Salem Dhif

dblp:383/3599 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2025
0009-0009-4157-8582ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%
Network and information security
1 paper
Systems and software security · 77% Usable security · 23%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › secure software development
secure code generation
0.912025
Prompting Techniques for Secure Code Generation: A Systematic Investigation · ACM Trans. Softw. Eng. Methodol. 2025
Program synthesis and code generation
code generation with language models
0.912025
Prompting Techniques for Secure Code Generation: A Systematic Investigation · ACM Trans. Softw. Eng. Methodol. 2025
Program synthesis and code generation › code generation with language models
secure code generation
0.912025
Prompting Techniques for Secure Code Generation: A Systematic Investigation · ACM Trans. Softw. Eng. Methodol. 2025
Usable security
developer-centered security
0.312025
Prompting Techniques for Secure Code Generation: A Systematic Investigation · ACM Trans. Softw. Eng. Methodol. 2025

Methods — techniques the papers use, named apart from their topics

systematic literature review · 1.7recursive criticism and improvement · 1.7prompting techniques · 1.7
YearPublicationVenuePosition
2025 Prompting Techniques for Secure Code Generation: A Systematic Investigation
abstract
Large Language Models (LLMs) are gaining momentum in software development with prompt-driven programming enabling developers to create code from Natural Language (NL) instructions. However, studies have questioned their ability to produce secure code and, thereby, the quality of prompt-generated software. Alongside, various prompting techniques that carefully tailor prompts have emerged to elicit optimal responses from LLMs. Still, the interplay between such prompting strategies and secure code generation remains under-explored and calls for further investigations. Objective : In this study, we investigate the impact of different prompting techniques on the security of code generated from NL instructions by LLMs. Method : First, we perform a systematic literature review to identify the existing prompting techniques that can be used for code generation tasks. A subset of these techniques are evaluated on GPT-3, GPT-3.5, and GPT-4 models for secure code generation. For this, we used an existing dataset consisting of 150 NL security-relevant code generation prompts. Results : Our work (i) classifies potential prompting techniques for code generation (ii) adapts and evaluates a subset of the identified techniques for secure code generation tasks, and (iii) observes a reduction in security weaknesses across the tested LLMs, especially after using an existing technique called Recursive Criticism and Improvement (RCI), contributing valuable insights to the ongoing discourse on LLM-generated code security.
Catherine Tony, Nicolás E. Díaz Ferreyra, Markus Mutas, Salem Dhif, Riccardo Scandariato
ACM Trans. Softw. Eng. Methodol.4