YaoHui Guan

dblp:424/3610 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2025
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Software engineering, systems software and programming languages · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Systems and software security · 100%
Software engineering, system software, and programming languages
1 paper
Program synthesis and code generation · 100%

Topics — the 4 heaviest of 4, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Systems and software security › vulnerability discovery
common weakness enumeration
0.912025
Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration · IEEE Trans. Software Eng. 2025
Systems and software security
vulnerability discovery
0.912025
Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration · IEEE Trans. Software Eng. 2025
Program synthesis and code generation
code generation with language models
0.912025
Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration · IEEE Trans. Software Eng. 2025
Program synthesis and code generation › code generation with language models
secure code generation
0.912025
Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration · IEEE Trans. Software Eng. 2025

Methods — techniques the papers use, named apart from their topics

retrieval-augmented generation · 1.7multi-label classification · 1.7large language model · 1.7
YearPublicationVenuePosition
2025 Towards Secure Code Generation With LLMs: A Study on Common Weakness Enumeration
abstract
Automated code generation has revolutionized software development, enabling developers to accelerate project timelines and reduce manual coding errors significantly. As reliance on these technologies grows, the inherent weaknesses of generated code become increasingly apparent. Recent studies have shown that code produced by AI is not inherently safer or of higher quality than human-written code, often replicating existing vulnerabilities.To this end, we propose SECURECODER, which integrates Retrieval-Augmented Generation (RAG) with Common Weakness Enumeration (CWE). SECURECODER first utilizes the advanced reasoning capabilities of large language models (LLMs) to generate natural language descriptions of the code’s core business logic and functionality. Then, from a semantic perspective, it matches the requirements of the code generation task with the CWE descriptions through a multi-label classification process. Finally, based on the matched CWE, SECURECODER generates a list of security guidelines the code generation model must adhere to. Breaking down end-to-end code generation tasks into single-target tasks that LLMs excel at ensures that the generated code not only meets functional requirements but also adheres to best security practices, thereby enhancing the interpretability of the automated code generation process. After evaluating 2 programming languages and 7 LLMs on Coploit-generated code, SECURECODER has great generalization capability and could be applied to more programming languages and vulnerability types. SECURECODER could significantly decrease the security weakness in the AI-generated code and is able to mitigate more than 65% of vulnerabilities exposed to software developers. Compared to the baseline open-source LLMs, code vulnerabilities were reduced by at least 14% and the code business logic was not affected.
Yuqiang Sun 0001, Cheng Huang 0003, YaoHui Guan, Yutong Zeng, Yang Liu 0003
IEEE Trans. Software Eng.5