Github's Copilot AI model, a programming assistant that can generate code and make feature suggestions in real time, has been upgraded and is now more secure.

The new model - which will be released next week - the company says will offer better quality suggestions in less time, as well as improve the efficiency of the developers who use it by increasing the acceptance rate.
See also: Copilot: The new AI code generation tool from GitHub and OpenAI
Copilot will revolutionize programming with its revolutionary “Fill-In-the-Middle” system. This process uses a collection of pre-existing code snippets and allows the AI tool to fill in the gaps, giving it greater accuracy and allowing uniformity in the program’s coding structure.
Additionally, GitHub upgraded the Copilot client to reduce unwanted suggestions by 4.5% to improve the overall code acceptance rate.
“When GitHub Copilot for Individuals first launched in June 2022, more than 27% of developers’ code files on average were created by GitHub Copilot. Today, Copilot is behind the average of 46% of a developer’s code across all programming languages—and in Java, the number is as high as 61%,” said Senior Director of Product Management Shuyin Zhao.
Read also: GitHub: Simplifies the process of identifying vulnerabilities

Safer suggestions
A very important feature in the new upgrade is the introduction of a new system that filters security vulnerabilities and helps identify and block unsafe suggestions such as hardcoded credentials, path imports, and SQL imports.
"The new system leverages LLMs (large language models) to approximate the behavior of static analysis tools. Thanks to its advanced artificial intelligence models and powerful computing resources, GitHub Copilot is incredibly fast and capable of identifying potential vulnerabilities in incomplete code segments," Zhao said.
“Security is of utmost importance and with that in mind, unsafe coding standards are quickly identified and replaced with recommended alternatives.”

According to the software company, Copilot is able to generate secrets such as keys, credentials, and passwords based on training data. However, these generated strings are purely contrived and will be rejected by the updated filtering system.
Proposal: Sue Microsoft for piracy of open source software via GitHub Copilot
The appearance of these secrets in Copilot's code, however, has sparked a backlash from the developer community, with many accusing Microsoft of using a large set of publicly available data to train AI models without taking security into account, even incorporating datasets containing the same sensitive details by mistake.
This real-time blocking can also provide resistance against attacks with contaminated datasets that aim to secretly train AI assistants to make suggestions containing malicious payloads.
Copilot LLMs are currently being taught to distinguish between vulnerable and secure code patterns. As a result, it is expected that the capabilities of AI models in this area will steadily improve over time.
Information source: bleepingcomputer.com
