{"id":"https://openalex.org/W7160419404","doi":"https://doi.org/10.1109/saner-c67878.2026.00041","title":"Can Developers Rely on LLMs for Secure IaC Development?","display_name":"Can Developers Rely on LLMs for Secure IaC Development?","publication_year":2026,"publication_date":"2026-03-17","ids":{"openalex":"https://openalex.org/W7160419404","doi":"https://doi.org/10.1109/saner-c67878.2026.00041"},"language":null,"primary_location":{"id":"doi:10.1109/saner-c67878.2026.00041","is_oa":false,"landing_page_url":"https://doi.org/10.1109/saner-c67878.2026.00041","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion (SANER-C)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5031213161","display_name":"Ehsan Firouzi","orcid":"https://orcid.org/0009-0000-7563-4196"},"institutions":[{"id":"https://openalex.org/I43980791","display_name":"Clausthal University of Technology","ror":"https://ror.org/04qb8nc58","country_code":"DE","type":"education","lineage":["https://openalex.org/I43980791"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Ehsan Firouzi","raw_affiliation_strings":["Technische Universit&#x00E4;t Clausthal,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technische Universit&#x00E4;t Clausthal,Germany","institution_ids":["https://openalex.org/I43980791"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5103439516","display_name":"Shardul Bhatt","orcid":null},"institutions":[{"id":"https://openalex.org/I43980791","display_name":"Clausthal University of Technology","ror":"https://ror.org/04qb8nc58","country_code":"DE","type":"education","lineage":["https://openalex.org/I43980791"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Shardul Bhatt","raw_affiliation_strings":["Technische Universit&#x00E4;t Clausthal,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technische Universit&#x00E4;t Clausthal,Germany","institution_ids":["https://openalex.org/I43980791"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5125035649","display_name":"Mohammad Ghafari","orcid":null},"institutions":[{"id":"https://openalex.org/I43980791","display_name":"Clausthal University of Technology","ror":"https://ror.org/04qb8nc58","country_code":"DE","type":"education","lineage":["https://openalex.org/I43980791"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Mohammad Ghafari","raw_affiliation_strings":["Technische Universit&#x00E4;t Clausthal,Germany"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"Technische Universit&#x00E4;t Clausthal,Germany","institution_ids":["https://openalex.org/I43980791"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.74041254,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":"257","last_page":"264"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.125,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.125,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.09920000284910202,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11504","display_name":"Advanced Authentication Protocols Security","score":0.05040000006556511,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/key","display_name":"Key (lock)","score":0.3398999869823456},{"id":"https://openalex.org/keywords/government","display_name":"Government (linguistics)","score":0.27720001339912415},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.2558000087738037},{"id":"https://openalex.org/keywords/context","display_name":"Context (archaeology)","score":0.2328999936580658}],"concepts":[{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.5349000096321106},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.49390000104904175},{"id":"https://openalex.org/C108827166","wikidata":"https://www.wikidata.org/wiki/Q175975","display_name":"Internet privacy","level":1,"score":0.49149999022483826},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.38420000672340393},{"id":"https://openalex.org/C39549134","wikidata":"https://www.wikidata.org/wiki/Q133080","display_name":"Public relations","level":1,"score":0.34040001034736633},{"id":"https://openalex.org/C26517878","wikidata":"https://www.wikidata.org/wiki/Q228039","display_name":"Key (lock)","level":2,"score":0.3398999869823456},{"id":"https://openalex.org/C2778137410","wikidata":"https://www.wikidata.org/wiki/Q2732820","display_name":"Government (linguistics)","level":2,"score":0.27720001339912415},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.2558000087738037},{"id":"https://openalex.org/C2779343474","wikidata":"https://www.wikidata.org/wiki/Q3109175","display_name":"Context (archaeology)","level":2,"score":0.2328999936580658},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.22869999706745148}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/saner-c67878.2026.00041","is_oa":false,"landing_page_url":"https://doi.org/10.1109/saner-c67878.2026.00041","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2026 IEEE International Conference on Software Analysis, Evolution and Reengineering - Companion (SANER-C)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.4665396213531494,"display_name":"Industry, innovation and infrastructure","id":"https://metadata.un.org/sdg/9"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":18,"referenced_works":["https://openalex.org/W2883411629","https://openalex.org/W2907854211","https://openalex.org/W2955656327","https://openalex.org/W2993710525","https://openalex.org/W3123074563","https://openalex.org/W4206969416","https://openalex.org/W4313563645","https://openalex.org/W4365801718","https://openalex.org/W4385848632","https://openalex.org/W4388858772","https://openalex.org/W4389629013","https://openalex.org/W4396811058","https://openalex.org/W4399567707","https://openalex.org/W4403413475","https://openalex.org/W4403607483","https://openalex.org/W4408214684","https://openalex.org/W4415313329","https://openalex.org/W7160430624"],"related_works":[],"abstract_inverted_index":{"We":[0],"investigated":[1],"the":[2,22,33,87,92,95,103,124,156],"capabilities":[3,164],"of":[4,40,86,102,123],"GPT-4o":[5],"and":[6,117],"Gemini":[7,146],"2.0":[8],"Flash":[9],"for":[10,158],"secure":[11,106,135,139,169],"Infrastructure":[12],"as":[13],"Code":[14],"(IaC)":[15],"development.":[16,171],"For":[17,105],"security":[18,41,50],"smell":[19],"detection,":[20],"on":[21],"Stack":[23],"Overflow":[24],"dataset,":[25],"which":[26,70],"primarily":[27],"contains":[28],"small,":[29],"simplified":[30],"code":[31,47,107,136],"snippets,":[32],"models":[34,96],"detected":[35],"at":[36,98],"least":[37,99],"71":[38],"%":[39,101,122],"smells":[42,88],"when":[43],"prompted":[44,110],"to":[45,64,133,142,161],"analyze":[46],"from":[48],"a":[49,55,76],"perspective":[51],"(general":[52],"prompt).":[53],"With":[54],"guided":[56,93],"prompt":[57,78],"(adding":[58],"clear,":[59],"step-by-step":[60],"instructions),":[61],"this":[62],"increased":[63,137],"78":[65],"%.":[66],"In":[67],"GitHub":[68],"repositories,":[69],"contain":[71],"complete,":[72],"real-world":[73],"project":[74],"scripts,":[75],"general":[77],"was":[79],"less":[80],"effective,":[81],"leaving":[82],"more":[83],"than":[84],"half":[85],"undetected.":[89],"However,":[90],"with":[91,112,168],"prompt,":[94],"uncovered":[97],"67":[100],"smells.":[104],"generation,":[108],"we":[109],"LLMs":[111],"89":[113],"vulnerable":[114],"synthetic":[115],"scenarios":[116],"observed":[118],"that":[119],"only":[120],"7":[121],"generated":[125],"scripts":[126],"were":[127],"secure.":[128],"Adding":[129],"an":[130],"explicit":[131],"instruction":[132],"generate":[134],"GPT":[138],"output":[140],"rate":[141],"17":[143],"%,":[144],"while":[145],"changed":[147],"little":[148],"<tex":[149],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[150],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">$(8":[151],"\\%)$</tex>.":[152],"These":[153],"results":[154],"highlight":[155],"need":[157],"further":[159],"research":[160],"improve":[162],"LLMs'":[163],"in":[165],"assisting":[166],"developers":[167],"IaC":[170]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-05-07T00:00:00"}
