Study Finds Iterative AI Code Generation Accumulates Security Vulnerabilities Over Multiple Iterations
A new study presented at IEEE-ISTAS 2025 demonstrates that iterative prompting of large language models for code generation causes progressive degradation of security properties.
Researchers began with 10 secure, vulnerability-free code samples written in C and Java. They then applied four distinct prompting strategies—adding features, optimizing performance, explicitly improving security, and using vague “make it better” requests—across 10 successive iterations, producing 400 code variants that were examined both manually and with automated scanners.
Key Findings on Vulnerability Accumulation
The number of vulnerabilities increased nonlinearly with each iteration. Prompts focused on adding functionality generated the highest total (158 vulnerabilities), while security-oriented prompts produced the lowest count (38). Nevertheless, even security-focused requests often replaced obvious flaws with more subtle ones.
A statistically significant positive correlation (r = 0.64) was observed between code complexity growth and vulnerability count. For every 10 % increase in complexity, researchers recorded an average 14.3 % rise in vulnerabilities.
Concrete Examples of Degradation
- Memory-management functions evolved from safe allocation routines into complex pointer arithmetic containing buffer-overflow and use-after-free risks by iteration 10.
- Authentication token checks acquired timing side-channels, parsing vulnerabilities, and flawed multi-factor recovery logic.
- Database access routines lost parameterization, introduced dynamic string concatenation, and later added transaction support that created race conditions.
Although 27 % of early security-oriented iterations (iterations 1–3) produced genuine improvements such as added input validation and NULL checks, these gains were typically offset by new hidden vulnerabilities in later rounds.
Recommendations and Limitations
The authors conclude that human oversight after every iteration—or at minimum after no more than three iterations—is essential. They also advise increased reliance on static application security testing (SAST) tools whenever code volume grows substantially.
The study tested only GPT-4o and did not allow human corrections during the iterative process, leaving open questions about whether newer models exhibit the same pattern at later iteration counts.
Related articles
Agent-Ops 0.4.0 Released: Methodology for Secure Human-AI Collaboration in IT Operations
Sergey Zhitinsky, founder of Git in Sky, has published the public normative candidate for Agent-Ops 0.4.0, an open industry methodology governing how engineers and AI agents jointly handle IT infrastructure tasks. The framework keeps humans firmly in the decision-making loop while using deterministic programs for data collection and approved changes. It addresses risks such as prompt injection through processed data, unverified model outputs, and unclear accountability when AI recommendations lead to incidents. The methodology divides work across eight explicit steps and three separate planes: data, governance, and independent verification performed by a Guardian role. Two additional companies have joined as maintainers following agreements at the IT Elements 2026 conference, turning the project into a multi-organization effort. Contributors are invited to help refine contracts, schemas, and operational scenarios through GitHub and GitVerse.
ProxyKey MCP: Securing API Access for AI Agents Without Exposing Credentials
ProxyKey has released an MCP server that allows AI coding agents such as Claude Code and Cursor to manage API credentials without ever reading the actual secret values. The solution addresses the risk that any key visible to an agent becomes compromised through logging, tracing, or prompt injection. Real provider keys are stored encrypted with AES-256-GCM and never returned by any API endpoint after initial entry. Agents instead receive limited virtual passes that support IP binding, rate limits, TTL, and detailed request logging. A pending-secret workflow lets agents prepare services before the real token exists, with the human entering the secret only through a web panel. The approach deliberately restricts the MCP tool contract so no operation can read or return secret values.
Shadow AI in CI/CD: Why AI Agents Must Be Modeled as Security Threats
A new analysis from the CNCF highlights the growing risks of Shadow AI within continuous integration and continuous deployment pipelines. The report argues that AI agents should be treated as potential threats rather than simple productivity tools. Starting from a developer's laptop and extending to Kubernetes clusters, these agents can introduce unauthorized access paths and data exposure risks. Security teams are urged to incorporate AI agent behavior into formal threat modeling exercises. The discussion emphasizes the need for visibility and control over autonomous AI components operating in production environments.
Detecting Lateral Movement with Neural Networks Trained Solely on Synthetic Data
A researcher generated entire corporate network histories using a 135-line configuration file to create synthetic authentication logs containing lateral movement attacks. Neural networks trained exclusively on these artificial datasets were then evaluated against 1.65 billion real authentication events from Los Alamos National Laboratory, including 749 red team events across 301 compromised machines. The best ensemble of six models flagged 3.6 million hourly machine windows and placed 16 genuine attacks among the top 23 highest-scoring entries, producing only seven false positives. In comparison, a simple threshold counter required 161,000 false alarms to reach the same detection level. The approach also demonstrated an iterative feedback loop where detector errors directly informed refinements to the synthetic world generator. The work shows that synthetic data can reach AUC performance comparable to models trained on real labeled attacks while providing full control over the underlying attack definitions.