Skip to content

Proposal: Security Assessment from Team Atlanta (DARPA AIxCC) #141936

@occia

Description

@occia

Hi cpython developers,

We (LeeSinLiang, and Cen Zhang, and a lot of our team members) are Team Atlanta from Georgia Institute of Technology, winners of DARPA's AI Cyber Challenge (AIxCC). We're reaching out to propose a security assessment collaboration with your project. This effort is recommended by DARPA's initiative to apply competition technologies to real-world open source projects.

Background

We have built an AI-enhanced CRS (Cyber Reasoning System) for automatic vulnerability detection and repair.

What we plan to provide

  • OSS-Fuzz Integration:
    • If your project isn't yet supported by OSS-Fuzz, we'll develop compatible fuzzing harnesses to enable its integration. This can make our system applicable to your project.
  • Security Assessment:
    • We'll run assessments locally on our infrastructure (no changes/efforts from your side) to identify potential vulnerabilities and synthesize corresponding patches.
  • Detailed Reports:
    • For any findings, we'll provide reports including: 1) identified vulnerabilities and explanations, 2) the proof-of-concept (PoC) to trigger those vulnerabilities, and 3) corresponding patches.
  • Responsible Disclosure:
    • We'll follow your preferred reporting channels (private email, OSS-Fuzz bug report system, or whatever channel you prefer) and coordinate disclosure timelines with your team. Note that all findings will be further manually validated by our researchers before reporting to ensure quality and accuracy.

What we need

A brief acknowledgment confirming your willingness to collaborate. This will serve as approval for our assessment plans.

Looking forward to your response and please let me know for any further issues/concerns!

Metadata

Metadata

Assignees

No one assigned

    Labels

    pendingThe issue will be closed if no feedback is providedtype-featureA feature request or enhancement

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions