{"id":"https://openalex.org/W4400121384","doi":"https://doi.org/10.1145/3634737.3661134","title":"An Investigation into Misuse of Java Security APIs by Large Language Models","display_name":"An Investigation into Misuse of Java Security APIs by Large Language Models","publication_year":2024,"publication_date":"2024-06-28","ids":{"openalex":"https://openalex.org/W4400121384","doi":"https://doi.org/10.1145/3634737.3661134"},"language":"en","primary_location":{"id":"doi:10.1145/3634737.3661134","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3661134","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://doi.org/10.1145/3634737.3661134","any_repository_has_fulltext":null},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100775113","display_name":"Zahra Mousavi","orcid":"https://orcid.org/0000-0001-6538-5966"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":true,"raw_author_name":"Zahra Mousavi","raw_affiliation_strings":["CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Cyber Security Cooperative Research Centre, CSIRO/Data61, Australia, Adelaide, Australia"],"affiliations":[{"raw_affiliation_string":"CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Cyber Security Cooperative Research Centre, CSIRO/Data61, Australia, Adelaide, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I5681781"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5012225295","display_name":"Chadni Islam","orcid":"https://orcid.org/0000-0002-6349-6483"},"institutions":[{"id":"https://openalex.org/I160993911","display_name":"Queensland University of Technology","ror":"https://ror.org/03pnv4752","country_code":"AU","type":"education","lineage":["https://openalex.org/I160993911"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Chadni Islam","raw_affiliation_strings":["Queensland University of Technology, Brisbane, Australia"],"affiliations":[{"raw_affiliation_string":"Queensland University of Technology, Brisbane, Australia","institution_ids":["https://openalex.org/I160993911"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5037106850","display_name":"Kristen Moore","orcid":"https://orcid.org/0000-0002-9962-5080"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I1292875679","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07","country_code":"AU","type":"funder","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Kristen Moore","raw_affiliation_strings":["CSIRO's Data61, Australia, Melbourne, Australia"],"affiliations":[{"raw_affiliation_string":"CSIRO's Data61, Australia, Melbourne, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I1292875679"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5086357020","display_name":"Alsharif Abuadbba","orcid":"https://orcid.org/0000-0001-9695-7947"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I1292875679","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07","country_code":"AU","type":"funder","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Alsharif Abuadbba","raw_affiliation_strings":["CSIRO's Data61, Australia, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"CSIRO's Data61, Australia, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I1292875679"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103075476","display_name":"Muhammad Ali Babar","orcid":"https://orcid.org/0000-0001-9696-3626"},"institutions":[{"id":"https://openalex.org/I5681781","display_name":"University of Adelaide","ror":"https://ror.org/00892tw58","country_code":"AU","type":"education","lineage":["https://openalex.org/I5681781"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"M. Ali Babar","raw_affiliation_strings":["CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Adelaide, Australia"],"affiliations":[{"raw_affiliation_string":"CREST - The Centre for Research on Engineering Software Technologies, University of Adelaide, Adelaide, Australia","institution_ids":["https://openalex.org/I5681781"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100775113"],"corresponding_institution_ids":["https://openalex.org/I42894916","https://openalex.org/I5681781"],"apc_list":null,"apc_paid":null,"fwci":6.0801,"has_fulltext":false,"cited_by_count":17,"citation_normalized_percentile":{"value":0.97178401,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":100},"biblio":{"volume":null,"issue":null,"first_page":"1299","last_page":"1315"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12479","display_name":"Web Application Security Vulnerabilities","score":0.9973999857902527,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8033181428909302},{"id":"https://openalex.org/keywords/java","display_name":"Java","score":0.7484237551689148},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.5041431188583374},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3371632695198059}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8033181428909302},{"id":"https://openalex.org/C548217200","wikidata":"https://www.wikidata.org/wiki/Q251","display_name":"Java","level":2,"score":0.7484237551689148},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.5041431188583374},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3371632695198059}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3634737.3661134","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3661134","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"}],"best_oa_location":{"id":"doi:10.1145/3634737.3661134","is_oa":true,"landing_page_url":"https://doi.org/10.1145/3634737.3661134","pdf_url":null,"source":null,"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th