about
Large Language Models and Simple, Stupid Bugs (arxiv.org)
2 points by agomez314 on Mar 31, 2023 | hide | past | pdf | discuss on HN

In plain words: They tested an AI code-completion tool trained on public GitHub code to see how often its suggestions contain tiny one-line mistakes called simple, stupid bugs. It copied known buggy lines up to twice as often as known correct ones, though it also avoided some mistakes.

Abstract

With the advent of powerful neural language models, AI-based systems to assist developers in coding tasks are becoming widely available; Copilot is one such system. Copilot uses Codex, a large language model (LLM), to complete code conditioned on a preceding "prompt". Codex, however, is trained on public GitHub repositories, viz., on code that may include bugs and vulnerabilities. Previous studies [1], [2] show Codex reproduces vulnerabilities seen in training. In this study, we examine how prone Codex is to generate an interesting bug category, single statement bugs, commonly referred to as simple, stupid bugs or SStuBs in the MSR community. We find that Codex and similar LLMs do help avoid some SStuBs, but do produce known, verbatim SStuBs as much as 2x as likely than known, verbatim correct code. We explore the consequences of the Codex generated SStuBs and propose avoidance strategies that suggest the possibility of reducing the production of known, verbatim SStubs, and increase the possibility of producing known, verbatim fixes.

Kevin Jesse, Toufique Ahmed, Premkumar T. Devanbu, Emily Morgan
arXiv:2303.11455 · cs.SE, cs.CL, cs.LG · submitted Mar 20, 2023
abstract · pdf · html · Accepted at International Conference on Mining Software Repositories (MSR-2023)

add comment on HN
Also discussed: Apr 2023 (1 point, 0 comments)