2026
Peer-Reviewed Research
Security Vulnerabilities in AI-Generated Code: A Large-Scale Analysis of Public GitHub Repositories
Material CWE-mapped weaknesses were identified in the dataset.
- Security & Supply Chain
- AI-Assisted Development
Evidence note
A large comparison of human-written and AI-generated Python and Java samples using defect, vulnerability and complexity analysis.
Comparison of human-written code with samples generated by ChatGPT, DeepSeek-Coder and Qwen-Coder.
More than 500,000 Python and Java code samples.
Why it matters. Lornets interpretation.
Code provenance is relevant context but not a technical verdict. Different development approaches can create different quality profiles, so production assessment should evaluate the actual properties that matter for the system.
This is the Lornets reading of the source, not a finding of the source itself.
Framework domains
Where this applies
Last verified 2026-08-11
2026
Peer-Reviewed Research
Material CWE-mapped weaknesses were identified in the dataset.
2026
Conference Paper
The lower-experience-proxy group submitted 2.15 times more commits per pull request.
23rd International Conference on Mining Software Repositories (MSR 2026), Mining Challenge
2025
Practitioner Reference
ASVS is designed around application-security verification requirements rather than high-level awareness categories.
OWASP Foundation, 5.0.0