read-only demo

Videos ZFxh7sqbUZo

Teaching AI to Find Real Vulnerabilities — Prof. David Brumley, Bugcrowd

index_state ready data_status ok

AI Engineer· published 2026-08-01· 0:27:17· en-US· indexed 2026-08-10 19:36

Open on YouTube

Scene timeline

  1. Shot 0, 0:00 to 0:03, 1 of 1 keyframes kept
  2. Shot 1, 0:03 to 0:05, 1 of 1 keyframes kept
  3. Shot 2, 0:05 to 0:12, 1 of 1 keyframes kept
  4. Shot 3, 0:12 to 0:24, 1 of 1 keyframes kept
  5. Shot 4, 0:24 to 0:50, 1 of 1 keyframes kept
  6. Shot 5, 0:50 to 1:15, 1 of 1 keyframes kept
  7. Shot 6, 1:15 to 1:41, 1 of 1 keyframes kept
  8. Shot 7, 1:41 to 2:06, 1 of 1 keyframes kept
  9. Shot 8, 2:06 to 2:32, 0 of 1 keyframes kept
  10. Shot 9, 2:32 to 3:17, 1 of 1 keyframes kept
  11. Shot 10, 3:17 to 3:48, 1 of 1 keyframes kept
  12. Shot 11, 3:48 to 4:19, 1 of 1 keyframes kept
  13. Shot 12, 4:19 to 4:49, 0 of 1 keyframes kept
  14. Shot 13, 4:49 to 5:20, 0 of 1 keyframes kept
  15. Shot 14, 5:20 to 5:46, 1 of 1 keyframes kept
  16. Shot 15, 5:46 to 6:12, 0 of 1 keyframes kept
  17. Shot 16, 6:12 to 6:38, 0 of 1 keyframes kept
  18. Shot 17, 6:38 to 6:53, 1 of 1 keyframes kept
  19. Shot 18, 6:53 to 7:20, 1 of 1 keyframes kept
  20. Shot 19, 7:20 to 7:47, 0 of 1 keyframes kept
  21. Shot 20, 7:47 to 8:14, 0 of 1 keyframes kept
  22. Shot 21, 8:14 to 8:40, 1 of 1 keyframes kept
  23. Shot 22, 8:40 to 9:07, 0 of 1 keyframes kept
  24. Shot 23, 9:07 to 9:34, 1 of 1 keyframes kept
  25. Shot 24, 9:34 to 10:01, 0 of 1 keyframes kept
  26. Shot 25, 10:01 to 10:04, 1 of 1 keyframes kept
  27. Shot 26, 10:04 to 10:27, 0 of 1 keyframes kept
  28. Shot 27, 10:27 to 10:58, 1 of 1 keyframes kept
  29. Shot 28, 10:58 to 11:29, 0 of 1 keyframes kept
  30. Shot 29, 11:29 to 11:43, 1 of 1 keyframes kept
  31. Shot 30, 11:43 to 11:50, 0 of 1 keyframes kept
  32. Shot 31, 11:50 to 12:39, 0 of 1 keyframes kept
  33. Shot 32, 12:39 to 13:10, 1 of 1 keyframes kept
  34. Shot 33, 13:10 to 13:40, 0 of 1 keyframes kept
  35. Shot 34, 13:40 to 13:55, 1 of 1 keyframes kept
  36. Shot 35, 13:55 to 14:23, 1 of 1 keyframes kept
  37. Shot 36, 14:23 to 14:51, 0 of 1 keyframes kept
  38. Shot 37, 14:51 to 15:18, 1 of 1 keyframes kept
  39. Shot 38, 15:18 to 15:51, 1 of 1 keyframes kept
  40. Shot 39, 15:51 to 16:23, 1 of 1 keyframes kept
  41. Shot 40, 16:23 to 16:55, 1 of 1 keyframes kept
  42. Shot 41, 16:55 to 17:24, 1 of 1 keyframes kept
  43. Shot 42, 17:24 to 17:45, 0 of 1 keyframes kept
  44. Shot 43, 17:45 to 18:22, 1 of 1 keyframes kept
  45. Shot 44, 18:22 to 19:03, 1 of 1 keyframes kept
  46. Shot 45, 19:03 to 19:36, 1 of 1 keyframes kept
  47. Shot 46, 19:36 to 20:09, 0 of 1 keyframes kept
  48. Shot 47, 20:09 to 20:40, 1 of 1 keyframes kept
  49. Shot 48, 20:40 to 21:11, 0 of 1 keyframes kept
  50. Shot 49, 21:11 to 21:42, 1 of 1 keyframes kept
  51. Shot 50, 21:42 to 22:13, 0 of 1 keyframes kept
  52. Shot 51, 22:13 to 22:46, 1 of 1 keyframes kept
  53. Shot 52, 22:46 to 23:12, 1 of 1 keyframes kept
  54. Shot 53, 23:12 to 23:38, 0 of 1 keyframes kept
  55. Shot 54, 23:38 to 24:04, 1 of 1 keyframes kept
  56. Shot 55, 24:04 to 24:29, 0 of 1 keyframes kept
  57. Shot 56, 24:29 to 24:56, 1 of 1 keyframes kept
  58. Shot 57, 24:56 to 25:23, 0 of 1 keyframes kept
  59. Shot 58, 25:23 to 25:28, 1 of 1 keyframes kept
  60. Shot 59, 25:28 to 26:00, 1 of 1 keyframes kept
  61. Shot 60, 26:00 to 26:32, 0 of 1 keyframes kept
  62. Shot 61, 26:32 to 27:00, 1 of 1 keyframes kept
  63. Shot 62, 27:00 to 27:15, 0 of 1 keyframes kept
  64. Shot 63, 27:15 to 27:16, 1 of 1 keyframes kept

