Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd

AI Engineer27mAug 1, 2026
Watch Original (opens in new tab)
0:00 / 27:17
Chapters9

No clickbait detected — the title and thumbnail deliver what they promise.

AI Opinion

Brumley convincingly argues that mirroring human learning strategies—specifically the gradual progression through increasingly complex challenges—offers a valuable framework for training AI in cybersecurity vulnerability discovery. However, the analogy between a high school student’s hacking journey and AI development relies on an assumption of comparable cognitive processes that warrants further scrutiny; while illustrative, it doesn't fully account for the differences between human intuition and algorithmic processing. Listeners should also be mindful that the claim about LLMs enabling nation-state level hacking is speculative, dependent on currently unrealized capabilities and significant computational resources. Finally, understanding the nuances of "out-of-sandbox" exploits requires familiarity with exploit development techniques beyond what’s presented in this discussion.

Avatars are AI rewrites of the same facts — style changes, not substance.

Summary

David Brumley’s discussion focuses on training AI models for cybersecurity tasks, drawing parallels between successful human learning and effective AI development. He highlights the story of a high school student who rapidly improved his hacking skills by studying competition write-ups and gradually increasing challenge difficulty—a process he likens to climbing a "ladder" of progressively complex tasks. To structure AI training, Brumley emphasizes two key axes: target complexity and exploitation difficulty. A crucial element is designing reliable “oracles” to verify vulnerability discovery, moving beyond traditional benchmarks towards an “open world grading” system that accounts for multiple vulnerabilities in real-world code. The discussion also addresses the limitations of using Large Language Models (LLMs) as judges in this process, advocating for alternative evaluation methods. Ultimately, Brumley emphasizes the importance of pursuing high-value "out-of-sandbox" exploits, like those found within Chrome’s V8 interpreter, which represent a significant security risk and command substantial rewards.

Avatars are AI rewrites of the same facts — style changes, not substance.

Key Points

01:05

The Fluorescent Hacker and Gradual Skill Development

David Brumley recounts the story of a high school student, 'fluorescence,' who rapidly improved his cybersecurity skills by studying write-ups from competitions like picoCTF. He would research vulnerabilities, emulate solutions, and gradually increase the difficulty of challenges he tackled. This approach allowed him to quickly advance, eventually becoming a Pwn2Own winner and earning $375,000.

03:24

Two Key Axes for Teaching AI Hacking

Brumley outlines two crucial axes when designing cybersecurity tasks for reinforcement learning: target difficulty and exploitation difficulty. Target difficulty refers to the complexity of the program being hacked, ranging from toy problems to hardened targets. Exploitation difficulty focuses on the specific skills required, such as identifying bugs, triggering crashes, or achieving arbitrary code execution.

04:55

Hacking as a Ladder

The speaker emphasizes that hacking can be conceptualized as a ladder of progressively challenging tasks. This structure aligns well with reinforcement learning, providing a clear progression for AI models to learn and master various cybersecurity skills. The structured approach allows for measurable progress tracking and evaluation of the model's capabilities.

05:22

Importance of Vulnerability Discovery Oracles

David Brumley introduces the topic of vulnerability discovery, focusing on the design of reliable oracles. These oracles are crucial for determining whether an AI model has successfully identified a vulnerability within a program. He notes that existing cybersecurity benchmarks represent valuable first-generation efforts in this area.

15:15

Open World Grading and Multiplicity of Vulnerabilities

David Brumley introduces a method called 'open world grading' to evaluate AI vulnerability detection. This approach moves away from defining single, perfect problems and instead utilizes real-world open-source tasks that inherently contain multiple vulnerabilities—both known and unknown. The system then uses post-hoc analysis of proof-of-vulnerability submissions, scoring precision and recall multiplicatively to prevent the model from focusing solely on easily exploitable bugs.

16:04

Stack Backtraces for Bug Uniquification

To handle scenarios where an AI identifies multiple vulnerabilities simultaneously, Brumley explains that the system employs a method analogous to how industry professionals differentiate bugs. This involves analyzing stack backtraces – records of function calls leading up to a crash, similar to what Microsoft or Apple use when receiving program crash reports. By examining these traces, the system can uniquely identify and score distinct vulnerabilities.

16:25

The Limitations of LLMs as Judges

A crucial point is raised regarding the unsuitability of Large Language Models (LLMs) as judges in vulnerability detection. Brumley argues that relying on an LLM to evaluate its own training process introduces a significant risk, potentially leading to biased results and hindering progress. He emphasizes that the system avoids using LLMs for judging, instead opting for alternative methods.

19:45

Focusing on Out-of-Sandbox Exploits in V8

The discussion shifts to high-value targets and the importance of out-of-sandbox exploits within Chrome's JavaScript Wasm interpreter, V8. While crashing an in-sandbox object is expected behavior, achieving an out-of-sandbox exploit—which requires chaining multiple vulnerabilities—is what commands significant financial rewards due to its potential for widespread impact, including compromising nation-state systems.

Chapters

9 chapters · 8 key moments
KEYkey momentNot checkable hereUnverified

Claims & Fact Check

We need to be able to check programs at machine speeds and scale.

Not checkable here

He was the first one to hack a Tesla.

?Unverified

The way we teach AI frontier models to hack is the same way that we've been successful teaching high school students.

Not checkable here

Hacking is bending computers to our will.

Not checkable here

Models will find tune on the information that a bug exists.

Not checkable here

Crashing a program is different than hacking it.

Not checkable here

If you could give Chrome to an LLM and it could come up with a zero-day, you would essentially be able to hack nation-states at that point.

Not checkable here

Was this digest good?

More from AI Engineer

Digest any single YouTube video — free.

3 free digests — no card, no sign-up wall.

Or just swap the domain of any YouTube link → instant digest