[ad_1]
Microsoft launched a bug bounty program providing rewards as much as $15,000 for locating vulnerabilities in AI programs, aiming to enhance AI security by means of exterior safety testing.
The preliminary scope of this system will cowl the AI-powered options in Bing, together with Bing Chat, Bing Picture Creator, and Bing integrations in Microsoft Edge, the Microsoft Begin app, and Skype.
The corporate highlighted this new bounty program in a presentation on the BlueHat safety convention. It goals to incentivize safety researchers to seek out bugs and flaws in Microsoft’s AI merchandise earlier than malicious actors can exploit them.
Microsoft states in an announcement:
“As shared in our bounty yr in evaluation weblog submit final month, we’re always rising, iterating, and evolving our bounty packages to assist Microsoft prospects keep forward of the curve within the ever-changing safety panorama and rising applied sciences.”
Microsoft’s Bounty Program Expands to Embody AI
Microsoft’s new bounty program is an extension of an current program, which has awarded over $13 million to researchers. It comes after the corporate not too long ago up to date its vulnerability severity scores for AI programs and held an AI safety analysis problem.
In response to the bounty program’s phrases, eligible vulnerabilities should meet Microsoft’s criticality thresholds, be beforehand unreported, and embrace clear, reproducible steps.
Submissions might be judged on technical severity in addition to the standard of the report.
The minimal bounty cost is $2,000 for a moderate-severity flaw, starting from $15,000 for vital vulnerabilities. Larger rewards are attainable at Microsoft’s discretion for points with important buyer influence.
How To Take part
Researchers fascinated by taking part can submit vulnerabilities by means of the Microsoft Safety Response Heart portal.
Microsoft advises moral bounty searching utilizing check accounts whereas avoiding buyer knowledge publicity or denial of service.
This system’s scope is restricted to technical vulnerabilities within the AI-powered Bing experiences. Some actions aren’t allowed, comparable to accessing knowledge that doesn’t belong to you, exploiting server-side issues past demonstrating proof of idea, and working automated checks that generate a number of visitors.
In Abstract
Microsoft’s AI bug bounty program alerts a broader business deal with figuring out and responsibly disclosing vulnerabilities in AI programs earlier than they are often exploited.
Whereas restricted to Bing’s AI options, the bounties could develop later as Microsoft builds out and secures extra AI capabilities.
Featured Picture: Andrii Yalanskyi/Shutterstock
[ad_2]
