A Qualitative Study on Using ChatGPT for Software Security: Perception vs. Practicality
M. Mehdi Kholoosi, M. Ali Babar, Roland Croft

TL;DR
This study explores both perceptions and practical effectiveness of ChatGPT in software security tasks, revealing positive views but limited industry applicability due to generic responses.
Contribution
It provides a dual analysis of ChatGPT's perceived benefits and practical limitations in software security, highlighting areas for future specialized LLM development.
Findings
Security practitioners see ChatGPT as beneficial for vulnerability detection and penetration testing.
ChatGPT responses are often generic and may not be suitable for industry use.
Practical deployment shows limitations in ChatGPT's current capabilities for security tasks.
Abstract
Artificial Intelligence (AI) advancements have enabled the development of Large Language Models (LLMs) that can perform a variety of tasks with remarkable semantic understanding and accuracy. ChatGPT is one such LLM that has gained significant attention due to its impressive capabilities for assisting in various knowledge-intensive tasks. Due to the knowledge-intensive nature of engineering secure software, ChatGPT's assistance is expected to be explored for security-related tasks during the development/evolution of software. To gain an understanding of the potential of ChatGPT as an emerging technology for supporting software security, we adopted a two-fold approach. Initially, we performed an empirical study to analyse the perceptions of those who had explored the use of ChatGPT for security tasks and shared their views on Twitter. It was determined that security practitioners view…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsArtificial Intelligence in Healthcare and Education · Artificial Intelligence in Healthcare · Technology and Data Analysis
MethodsSoftmax · Attention Is All You Need
