[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-86559-en":3,"doc-seo-86559-105":30,"detail-sidebar-cat-0-en-105":92},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},86559,1374391974585,"Genevieve","https://ap-avatar.wpscdn.com/davatar_276721f389ce27ea32af1340a28f341c",8,"Research & Report","Understanding the Impact of AI Code Assistants on Security API Usage: An Empirical Study","AI code assistants are reshaping software development, yet software security—especially around security APIs—remains a critical risk area. Security APIs are essential for protecting systems, but their complexity often results in incorrect use and serious vulnerabilities. This study provides an evidence-based, developer-centered investigation of how AI assistants affect professional security API usage. A controlled study with 44 developers using or not using GitHub Copilot shows improved functional correctness, but no significant improvement in secure usage, and limited recognition of remaining insecurity.","arXiv :2607 . 1 1348v 1 [ cs . SE] 13 Jul 2026  \nUnderstanding the Impact of AI Code Assistants on Security API  \nUsage: An Empirical Study  \nZahra Mousavi 1 Chadni Islam2 M. Ali Babar 1 Alsharif Abuadbba3  \nKristen Moore3  \n1 Centre for Research on Engineering Software Technologies (CREST) & Adelaide University, Australia  \n2 Edith Cowan University, Australia 3 CSIRO’s Data61, Australia  \nAbstract  \nAI code assistants are transforming software development, but their implications for software security remain a major concern, particularly in the context of security APIs. These APIs are critical for safeguarding software systems, yet their complexity often leads to incorrect use and serious vulnerabilities. Developing an evidence-based understanding of how AI assistants influence developers’ use of these APIs is therefore essential for informing effective mitigation strategies. While a few user studies have examined the broader impact of AI assistantson software vulnerabilities, the use of security APIs remains unexplored from a developer-centered perspective. This study addresses this gap by presenting the first empirical investigation into how AI code assistants affect professional developers’ use of security APIs. We conducted a study with 44 developers who completed security API programming tasks with and without GitHub Copilot assistance. Our findings show that, while Copilot improves functional correctness and marginally reduces certain insecure patterns, it does not significantly improve secure API usage. We also found that developers rarely raised security concerns when engaging with Copilot, and many did not recognize that their final implementations remained insecure. Finally, we offer recommendations for enhancing security awareness among developers and propose future research directions to support safer AI-assisted software development.  \nKeywords: Security API · AI Code Assistants · Software Security  \n1 Introduction  \nSecurity Application Programming Interfaces (APIs) play a crucial role in modern software development by providing essential functionalities, such as encryption and secure communication [1] . Developers rely heavily on these APIs to protect various types of applications against cyber threats. SSL/TLS APIs are a prominent example and are extensively integrated within a wide range of platforms, including web browsers, mobile applications, and cloud services, to ensure the confidentiality and integrity of data transmitted over networks [2] .  \nHowever, using security APIs correctly remains a significant challenge for developers, resulting in their widespread misuse (i.e., incorrect use) across real-world software systems and open-source codebases [1,3–8] . Notably, security API misuse accounts for a substantial number of security vulnerabilities that expose systems to large-scale data breaches and significant financial losses [3–8] . A preliminary study on non-browser software found critical misuses of SSL/TLS APIs, such as bypassing certificate validation in security-critical applications and libraries, ranging from payment gateways to mobile banking apps [3] . Such misuse exposes software to Man-in-the-Middle (MitM) attacks, compromising the confidentiality and integrity of network communications. Fig. 1 illustrates this type of misuse. A developer uses an SSL/TLS API to establish a secure connection with a server (Step ○1 ) but incorrectly configures it to trust all certificates (Step ○2 ) . This misuse enables a MitM attacker to impersonate the server, intercept the commu-  \nnication between a user and the application, and obtain unauthorized access to the user’s information (Step ○3 ) .  \nThe underlying reasons for the prevalent misuse of security APIs include insufficient security training among developers [9–11], inadequate or unclear API documentation [12], and the inherent complexity of the security APIs themselves [3], which can overwhelm developers with a confusing range of configurations and ","cbCaitJuyA78W1Gc","https://ap.wps.com/l/cbCaitJuyA78W1Gc","pdf",3286592,5,1,15,"English","en",105,"# Abstract\n# Introduction","[{\"question\":\"What security risk does the paper focus on regarding security APIs?\",\"answer\":\"The paper focuses on incorrect security API usage that leads to serious vulnerabilities and large-scale breaches, with misuse patterns such as improper SSL/TLS certificate validation enabling man-in-the-middle attacks.\"},{\"question\":\"How was the empirical study conducted?\",\"answer\":\"The authors ran a study with 44 developers who completed security API programming tasks both with and without GitHub Copilot assistance, enabling a comparison of outcomes under AI support.\"},{\"question\":\"Do AI code assistants improve secure API usage according to the results?\",\"answer\":\"Copilot improves functional correctness and reduces some insecure patterns marginally, but it does not significantly improve secure API usage. Developers also rarely raised security concerns and many did not recognize that their final implementations remained insecure.\"}]",1784212631,38,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":87,"head_meta":89,"extra_data":91,"updated_unix":28},"understanding-the-impact-of-ai-code-assistants-on-security-api-usage-an-empirical-study","",{"@graph":36,"@context":86},[37,54,69],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,48,51],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":47},"https://docshare.wps.com/document/","Document",2,{"item":49,"name":12,"@type":43,"position":50},"https://docshare.wps.com/document/research-report/",3,{"item":52,"name":13,"@type":43,"position":53},"https://docshare.wps.com/document/understanding-the-impact-of-ai-code-assistants-on-security-api-usage-an-empirical-study/86559/",4,{"url":52,"name":13,"@type":55,"author":56,"headline":13,"publisher":58,"fileFormat":61,"inLanguage":24,"description":14,"dateModified":62,"datePublished":63,"encodingFormat":61,"isAccessibleForFree":64,"interactionStatistic":65},"DigitalDocument",{"name":9,"@type":57},"Person",{"url":41,"name":59,"@type":60},"DocShare","Organization","application/pdf","2026-07-27","2026-07-16",true,{"@type":66,"interactionType":67,"userInteractionCount":20},"InteractionCounter",{"@type":68},"ViewAction",{"@type":70,"mainEntity":71},"FAQPage",[72,78,82],{"name":73,"@type":74,"acceptedAnswer":75},"What security risk does the paper focus on regarding security APIs?","Question",{"text":76,"@type":77},"The paper focuses on incorrect security API usage that leads to serious vulnerabilities and large-scale breaches, with misuse patterns such as improper SSL/TLS certificate validation enabling man-in-the-middle attacks.","Answer",{"name":79,"@type":74,"acceptedAnswer":80},"How was the empirical study conducted?",{"text":81,"@type":77},"The authors ran a study with 44 developers who completed security API programming tasks both with and without GitHub Copilot assistance, enabling a comparison of outcomes under AI support.",{"name":83,"@type":74,"acceptedAnswer":84},"Do AI code assistants improve secure API usage according to the results?",{"text":85,"@type":77},"Copilot improves functional correctness and reduces some insecure patterns marginally, but it does not significantly improve secure API usage. Developers also rarely raised security concerns and many did not recognize that their final implementations remained insecure.","https://schema.org",{"og:url":52,"og:type":88,"og:title":13,"og:site_name":59,"og:description":14},"article",{"robots":90,"canonical":52},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":93},[94,98,102,106,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":95,"show_sort_weight":96,"slug":97},"Story & Novel",90,"story-novel",{"id":47,"doc_module":4,"doc_module_name":46,"category_name":99,"show_sort_weight":100,"slug":101},"Literature",80,"literature",{"id":53,"doc_module":4,"doc_module_name":46,"category_name":103,"show_sort_weight":104,"slug":105},"Exam",70,"exam",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":20,"slug":138},19,"General","general"]