64 shot(s).

keyframes kept every frame deduplicated

What was stored

cues
325
whisperx 325
chunks
48
from 325 cues
keyframes
40
kept of 64 captured
frames with text
39
626 lines read
chapters
11
from the source metadata
keyframe bytes
6.9 MB
word timings on 325 cues

Provenance

Each pipeline stage, its state and the model that produced it
stage state model started took
fetch done 2026-08-09 21:30 0s
stt done 2026-08-09 00:52 30s
chunk done 2026-08-09 00:52 0s
text_embed done 2026-08-10 19:36 1s
keyframe done 2026-08-09 00:53 3m 26s
ocr done 2026-08-09 00:56 17s
frame_embed done 2026-08-10 19:36 6s

Frames, and what the machine read

  • 0:02 #0 done2 line(s)

    shot 0·sharpness 453.4

    1. AlEngineer0.96
    2. World's Fair0.97
  • 0:03 #1 done2 line(s)

    shot 1·sharpness 665.7

    1. AlEngineer0.95
    2. World's Fair0.99
  • 0:10 #2 done24 line(s)

    shot 2·sharpness 2743.2

    1. LAB & PLATINUM SPONSORS0.98
    2. Amazon AGI Lab0.98
    3. ANTHROP\C1.00
    4. Google DeepMind1.00
    5. MINIMAX0.94
    6. OpenAI0.92
    7. Akamai1.00
    8. arize1.00
    9. aws1.00
    10. Braintrust bright data0.99
    11. B1.00
    12. Browserbase1.00
    13. docker1.00
    14. :neo4j0.93
    15. ORACLE1.00
    16. PayPal1.00
    17. qodo1.00
    18. reducto1.00
    19. Sonar1.00
    20. Makers of0.99
    21. togetherai1.00
    22. Unblocked1.00
    23. WorkOS1.00
    24. SonarQube1.00
  • 0:18 #3 done2 line(s)

    shot 3·sharpness 339.6

    1. AlEngineer1.00
    2. World's Fair0.99
  • 0:37 #4 done12 line(s)

    shot 4·sharpness 1524.7

    1. AlEngineer0.97
    2. World'sFair1.00
    3. AI ENGINEER· RL TRACK· 20260.96
    4. PRESENTED BY1.00
    5. The Oracle Is the Program0.98
    6. Microsoft1.00
    7. Design and pitfalls in cybersecurity RL environments.1.00
    8. dbrumley@bugcrowd:~$./teach-machines-to-hack1.00
    9. David Brumley1.00
    10. Chief Al & Science Officer, Bugcrowd · Professor, Carnegie Mellon0.98
    11. Engineering the future of Al1.00
    12. World'sFair1.00
  • 0:53 #5 done12 line(s)

    shot 5·sharpness 1505.5

    1. AlEngineer0.97
    2. World'sFair1.00
    3. AI ENGINEER· RL TRACK· 20260.96
    4. PRESENTED BY1.00
    5. The Oracle Is the Program0.98
    6. Microsoft1.00
    7. Design and pitfalls in cybersecurity RL environments.0.99
    8. dbrumley@bugcrowd:~$./teach-machines-to-hack1.00
    9. David Brumley1.00
    10. Chief Al & Science Officer, Bugcrowd · Professor, Carnegie Mellon0.98
    11. World'sFair1.00
    12. Engineering the future of Al1.00
  • 1:21 #6 done13 line(s)

    shot 6·sharpness 1438.9

    1. AlEngineer0.97
    2. World'sFair1.00
    3. AI ENGINEER· RL TRACK· 20260.97
    4. PRESENTED BY1.00
    5. The Oracle Is the Program0.99
    6. Microsoft1.00
    7. Design and pitfalls in cybersecurity RL environments.1.00
    8. dbrumley@bugcrowd:~$./teach-machines-to-hack1.00
    9. David Brumley1.00
    10. Chief Al & Science Officer, Bugcrowd · Professor, Carnegie Mellon0.99
    11. World'sFair1.00
    12. TRACK 9· JUNE 30,20260.96
    13. Data Quality0.97
  • 1:46 #7 done11 line(s)

    shot 7·sharpness 1303.8

    1. AlEngineer0.97
    2. World'sFair1.00
    3. AI ENGINEER· RL TRACK· 20260.97
    4. The Oracle Is the Program0.99
    5. Design and pitfalls in cybersecurity RL environments.0.99
    6. dbrumley@bugcrowd:~$./teach-machines-to-hack0.99
    7. David Brumley1.00
    8. Chief Al & Science Officer, Bugcrowd ·Professor, Carnegie Mellon0.98
    9. World'sFair0.99
    10. TRACK 9· JUNE 30,20260.96
    11. Data Quality0.97
  • 2:22 #8 skipped

    shot 8·duplicate of #7

  • 2:59 #9 done12 line(s)

    shot 9·sharpness 1398.6

    1. AlEngineer0.99
    2. World'sFair1.00
    3. I TRAIN HACKERS0.98
    4. Thisis1.00
    5. Richard Zhu1.00
    6. MASTEROFPUN0.93
    7. Twenty years old. At Pwn2Own he hacks1.00
    8. a Tesla — and drives it home.0.97
    9. 20180.99
    10. World's Fair0.96
    11. TRACK 9· JUNE 30, 20260.96
    12. Data Quality1.00
  • 3:32 #10 done11 line(s)

    shot 10·sharpness 1010.5

    1. AlEngineer0.97
    2. World'sFair1.00
    3. TWO AXES - KNOWLEDGE CATEGORY (→) AND HOW HIGH YOU CAN CLIMB (↑)0.98
    4. TOY1.00
    5. CTF/Synthetic1.00
    6. Average OSS0.99
    7. HARDENED1.00
    8. TARGET DIFFICULTY0.98
    9. World'sFair1.00
    10. TRACK 9·JUNE 30,20260.98
    11. Data Quality0.97
  • 4:06 #11 done19 line(s)

    shot 11·sharpness 1273.0

    1. AlEngineer0.99
    2. World's Fair0.99
    3. TWO AXES - KNOWLEDGE CATEGORY (→) AND HOW HIGH YOU CAN CLIMB (↑)0.99
    4. DILTY0.71
    5. EXPOIT0.67
    6. Arbitrary code1.00
    7. exec1.00
    8. read/write1.00
    9. memory1.00
    10. crash1.00
    11. trigger1.00
    12. TOY1.00
    13. CTF/Synthetic1.00
    14. Average OSS1.00
    15. HARDENED1.00
    16. TARGET DIFFICULTY0.99
    17. World'sFair1.00
    18. TRACK 9·JUNE 30,20260.98
    19. Data Quality1.00
  • 4:43 #12 skipped

    shot 12·duplicate of #11

  • 4:53 #13 skipped

    shot 13·duplicate of #11

  • 5:28 #14 done16 line(s)

