Shock horror — AI-generated security patches fall short of actually solving all the problems they were meant to fix



  • Researchers tested AI-generated patches on six CVEs with poor success rates
  • Many fixes failed, altered behavior, or introduced new vulnerabilities
  • Guidance improved outcomes, leading to FLAWED evaluation harness release

When using Generative Artificial Intelligence (GenAI) to fix vulnerabilities, security professionals are most of the time just robbing Peter to pay Paul, experts have warned.

Researchers from 1Passwords Off-by-1 Labs analyzed fixes proposed by two frontier models – ChatGPT 5.5 at “medium” effort, and Claude Opus 4.8 at “high” effort.

https://cdn.mos.cms.futurecdn.net/TaxPLZc75WiicpmgZNzWzL-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img