Google has developed a new framework called “Project Naptime ,” which promises to leverage a large language model (LLM) in vulnerability search, with the goal of improving automated discovery methods .

“Naptime focuses on the interaction between an AI agent and a targeted codebase,” explain Google Project ZeroSergei Glazunov and Mark Brand. “The agent is equipped with a set of specialized tools designed to simulate the workflow of a human security researcher.”
Read also: The importance of encryption in cloud data
This initiative takes its name from its ability to allow people to “take regular naps,” while also contributing to vulnerability research and automated variant analysis. Essentially, this approach seeks to leverage advances in code and the general reasoning ability of LLMs (large language models), enabling them to mimic human behavior in terms of identifying and exploiting security vulnerabilities.
The approach includes several components: a code browsing tool that allows the AI to navigate the target code base, a Python for running scripts in a sandbox environment for fuzzing, a debugger tool for monitoring program behavior, and a Reporter tool for monitoring the progress of a task.
See also: Meta: Stops training AI with user data
Google said that Naptime is model-agnostic and backend-agnostic. It also outperforms in detecting buffer overflows and advanced memory flaws, according to the CYBERSECEVAL 2 benchmark. CYBERSECEVAL 2, released last April by researchers at Meta, is a comprehensive assessment suite for measuring the security of LLMs.
In tests conducted by Google to reproduce and exploit the flaws, the two categories of vulnerabilities achieved new peak scores of 1.00 and 0.76, compared to the previous 0.05 and 0.24 for OpenAI GPT-4 Turbo.

“Project Naptime enables a LLM (large language model) to conduct vulnerability research that closely approximates the iterative, hypothesis-driven method of human security experts,” the researchers said. “This architecture not only enhances the agent’s ability to detect and analyze vulnerabilities, but also ensures that the results are accurate.”
Read more: Google Meet adds support for over 50 languages in subtitles
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
