Skip to main navigation Skip to search Skip to main content

Pedalogical: Feedback Tool to Reduce Software Vulnerabilities in Non-Security Computer Science Courses

Research output: Chapter in Book/Report/Conference proceedingConference contribution

Abstract

This full research paper describes our proposed software vulnerability analysis and feedback pedagogical tool to help students understand and reduce the vulnerabilities introduced in their produced software. Despite a growing emphasis on secure coding in education, students in computing courses frequently introduce software vulnerabilities in their submissions. Prior work focuses on developing software vulnerability detection tools or curriculum changes that require secure coding expertise. We introduce Pedalogical, a web-based platform combining code security analysis with AI-generated feedback for improved secure coding. Feecback is produced using a static analysis tool supplemented with Large Language Model (LLM) responses to provide tailored feedback based on the student's code and the learning outcomes of the assignment. Pedalogical offers varying levels of feedback to provide students with actionable fixes or conceptual guidance depending on their proficiency. A proposed study is discussed across multiple CS courses at two universities. Students would be asked to submit their course assignments to both the learning management system in which they would be graded as normal for functionality, and also to the Pedalogical platform to be given feedback on the software vulnerabilities found in their code. The goal is to analyze whether AI-generated vulnerability feedback leads to improved secure coding practices in students and a reduction of vulnerabilities in assignment submissions. Data is planned to be collected from static analysis reports, LLM prompts and responses, student code submission diffs, student engagement metrics, and pre/post-study surveys. Our findings could have implications for computer science and cybersecurity curriculum design.

Original languageEnglish (US)
Title of host publication55th IEEE Annual Frontiers in Education Conference, FIE 2025 - Conference Proceedings
PublisherInstitute of Electrical and Electronics Engineers Inc.
ISBN (Electronic)9798331501051
DOIs
StatePublished - 2025
Event55th IEEE Annual Frontiers in Education Conference, FIE 2025 - Nashville, United States
Duration: Nov 2 2025Nov 5 2025

Publication series

NameProceedings - Frontiers in Education Conference, FIE
ISSN (Print)1539-4565

Conference

Conference55th IEEE Annual Frontiers in Education Conference, FIE 2025
Country/TerritoryUnited States
CityNashville
Period11/2/2511/5/25

Keywords

  • Computer science
  • Computing skills
  • Engineering curriculum
  • Undergraduate

ASJC Scopus subject areas

  • Software
  • Education
  • Computer Science Applications

Fingerprint

Dive into the research topics of 'Pedalogical: Feedback Tool to Reduce Software Vulnerabilities in Non-Security Computer Science Courses'. Together they form a unique fingerprint.

Cite this