Frontiers in Emerging Engineering & Technologies

Open Access Peer Review International
Open Access

A Human-Centric Framework For Secure AI-Assisted Code Generation: Embedding Security Heuristics In The Software Synthesis Process

4 Department of Emerging Engineering & Technologies National Institute of Technology, Sri Lanka
4 Department of Emerging Engineering & Technologies Research and Innovation Center, Sri Lanka

Abstract

The rapid advancement of artificial intelligence (AI) has transformed software development by enabling automated code generation through large language models (LLMs). Contemporary AI coding assistants can generate functional software components, accelerate development cycles, and improve programmer productivity. However, growing evidence indicates that AI-generated code frequently contains security vulnerabilities, insecure coding patterns, and implementation flaws that may expose software systems to cyber threats. Existing studies demonstrate that AI-generated code often reproduces insecure practices learned from training data and may fail to adhere to established security standards. Consequently, organizations increasingly face challenges in balancing productivity gains from AI-assisted programming with software security requirements. This study proposes a human-centric framework for secure AI-assisted code generation that embeds security heuristics throughout the software synthesis process. The framework integrates human-in-the-loop validation, security-aware prompt engineering, vulnerability assessment, explainability mechanisms, and iterative feedback loops to improve code quality and security outcomes. A comprehensive review of literature on AI code generation, human-centered AI, software engineering, explainable machine learning, and cybersecurity is conducted to establish the theoretical foundation of the framework. The proposed model emphasizes collaborative intelligence between human developers and AI systems rather than complete automation. Findings indicate that integrating security heuristics with human oversight significantly enhances vulnerability detection, code reliability, and user trust while reducing the likelihood of insecure software deployment. The study contributes a structured conceptual model that supports secure AI adoption in software engineering and identifies future research directions for adaptive, explainable, and security-aware code synthesis systems.

 

How to Cite

Perera, D. K., & Fernando, M. D. (2026). A Human-Centric Framework For Secure AI-Assisted Code Generation: Embedding Security Heuristics In The Software Synthesis Process. Frontiers in Emerging Engineering & Technologies, 3(03), 01–09. Retrieved from https://irjernet.com/index.php/feet/article/view/442

References

E. Bagdasaryan, A. Veit, Y. Hua, D. Estrin, and V. Shmatikov, ”How to Backdoor Federated Learning,” in Artificial Intelligence and Statistics (AISTATS), 2020.
J. Brooke, ”SUS: A ‟quick and dirty‟ usability scale,” in Usability evaluation in industry, CRC Press, 1996, pp. 189-194.
M. Chen et al., ”Evaluating Large Language Models Trained on Code,” arXiv preprint arXiv:2107.03374, 2021.
M. D. Ernst, ”The future of software engineering,” in Proceedings of the 39th International Conference on Software Engineering: Future of Software Engineering Track, 2017, pp. 103-118.
D. Hendrycks, C. Burns, S. Kadavath, A. Arora, S. Basart, E. L. Dyer, D. Song, and J. Steinhardt, ”Measuring Coding Challenge Competence With APPS,” arXiv preprint arXiv:2105.09938, 2021.
Karpathy, J. Johnson, and L. Fei-Fei, ”Visualizing and Understanding Recurrent Networks,” arXiv preprint arXiv:1506.02078, 2015.
H. B. McMahan, E. Moore, D. Ramage, S. Hampson, and B. A. y Arcas, ”Communication-Efficient Learning of Deep Networks from Decentralized Data,” in Artificial Intelligence and Statistics (AISTATS), 2017.
MITRE 2023, CWE Top 25 Most Dangerous Software Weaknesses,” MITRE Corporation, 2023. [Online]. Available: https://cwe.mitre.org/top25/archive/2023/2023cwetop25.html
R. C. Monarch, Human-in-the-Loop Machine Learning: Active Learning and Annotation for Human-Centered AI. Manning Publications, 2021.
N. D. Nguyen et al., ”Federated Learning for Intrusion Detection: A Survey,” ACM Computing Surveys, vol. 54, no. 10s, pp. 1-36, 2022.
OWASP, OWASP Top Ten,” Open Web Application Security Project, 2021. [Online]. Available: https://owasp.org/www-project-top-ten/
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, ”Asleep at the Keyboard? Assessing the Security of GitHub Copilot‟s Code Contributions,” in IEEE Symposium on Security and Privacy (S&P), 2022.
S. Ross, M. C. Hughes, and F. Doshi-Velez, ”Right for the right reasons: Training differentiable models by constraining their explanations,” in Proceedings of the Twenty-Sixth International Joint Conference on Artificial Intelligence, 2017, pp. 2662-2670.
M. I. Siddiq and T. F. Bissyande, ”Security Smells in AI-Generated Code: An Empirical Study of GitHub Copilot,” in 2023 IEEE International Conference on Software Maintenance and Evolution (ICSME), 2023.
R. Sobania, D. Briesch, M. and C.J. Karl, ”An Analysis of the Security and Code Quality of AI-Coders,” in 2023 IEEE/ACM 45th International Conference on Software Engineering (ICSE), 2023.
Vaswani et al., ”Attention Is All You Need,” in Advances in Neural Information Processing Systems (NeurIPS), 2017.