Teaching AI to Find Real Vulnerabilities — Prof. David Brumley, Bugcrowd
AI Engineer World's Fair 2026 · 27:17
Crowdsourced cybersecurity and AI security testing
Bugcrowd provides a cybersecurity platform that connects security teams with hackers to find and address vulnerabilities. Its Bug Bounty offering supports continuous vulnerability hunting with payment for results, while vulnerability disclosure programs help organizations receive, prioritize, and remediate submissions. Penetration testing supports compliance work, and red teaming simulates real-world threats. Together, these services give organizations access to security expertise beyond their internal teams.
Founder Casey Ellis launched Bugcrowd and its first bug bounty programs in 2012; Dave Gerry is CEO. Bugcrowd acquired Mayhem Security in 2025, adding autonomous code and API testing capabilities. Mayhem’s research lineage includes its 2016 DARPA Cyber Grand Challenge win with a system that discovered, diagnosed, and repaired software flaws. Carnegie Mellon University is a separate institution: Mayhem originated with its researchers, and Bugcrowd’s Chief AI and Science Officer, David Brumley, is a Carnegie Mellon professor.
That acquisition also underpins Bugcrowd’s Reinforcement Learning Environments, which let AI developers train agents to find, exploit, and fix vulnerabilities in real software with scored feedback. Launched in 2026, the offering uses environments derived exclusively from open-source software. Beyond AI model development, Bugcrowd serves corporate and government security programs: in 2024, the company reported more than 1,200 customers, including OpenAI, Google, T-Mobile, and the U.S. Defense Department’s Chief Digital and Artificial Intelligence Office.
AI Engineer World's Fair 2026 · 27:17
Affiliations reflect their AIE appearances, not necessarily current employment.
Brumley emphasizes deterministic grading instead of LLM judges and audit tasks that assess multiple vulnerabilities. Reward hacking and evaluating newly discovered vulnerabilities remain challenges for this approach.
Affiliations reflect each recorded session, not necessarily current employment.