i'm not entirely convinced "AI makes slop" is the most productive way to think about what's happening to bug bounty programs. to me, it's an interesting collision between the changing economics of vulnerability disclosure and measurement theory(specifically, goodhart's law making yet another appearance) this is a concept that gets brought up a lot in economics and AI alignment, but i think it also gives us a surprisingly useful lens for understanding what's happening to bug bounty programs in the absolute tsunami of llm-generated reports. now theres two dynamics at play here(a "double Goodhart", if you will): for years, things like polished writeups, detailed reproduction steps, and technically convincing reports were good proxies for genuine security research. but what happens when those proxies become almost free to generate? suddenly, the thing we were measuring isn't necessarily the thing we care about anymore. at the same time, the some participants themselves started optimising for their own metrics, resulting in an adversarial Goodhart effect, and the combination of these factors may help explain the overall degradation of many bug bounty programs for all researchers. we published an article at APIsec Research Labs recently, drawing inferences based on curl report data published by Daniel Stenberg in his blog posts, as well as other sources like H1. our goal with this article was to give the industry a fresh lens to think about these shifts in bug bounty platforms and vuln disclosure practices. we break down what happens when the economics of producing a signal change and why that matters for security, evaluation, and the way we design incentives. link in the comments!! would love to hear whether people think Goodhart's Law is the right framework here, or if there's a better way to think about what's happening. as always, happy hacking!! HackWitHer 🩷 Rajaram (Raj) Ramanathan José Haro Peralta Mohsin Niyazi Corey J. Ball Jess Freeman #CyberSecurity #AISecurity #BugBounty #LLMs #GoodhartsLaw
Nice GenZ Research! Smart take on how incentives and AI are reshaping bug bounties. Platforms need better verification, impact-based rewards, and stronger reputation systems. What changes do you think would actually help?
I think with time things have become better. Previously, the reports were mostly 'slop,' but now that actual good researchers are incorporating AI into their research flow, it has divided these AI reports into two categories: the good ones (which were previously few and far between have now increased by a lot) and the bad ones. Even Mr. Stenberg talked about how the quality of AI reports has increased and they now contain actual findings rather than just hallucinations
Such a fantastic read, Bandana Kaur! The sloptimism framing is spot-on. When the cost of generating a highly convincing report drops to zero, the traditional heuristics triagers used completely fall apart. We really have to shift our focus to direct, automated validation of findings rather than how pretty the write-up looks.
Superb
If AI is the plane, you are the pilot
Super
the full article: https://labs.apisec.ai/research/articles/goodharts-law-broke-vulnerability-disclosure/