PRESS-NEWS.org - Press Release Distribution
PRESS RELEASES DISTRIBUTION

AI threats in software development revealed in new study from The University of Texas at San Antonio

AI threats in software development revealed in new study from The University of Texas at San Antonio
2025-04-08
(Press-News.org) UTSA researchers recently completed one of the most comprehensive studies to date on the risks of using AI models to develop software. In a new paper, they demonstrate how a specific type of error could pose a serious threat to programmers that use AI to help write code.

Joe Spracklen, a UTSA doctoral student in computer science, led the study on how large language models (LLMs) frequently generate insecure code. His team’s paper has been accepted for publication at the USENIX Security Symposium 2025, a premier cybersecurity and privacy conference.

The multi-institutional collaboration featured three additional researchers from UTSA: doctoral student A.H.M. Nazmus Sakib, postdoctoral researcher Raveen Wijewickrama, and Associate Professor Dr. Murtuza Jadliwala, director of the SPriTELab (Security, Privacy, Trust, and Ethics in Computing Research Lab). Additional collaborators were Anindya Maita from the University of Oklahoma (a former UTSA postdoctoral researcher) and Bimal Viswanath from Virginia Tech.

Hallucinations in LLMs occur when the model produces content that is factually incorrect, nonsensical or completely unrelated to the input task. Most current research so far has focused mainly on hallucinations in classical natural language generation and prediction tasks such as machine translation, summarization and conversational AI.

The research team focused on the phenomenon of package hallucination, which occurs when an LLM generates or recommends the use of a third-party software library that does not actually exist.

What makes package hallucinations a fascinating area of research is how something so simple—a single, everyday command—can lead to serious security risks.

“It doesn’t take a convoluted set of circumstances or some obscure thing to happen,” Spracklen said. “It’s just typing in one command that most people who work in those programming languages type every day. That’s all it takes. It’s very direct and very simple.”

“It’s also ubiquitous,” he added. “You can do very little with your basic Python coding language. It would take you a long time to write the code yourself, so it is universal to rely on open-source software to extend the capabilities of your programming language to accomplish specific tasks.”

LLMs are becoming increasingly popular among developers, who use the AI models to assist in assembling programs. According to the study, up to 97% of software developers incorporate generative AI into their workflow, and 30% of code written today is AI-generated. Additionally, many popular programming languages, like PyPI for Python and npm for JavaScript, rely on the use of a centralized package repository. Because the repositories are often open source, bad actors can upload malicious code disguised as legitimate packages.

For years, attackers have employed various tricks to get users to install their malware. Package hallucinations are the latest tactic.

“So, let’s say I ask ChatGPT to help write some code for me and it writes it. Now, let’s say in the generated code it includes a link to some package, and I trust it and run the code, but the package does not exist, it’s some hallucinated package. An astute adversary/hacker could see this behavior (of the LLM) and realize that the LLM is telling people to use this non-existent package, this hallucinated package. The adversary can then just trivially create a new package with the same name as the hallucinated package (being recommended by the LLM) and inject  some bad code in it. Now, next time the LLM recommends the same package in the generated code and an unsuspecting user executes the code, this malicious package is now downloaded and executed on the user’s machine,” Jadliwala explained.

The UTSA researchers evaluated the occurrence of package hallucinations across different programming languages, settings and parameters, exploring the likelihood of erroneous package recommendations and identifying root causes.

Across 30 different tests carried out by the UTSA researchers, 440,445 of 2.23 million code samples they generated in Python and JavaScript using LLM models referenced hallucinated packages. Of the LLMs researchers tested, “GPT-series models were found four times less likely to generate hallucinated packages compared to open-source models, with a 5.2% hallucination rate compared to 21.7%,” the study stated. Python code was less susceptible to hallucinations than JavaScript, researchers found.

These attacks often involve naming a malicious package to mimic a legitimate one, a tactic known as a package confusion attack. In a package hallucination attack, an unsuspecting LLM user would be recommended the package in their generated code, and trusting the LLM, would download the adversary-1created malicious package, resulting in a compromise.

The insidious element of this vulnerability is that it exploits growing trust in LLMs. As they continue to get more proficient in coding tasks, users will be more likely to blindly trust their output and potentially fall victim to this attack.

“If you code a lot, it’s not hard to see how this happens. We talked to a lot of people and almost everyone says they’ve noticed a package hallucination happen to them while they’re coding, but they never considered how it could be used maliciously,” Spracklen explained. “You’re placing a lot of implicit trust on the package publisher that the code they’ve shared is legitimate and not malicious. But every time you download a package; you’re downloading potentially malicious code and giving it complete access to your machine.”

