PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

AI threats in software development revealed in new study from The University of Texas at San Antonio

AI threats in software development revealed in new study from The University of Texas at San Antonio
2025-04-08
(Press-News.org) UTSA researchers recently completed one of the most comprehensive studies to date on the risks of using AI models to develop software. In a new paper, they demonstrate how a specific type of error could pose a serious threat to programmers that use AI to help write code.

Joe Spracklen, a UTSA doctoral student in computer science, led the study on how large language models (LLMs) frequently generate insecure code. His team’s paper has been accepted for publication at the USENIX Security Symposium 2025, a premier cybersecurity and privacy conference.

The multi-institutional collaboration featured three additional researchers from UTSA: doctoral student A.H.M. Nazmus Sakib, postdoctoral researcher Raveen Wijewickrama, and Associate Professor Dr. Murtuza Jadliwala, director of the SPriTELab (Security, Privacy, Trust, and Ethics in Computing Research Lab). Additional collaborators were Anindya Maita from the University of Oklahoma (a former UTSA postdoctoral researcher) and Bimal Viswanath from Virginia Tech.

Hallucinations in LLMs occur when the model produces content that is factually incorrect, nonsensical or completely unrelated to the input task. Most current research so far has focused mainly on hallucinations in classical natural language generation and prediction tasks such as machine translation, summarization and conversational AI.

The research team focused on the phenomenon of package hallucination, which occurs when an LLM generates or recommends the use of a third-party software library that does not actually exist.

What makes package hallucinations a fascinating area of research is how something so simple—a single, everyday command—can lead to serious security risks.

“It doesn’t take a convoluted set of circumstances or some obscure thing to happen,” Spracklen said. “It’s just typing in one command that most people who work in those programming languages type every day. That’s all it takes. It’s very direct and very simple.”

“It’s also ubiquitous,” he added. “You can do very little with your basic Python coding language. It would take you a long time to write the code yourself, so it is universal to rely on open-source software to extend the capabilities of your programming language to accomplish specific tasks.”

LLMs are becoming increasingly popular among developers, who use the AI models to assist in assembling programs. According to the study, up to 97% of software developers incorporate generative AI into their workflow, and 30% of code written today is AI-generated. Additionally, many popular programming languages, like PyPI for Python and npm for JavaScript, rely on the use of a centralized package repository. Because the repositories are often open source, bad actors can upload malicious code disguised as legitimate packages.

For years, attackers have employed various tricks to get users to install their malware. Package hallucinations are the latest tactic.

“So, let’s say I ask ChatGPT to help write some code for me and it writes it. Now, let’s say in the generated code it includes a link to some package, and I trust it and run the code, but the package does not exist, it’s some hallucinated package. An astute adversary/hacker could see this behavior (of the LLM) and realize that the LLM is telling people to use this non-existent package, this hallucinated package. The adversary can then just trivially create a new package with the same name as the hallucinated package (being recommended by the LLM) and inject  some bad code in it. Now, next time the LLM recommends the same package in the generated code and an unsuspecting user executes the code, this malicious package is now downloaded and executed on the user’s machine,” Jadliwala explained.

The UTSA researchers evaluated the occurrence of package hallucinations across different programming languages, settings and parameters, exploring the likelihood of erroneous package recommendations and identifying root causes.

Across 30 different tests carried out by the UTSA researchers, 440,445 of 2.23 million code samples they generated in Python and JavaScript using LLM models referenced hallucinated packages. Of the LLMs researchers tested, “GPT-series models were found four times less likely to generate hallucinated packages compared to open-source models, with a 5.2% hallucination rate compared to 21.7%,” the study stated. Python code was less susceptible to hallucinations than JavaScript, researchers found.

These attacks often involve naming a malicious package to mimic a legitimate one, a tactic known as a package confusion attack. In a package hallucination attack, an unsuspecting LLM user would be recommended the package in their generated code, and trusting the LLM, would download the adversary-1created malicious package, resulting in a compromise.

The insidious element of this vulnerability is that it exploits growing trust in LLMs. As they continue to get more proficient in coding tasks, users will be more likely to blindly trust their output and potentially fall victim to this attack.

“If you code a lot, it’s not hard to see how this happens. We talked to a lot of people and almost everyone says they’ve noticed a package hallucination happen to them while they’re coding, but they never considered how it could be used maliciously,” Spracklen explained. “You’re placing a lot of implicit trust on the package publisher that the code they’ve shared is legitimate and not malicious. But every time you download a package; you’re downloading potentially malicious code and giving it complete access to your machine.”