ACM Asia Conference on Computer and Communications Security","raw_type":"proceedings-article"},"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":52,"referenced_works":["https://openalex.org/W2008810193","https://openalex.org/W2012921353","https://openalex.org/W2103370348","https://openalex.org/W2112995928","https://openalex.org/W2116304133","https://openalex.org/W2133723082","https://openalex.org/W2145994642","https://openalex.org/W2187511152","https://openalex.org/W2218971720","https://openalex.org/W2257242910","https://openalex.org/W2511044583","https://openalex.org/W2536964484","https://openalex.org/W2576128915","https://openalex.org/W2698406033","https://openalex.org/W2742082076","https://openalex.org/W2766347289","https://openalex.org/W2804959968","https://openalex.org/W2888959482","https://openalex.org/W2894351723","https://openalex.org/W2916399511","https://openalex.org/W2963725780","https://openalex.org/W2965807990","https://openalex.org/W2973035781","https://openalex.org/W2985320478","https://openalex.org/W2998879240","https://openalex.org/W3011564318","https://openalex.org/W3018931209","https://openalex.org/W3031020798","https://openalex.org/W3031272488","https://openalex.org/W3198867963","https://openalex.org/W3200911260","https://openalex.org/W3202114283","https://openalex.org/W3215012555","https://openalex.org/W4200634422","https://openalex.org/W4205392403","https://openalex.org/W4211233231","https://openalex.org/W4225326198","https://openalex.org/W4231440932","https://openalex.org/W4255039277","https://openalex.org/W4283651643","https://openalex.org/W4288057765","https://openalex.org/W4292956935","https://openalex.org/W4300424244","https://openalex.org/W4315815628","https://openalex.org/W4383860339","https://openalex.org/W4385477851","https://openalex.org/W4388858772","https://openalex.org/W4389768548","https://openalex.org/W6749612936","https://openalex.org/W6754369729","https://openalex.org/W7008546652","https://openalex.org/W7010933560"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W4396696052","https://openalex.org/W2382290278","https://openalex.org/W4395014643"],"abstract_inverted_index":{"The":[0],"increasing":[1],"trend":[2],"of":[3,15,29,116,154,177],"using":[4],"Large":[5],"Language":[6],"Models":[7],"(LLMs)":[8],"for":[9,32,99,120,145,174],"code":[10,30,97,141,156],"generation":[11,31,98],"raises":[12],"the":[13,27,43,140,155,178],"question":[14],"their":[16],"capability":[17],"to":[18,68,76,133,191,199],"generate":[19],"trustworthy":[20],"code.":[21,204],"While":[22],"many":[23],"researchers":[24],"are":[25,150],"exploring":[26],"utility":[28],"uncovering":[33],"software":[34,56,75],"vulnerabilities,":[35],"one":[36],"crucial":[37],"but":[38],"often":[39],"overlooked":[40],"aspect":[41],"is":[42,187],"security":[44,61,100,124,136,164,202],"Application":[45],"Programming":[46],"Interfaces":[47],"(APIs).":[48],"APIs":[49,62],"play":[50],"an":[51,113],"integral":[52],"role":[53],"in":[54,96,104,139],"upholding":[55],"security,":[57],"yet":[58],"effectively":[59,134],"integrating":[60],"presents":[63],"substantial":[64],"challenges.":[65],"This":[66],"leads":[67],"inadvertent":[69],"misuse":[70,138,170],"by":[71,143],"developers,":[72],"thereby":[73],"exposing":[74],"vulnerabilities.":[77],"To":[78,106],"overcome":[79],"these":[80,146],"challenges,":[81],"developers":[82,194],"may":[83],"seek":[84],"assistance":[85],"from":[86],"LLMs.":[87],"In":[88],"this":[89,180],"paper,":[90],"we":[91,111],"systematically":[92],"assess":[93],"ChatGPT's":[94],"trustworthiness":[95],"API":[101,137,165,203],"use":[102],"cases":[103],"Java.":[105],"conduct":[107],"a":[108,188],"thorough":[109],"evaluation,":[110],"compile":[112],"extensive":[114],"collection":[115],"48":[117],"programming":[118],"tasks":[119],"5":[121],"widely":[122],"used":[123],"APIs.":[125],"We":[126],"employ":[127],"both":[128],"automated":[129],"and":[130],"manual":[131],"approaches":[132],"detect":[135],"generated":[142],"ChatGPT":[144,198],"tasks.":[147],"Our":[148],"findings":[149],"concerning:":[151],"around":[152],"70%":[153],"instances":[157],"across":[158],"30":[159],"attempts":[160],"per":[161],"task":[162],"contain":[163],"misuse,":[166],"with":[167],"20":[168],"distinct":[169],"types":[171],"identified.":[172],"Moreover,":[173],"roughly":[175],"half":[176],"tasks,":[179],"rate":[181],"reaches":[182],"100%,":[183],"indicating":[184],"that":[185],"there":[186],"long":[189],"way":[190],"go":[192],"before":[193],"can":[195],"rely":[196],"on":[197],"securely":[200],"implement":[201]},"counts_by_year":[{"year":2026,"cited_by_count":3},{"year":2025,"cited_by_count":12},{"year":2024,"cited_by_count":2}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
