Project Rudzik - LLM assisted vulnerability hunting in open source projects
Securing core open source projects is important for obvious reasons.
AI / LLMs are another potential option in our toolset to help with this.
In this research I tested different prompts, approaches and versions of LLMs to aid in my code reviewing process. This research led to a significant list of vulnerability findings.
In this talk, I go over some lessons learned from my LLM assisted security research.
Topics covered:
- Different approaches tested
- Some lessons learned
- A few vulnerabilities discovered
Jeroen Pinoy
I am a computer scientist with a background in software testing (automation), incident handling, threat intelligence sharing and security research.