While cross-referencing generated packages with a master list may help mitigate hallucinations, UTSA researchers said the best solution is to address the foundation of LLMs during its own development. The team has disclosed its findings to model providers including OpenAI, Meta, DeepSeek and Mistral AI.

END

[Attachments] See images for this press release:
AI threats in software development revealed in new study from The University of Texas at San Antonio

ELSE PRESS RELEASES FROM THIS DATE:

Funding to support mental health at work is failing to deliver results

2025-04-08
EMBARGOED UNTIL TUESDAY 8TH APRIL AT 10:30 CEST  FUNDING TO SUPPORT MENTAL HEALTH AT WORK IS FAILING TO DELIVER RESULTS    Tuesday 8th April 2025 – 10:30 CEST - New research presented at the 2025 European Congress of Psychiatry reveals that in the last 25 years, although there has never been this level of funding, guidelines and regulation aimed towards mental health at work, employees are now reporting greater workplace demands and increasingly less control over work deadlines. Many also report that they fear their job will make them ill. These stressors have a stronger negative impact ...

The Lancet: Nearly 500,000 children could die from AIDS-related causes by 2030 without stable PEPFAR programmes, expert policy analysis estimates

2025-04-08
Peer-reviewed/ Review, Analysis and Opinion / People     The Lancet: Nearly 500,000 children could die from AIDS-related causes by 2030 without stable PEPFAR programmes, expert policy analysis estimates   Experts assessed the potential impacts on HIV/AIDS treatment and prevention efforts in sub-Saharan Africa if the US President’s Emergency Plan for AIDS Relief (PEPFAR) is suspended or only receives limited, short-term funding, estimating that 1 million additional children could become infected with HIV and nearly 500,000 children could ...

Eclipse echoes: groundbreaking study reveals surprising avian vocal patterns during solar eclipse

Eclipse echoes: groundbreaking study reveals surprising avian vocal patterns during solar eclipse
2025-04-08
A new study published today in Scientific Reports reveals how birds responded to the April 8, 2024, total solar eclipse across North America. The study finds bird vocalizations significantly declined only where more than 99% solar obscuration occurred. Researchers from Loggerhead Instruments, Inc. and the K. Lisa Yang Center for Conservation Bioacoustics at the Cornell Lab of Ornithology analyzed data from 344 community-based acoustic monitoring devices, called Haikuboxes, using a novel neural network approach. Unlike previous studies, ...

Mirvie announces results from largest molecular study in pregnancy and clinical validation of simple blood test to predict risk for preeclampsia months before symptoms

2025-04-08
South San Francisco, CA (April 8, 2025) - Today, Mirvie announced results of a breakthrough study published in Nature Communications, revealing new advances in the biological understanding of hypertensive disorders of pregnancy (HDP), including preeclampsia - a leading cause of maternal morbidity and mortality as well as preterm birth. Researchers used data from more than 9,000 pregnancies within the multi-center Mirvie-sponsored Miracle of Life prospective study to discover and validate RNA signatures capable of distinguishing between severe and mild hypertensive disorders of pregnancy, including preeclampsia, months before ...

Eating only during the daytime could protect people from heart risks of shift work

2025-04-08
A study led by researchers at Mass General Brigham suggests that, when it comes to cardiovascular health, food timing could be a bigger risk factor than sleep timing Numerous studies have shown that working the night shift is associated with serious health risks, including to the heart. However, a new study from Mass General Brigham suggests that eating only during the daytime could help people avoid the health risks associated with shift work. Results are published in Nature Communications. “Our prior research has shown that circadian misalignment – the mistiming of our behavioral cycle relative to our internal body clock – increases cardiovascular risk factors,” ...

Discovery of mitochondrial protein by researchers at Lewis Katz School of Medicine at Temple University opens path to therapeutic advances for heart and Alzheimer’s disease

2025-04-08
(Philadelphia, PA) – Calcium transport into and out of mitochondria – the powerhouses of cells – is central to cellular energy production and cell death. To maintain the balance of calcium within these powerhouses, cells rely on a protein known as the mitochondrial sodium-calcium exchanger, or NCLX. Now, in new research, scientists at the Lewis Katz School of Medicine at Temple University have discovered a novel regulator of NCLX activity, a protein called TMEM65, which helps move ...

Recognizing the bridge builders between neuroscience and psychiatry

Recognizing the bridge builders between neuroscience and psychiatry
2025-04-08
Mental health is in crisis worldwide. While the neurosciences are advancing rapidly, psychiatry still struggles to diagnose and effectively treat many disorders. The Synapsy Center for Neuroscience and Mental Health Research at the University of Geneva, Switzerland, is launching a new international prize to reward those who bring these two worlds closer together. A new research model is needed Depression, schizophrenia, anxiety or bipolar disorders: psychiatric illnesses affect hundreds of millions of people worldwide and are among the leading causes of disability, suffering and mortality. Yet clinical advances remain limited. Many diagnoses ...

