{"id":"W4406602186","doi":"10.1145/3610721","title":"Asleep at the Keyboard? Assessing the Security of GitHub Copilot’s Code Contributions","year":2025,"lang":"en","type":"article","venue":"Communications of the ACM","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":65,"is_retracted":false,"has_abstract":true,"ca_institutions":"University of Calgary","funders":"Office of Naval Research; New York University Abu Dhabi; National Science Foundation","keywords":"Computer science; Code (set theory); Computer security; Programming language","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.002758563,0.0008141149,0.0003082934,0.001816242,0.0005947571,0.001088028,0.0009756367,0.0008090374,0.001487471],"category_scores_gemma":[0.03336704,0.0004053382,0.0003800756,0.0008198848,0.001158635,0.001541478,0.001479325,0.001181121,0.001139074],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0008644658,"about_ca_system_score_gemma":0.0008321234,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.004082603,"about_ca_topic_score_gemma":0.007943091,"domain_scores_codex":[0.9976483,0.0006201306,0.0001140718,0.0003770385,0.001029415,0.0002109883],"domain_scores_gemma":[0.9791837,0.01286109,0.002402443,0.002176575,0.002455175,0.0009210424],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"observational","study_design_gemma":"observational","study_design_scores_codex":[0.003754807,0.001124639,0.5195254,0.001575921,0.0002566849,0.003751133,0.0120529,0.05434673,0.04491661,0.004475651,0.05691164,0.297308],"study_design_scores_gemma":[0.0002359219,0.003125038,0.3196829,0.0005965571,0.000211812,0.004167568,0.00643392,0.541176,0.07659677,0.004913246,0.04259726,0.0002630837],"study_design_candidate":"observational","study_design_consensus":"observational","genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.9870102,0.0001749852,0.004906883,0.0003442788,0.0000328031,0.0001253336,0.0007387173,0.003749409,0.00291723],"genre_scores_gemma":[0.9812494,0.0001247404,0.01352196,0.0002368922,0.00001355173,0.00009009954,0.002369603,0.001016384,0.001377388],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.004082603,"threshold_uncertainty_score":0.01458883,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.02508575404232899,"score_gpt":0.3632643177526665,"score_spread":0.3381785637103375,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}