Google Expands Bug Bounty Program to Combat Generative AI Vulnerabilities

In response to ongoing concerns about generative AI, Google has announced an expansion of its Vulnerability Rewards Program (VRP), targeting AI-specific security threats. The updated guidelines clarify which findings are eligible for rewards, while outlining exclusions. For instance, discoveries involving training data extraction that reveals private, sensitive information are rewarded, while those that only expose public, non-sensitive data do not qualify.

Last year, Google awarded security researchers $12 million for bug discoveries. The company emphasized that AI introduces unique security challenges, including model manipulation and inherent bias, necessitating tailored guidelines. "We believe expanding the VRP will incentivize research around AI safety and security and highlight potential issues that will ultimately enhance AI safety for everyone," Google stated. They also announced an expansion of their open-source security initiatives, aiming to make AI supply chain security information universally accessible and verifiable.

Earlier this year, AI companies, including Google, met at the White House to enhance awareness and discovery of AI vulnerabilities. This expansion of the VRP precedes a significant executive order from President Biden, expected to implement strict assessments and requirements for AI models used by government agencies.

Most people like

Find AI tools in YBX