Lactic acid bacteria can improve plant-based dairy alternatives

Lactic acid bacteria can improve plant-based dairy alternatives
2025-04-08
A new study maps how specific lactic acid bacteria can enhance both the flavour and nutritional quality of plant-based dairy alternatives. The findings may have wide-reaching perspectives for the further development of sustainable foods. Plant-based dairy alternatives – such as soy, oat, and almond drinks – are produced without animal ingredients for consumers seeking plant-based substitutes for milk and yoghurt. However, many of these products have the similar shortcomings: flavours that do not always appeal ...

Public housing smoking ban reduced heart attacks and strokes

2025-04-08
A new paper in Nicotine & Tobacco Research, published by Oxford University Press, finds that a 2018 U.S. ban on smoking in public housing led to a reduction in hospitalizations for cardiovascular problems. Tobacco use and exposure to secondhand smoke is a leading cause of preventable death in the United States. Some 480,000 Americans die every year due to tobacco. While the prevalence of adults exposed to secondhand smoke decreased dramatically between 1988 and 2014 (from 87.5% to 25.2%), about 58 million non-smokers in the U.S. experience tobacco smoke, primarily at home. Beginning in the early 2000s, ...

Positron emission tomography in psychiatry: Dr. Romina Mizrahi maps the molecular future

Positron emission tomography in psychiatry: Dr. Romina Mizrahi maps the molecular future
2025-04-08
MONTRÉAL, Québec, Canada, 8 April 2025 – In a powerful and deeply reflective Genomic Press Interview, published in Brain Medicine, Dr. Romina Mizrahi, Professor of Psychiatry at McGill University and Principal Investigator of the CaTS (Clinical and Translational Sciences) Lab at the Douglas Research Center, charts a new path forward in psychiatric research—one that begins at the molecular level. Harnessing the power of positron emission tomography (PET), Dr. Mizrahi’s work sheds light on the invisible workings of the human brain. Where traditional psychiatric diagnosis often relies on subjective symptom clusters, her approach integrates in-vivo imaging, ...

LAST 30 PRESS RELEASES:

New discovery sheds light on evolutionary crossroads of vertebrates   

Aortic hemiarch reconstruction safely matches complex aortic arch reconstruction for acute dissection in older adults

Destination Earth digital twin to improve AI climate and weather predictions

Late-breaking study finds comparable long-term survival between two leading multi-arterial CABG strategies

Lymph node examination should be expanded to accurately assess cancer spread in patients with lung cancer

Study examines prediction of surgical risk in growing population of adults with congenital heart disease

Novel radiation therapy QA method: Monte Carlo simulation meets deep learning for fast, accurate epid transmission dose generation

A 100-fold leap into the unknown: a new search for muonium conversion into antimuonium

A new approach to chiral α-amino acid synthesis - photo-driven nitrogen heterocyclic carbene catalyzed highly enantioselective radical α-amino esterification

Physics-defying discovery sheds new light on how cells move

Institute for Data Science in Oncology announces new focus-area lead for advancing data science to reduce public cancer burden

Mapping the urban breath

Waste neem seeds become high-performance heat batteries for clean energy storage

Scientists map the “physical genome” of biochar to guide next generation carbon materials

Mobile ‘endoscopy on wheels’ brings lifesaving GI care to rural South Africa

Taming tumor chaos: Brown University Health researchers uncover key to improving glioblastoma treatment

Researchers enable microorganisms to build molecules with light

Laws to keep guns away from distressed individuals reduce suicides

Study shows how local business benefits from city services

RNA therapy may be a solution for infant hydrocephalus

Global Virus Network statement on Nipah virus outbreak

A new molecular atlas of tau enables precision diagnostics and drug targeting across neurodegenerative diseases

Trends in US live births by race and ethnicity, 2016-2024

Sex and all-cause mortality in the US, 1999 to 2019

Nasal vaccine combats bird flu infection in rodents

Sepsis study IDs simple ways to save lives in Africa

“Go Red. Shop with Heart.” to save women’s lives and support heart health this February

Korea University College of Medicine successfully concludes the 2025 Lee Jong-Wook Fellowship on Infectious Disease Specialists Program

Girls are happiest at school – for good reasons

Researchers from the University of Maryland School of Medicine discover genetic ancestry is a critical component of assessing head and neck cancerous tumors

[Press-News.org] AI threats in software development revealed in new study from The University of Texas at San Antonio