AI RESEARCH

Broken by Default: A Formal Verification Study of Security Vulnerabilities in AI-Generated Code

arXiv CS.AI

ArXi:2604.05292v1 Announce Type: cross AI coding assistants are now used to generate production code in security-sensitive domains, yet the exploitability of their outputs remains unquantified. We address this gap with Broken by Default: a formal verification study of 3,500 code artifacts generated by seven frontier LLMs across 500 security-critical prompts (five CWE categories, 100 prompts each). Each artifact is subjected to the Z3 SMT solver via the COBALT analysis pipeline, producing mathematical satisfiability witnesses rather than.