Google closes bug bounty program due to AI-generated spam
Google has decided to shut down its Open Source Software Vulnerability Rewards Program after facing an influx of invalid submissions, many of which were likely generated by AI. The program, which rewarded individuals for identifying vulnerabilities in open-source software, became overwhelmed by what Google calls "AI slop." These submissions did not meet the criteria for valid vulnerability reports, compromising the program's integrity.
The rise in AI-generated reports has made it difficult for Google to maintain the program's effectiveness. The company has not announced any plans to replace it, but remains committed to improving software security through other means.
The closure highlights the growing impact of AI on software development and cybersecurity. IBM notes that AI tools are increasingly used to generate code and test software, but their misuse in submitting invalid bug reports presents new challenges for tech companies.
The Software Engineering Institute at Carnegie Mellon University emphasizes the need to advance AI and software engineering to address these challenges. Their work focuses on enhancing cybersecurity and software quality.