Toggle Main Menu Toggle Search

Open Access padlockePrints

LLM-CSEC: Empirical Evaluation of Security in C/C++ Code Generated by Large Language Models

Lookup NU author(s): Muhammad Usman Shahid, Dr Mujeeb AhmedORCiD, Professor Raj Ranjan

Downloads


Licence

This work is licensed under a Creative Commons Attribution 4.0 International License (CC BY 4.0).


Abstract

The security of code generated by large language models (LLMs) is a significant concern, as studies indicate that such code often contains vulnerabilities and lacks essential defensive programming constructs. This work focuses on examining and evaluating the security of LLM-generated code, particularly in the context of C/C++. We categorized known vulnerabilities using the Common Weakness Enumeration (CWE) and, to study their criticality, mapped them to CVEs. We used ten different LLMs for code generation and analyzed the outputs through static analysis. The amount of CWEs present in AI-generated code is concerning. Our findings highlight the need for developers to be cautious when using LLM-generated code. This study provides valuable insights to advance automated code generation and encourage further research in this domain. The security of code generated by large language models (LLMs) is a significant concern, as studies indicate that such code often contains vulnerabilities and lacks essential defensive programming constructs. This work focuses on examining and evaluating the security of LLM-generated code, particularly in the context of C/C++. We categorized known vulnerabilities using the Common Weakness Enumeration (CWE) and, to study their criticality, mapped them to CVEs. We used ten different LLMs for code generation and analyzed the outputs through static analysis. The amount of CWEs present in AI-generated code is concerning. Our findings highlight the need for developers to be cautious when using LLM-generated code. This study provides valuable insights to advance automated code generation and encourage further research in this domain.


Publication metadata

Author(s): Shahid MU, Ahmed CM, Ranjan R

Publication type: Conference Proceedings (inc. Abstract)

Publication status: Published

Conference Name: 41st ACM/SIGAPP Symposium on Applied Computing (SAC '26)

Year of Conference: 2026

Pages: 1505-1514

Print publication date: 09/06/2026

Online publication date: 09/06/2026

Acceptance date: 12/01/2026

Date deposited: 10/08/2026

Publisher: ACM

URL: https://doi.org/10.1145/3748522.3780027

DOI: 10.1145/3748522.3780027

Library holdings: Search Newcastle University Library for this item

ISBN: 9798400722943


Share