Mid Sweden University

miun.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Säkerhetsanalys av AI-genererad kod: Analys genom statiska kodanalysverktyg
Mid Sweden University, Faculty of Science, Technology and Media, Department of Computer and Electrical Engineering (2023-).
2026 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE creditsStudent thesis
Abstract [sv]

Den ökande användningen av AI-verktyg i mjukvaruutveckling skapar ett behov av metoder för att systematiskt bedöma säkerhetskvaliteten i AI-genererad kod. Syftet med denna studie är att undersöka i vilken utsträckning statiska analysverktyg kan detektera säkerhetssårbarheter i Pythonkod genererad av Claude Code, samt att analysera hur kodkomplexitet och detektionsförmågan. kombination av verktyg påverkar Studien genomfördes som ett kontrollerat kvantitativt experiment. Två experimentella projekt konstruerades med stigande komplexitet: ett Flask-baserat REST API och ett FastAPI-baserat REST API med rollbaserad åtkomstkontroll. Varje projekt byggdes iterativt genom fem GitHub-liknande issue-poster, vilket simulerar ett realistiskt agilt arbetsflöde. De fyra verktygen Bandit, Semgrep, detect-secrets och pip audit kördes i en automatiserad pipeline mot tio kumulativa datasatser. Kända sårbara biblioteksversioner inkluderades för att skapa ett kontrollerbart ground truth. Resultaten visar att den kombinerade pipelinen uppnådde fullständig recall (100 %) mot det definierade ground truth. pip-audit identifierade samtliga 42 beroendesårbarheter, medan Bandit och Semgrep vardera fångade två av tre verifierade SAST-fynd. Verktygen visade sig i hög grad komplementära, med minimal överlappning och distinkta kompetensprofiler. Kodkomplexitetens effekt på detektion var inte linjär utan språngvis, kopplad till specifika iterationer med stor kodtillväxt. Studien drar slutsatsen att automatiserad statisk analys kan fungera som ett praktiskt säkerhetsstöd för AI-genererad kod. Ett negativt resultat från verktygen innebär inte frånvaro av säkerhetsproblem, utan frånvaro av kända mönster. Kombinationen av fyra verktyg med olika kompetensprofiler rekommenderas som ett komplement till, inte ett substitut för, mänsklig granskning.

Abstract [en]

The increasing adoption of AI-assisted coding tools has created a need for systematic methods to evaluate the security quality of AI-generated code. This study investigates to what extent automated static analysis tools can detect security vulnerabilities in Python code generated by Claude Code, as well as to analyze how code complexity and the combination of tools affect detection capability. The study was conducted as a controlled quantitative experiment. Two projects of increasing complexity were constructed: a Flask-based REST API and a FastAPI-based REST API with role-based access control. Each project was built iteratively through five GitHub-like issues, simulating a realistic agile development workflow. The four tools Bandit, Semgrep, detect-secrets, and pip-audit were executed in an automated pipeline against ten cumulative datasets. Known vulnerable library versions were deliberately included to establish a verifiable ground truth. The combined pipeline achieved 100% recall against the defined ground truth. pip-audit identified all 42 dependency vulnerabilities, while Bandit and Semgrep each detected two of three verified SAST findings. The tools proved largely complementary, with minimal overlap and distinct competency profiles. The effect of code complexity on detection was not linear but incremental, tied to specific iterations with substantial code growth. The study concludes that automated static analysis can serve as a practical security support for AI-generated code. A negative result from the tools does not imply the absence of vulnerabilities, only the absence of known patterns. A combination of four tools with different competency profiles is recommended as a complement to, not a substitute for, human code review.

Place, publisher, year, edition, pages
2026. , p. 98
Keywords [en]
AI-generated code, static code analysis, SAST, security vulnerabilities, tool complementarity, Python
Keywords [sv]
AI-genererad kod, statisk kodanalys, säkerhetssårbarheter, verktygskomplementaritet, Python
National Category
Software Engineering
Identifiers
URN: urn:nbn:se:miun:diva-58008Local ID: DT-V26-G3-019OAI: oai:DiVA.org:miun-58008DiVA, id: diva2:2081882
Subject / course
Computer Engineering DT1
Educational program
Computer Science TDATG 180 higher education credits
Supervisors
Examiners
Available from: 2026-06-30 Created: 2026-06-30 Last updated: 2026-06-30Bibliographically approved

Open Access in DiVA

fulltext(1805 kB)13 downloads
File information
File name FULLTEXT01.pdfFile size 1805 kBChecksum SHA-512
64b01c1b88bfb14a729d491ca59d9341313b1ed5eaf3943e2481fda2a5e9148c35ef376cef85aa8e287430fc4a0e2c06ba8fbb6063aace249403c1cdd99e6847
Type fulltextMimetype application/pdf

Search in DiVA

By author/editor
Alhamid, Ahmad
By organisation
Department of Computer and Electrical Engineering (2023-)
Software Engineering

Search outside of DiVA

GoogleGoogle Scholar
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 18 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf