Google halts bug bounty program amid AI-generated spam
Google has decided to shutter its Open Source Software Vulnerability Rewards Program, citing an overwhelming surge of invalid submissions, many of which are believed to be AI-generated. The program, which rewarded individuals for identifying vulnerabilities in open-source software, has reportedly been flooded with what Google refers to as "AI slop." This influx of low-quality reports has compromised the program's effectiveness and integrity.
The tech giant explained that the rise in AI-driven submissions has made it increasingly difficult to distinguish valid vulnerability reports from spam. This issue highlights the broader challenges that artificial intelligence poses for software development and cybersecurity. As AI tools become more widespread, they are being used both to generate code and to test software, but their misuse in submitting invalid bug reports is creating new hurdles for companies.
Experts, including those at the Software Engineering Institute at Carnegie Mellon University, emphasize the need to advance AI and software engineering to tackle these emerging challenges. Their work focuses on improving cybersecurity and software quality. Despite the program's closure, Google remains dedicated to enhancing software security and is exploring alternative methods to address vulnerabilities in its products.