{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:QLLWLLFVZLIFGKWU6NIFBN7NFU","short_pith_number":"pith:QLLWLLFV","schema_version":"1.0","canonical_sha256":"82d765acb5cad0532ad4f35050b7ed2d30dd010d4e601d795ff2c15d154403a3","source":{"kind":"arxiv","id":"2311.00889","version":3},"attestation_state":"computed","paper":{"title":"SALLM: Security Assessment of Generated Code","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.SE","authors_text":"Anna Muller, Joanna C. S. Santos, Mohammed Latif Siddiq, Sajith Devareddy","submitted_at":"2023-11-01T22:46:31Z","abstract_excerpt":"With the growing popularity of Large Language Models (LLMs) in software engineers' daily practices, it is important to ensure that the code generated by these tools is not only functionally correct but also free of vulnerabilities. Although LLMs can help developers to be more productive, prior empirical studies have shown that LLMs can generate insecure code. There are two contributing factors to the insecure code generation. First, existing datasets used to evaluate LLMs do not adequately represent genuine software engineering tasks sensitive to security. Instead, they are often based on comp"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2311.00889","kind":"arxiv","version":3},"metadata":{"license":"http://creativecommons.org/licenses/by/4.0/","primary_cat":"cs.SE","submitted_at":"2023-11-01T22:46:31Z","cross_cats_sorted":["cs.AI"],"title_canon_sha256":"36ef651f51cba2084e809100dc475c14ef5fa9b9d117c88910d5c7fe399f2162","abstract_canon_sha256":"21b2c6965e41c7396108271dd4a21cd6665bb0da15fff5ecd14c36d1d9707294"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T09:03:17.077036Z","signature_b64":"5e77lZ+8YMzn9+ZyVaJvyfZM0LOQ12UOGm2MUvYqp/Lthytb5TJTB7PpfvJWU1Rkuehr8H7+ynmGMkREsZ3ZBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"82d765acb5cad0532ad4f35050b7ed2d30dd010d4e601d795ff2c15d154403a3","last_reissued_at":"2026-07-05T09:03:17.076402Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T09:03:17.076402Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"SALLM: Security Assessment of Generated Code","license":"http://creativecommons.org/licenses/by/4.0/","headline":"","cross_cats":["cs.AI"],"primary_cat":"cs.SE","authors_text":"Anna Muller, Joanna C. S. Santos, Mohammed Latif Siddiq, Sajith Devareddy","submitted_at":"2023-11-01T22:46:31Z","abstract_excerpt":"With the growing popularity of Large Language Models (LLMs) in software engineers' daily practices, it is important to ensure that the code generated by these tools is not only functionally correct but also free of vulnerabilities. Although LLMs can help developers to be more productive, prior empirical studies have shown that LLMs can generate insecure code. There are two contributing factors to the insecure code generation. First, existing datasets used to evaluate LLMs do not adequately represent genuine software engineering tasks sensitive to security. Instead, they are often based on comp"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2311.00889","kind":"arxiv","version":3},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2311.00889/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2311.00889","created_at":"2026-07-05T09:03:17.076469+00:00"},{"alias_kind":"arxiv_version","alias_value":"2311.00889v3","created_at":"2026-07-05T09:03:17.076469+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2311.00889","created_at":"2026-07-05T09:03:17.076469+00:00"},{"alias_kind":"pith_short_12","alias_value":"QLLWLLFVZLIF","created_at":"2026-07-05T09:03:17.076469+00:00"},{"alias_kind":"pith_short_16","alias_value":"QLLWLLFVZLIFGKWU","created_at":"2026-07-05T09:03:17.076469+00:00"},{"alias_kind":"pith_short_8","alias_value":"QLLWLLFV","created_at":"2026-07-05T09:03:17.076469+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":0,"sample":[{"citing_arxiv_id":"2605.24298","citing_title":"An Empirical Evaluation of LLM-Generated Code Security Across Prompting Methods","ref_index":39,"is_internal_anchor":false},{"citing_arxiv_id":"2411.10656","citing_title":"Precision or Peril: A PoC of Python Code Quality from Quantized Large Language Models","ref_index":11,"is_internal_anchor":false},{"citing_arxiv_id":"2604.19354","citing_title":"Do Agents Dream of Root Shells? Partial-Credit Evaluation of LLM Agents in Capture the Flag Challenges","ref_index":19,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU","json":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU.json","graph_json":"https://pith.science/api/pith-number/QLLWLLFVZLIFGKWU6NIFBN7NFU/graph.json","events_json":"https://pith.science/api/pith-number/QLLWLLFVZLIFGKWU6NIFBN7NFU/events.json","paper":"https://pith.science/paper/QLLWLLFV"},"agent_actions":{"view_html":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU","download_json":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU.json","view_paper":"https://pith.science/paper/QLLWLLFV","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2311.00889&json=true","fetch_graph":"https://pith.science/api/pith-number/QLLWLLFVZLIFGKWU6NIFBN7NFU/graph.json","fetch_events":"https://pith.science/api/pith-number/QLLWLLFVZLIFGKWU6NIFBN7NFU/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU/action/timestamp_anchor","attest_storage":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU/action/storage_attestation","attest_author":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU/action/author_attestation","sign_citation":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU/action/citation_signature","submit_replication":"https://pith.science/pith/QLLWLLFVZLIFGKWU6NIFBN7NFU/action/replication_record"}},"created_at":"2026-07-05T09:03:17.076469+00:00","updated_at":"2026-07-05T09:03:17.076469+00:00"}