Education DCL: EAGER: Advancing Secure Coding Education: Empowering Students to Safely Utilize AI-powered Coding Assistant Tools
教育 DCL:EAGER:推进安全编码教育:使学生能够安全地利用人工智能驱动的编码辅助工具
基本信息
- 批准号:2335798
- 负责人:
- 金额:$ 30万
- 依托单位:
- 依托单位国家:美国
- 项目类别:Standard Grant
- 财政年份:2023
- 资助国家:美国
- 起止时间:2023-10-01 至 2025-09-30
- 项目状态:未结题
- 来源:
- 关键词:
项目摘要
The advent of Artificial Intelligence (AI) has transformed the landscape of the software engineering ecosystem. Particularly, AI-powered coding assistant tools (e.g., ChatGPT and GitHub Copilot) are believed to potentially revolutionize the software development landscape. The tools can enhance software developers' efficiency and productivity in software development by generating boilerplate code for developers. Unfortunately, the tools can generate (or suggest) insecure code for developers because (1) the models that the tools rely on can inadvertently learn from insecure code snippets of untrusted, unverified open-source projects, or (2) the models are also vulnerable to poisoning attacks. The project's novelties are to develop new curricular modules and hands-on exercises for computer science students and the software development workforce to enhance their secure coding practices when using the tools. The project's broader significance and importance are to equip students and the workforce with secure coding practices when using AI-powered coding assistant tools, thereby enabling them to develop secure programs in the future. Moreover, this project's activities will be used to attract undergraduate students from underrepresented groups to cybersecurity.The main objective of this education project is to help students and the workforce have secure coding practices. First, this project develops new hands-on exercises where the students and the workforce can learn how suggested insecure code can impact their software and how the software can be vulnerable and exploited by adversaries. This engages them in active security-oriented learning to cultivate their secure coding practices when using AI-powered coding assistant tools. The hands-on materials include a real-world programming environment where the learners are expected to have experience with poisoned models. Second, this project actively pursues the involvement of undergraduate/high school students in research, including underrepresented groups (specifically the Appalachia region). Third, the project team host workshops in the summer to assist participating faculty in learning how to use our hands-on lab materials developed through this projectThis award reflects NSF's statutory mission and has been deemed worthy of support through evaluation using the Foundation's intellectual merit and broader impacts review criteria.
人工智能(AI)的出现改变了软件工程生态系统的景观。特别是,据信,AI驱动的编码助理工具(例如Chatgpt和Github Copilot)可能会彻底改变软件开发格局。这些工具可以通过为开发人员生成样板代码来提高软件开发人员在软件开发中的效率和生产率。不幸的是,这些工具可以为开发人员生成(或建议)不安全的代码,因为(1)工具依赖的模型可以无意间从不安全,未经验证的未经验证的开源项目的不安全代码段中学习,或者(2)模型也容易受到中毒的攻击。该项目的新颖性是为计算机科学专业的学生和软件开发人员开发新的课程模块和动手练习,以在使用工具时增强其安全的编码实践。该项目使用AI驱动的编码助理工具时,该项目的重要性和重要性是为学生和劳动力提供安全的编码实践,从而使他们能够在将来开发安全的程序。此外,该项目的活动将用于吸引从代表性不足的团体到网络安全的本科生。该教育项目的主要目标是帮助学生和劳动力具有安全的编码实践。首先,该项目开发了新的动手练习,学生和劳动力可以在其中学习建议的不安全代码如何影响其软件以及该软件如何脆弱和受到对手的影响。这使他们参与了以安全性为导向的学习,以便在使用AI驱动的编码助手工具时培养其安全的编码实践。动手的材料包括一个现实世界中的编程环境,希望学习者具有有毒模型的经验。其次,该项目积极追求本科/高中学生参与研究的参与,包括代表性不足的群体(特别是阿巴拉契亚地区)。第三,项目团队在夏季举办研讨会,以协助参与教师学习如何通过该项目奖开发的动手实验室材料反映了NSF的法定任务,并被认为是值得通过基金会的知识分子和更广泛影响的评估评估标准通过评估来获得支持的。
项目成果
期刊论文数量(0)
专著数量(0)
科研奖励数量(0)
会议论文数量(0)
专利数量(0)

暂无数据
数据更新时间:2024-06-01
Doowon Kim其他文献
