יום שבת, 1 באוגוסט 2026 LIVE
AI־INFO

וידאו YT AI Engineer ·

לימוד AI לאיתור פגיעויות אמיתיות

Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd
▶ צפה כאן — בלי לצאת מהאתר
דייוויד ברומלי מלמד מודלים לאתר פגיעויות באבטחה. הוא משתמש בסביבות למידה חיזוקית ובמדדים מדויקים כדי לבדוק את יכולת המודל למצוא פגיעויות אמיתיות. הניסויים נערכו על מנוע JavaScript V8 של גוגל כרום.
תקציר מקורי באנגליתDavid Brumley has spent two decades turning people into hackers, from founding picoCTF to recruiting pwn2own winners at Carnegie Mellon, and his argument is that you teach a model to hack the same way: a ladder of tasks that climbs from triggering a crash to reading and writing arbitrary memory to a full working exploit. The catch is measurement. Hacking has no single answer, so the usual benchmark setup breaks down when a target has multiple vulnerabilities and a language model can always claim it found one, and grading oracles that just ask the model whether it succeeded are hopeless. So Brumley's team builds real reinforcement learning environments instead: reproducible, sandboxed, and scored by deterministic graders that check whether an exploit actually triggers the specific bug, borr
קרא במקור המקורי