While cross-referencing generated packages with a master list may help mitigate hallucinations, UTSA researchers said the best solution is to address the foundation of LLMs during its own development. The team has disclosed its findings to model providers including OpenAI, Meta, DeepSeek and Mistral AI.

END

[Attachments] See images for this press release:
AI threats in software development revealed in new study from The University of Texas at San Antonio

ELSE PRESS RELEASES FROM THIS DATE:

Funding to support mental health at work is failing to deliver results

2025-04-08
EMBARGOED UNTIL TUESDAY 8TH APRIL AT 10:30 CEST  FUNDING TO SUPPORT MENTAL HEALTH AT WORK IS FAILING TO DELIVER RESULTS    Tuesday 8th April 2025 – 10:30 CEST - New research presented at the 2025 European Congress of Psychiatry reveals that in the last 25 years, although there has never been this level of funding, guidelines and regulation aimed towards mental health at work, employees are now reporting greater workplace demands and increasingly less control over work deadlines. Many also report that they fear their job will make them ill. These stressors have a stronger negative impact ...

The Lancet: Nearly 500,000 children could die from AIDS-related causes by 2030 without stable PEPFAR programmes, expert policy analysis estimates

2025-04-08
Peer-reviewed/ Review, Analysis and Opinion / People     The Lancet: Nearly 500,000 children could die from AIDS-related causes by 2030 without stable PEPFAR programmes, expert policy analysis estimates   Experts assessed the potential impacts on HIV/AIDS treatment and prevention efforts in sub-Saharan Africa if the US President’s Emergency Plan for AIDS Relief (PEPFAR) is suspended or only receives limited, short-term funding, estimating that 1 million additional children could become infected with HIV and nearly 500,000 children could ...

Eclipse echoes: groundbreaking study reveals surprising avian vocal patterns during solar eclipse

Eclipse echoes: groundbreaking study reveals surprising avian vocal patterns during solar eclipse
2025-04-08
A new study published today in Scientific Reports reveals how birds responded to the April 8, 2024, total solar eclipse across North America. The study finds bird vocalizations significantly declined only where more than 99% solar obscuration occurred. Researchers from Loggerhead Instruments, Inc. and the K. Lisa Yang Center for Conservation Bioacoustics at the Cornell Lab of Ornithology analyzed data from 344 community-based acoustic monitoring devices, called Haikuboxes, using a novel neural network approach. Unlike previous studies, ...

Mirvie announces results from largest molecular study in pregnancy and clinical validation of simple blood test to predict risk for preeclampsia months before symptoms

2025-04-08
South San Francisco, CA (April 8, 2025) - Today, Mirvie announced results of a breakthrough study published in Nature Communications, revealing new advances in the biological understanding of hypertensive disorders of pregnancy (HDP), including preeclampsia - a leading cause of maternal morbidity and mortality as well as preterm birth. Researchers used data from more than 9,000 pregnancies within the multi-center Mirvie-sponsored Miracle of Life prospective study to discover and validate RNA signatures capable of distinguishing between severe and mild hypertensive disorders of pregnancy, including preeclampsia, months before ...

Eating only during the daytime could protect people from heart risks of shift work

2025-04-08
A study led by researchers at Mass General Brigham suggests that, when it comes to cardiovascular health, food timing could be a bigger risk factor than sleep timing Numerous studies have shown that working the night shift is associated with serious health risks, including to the heart. However, a new study from Mass General Brigham suggests that eating only during the daytime could help people avoid the health risks associated with shift work. Results are published in Nature Communications. “Our prior research has shown that circadian misalignment – the mistiming of our behavioral cycle relative to our internal body clock – increases cardiovascular risk factors,” ...

Discovery of mitochondrial protein by researchers at Lewis Katz School of Medicine at Temple University opens path to therapeutic advances for heart and Alzheimer’s disease

2025-04-08
(Philadelphia, PA) – Calcium transport into and out of mitochondria – the powerhouses of cells – is central to cellular energy production and cell death. To maintain the balance of calcium within these powerhouses, cells rely on a protein known as the mitochondrial sodium-calcium exchanger, or NCLX. Now, in new research, scientists at the Lewis Katz School of Medicine at Temple University have discovered a novel regulator of NCLX activity, a protein called TMEM65, which helps move ...

Recognizing the bridge builders between neuroscience and psychiatry

Recognizing the bridge builders between neuroscience and psychiatry
2025-04-08
Mental health is in crisis worldwide. While the neurosciences are advancing rapidly, psychiatry still struggles to diagnose and effectively treat many disorders. The Synapsy Center for Neuroscience and Mental Health Research at the University of Geneva, Switzerland, is launching a new international prize to reward those who bring these two worlds closer together. A new research model is needed Depression, schizophrenia, anxiety or bipolar disorders: psychiatric illnesses affect hundreds of millions of people worldwide and are among the leading causes of disability, suffering and mortality. Yet clinical advances remain limited. Many diagnoses ...