An Inconvenient Trust: User Attitudes toward Security and Usability Tradeoffs for Key-Directory Encryption Systems
不方便的信任:用户对密钥目录加密系统的安全性和可用性权衡的态度
- DOI:
- 发表时间:20162016
- 期刊:
- 影响因子:0
- 作者:Wei Bai;M. Namara;Yichen Qian;Patrick Gage Kelley;Michelle L. Mazurek;Doowon KimWei Bai;M. Namara;Yichen Qian;Patrick Gage Kelley;Michelle L. Mazurek;Doowon Kim
- 通讯作者:Doowon KimDoowon Kim
Balancing Security and Usability in Encrypted Email
平衡加密电子邮件的安全性和可用性
- DOI:10.1109/mic.2017.5710.1109/mic.2017.57
- 发表时间:20172017
- 期刊:
- 影响因子:3.2
- 作者:Wei Bai;Doowon Kim;M. Namara;Yichen Qian;Patrick Gage Kelley;Michelle L. MazurekWei Bai;Doowon Kim;M. Namara;Yichen Qian;Patrick Gage Kelley;Michelle L. Mazurek
- 通讯作者:Michelle L. MazurekMichelle L. Mazurek
Lessons Learned from Using an Online Platform to Conduct Large-Scale, Online Controlled Security Experiments with Software Developers
使用在线平台与软件开发人员进行大规模在线控制安全实验的经验教训
- DOI:
- 发表时间:20172017
- 期刊:
- 影响因子:0
- 作者:Christian Stransky;Y. Acar;Duc Cuong Nguyen;Dominik Wermke;Doowon Kim;Elissa M. Redmiles;M. Backes;S. Garfinkel;Michelle L. Mazurek;S. FahlChristian Stransky;Y. Acar;Duc Cuong Nguyen;Dominik Wermke;Doowon Kim;Elissa M. Redmiles;M. Backes;S. Garfinkel;Michelle L. Mazurek;S. Fahl
- 通讯作者:S. FahlS. Fahl
Demystifying the Regional Phishing Landscape in South Korea
揭秘韩国区域网络钓鱼格局
- DOI:
- 发表时间:20232023
- 期刊:
- 影响因子:3.9
- 作者:Hyunjun Park;Kyungchan Lim;Doowon Kim;Donghyun Yu;Hyungjoon KooHyunjun Park;Kyungchan Lim;Doowon Kim;Donghyun Yu;Hyungjoon Koo
- 通讯作者:Hyungjoon KooHyungjoon Koo
An Adaptive Primary Path Switching Scheme for Seamless mSCTP Handover
一种用于无缝 mSCTP 切换的自适应主路径切换方案
- DOI:10.6029/smartcr.2011.02.00610.6029/smartcr.2011.02.006
- 发表时间:20112011
- 期刊:
- 影响因子:0
- 作者:Jinsuk Baek;Doowon Kim;P. Fisher;Minho JoJinsuk Baek;Doowon Kim;P. Fisher;Minho Jo
- 通讯作者:Minho JoMinho Jo
共 8 条
- 1
- 2
相似国自然基金
OH+HCl/DCl↔H2O/HOD+Cl态-态反应的全维微分截面研究
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
番茄抗病毒基因DCL2b受病毒诱导调控的分子机理
- 批准号:32272744
- 批准年份:2022
- 资助金额:54.00 万元
- 项目类别:面上项目
番茄抗病毒基因DCL2b受病毒诱导调控的分子机理
- 批准号:
- 批准年份:2022
- 资助金额:54 万元
- 项目类别:面上项目
OH+HCl/DCl↔H2O/HOD+Cl态-态反应的全维微分截面研究
- 批准号:22273104
- 批准年份:2022
- 资助金额:54.00 万元
- 项目类别:面上项目
RNAi介导的转S1基因大豆对SMV广谱抗性启动机制的解析
- 批准号:31801388
- 批准年份:2018
- 资助金额:25.0 万元
- 项目类别:青年科学基金项目
相似海外基金
Education DCL: EAGER: Teaching Privacy via Stakeholder Modeling
教育 DCL:EAGER:通过利益相关者建模教授隐私
- 批准号:23356252335625
- 财政年份:2024
- 资助金额:$ 30万$ 30万
- 项目类别:Standard GrantStandard Grant
Education DCL: EAGER: An Embedded Case Study Approach for Broadening Students' Mindset for Ethical and Responsible Cybersecurity
教育 DCL:EAGER:一种嵌入式案例研究方法,用于拓宽学生道德和负责任的网络安全思维
- 批准号:23356362335636
- 财政年份:2024
- 资助金额:$ 30万$ 30万
- 项目类别:Standard GrantStandard Grant
Education DCL: EAGER: Experiential Learning Platform and Curricular Modules for Quantum Computing Security and Privacy Education
教育 DCL:EAGER:量子计算安全和隐私教育的体验式学习平台和课程模块
- 批准号:23357882335788
- 财政年份:2023
- 资助金额:$ 30万$ 30万
- 项目类别:Standard GrantStandard Grant
Collaborative Research: Education DCL: EAGER: Harnessing the Power of Large Language Models in Digital Forensics Education at MSI and HBCU
合作研究:教育 DCL:EAGER:在 MSI 和 HBCU 的数字取证教育中利用大型语言模型的力量
- 批准号:23339512333951
- 财政年份:2023
- 资助金额:$ 30万$ 30万
- 项目类别:Standard GrantStandard Grant
Collaborative Research: Education DCL: EAGER: Redefining Cybersecurity Education for Criminal Justice Professionals: Bridging the Gap in National Cyber Capabilities
合作研究:教育 DCL:EAGER:重新定义刑事司法专业人员的网络安全教育:缩小国家网络能力的差距
- 批准号:23341962334196
- 财政年份:2023
- 资助金额:$ 30万$ 30万
- 项目类别:Standard GrantStandard Grant