SecDrift: Benchmarking the Impact of Industry-Specific Prompts on Security of AI-Generated Code
A new arXiv preprint introduces SecDrift, a benchmark designed to test whether prompting large language models (LLMs) with industry-specific context affects the security of generated code. Evaluating seven LLMs across eight critical infrastructure sectors, the study finds no statistically significant increase in vulnerabilities due to sector-specific prompting. Instead, the choice of model has a much larger and consistent impact on code security than prompt framing.
Why it matters: This finding suggests that efforts to improve the security of AI-generated code should prioritize model selection over prompt engineering, especially in critical infrastructure contexts.
Full story at: arXiv Cryptography and Security ↗