Mozilla、AI脆弱性検出ツール「Mythos」の精度を報告:偽陽性がほぼゼロ
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Ars Technica AI
Mozilla は、AI を活用した脆弱性検出ツール「Mythos」が約 271 の脆弱性を特定し、誤検知(偽陽性)がほとんどなかったと発表した。同社はこれにより、ゼロデイ攻撃の脅威に対抗する防御側が有利になる可能性を示唆している。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
先月、Mozilla の CTO が AI を活用した脆弱性検出により「ゼロデイは数えきれないほど減った」かつ「防御側がついに決定的に勝つチャンスを得た」と宣言した際、その不信感は明白だった。結局のところ、それはあまりにもお馴染みのパターンに見えたのだ:印象的な AI による成果の一部だけを抽出し、よりニュアンスのある状況を伝えるかもしれない細則をすべて省略し、過剰な期待という列車が走り続けるのを放っておく。
懐疑論を意識した Mozilla は木曜日に、Anthropic Mythos(ソフトウェアの脆弱性を特定するための AI モデル)を活用して 2 ヶ月間で Firefox のセキュリティ欠陥 271 件を発見するまでの裏側を公開した。投稿の中で Mozilla のエンジニアたちは、ついに本格的に活用できる画期的成果が主に 2 つの結果によるものだと説明した:(1) モデル自体の改善と (2) Mythos が Firefox ソースコードを分析する際にそれを支援するために Mozilla が開発した独自のカスタム「ハネス」である。
「偽陽性はほぼない」
エンジニアたちは、以前の AI 活用脆弱性検出との遭遇は「望ましくないノイズ」に満ちていたと語った。通常、誰かがモデルに対してコードのブロックを分析するようプロンプトを入力すると、モデルは妥当に読めるバグレポートを生成し、しば前所未有的な規模で出力される。しかし、人間が開発者がさらに調査を進めると、必ずや詳細の大部分が幻覚(ハルシネーション)であると判明した。その後、人間側は従来の方法で脆弱性レポートに対処するために多大な労力を投入する必要があった。
Read full article
Comments
原文を表示
The disbelief was palpable when Mozilla’s CTO last month declared that AI-assisted vulnerability detection meant “zero-days are numbered” and “defenders finally have a chance to win, decisively.” After all, it looked like part of an all-too familiar pattern: Cherry pick a handful of impressive AI-achieved results, leave out any of the fine print that might paint a more nuanced picture, and let the hype train roll on.
Mindful of the skepticism, Mozilla on Thursday provided a behind-the-scenes look into its use of Anthropic Mythos—an AI model for identifying software vulnerabilities—to ferret out 271 Firefox security flaws over two months. In a post, Mozilla engineers said the finally ready-for-prime-time breakthrough they achieved was primarily the result of two things: (1) improvement in the models themselves and (2) Mozilla’s development of a custom “harness” that supported Mythos as it analyzed Firefox source code.
"Almost no false positives"
The engineers said their earlier brushes with AI-assisted vulnerability detection were fraught with “unwanted slop.” Typically, someone would prompt a model to analyze a block of code. The model would then produce plausible-reading bug reports, and often at unprecedented scales. Invariably, however, when human developers further investigated, they’d find a large percentage of the details had been hallucinated. The humans would then need to invest significant work handling the vulnerability reports the old-fashioned way.
Read full article
Comments
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み