Cheap AI tools re-found most real security bugs — when handed the right filesمدلهای ارزانقیمت هوش مصنوعی بیشتر باگهای امنیتی واقعی را بازیافتند — وقتی فایلهای درست در اختیارشان گذاشته شد
Small, low-cost AI models re-found most of 95 real security flaws in widely used software, but only after several tries. Each of ten models scanned the faulty files four times: the best found 65 flaws, and all ten together found 84.مدلهای کوچک و کمهزینه هوش مصنوعی توانستند بیشتر از 95 نقص امنیتی واقعی در نرمافزارهای پرکاربرد را دوباره پیدا کنند، اما فقط پس از چند بار تلاش. هر یک از 10 مدل، فایلهای دارای ایراد را 4 بار اسکن کرد: بهترین مدل 65 نقص را پیدا کرد و هر 10 مدل رویهمرفته 84 نقص را یافتند.
ترجمهٔ ماشینی است؛ برای دقت به متن اصلی انگلیسی مراجعه کنید.
Why it matters
Code like OpenSSL and curl handles the secure connections inside billions of phones, websites and bank servers. Hunting for mistakes in that code is slow and costly, so cheap help would matter to almost everyone online. This test suggests that running small, inexpensive models a few times each finds more than running one strong model once. But the models were told which files held the bug, and the bugs were already public, so searching a whole project from scratch will be much harder.کدهایی مثل OpenSSL و curl، اتصالهای امن میلیاردها گوشی، وبسایت و سرور بانکی را مدیریت میکنند. پیدا کردن خطا در چنین کدهایی کند و پرهزینه است، پس هر کمک ارزانقیمتی میتواند برای تقریباً همه کاربران اینترنت اهمیت داشته باشد. این آزمایش نشان میدهد اجرای چندبارهٔ مدلهای کوچک و ارزان، نتیجه بهتری از اجرای یکبارهٔ یک مدل قوی میدهد. اما از آنجا که به مدلها گفته شده بود کدام فایلها باگ دارند و خود باگها هم از قبل عمومی بودند، جستوجوی کل یک پروژه از صفر بسیار سختتر خواهد بود.
Who's behind it: P. Simecek, S. Fort and colleagues, AISLE, a company that sells AI-based vulnerability-detection systems. No outside funder named; the work was done in-house.
Summary by the Lemma AI · how we grade