Uppsats

Compliance Issues in GenAI Based Code Generation for Automotive Software : A Safety and Security Perspective

Magister-uppsats

Blekinge Tekniska Högskola/Institutionen för programvaruteknik

Publicerad: 2026

Språk: Engelska

Sammanfattning

Background. Generative AI (GenAI) tools are increasingly capable of generating code from natural language prompts, creating a compelling opportunity for their use in safety and security-critical automotive software development. However, there is a lack of systematic study examining the compliance issues that arise when using GenAI tools for code generation under automotive standards such as ISO 26262 and ISO/SAE 21434. Objectives. This study examines and categorises the compliance issues that arise when GenAI tools generate AUTOSAR module code, and measures the frequency, severity, and correction effort associated with those issues, with specific reference to ISO 26262 and ISO/SAE 21434. Methods. Following a quasi-experimental design, four GenAI tools, Google AI Studio,Claude.ai, Mistral Le Chat, and OpenAI Codex, were used to generate C++ implementations of an AUTOSAR Adaptive Platform functional cluster from a formal software specification using a role-based zero-shot prompting strategy. Generated artifacts were evaluated through a compliance pipeline comprising compilation testing, static code analysis against MISRA C++, CERT C++ and CWE and manual requirements traceability analysis. Results. All four tools failed initial compilation and required iterative self-correction, with correction effort varying considerably across tools; one tool required manual intervention to reach a successful build. Static code analysis revealed violations across all tools and all evaluated categories from the outset, with exception handling and dynamic memory management as the most frequently occurring non-compliance categories,and violations persisted across all tools after iterative correction. No critical severity cybersecurity weaknesses were identified in any codebase. None of the tools achieved full requirements implementation coverage, and traceability coverage and tag accuracy varied considerably across tools. Conclusions. This exploratory study contributes a four dimension compliance assessment framework, compilation correctness, MISRA C++ static code analysis,CERT C++ and CWE static code analysis, and requirements traceability. It is applied to a single AUTOSAR Adaptive Platform module generated by four GenAItools in one experimental run per tool. All four tools produced compilation errors and static code analysis violations across multiple categories, with static code analysis violations persisting even after iterative correction. None of the tools achieved full requirements implementation coverage, and traceability accuracy varied substantially, establishing that both require explicit and independent verification in GenAI assisted development workflow.. These findings are bounded to the conditions of this study and require validation across further AUTOSAR modules and GenAI tools. They are presented as an initial characterisation of the compliance landscape.

Information

Författare
Vattian, Masood
Lärosäte / institution
Blekinge Tekniska Högskola/Institutionen för programvaruteknik
Publiceringsdatum
2026
Uppsatstyp
Magister-uppsats
Språk
Engelska

Utforska vidare

Liknande uppsatser

Uppsatser med liknande ämnen och nyckelord.