Google ends bug bounty program due to AI-generated submissions
Google has decided to end its Open Source Software Vulnerability Rewards Program due to a surge in invalid submissions, many of which were generated by AI. The program, which rewarded individuals for finding vulnerabilities in open-source software, has been overwhelmed by what Google refers to as "AI slop." These submissions did not meet the criteria for valid vulnerability reports, compromising the program's effectiveness.
The company cited the rise in AI-generated reports as a key factor in its decision. The influx of such submissions made it difficult to maintain the program's integrity, leading to its termination. This move underscores the broader impact of AI on software development and cybersecurity, as AI tools are increasingly used to generate code and test software.
IBM noted that AI's prevalence in software testing presents both opportunities and challenges. Meanwhile, the Software Engineering Institute at Carnegie Mellon University emphasizes the need to advance AI and software engineering to address these issues. Their work focuses on enhancing cybersecurity and software quality.
Despite closing this program, Google remains committed to improving software security. The company is exploring new methods to address vulnerabilities in its software products but has not announced plans to replace the program.