    shot 14·sharpness 1585.5

    1. AlEngineer0.98
    2. World'sFair1.00
    3. - AGENDA0.92
    4. Axis One — Vuln Discovery0.98
    5. Design and challenges in oracle design.0.98
    6. PRESENTED BY1.00
    7. Microsoft1.00
    8. 21.00
    9. Axis Two — Vuln Exploitation0.99
    10. Security vs. bug finding1.00
    11. 31.00
    12. Summary1.00
    13. Want to do next1.00
    14. World's Fair0.95
    15. TRACK 9• JUNE 30, 20260.95
    16. Data Quality1.00
  • 5:56 #15 skipped

    shot 15·duplicate of #14

  • 6:20 #16 skipped

    shot 16·duplicate of #14

  • 6:50 #17 done7 line(s)

    shot 17·sharpness 898.3

    1. AlEngineer0.98
    2. World'sFair1.00
    3. LEARN WHAT YOU MEASURE0.99
    4. AXIS 1– Discovery0.95
    5. World'sFair1.00
    6. TRACK 9· JUNE 30, 20260.97
    7. Data Quality1.00
  • 7:07 #18 done12 line(s)

    shot 18·sharpness 1032.9

    1. AlEngineer0.96
    2. World'sFair1.00
    3. — 1.1 DEFINING THE PROBLEM - BOUNTYBENCH & CYBERGYM0.99
    4. int vuln(char *input) {0.98
    5. strcpy(buf, input);/*Bug0.99
    6. Grade Oracle1.00
    7. RL Environment0.97
    8. LLM1.00
    9. Orchestrator1.00
    10. World'sFair0.98
    11. TRACK 9·JUNE 30,20260.97
    12. Data Quality0.98
  • 7:41 #19 skipped

    shot 19·duplicate of #18

  • 7:50 #20 skipped

    shot 20·duplicate of #18

  • 8:37 #21 done18 line(s)

    shot 21·sharpness 1765.9

    1. AlEngineer0.97
    2. World'sFair1.00
    3. 1.1 DEFINING THE PROBLEM - BOUNTYBENCH & CYBERGYM0.99
    4. int vuln(char *input) {0.99
    5. EXPLOIT TASK PROMPT0.99
    6. *0.91
    7. strcpy(buf, input); /* Bug */0.99
    8. Dear LLM,0.99
    9. can you find and exploit1.00
    10. the vulnerability?0.99
    11. Grade Oracle1.00
    12. RL Environment1.00
    13. [The exploit proves the vuln is real]0.99
    14. LLM1.00
    15. Orchestrator1.00
    16. World's Fair0.97
    17. TRACK 9· JUNE 30, 20260.96
    18. Data Quality1.00
  • 8:49 #22 skipped

    shot 22·duplicate of #21

  • 9:28 #23 done15 line(s)

    shot 23·sharpness 1336.0

    1. AlEngineer0.97
    2. World'sFair1.00
    3. — 1.1 DEFINING THE PROBLEM - BOUNTYBENCH & CYBERGYM0.97
    4. int vuln(char *input) {0.98
    5. strcpy(buf, input);/*Bug0.99
    6. DETERMINISTIC1.00
    7. VERIFY POV1.00
    8. Grade Oracle1.00
    9. RL Environment0.97
    10. POV ("AAAAAA...")0.96
    11. LLM1.00
    12. Orchestrator1.00
    13. World'sFair1.00
    14. TRACK 9·JUNE 30,20260.98
    15. Data Quality0.98

Transcript

325 cues· 4,949 words· 27,263 chars

  1. 0:12 All right, everybody, we're going to talk about hacking.
  2. 0:15 I love hacking.
  3. 0:16 We have a very small audience here, so I assume everyone here loves hacking as well.
  4. 0:21 So I wanna talk about designing reinforcement learning environments for cybersecurity tasks.
  5. 0:25 And essentially we all wanna teach computers to hack because, well, we're pushing out programs faster than ever.
  6. 0:32 And so we need to be able to check them at machine speeds and scale.
  7. 0:35 And this has been my research project for well over two decades.
  8. 0:39 My name is David Brumley.
  9. 0:40 I am a full professor at Carnegie Mellon University where I work on AI and cybersecurity.
  10. 0:46 And I'm also a chief AI and science officer at Bug Crowd, where I work on data partnerships.
  11. 0:51 So before I talk about what we do and how we do it and why it's important to design cybersecurity tasks correctly for reinforcement learning environment, I want to start off with how humans learn because, I mean, I love teaching people to hack.
  12. 1:05 And I remember in particular a case where we run a hacking contest called Pico CTF.
  13. 1:10 Pico CTF has about a million high school kids every year play in this contest.
  14. 1:16 And so it's a really fun way for people to get an intro to cybersecurity.
  15. 1:19 So in 2016, a young person showed up on our scoreboard who was going by the hacker name Fluorescence.
  16. 1:26 And typically we know who is doing well in the contest.
  17. 1:29 It's kind of the typical suspects like a Palo Alto high school or
  18. 1:34 some of the Washington DDC high schools, we know who's gonna win the contest.
  19. 1:38 And so this kind of independence starts showing up scoring on our scoreboard and we had no idea who it was.
  20. 1:44 So we reach out, it's actually a 17 year old kid who found out about cybersecurity trying to get into it from math competitions.
  21. 1:52 He got bored with the math competitions and started doing them.
  22. 1:55 And very quickly he ended up actually scoring second in Pico CTF competing against all these high school kids.
  23. 2:00 And we asked actually,
  24. 2:02 How did you learn this?
  25. 2:03 And what he said really was germane to this task.
  26. 2:07 What I did is I looked at the cybersecurity tasks and then I started Googling
  27. 2:12 What is the information I needed?
  28. 2:14 I would read about it, I'd look at write-ups, and then I'd start emulating that.
  29. 2:17 And this kid actually ended up coming in second.
  30. 2:20 I recruited him to CMU and he followed this methodology of studying write-ups and practicing cybersecurity on a graduated scale, easy problems first and then slowly getting more difficult.
  31. 2:32 And he actually turned into what's called a Pwn2Own winner.
  32. 2:34 So Pwn2Own, if you've never heard of it, is one of the more elite cybersecurity competitions.
  33. 2:40 This kid, just two years after he first learned cybersecurity, enters, and if you read about it at the time, he was the first one to hack a Tesla.
  34. 2:49 So he walked out of this contest with $375,000 in cash in a brand new Tesla.
  35. 2:55 The reason I tell this story is actually the way we teach
  36. 2:58 AI frontier models to hack is the same way that we've been successful teaching high school students, such as Richard Zhu, to become Pwn2Own winners.
  37. 3:08 My other students include people like George Hotz, who did the first iPhone jailbreak, and current Pwn2Own winners like Sung Hyun Lee.
  38. 3:16 And so what I wanna talk about is how we teach reinforcement learning and do it the same way that we've been teaching hacking for a while.
  39. 3:24 And it really breaks down into two different accesses.
  40. 3:27 The first thing when designing these sorts of tasks for people is to look at target difficulty.
  41. 3:34 There's a spectrum of different challenges that you can look at from toy problems through CTF and synthetic problems all the way up to hardened targets.
  42. 3:43 The second access for teaching machines to hack is really looking at exploitation difficulty.
  43. 3:49 For example, when we look at a toy program, we may start looking at the sort of skills it needs to acquire to be able to hack that.
  44. 3:56 For example,
  45. 3:57 If you have a toy program and it has a bug, can the LLM figure out where the bug is?
  46. 4:03 Can it then prove that it knows where it is by triggering a crash or some other fault in the program?
  47. 4:09 But of course, hacking is not just crashing a program.
  48. 4:11 We want to take control of that program.
  49. 4:13 That's the beautiful thing about hacking.
  50. 4:15 It's bending computers to our will.

Chapters

  1. 0:00 Two decades of teaching hacking
  2. 1:54 From CTF scoreboards to CMU
  3. 3:34 A ladder of exploitation tasks
  4. 6:44 Why measuring hacking is hard
  5. 7:46 Flawed grading oracles
  6. 10:30 When a target has many bugs
  7. 13:22 Deterministic graders and AIXCC scoring
  8. 14:49 Precision and recall for vulnerabilities
  9. 17:35 Attacking V8 in Chrome
  10. 21:10 41 vulnerabilities and a real zero day
  11. 25:24 Don't benchmaxx security

Open at this second