paper-with-me

홈 › Papers

OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security

2026-03-09 · Andrew Chin, Dongkwan Kim, Yu-Fu Fu, Fabian Fleischer, Youngjoon Kim, HyungSeok Han, Cen Zhang, Brian Junekyu Lee, Hanqing Zhao, Taesoo Kim arxiv

DARPA's AI Cyber Challenge (AIxCC) showed that cyber reasoning systems (CRSs) can go beyond vulnerability discovery to autonomously confirm and patch bugs: seven teams built such systems and open-sourced them after the competition. Yet all seven open-sourced CRSs remain largely unusable outside their original teams, each bound to the competition cloud infrastructure that no longer exists. We present OSS-CRS, an open, locally deployable framework for running and combining CRS techniques against real-world open-source projects, with budget-aware resource management. We ported the first-place system (Atlantis) and discovered 10 previously unknown bugs (three of high severity) across 8 OSS-Fuzz projects. OSS-CRS is publicly available.

📄 PDF Abstract BibTeX arXiv:2603.08566

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

SoK: DARPA's AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned

2026-02-07 · Cen Zhang, Younggi Park, Fabian Fleischer, Yu-Fu Fu 외 arxiv

DARPA's AI Cyber Challenge (AIxCC, 2023--2025) is the largest competition to date for building fully autonomous cyber reasoning systems (CRSs) that leverage recent advances in AI -- particularly large language models (LL…

ATLANTIS: AI-driven Threat Localization, Analysis, and Triage Intelligence System

2025-09-18 · Taesoo Kim, HyungSeok Han, Soyeon Park, Dae R. Jeong 외 arxiv

We present ATLANTIS, the cyber reasoning system developed by Team Atlanta that won 1st place in the Final Competition of DARPA's AI Cyber Challenge (AIxCC) at DEF CON 33 (August 2025). AIxCC (2023-2025) challenged teams …

Program Repair

AI Cyber Risk Benchmark: Automated Exploitation Capabilities

2024-10-29 · Dan Ristea, Vasilios Mavroudis, Chris Hicks

We introduce a new benchmark for assessing AI models' capabilities and risks in automated software exploitation, focusing on their ability to detect and exploit vulnerabilities in real-world software systems. Using DARPA…

BenchmarkingVulnerability Detection

Conversational Swarm Intelligence, a Pilot Study

2023-08-31 · Louis Rosenberg, Gregg Willcox, Hans Schumann, Miles Bader 외

Conversational Swarm Intelligence (CSI) is a new method for enabling large human groups to hold real-time networked conversations using a technique modeled on the dynamics of biological swarms. Through the novel use of c…

CyPhERS: A Cyber-Physical Event Reasoning System providing real-time situational awareness for attack and fault response

2023-05-26 · Nils Müller, Kaibin Bao, Jörg Matthes, Kai Heussen

Cyber-physical systems (CPSs) constitute the backbone of critical infrastructures such as power grids or water distribution networks. Operating failures in these systems can cause serious risks for society. To avoid or m…