Cheap AI tools re-found most real security bugs — when handed the right filesمدل‌های ارزان‌قیمت هوش مصنوعی بیشتر باگ‌های امنیتی واقعی را بازیافتند — وقتی فایل‌های درست در اختیارشان گذاشته شد

Small, low-cost AI models re-found most of 95 real security flaws in widely used software, but only after several tries. Each of ten models scanned the faulty files four times: the best found 65 flaws, and all ten together found 84.مدل‌های کوچک و کم‌هزینه هوش مصنوعی توانستند بیشتر از 95 نقص امنیتی واقعی در نرم‌افزارهای پرکاربرد را دوباره پیدا کنند، اما فقط پس از چند بار تلاش. هر یک از 10 مدل، فایل‌های دارای ایراد را 4 بار اسکن کرد: بهترین مدل 65 نقص را پیدا کرد و هر 10 مدل روی‌هم‌رفته 84 نقص را یافتند.

ترجمهٔ ماشینی است؛ برای دقت به متن اصلی انگلیسی مراجعه کنید.

Why it matters

Code like OpenSSL and curl handles the secure connections inside billions of phones, websites and bank servers. Hunting for mistakes in that code is slow and costly, so cheap help would matter to almost everyone online. This test suggests that running small, inexpensive models a few times each finds more than running one strong model once. But the models were told which files held the bug, and the bugs were already public, so searching a whole project from scratch will be much harder.کدهایی مثل OpenSSL و curl، اتصال‌های امن میلیاردها گوشی، وب‌سایت و سرور بانکی را مدیریت می‌کنند. پیدا کردن خطا در چنین کدهایی کند و پرهزینه است، پس هر کمک ارزان‌قیمتی می‌تواند برای تقریباً همه کاربران اینترنت اهمیت داشته باشد. این آزمایش نشان می‌دهد اجرای چندبارهٔ مدل‌های کوچک و ارزان، نتیجه بهتری از اجرای یک‌بارهٔ یک مدل قوی می‌دهد. اما از آنجا که به مدل‌ها گفته شده بود کدام فایل‌ها باگ دارند و خود باگ‌ها هم از قبل عمومی بودند، جست‌وجوی کل یک پروژه از صفر بسیار سخت‌تر خواهد بود.

Who's behind it: P. Simecek, S. Fort and colleagues, AISLE, a company that sells AI-based vulnerability-detection systems. No outside funder named; the work was done in-house.

Summary by the Lemma AI · how we grade

Read the original paper (arxiv.org)