← Back to KHAO

The Information · AI Agent ·

MLSN #22: Turning Cyber Vulnerabilities Into Exploits

2 min read

Compiled by KHAO Editorial — aggregated from 1 source + 1 reference discovered via search. See llms.txt for citation guidance.

◌ Single Source

The evaluation flow for ExploitGym.

TLDR: Two new benchmarks show that frontier LLMs can use knowledge of cyber vulnerabilities to develop working exploits on a meaningful fraction of software targets.

Key facts

Summary

Recent AI systems have brought a wave of discoveries of novel critical software vulnerabilities across major operating systems, web browsers, and software tools. Both benchmarks involve giving an AI agent access to a computer running software known to be compromised, and prompting it to access different pieces of information and disrupt various core systems. ExploitGym focuses on several different pieces of software and a single piece of information to exfiltrate, whereas ExploitBench focuses on only one piece of software (V8, a major JavaScript engine) and measures a wide scale of malicious capabilities, including complete control of the target computer. ExploitGym, led by researchers from UC Berkeley, the Max Planck Institute for Security and Privacy, and UC Santa Barbara, comprises existing, known vulnerabilities from the Linux kernel, V8 (a major JavaScript engine), and other programs.

Read full article at AI Safety Newsletter →

#The Information #United Kingdom #AI Agent