Säkerhetsanalys av AI-genererad kod: Analys genom statiska kodanalysverktyg
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [sv]
Den ökande användningen av AI-verktyg i mjukvaruutveckling skapar ett behov av metoder för att systematiskt bedöma säkerhetskvaliteten i AI-genererad kod. Syftet med denna studie är att undersöka i vilken utsträckning statiska analysverktyg kan detektera säkerhetssårbarheter i Pythonkod genererad av Claude Code, samt att analysera hur kodkomplexitet och detektionsförmågan. kombination av verktyg påverkar Studien genomfördes som ett kontrollerat kvantitativt experiment. Två experimentella projekt konstruerades med stigande komplexitet: ett Flask-baserat REST API och ett FastAPI-baserat REST API med rollbaserad åtkomstkontroll. Varje projekt byggdes iterativt genom fem GitHub-liknande issue-poster, vilket simulerar ett realistiskt agilt arbetsflöde. De fyra verktygen Bandit, Semgrep, detect-secrets och pip audit kördes i en automatiserad pipeline mot tio kumulativa datasatser. Kända sårbara biblioteksversioner inkluderades för att skapa ett kontrollerbart ground truth. Resultaten visar att den kombinerade pipelinen uppnådde fullständig recall (100 %) mot det definierade ground truth. pip-audit identifierade samtliga 42 beroendesårbarheter, medan Bandit och Semgrep vardera fångade två av tre verifierade SAST-fynd. Verktygen visade sig i hög grad komplementära, med minimal överlappning och distinkta kompetensprofiler. Kodkomplexitetens effekt på detektion var inte linjär utan språngvis, kopplad till specifika iterationer med stor kodtillväxt. Studien drar slutsatsen att automatiserad statisk analys kan fungera som ett praktiskt säkerhetsstöd för AI-genererad kod. Ett negativt resultat från verktygen innebär inte frånvaro av säkerhetsproblem, utan frånvaro av kända mönster. Kombinationen av fyra verktyg med olika kompetensprofiler rekommenderas som ett komplement till, inte ett substitut för, mänsklig granskning.
Abstract [en]
The increasing adoption of AI-assisted coding tools has created a need for systematic methods to evaluate the security quality of AI-generated code. This study investigates to what extent automated static analysis tools can detect security vulnerabilities in Python code generated by Claude Code, as well as to analyze how code complexity and the combination of tools affect detection capability. The study was conducted as a controlled quantitative experiment. Two projects of increasing complexity were constructed: a Flask-based REST API and a FastAPI-based REST API with role-based access control. Each project was built iteratively through five GitHub-like issues, simulating a realistic agile development workflow. The four tools Bandit, Semgrep, detect-secrets, and pip-audit were executed in an automated pipeline against ten cumulative datasets. Known vulnerable library versions were deliberately included to establish a verifiable ground truth. The combined pipeline achieved 100% recall against the defined ground truth. pip-audit identified all 42 dependency vulnerabilities, while Bandit and Semgrep each detected two of three verified SAST findings. The tools proved largely complementary, with minimal overlap and distinct competency profiles. The effect of code complexity on detection was not linear but incremental, tied to specific iterations with substantial code growth. The study concludes that automated static analysis can serve as a practical security support for AI-generated code. A negative result from the tools does not imply the absence of vulnerabilities, only the absence of known patterns. A combination of four tools with different competency profiles is recommended as a complement to, not a substitute for, human code review.
Place, publisher, year, edition, pages
2026. , p. 98
Keywords [en]
AI-generated code, static code analysis, SAST, security vulnerabilities, tool complementarity, Python
Keywords [sv]
AI-genererad kod, statisk kodanalys, säkerhetssårbarheter, verktygskomplementaritet, Python
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:miun:diva-58008Local ID: DT-V26-G3-019OAI: oai:DiVA.org:miun-58008DiVA, id: diva2:2081882
Subject / course
Computer Engineering DT1
Educational program
Computer Science TDATG 180 higher education credits
Supervisors
Examiners
2026-06-302026-06-302026-06-30Bibliographically approved