"Tab, Tab, Bug": Security Pitfalls of Next Edit Suggestions in AI-Integrated IDEs
cs.CR, cs.HC
Submitted: 2026-02-06
Updated: 2026-09-09
Comments: To appear in ACM CCS 2026
Code: https://github.com/tree-sitter/tree-sitter
Project page: https://microsoft.github.io/languageserver-protocol
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Efficient Training of Language Models to Fill in the Middle
- Purple Llama CyberSecEval: A Secure Coding Benchmark for Language Models
- Qwen3-Coder-Next Technical Report
- Evaluating Large Language Models Trained on Code
- NES: An Instruction-Free, Low-Latency Next Edit Suggestion Framework Powered by Learned Historical Editing Trajectories
- DeepSeek-Coder: When the Large Language Model Meets Programming -- The Rise of Code Intelligence
- Qwen2.5-Coder Technical Report
- How Secure is Code Generated by ChatGPT?
- Structured Generative Models of Natural Source Code
- Training language models to follow instructions with human feedback
- Asleep at the Keyboard? Assessing the Security of GitHub Copilot's Code Contributions
- The Impact of AI on Developer Productivity: Evidence from GitHub Copilot
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs