Beyond AI Delegation: A Prompt Pattern Framework for Productive Struggle and Evaluative Judgement in Secure Coding Education
This paper presents a Design Science Research-based framework that adapts nine prompt engineering patterns to scaffold Productive Struggle and Evaluative Judgement in secure coding education, ensuring students remain actively engaged in reasoning rather than delegating cognitive tasks to generative AI.
Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer
Imagine you are teaching a student how to swim. In the past, you might have thrown them in the deep end with a life vest, forcing them to paddle and figure out how to stay afloat. That "struggle" is actually where the learning happens; their muscles get stronger, and they understand the water.
Now, imagine a magical robot that can instantly swim perfectly for them. If you just let the robot do the swimming, the student never learns. They get to the other side of the pool, but they can't swim a stroke on their own.
This is the problem the paper addresses regarding Generative AI (like ChatGPT) in education. Students are using AI to do the "swimming" (the thinking and problem-solving) for them, skipping the hard work that builds real understanding.
Here is the paper's solution, explained simply:
The Core Idea: Don't Ban the Robot, Change the Rules
Instead of banning AI (which is hard to enforce) or letting it do all the work, the authors propose a new way to talk to the AI. They call this Prompt Engineering, but think of it as "Giving the AI a Job Description that forces the student to think."
The authors created a "menu" of 9 specific ways to ask the AI questions. They call these Prompt Patterns. Just like a chef has different knives for chopping, slicing, and dicing, teachers can use different "prompt patterns" to make sure the student does the heavy lifting while the AI acts as a helpful assistant, not a replacement.
The Two Golden Rules
The paper says these 9 patterns are designed to protect two important things:
- Productive Struggle: The good kind of hard work where you get stuck, think hard, and then figure it out. The AI shouldn't give you the answer immediately; it should make you work for it.
- Evaluative Judgement: The ability to look at a piece of work (even if an AI made it) and say, "Is this actually good? Is this safe?"
The "Menu" of 9 Patterns (With Analogies)
The paper groups these 9 patterns into four categories. Here is how they work in plain English:
- The "Role-Player" (Persona): You tell the AI, "Act like a grumpy, skeptical code reviewer." Instead of just saying "Yes, that's good," the AI challenges the student's ideas.
- Analogy: It's like hiring a strict coach who won't let you pass a drill until you explain why you did it that way.
- The "Socratic Interviewer" (Flipped Interaction): This is a big one. Instead of the student asking the AI for answers, the AI asks the student questions.
- Analogy: Imagine a detective (the AI) asking the suspect (the student) questions one by one to solve a crime. The AI won't solve the crime for the student; it just keeps asking, "What about this clue?" until the student figures it out.
- The "Option Generator" (Alternative Approaches): You ask the AI to give you three different solutions, not just one.
- Analogy: Instead of the AI saying "Take Route A," it says "Here are Routes A, B, and C. Now, you tell me which one is best and why." This forces the student to compare and judge.
- The "Step-by-Step Tracker" (Cognitive Verifier): You ask the AI to show its work, step by step.
- Analogy: It's like asking a math teacher to write out every single step of the equation on the board, rather than just giving you the final number. If the teacher skips a step, the student can spot the error.
The Real-World Test: The "Secure Coding" Class
To prove this works, the authors tried it in a master's-level computer security class.
- The Problem: Students usually just ask AI, "Fix this security bug," and copy the answer.
- The Fix: They used the "Socratic Interviewer" pattern. The AI was programmed to ask the student questions about the code one by one. The student had to look at the code and answer. The AI would only move to the next question once the student showed they understood the current one.
- The Result: The student couldn't just copy-paste an answer. They had to actually find the bug themselves, with the AI acting as a guide, not a solver.
The Bottom Line
The paper concludes that AI is a powerful tool, but it's currently too easy to use as a "cheat code." By using these specific Prompt Patterns, teachers can turn the AI from a "homework solver" into a "thinking partner."
The goal isn't to stop students from using AI; it's to make sure that when they use it, they are still the ones doing the thinking, the struggling, and the judging. The AI becomes the gym equipment, not the personal trainer who lifts the weights for you.
Drowning in papers in your field?
Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.