [1] interviewed industry practitioners and derived guidelines to help software engineers develop secure web applications. As LLM is increasingly integrated into the workflow of developers, we now want to investigate whether a combination of these security guidelines with LLMs can be used to address vulnerabilities in web applications. [1] Svensson, Klara, et al. "Guidelines for Supporting Software Engineers in Developing Secure Web Applications." International Conference on Product-Focused Software Process Improvement. Cham: Springer Nature Switzerland, 2024.