In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset. Without the description, it could only exploit 7%. This provided a “margin of safety” for the industry because while AI could exploit known vulnerabilities, it could not discover them.
However, on April 7,
Researchers found GPT-4 exploits 87% of known vulnerabilities, highlighting slow patching processes. Industry reliance on AI for security must evolve. Reportedly, a study from the University of Illinois showed AI’s capabilities in exploiting known bugs, emphasizing the need for better vulnerability management systems. In 2024, researchers from the University of Illinois found that GPT-4, when provided with a common vulnerabilities and exposures (CVE) description, could autonomously exploit 87% of a curated 15-vulnerability one-day dataset.Technical Analysis
Key Points