Insecure Coding Preferences in Long-Term Memory: Security Risks for LLM-based Code Generation
Yuchen Chen, Wei Cheng, Yuan Xiao, Zhou Yang, Weifeng Sun, Chunrong Fang, Xiang Chen, Baowen Xu, David Lo, Zhenyu Chen
cs.CR
Submitted: 2026-07-20
Comments: Accepted to the 35th ACM SIGSOFT International Symposium on Software Testing and Analysis (ISSTA 2026)
Code: https://github.com/filestack/filestack-python
License: http://arxiv.org/licenses/nonexclusive-distrib/1.0/
Terminology
Sources
- Constitutional AI: Harmlessness from AI Feedback
- Evaluating Large Language Models Trained on Code
- Security of Language Models for Code: A Systematic Literature Review
- Rethinking the Evaluation of Secure Code Generation
- Security Weaknesses of Copilot-Generated Code in GitHub Projects: An Empirical Study
- DeepSeek-Coder: When the Large Language Model Meets Programming -- The Rise of Code Intelligence
- A Survey on Large Language Models for Code Generation
- PurpCode: Reasoning for Safer Code Generation
- Prompt Injection attack against LLM-integrated Applications
- Can We Trust Large Language Models Generated Code? A Framework for In-Context Learning, Security Patterns, and Code Evaluations Across Diverse LLMs
- From Human Memory to AI Memory: A Survey on Memory Mechanisms in the Era of LLMs
- Robustness, Security, Privacy, Explainability, Efficiency, and Usability of Large Language Models for Code
- A Survey on the Memory Mechanism of Large Language Model based Agents
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs