HomeUpdatesGoogle: Launches "Project Naptime" for AI-based vulnerability research

Google launches 'Project Naptime' for AI-powered vulnerability research

Google has developed a new framework called “Project Naptime ,” which promises to leverage a large language model (LLM) in vulnerability search, with the goal of improving automated discovery methods .

Google Project Naptime

“Naptime focuses on the interaction between an AI agent and a targeted codebase,” explain Google Project ZeroSergei Glazunov and Mark Brand. “The agent is equipped with a set of specialized tools designed to simulate the workflow of a human security researcher.”

Read also: The importance of encryption in cloud data

This initiative takes its name from its ability to allow people to “take regular naps,” while also contributing to vulnerability research and automated variant analysis. Essentially, this approach seeks to leverage advances in code and the general reasoning ability of LLMs (large language models), enabling them to mimic human behavior in terms of identifying and exploiting security vulnerabilities.

The approach includes several components: a code browsing tool that allows the AI ​​to navigate the target code base, a Python for running scripts in a sandbox environment for fuzzing, a debugger tool for monitoring program behavior, and a Reporter tool for monitoring the progress of a task.

See also: Meta: Stops training AI with user data

Google said that Naptime is model-agnostic and backend-agnostic. It also outperforms in detecting buffer overflows and advanced memory flaws, according to the CYBERSECEVAL 2 benchmark. CYBERSECEVAL 2, released last April by researchers at Meta, is a comprehensive assessment suite for measuring the security of LLMs.

In tests conducted by Google to reproduce and exploit the flaws, the two categories of vulnerabilities achieved new peak scores of 1.00 and 0.76, compared to the previous 0.05 and 0.24 for OpenAI GPT-4 Turbo.

Google Project Naptime

“Project Naptime enables a LLM (large language model) to conduct vulnerability research that closely approximates the iterative, hypothesis-driven method of human security experts,” the researchers said. “This architecture not only enhances the agent’s ability to detect and analyze vulnerabilities, but also ensures that the results are accurate.”

Read more: Google Meet adds support for over 50 languages ​​in subtitles

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS