Google ends bug bounty program due to AI-generated spam
Google has decided to shut down its Open Source Software Vulnerability Rewards Program due to an influx of invalid submissions, many of which appear to be generated by artificial intelligence. The program, which rewarded individuals for identifying vulnerabilities in open-source software, has been overwhelmed by what Google describes as "AI slop." This surge in AI-generated submissions has made it difficult to maintain the program's integrity and effectiveness.
The rise of AI tools in software development and cybersecurity has led to increased misuse, as these tools are now being used to generate invalid bug reports. IBM noted that AI is becoming more prevalent in code generation and software testing, but this shift has presented new challenges for tech companies. The Software Engineering Institute at Carnegie Mellon University emphasizes the need to advance AI and software engineering to address these issues, focusing on enhancing cybersecurity and software quality.
Despite the closure of this program, Google remains committed to improving software security and continues to explore new methods to address vulnerabilities. However, the company has not announced any plans to replace the program at this time.