Google ends bug bounty program due to AI-generated spam
Google has decided to shut down its Open Source Software Vulnerability Rewards Program due to an influx of invalid submissions, many of which were generated by artificial intelligence. The program, which aimed to reward individuals for identifying vulnerabilities in open-source software, has struggled to maintain its effectiveness as a result of what Google describes as "AI slop." This term refers to low-quality, AI-generated reports that do not meet the criteria for valid vulnerability reports.
The decision to close the program comes after a significant rise in submissions that failed to meet the necessary standards. Google stated that the increase in AI-generated submissions has made it difficult to uphold the program's integrity. While AI tools are becoming more common in software development and cybersecurity, their misuse in submitting invalid bug reports presents new challenges for tech companies.
The Software Engineering Institute at Carnegie Mellon University highlights the need to advance AI and software engineering to address these challenges. Their work focuses on improving cybersecurity and software quality. Despite the closure of this program, Google remains committed to enhancing software security and continues to explore new methods to address vulnerabilities in its software products. No plans to replace the program have been announced at this time.