{"title":"Can generative AI detect and fix real-world cryptographic misuses?","authors":"Ehsan Firouzi, Mohammad Ghafari","doi":"10.1016/j.jss.2025.112650","DOIUrl":null,"url":null,"abstract":"<div><div>We evaluate ChatGPT’s ability to detect and fix cryptographic API misuses. We show that GPT-4o can achieve F1 scores above 0.90 on two established benchmarks. We also assess the model on real-world code: on the GitHub samples, it attains an F1 score of 0.84 and a Matthews Correlation Coefficient (MCC) of 0.81; on the Android samples, it achieves an F1 score of 0.85 but a slightly lower MCC of 0.76. We noted that several factors such as naming conventions and code structure influence GPT’s performance. However, when it correctly flags a misuse, it is often able to suggest effective fixes. We also reported the identified misuses in GitHub repositories and received promising feedback from developers. Finally, a comparison between GPT and a state-of-the-art crypto-misuse detector shows GPT’s strong potential for adoption in real-world settings.</div></div>","PeriodicalId":51099,"journal":{"name":"Journal of Systems and Software","volume":"232 ","pages":"Article 112650"},"PeriodicalIF":4.1000,"publicationDate":"2025-10-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"Journal of Systems and Software","FirstCategoryId":"94","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S016412122500319X","RegionNum":2,"RegionCategory":"计算机科学","ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"COMPUTER SCIENCE, SOFTWARE ENGINEERING","Score":null,"Total":0}
引用次数: 0
Abstract
We evaluate ChatGPT’s ability to detect and fix cryptographic API misuses. We show that GPT-4o can achieve F1 scores above 0.90 on two established benchmarks. We also assess the model on real-world code: on the GitHub samples, it attains an F1 score of 0.84 and a Matthews Correlation Coefficient (MCC) of 0.81; on the Android samples, it achieves an F1 score of 0.85 but a slightly lower MCC of 0.76. We noted that several factors such as naming conventions and code structure influence GPT’s performance. However, when it correctly flags a misuse, it is often able to suggest effective fixes. We also reported the identified misuses in GitHub repositories and received promising feedback from developers. Finally, a comparison between GPT and a state-of-the-art crypto-misuse detector shows GPT’s strong potential for adoption in real-world settings.
期刊介绍:
The Journal of Systems and Software publishes papers covering all aspects of software engineering and related hardware-software-systems issues. All articles should include a validation of the idea presented, e.g. through case studies, experiments, or systematic comparisons with other approaches already in practice. Topics of interest include, but are not limited to:
•Methods and tools for, and empirical studies on, software requirements, design, architecture, verification and validation, maintenance and evolution
•Agile, model-driven, service-oriented, open source and global software development
•Approaches for mobile, multiprocessing, real-time, distributed, cloud-based, dependable and virtualized systems
•Human factors and management concerns of software development
•Data management and big data issues of software systems
•Metrics and evaluation, data mining of software development resources
•Business and economic aspects of software development processes
The journal welcomes state-of-the-art surveys and reports of practical experience for all of these topics.