Lactic acid bacteria can improve plant-based dairy alternatives

Lactic acid bacteria can improve plant-based dairy alternatives
2025-04-08
A new study maps how specific lactic acid bacteria can enhance both the flavour and nutritional quality of plant-based dairy alternatives. The findings may have wide-reaching perspectives for the further development of sustainable foods. Plant-based dairy alternatives – such as soy, oat, and almond drinks – are produced without animal ingredients for consumers seeking plant-based substitutes for milk and yoghurt. However, many of these products have the similar shortcomings: flavours that do not always appeal ...

Public housing smoking ban reduced heart attacks and strokes

2025-04-08
A new paper in Nicotine & Tobacco Research, published by Oxford University Press, finds that a 2018 U.S. ban on smoking in public housing led to a reduction in hospitalizations for cardiovascular problems. Tobacco use and exposure to secondhand smoke is a leading cause of preventable death in the United States. Some 480,000 Americans die every year due to tobacco. While the prevalence of adults exposed to secondhand smoke decreased dramatically between 1988 and 2014 (from 87.5% to 25.2%), about 58 million non-smokers in the U.S. experience tobacco smoke, primarily at home. Beginning in the early 2000s, ...

Positron emission tomography in psychiatry: Dr. Romina Mizrahi maps the molecular future

Positron emission tomography in psychiatry: Dr. Romina Mizrahi maps the molecular future
2025-04-08
MONTRÉAL, Québec, Canada, 8 April 2025 – In a powerful and deeply reflective Genomic Press Interview, published in Brain Medicine, Dr. Romina Mizrahi, Professor of Psychiatry at McGill University and Principal Investigator of the CaTS (Clinical and Translational Sciences) Lab at the Douglas Research Center, charts a new path forward in psychiatric research—one that begins at the molecular level. Harnessing the power of positron emission tomography (PET), Dr. Mizrahi’s work sheds light on the invisible workings of the human brain. Where traditional psychiatric diagnosis often relies on subjective symptom clusters, her approach integrates in-vivo imaging, ...

LAST 30 PRESS RELEASES:

Veterinary: UK dog owners prefer crossbreeds and imports to domestic pedigree breeds

Study links climate change to rising arsenic levels in paddy rice, increasing health risks

Study indicates that risky surgery after a stroke due to carotid artery stenosis is no longer necessary for majority of patients

Blood pressure: New research shows a changing climate may jeopardise global blood supply

Start of US hunting season linked to increased firearm incidents, including violent crimes and suicide

New system could help reduce unnecessary surgery to prevent strokes

Strongest hints yet of biological activity outside the solar system

Children face ‘lifelong psychological wounds’ from entrenched inequities made worse by pandemic, doctor warns

New research reveals socio-economic influences on how the body regulates eating

Unhealthy metabolic profile sharply increases risk of breast cancer returning and subsequent death from breast cancer among those who have survived the disease

Marine radar can accurately monitor vessel speeds to protect whales, study finds

National Center to Reframe Aging teams up with West End Home Foundation

How do age, sex, hormones and genetics affect dementia biomarkers in the blood?

NSF NOIRLab astronomer discovers oldest known spiral galaxy in the Universe

Iron Age purple dye "factory" in Israel was in operation for almost 500 years, using mollusks in large-scale specialized manufacturing process

Even vegans who get enough total protein may fall short for some essential amino acids

RoboBee comes in for a landing

“Ban-the-Box” policy did not effectively help job applicants with criminal records in one analysis

Sunscreen, clothes and caves may have helped Homo sapiens survive 41,000 years ago

"Big surprise": astronomers find planet in perpendicular orbit around pair of stars

Astronomers find rare twist in exoplanet’s twin star orbit

Crystal clues on Mars point to watery and possibly life-supporting past

Microbes in Brooklyn Superfund site teach lessons on fighting industrial pollution

Porous and powerful: How multidirectional grading enhances piezoelectric plate performance

Study finds dramatic boost in air quality from electrifying railways

Bite-sized chunks of chicken with the texture of whole meat can be grown in the lab

A compact, mid-infrared pulse generator

Sex-based differences in binge and heavy drinking among US adults

Using vibrations to see into Yellowstone's magma reservoir

From disorder to order: scientists rejuvenate aging batteries

[Press-News.org] AI threats in software development revealed in new study from The University of Texas at San Antonio