Google closes bug bounty program overwhelmed by AI-generated submissions
Google has decided to shut down its Open Source Software Vulnerability Rewards Program due to an overwhelming influx of invalid submissions, many of which are believed to be generated by artificial intelligence. The program, which rewarded individuals for identifying vulnerabilities in open-source software, has been terminated because of what Google refers to as "AI slop."
The tech giant explained that the surge in submissions failing to meet the criteria for valid vulnerability reports made it difficult to maintain the program's integrity. The rise of AI-generated submissions has created new challenges for tech companies, as these tools are increasingly used to generate code and test software.
IBM has noted the growing prevalence of AI tools in software development and cybersecurity. However, the misuse of AI to submit invalid bug reports has raised concerns about the future of such programs. The Software Engineering Institute at Carnegie Mellon University is working to address these challenges by advancing AI and software engineering to enhance cybersecurity and software quality.
Despite the closure of this program, Google remains committed to improving software security and is exploring new methods to address vulnerabilities. The company has not announced any plans to replace the terminated program at this time.