infernosec's profile picture. Principal Engineer, AI Security at Google

Abhishek Arya

@infernosec

Principal Engineer, AI Security at Google

Abhishek Arya reposted

🚨 Our amazing #FUZZING'24 keynotes are online! "Reasons for the Unreasonable Success of Fuzzing" by Thomas Dullien (@halvarflake) youtu.be/Jd1hItbf52k "Is 'AI' useful for fuzzing?" by Brendan Dolan-Gavitt (@moyix) youtu.be/4BPJXmrdmls //@mboehme_, @lszekeres


Sharing slides and video for my keynote at OSS EU'24: "Securing the software commons: Standards, Automation, and AI for a Resilient Open Source Future" Slides: drive.google.com/file/d/186iq3Y… Video: youtube.com/watch?v=NwI2Mk…

infernosec's tweet card. Keynote: Securing the Software Commons: Standards, Automation, and AI...

youtube.com

YouTube

Keynote: Securing the Software Commons: Standards, Automation, and AI...


Abhishek Arya reposted

Live now at #OSSummit: Securing the Software Commons: Standards, Automation, and AI for a Resilient Open Source Future - Abhishek Arya, Principal Engineer, Google Open Source and Supply Chain Security, Google Keynote Livestream: bit.ly/47vTfO0


Abhishek Arya reposted

🔑 Abhishek Arya from Google delivers a keynote on "Securing the Software Commons: Standards, Automation, & AI for a Resilient Open Source Future." He highlights frameworks like SLSA, OpenSSF Scorecard, and more for building a safe and secure software supply chain. #OSSSummit

openssf's tweet image. 🔑 Abhishek Arya from Google delivers a keynote on "Securing the Software Commons: Standards, Automation, & AI for a Resilient Open Source Future." He highlights frameworks like SLSA, OpenSSF Scorecard, and more for building a safe and secure software supply chain. #OSSSummit

Abhishek Arya reposted

Join Abhishek Arya @infernosec at Open Source Summit EU as he discusses how Standards, Automation and AI can transform OSS security, scaling our defenses to meet growing threats. #OSSummit Listen Sept. 16 → goo.gle/47ouWBb

GoogleOSS's tweet image. Join Abhishek Arya @infernosec at Open Source Summit EU as he discusses how Standards, Automation and AI can transform OSS security, scaling our defenses to meet growing threats. #OSSummit 

Listen Sept. 16 → goo.gle/47ouWBb

Abhishek Arya reposted

This week we've added another 8 trophies to OSS-Fuzz-Gen (for a total of 14)! These are vulnerabilities found by LLM-generated harnesses. The interesting bit here is many of these are in well-fuzzed projects with thousands of hours of fuzzing already. github.com/google/oss-fuz…


AI on Java fuzzing!

Second OSS-Fuzz blog post on fuzz harness generation for Java! blog.oss-fuzz.com/posts/introduc… We've been quiet for a while but have a few interesting posts coming in the pipeline about our research.



Abhishek Arya reposted

As we look to the future of open source, we're investing in improving security posture of open source projects and ecosystems. 💡 Learn more about our efforts to secure open source supply chains ⬇️ goo.gle/3X1QZKv


The @DARPA's AI Cyber Challenge is in full swing with its Semifinal Competition. Learn how competitors can take advantage of @Google resources for the challenge and what we're doing at the AIxCC event at @defcon 32 in Las Vegas next week: blog.google/technology/saf…


Abhishek Arya reposted

Are YOU ready?! @infernosec of @Google is taking the stage @ #OSSummit Europe! Dive into the schedule, showcasing a dynamic lineup at the forefront of all things #OpenSource: hubs.la/Q02JkQBm0. Register & join us 16-18 September in Vienna, Austria! hubs.la/Q02JkjC70

linuxfoundation's tweet image. Are YOU ready?! @infernosec of @Google is taking the stage @ #OSSummit Europe! Dive into the schedule, showcasing a dynamic lineup at the forefront of all things #OpenSource: hubs.la/Q02JkQBm0. Register & join us 16-18 September in Vienna, Austria! hubs.la/Q02JkjC70

Abhishek Arya reposted

The Coalition for Secure AI (#CoSAI) officially launched today at the Aspen Security Forum! Hosted by OASIS, CoSAI will provide the guidance and tools needed to create AI systems that are Secure-by-Design. oasis-open.org/2024/07/18/int… #CoSAI #AI #AIsecurity #OpenSource #OASIS


Excited to see the incubation of "Software Supply Chain Security for AI systems" workstream in CoSAI. This workstream will aim to improve AI security by providing guidance on evaluating provenance, managing third-party model risks, and assessing full AI application provenance by…


Abhishek Arya reposted

🚨💰 Google VRP Reward Update 💰🚨 Good news, we are significantly increasing the reward amounts offered by the Google VRP! Look out for up to 5x higher payouts and a maximum reward of $151,515! Details here: bughunters.google.com/blog/540051395…


The deadline for @DARPA #AIxCC is just a week away. I am beyond excited on what participants will accomplish to push the state of the art in vuln finding and fixing using #Gemini! With #Gemini 1.5 Pro and 1M context window, we see early promising results in vulnerability analysis…


Abhishek Arya reposted

🚀 @chainguard_dev is now publishing its security advisory feed in the Open Source Vulnerabilities (OSV) format. chainguard.dev/unchained/chai…


The @DARPA #AIxCC will help design new #AI systems to secure major open source projects that our critical infrastructure relies upon. Learn how @Google's OSS-Fuzz can show opportunities where AI can help find and patch vulnerabilities for the challenge: security.googleblog.com/2024/06/hackin…


Abhishek Arya reposted

CodeRover++, new version of AutoCodeRover, is here! A pragmatic outlook to autonomous software engineering of the future ! Optimising for multiple objectives (efficacy, cost and time), while automatically solving software engineering tasks. Future Large Language Model (LLM)…

The latest version of AutoCodeRover (using GPT-4o) resolves 30.67% of the tasks (pass @1) in SWE-bench Lite. Achieving this efficacy while economical with only 0.12m tokens costing $0.7 per task and completing each task within 7 mins. #AutoCodeRover #AISE #AIDeveloper #SWEBench

autocoderover's tweet image. The latest version of AutoCodeRover (using GPT-4o) resolves 30.67% of the tasks (pass @1) in SWE-bench Lite. Achieving this efficacy while economical with only 0.12m tokens costing $0.7 per task and completing each task within 7 mins.

#AutoCodeRover #AISE #AIDeveloper #SWEBench
autocoderover's tweet image. The latest version of AutoCodeRover (using GPT-4o) resolves 30.67% of the tasks (pass @1) in SWE-bench Lite. Achieving this efficacy while economical with only 0.12m tokens costing $0.7 per task and completing each task within 7 mins.

#AutoCodeRover #AISE #AIDeveloper #SWEBench


I couldn't agree more!

.@sethvargo is a fantastic and incredibly well rounded technologist - worth a listen cloud.withgoogle.com/cloudsecurity/…



Yet another win for @openssf OSV Schema and overall open source ecosystem: "Ubuntu Security Notices Now Available in OSV" - openssf.org/blog/2024/06/1…


Loading...

Something went wrong.


Something went wrong.