Uppsats
Security Vulnerabilities in AI-Generated JWT Authentication Code for Spring Boot
Kandidat-uppsats
Linnéuniversitetet/Institutionen för datavetenskap och medieteknik (DM)
Publicerad: 2026
Språk: Engelska
Nyckelord
klicka för att sökaSammanfattning
The rapid adoption of AI-assisted programming tools has introduced new challenges forsoftware security, particularly when developers use large language models to generatesecurity-critical code. This study investigates the security vulnerabilities present in AI-generated JWT authentication code for Java Spring Boot Representational State TransferApplication Programming Interfaces (REST API), a domain that existing literature has notspecifically examined. Using a controlled experimental design, 60 code variants weregenerated by two AI models, Gemma 4 and Qwen 3 Coder Plus, and analysed using twocomplementary Static Application Security Testing (SAST) tools, SonarQube andSpotBugs. Every generated variant contained at least one security-relevant finding acrosseight distinct Common Weakness Enumeration (CWE) categories. The two modelsproduced meaningfully different vulnerability profiles, with neither clearly outperformingthe other from a security standpoint. The findings reinforce that AI-generated JSON WebToken (JWT) authentication code requires dedicated security review.
Information
- Författare
- Hmudda, Mezid, Long Nguyen, Hoang
- Lärosäte / institution
- Linnéuniversitetet/Institutionen för datavetenskap och medieteknik (DM)
- Publiceringsdatum
- 2026
- Uppsatstyp
- Kandidat-uppsats
- Språk
- Engelska
Utforska vidare
Liknande uppsatser
Uppsatser med liknande ämnen och nyckelord.
Kandidat-uppsats, KTH/Hälsoinformatik och logistik
Pececnik Almlöf, Elias, Karlsson, Johan
Publicerad: 2026
M1-uppsats, Mittuniversitetet/Institutionen för data- och elektroteknik (2023-)
Persdotter, Amanda
Publicerad: 2026