Pith. sign in

Lee, Joshua Wang, Michael Pelican, David J

4 Pith papers cite this work. Polarity classification is still indexing.

4 Pith papers citing it
abstract

DARPA's AI Cyber Challenge (AIxCC, 2023--2025) is the largest competition to date for building fully autonomous cyber reasoning systems (CRSs) that leverage recent advances in AI -- particularly large language models (LLMs) -- to discover and remediate vulnerabilities in real-world open-source software. This paper presents the first systematic analysis of AIxCC. Drawing on design documents, source code, execution traces, and discussions with organizers and competing teams, we examine the competition's structure and key design decisions, characterize the architectural approaches of finalist CRSs, and analyze competition results beyond the final scoreboard. Our analysis reveals the factors that truly drove CRS performance, identifies genuine technical advances achieved by teams, and exposes limitations that remain open for future research. We conclude with lessons for organizing future competitions and broader insights toward deploying autonomous CRSs in practice.

fields

cs.CR 4

years

2026 4

representative citing papers

OverrideFuzz: Semantic-Aware Grammar Fuzzing for Script-Runtime Vulnerabilities

cs.CR · 2026-05-12 · conditional · novelty 7.0

OverrideFuzz uses semantic-aware grammar fuzzing with reflection to model override hooks and dynamic rebinding, producing coverage growth and inputs that match known vulnerability patterns on CPython, Lua, and QuickJS without discovering new bugs in the evaluation window.

Chai: Agentic Discovery of Cryptographic Misuse Vulnerabilities

cs.CR · 2026-06-25 · unverdicted · novelty 6.0

Chai uses AI to enhance differential testing for cryptographic misuse, cataloging library-level flaws and propagating them to find over 100 vulnerabilities including a critical one in a widely deployed SSL library.

Quality-Assured Fuzz Harness Generation via the Four Principles Framework

cs.CR · 2026-05-20 · unverdicted · novelty 6.0

QuartetFuzz introduces the Four Principles framework for harness correctness and deploys an autonomous LLM agent that produces verified harnesses, yielding 29 confirmed bugs across 23 projects and identifying violations in existing harnesses.

citing papers explorer

Showing 4 of 4 citing papers.