Most AI-for-cyber work is evaluated on toy tasks & artificial benchmarks. AISLE goes after the real thing = previously unknown zero-days in some of the world's most secure code. And we're matching & beating frontier systems using widely available & open-source-derived models.
Stanislav Fort
@stanislavfort.bsky.social
AI + security at AISLE | Stanford PhD in AI & Cambridge physics | scientific progress
That "Squidbleed" vulnerability (CVE-2026-47729) that Mythos"discovered" in April? Yeah no AISLE actually already reported it back in March, full 44 days before Mythos. Another great live example of the value of the system over the model in zero-day discovery.
Mythos discovers 'Squidbleed,' a memory leak that's gone undetected since Clinton era
We matched Mythos on public zero-days with CVEs using widely available & open-source derived models & can run it air-gapped if needed. All this with a small team out of Europe Berkeley study ranks us #1 globally in 3 of 8 categories The full evidence: stanislavfort.substack.com/p/mythos-at-...
"Mythos" at Home, and It's Called AISLE
A startup out of Europe built an AI system that matches Mythos on zero-day discovery, using widely available models, even air-gapped. You've probably never heard of it. Here's the evidence.
stanislavfort.substack.com
Anthropic just got ordered to suspend all access to Mythos & Fable & every customer lost access overnight. This is why we built AISLE to run even on open-source models, air-gapped. We match Mythos on zero-days, based out of Europe: aisle.com/blog/aisle-matches-anthropic-mythos-on-freebsd-zero-days
Berkeley's independent rating of AI for zero-days just dropped (vuln.cs.berkeley.edu): My startup AISLE is #1 globally in 3 out of 8 categories! 1) total zero-days with CVEs 2) breadth of vuln types 3) coverage of most dangerous vuln types Beating both Google and Anthropic!
Anthropic chose FreeBSD to showcase their Mythos zero-days. In the latest release, 8 CVEs were announced: 3 found by Anthropic, 3 discovered by AISLE's AI (!) AISLE is matching Mythos 3-for-3 on zero-days on the very codebase of their choosing at a fraction of the cost
AISLE is proud to partner with OpenEMR, the open-source medical records platform used by 100k providers & 200M+ patients globally. Our AI security system uncovered 38 historical CVEs in OpenEMR, including 2 max critical severity CVSS 10.0 zero-days.
AISLE has discovered 20 of 23 OpenSSL zero-days (CVEs) across the last 3 consecutive security releases Latest release: 5 of 7 are AISLE 1 was co-reported by Anthropic (Mythos?) 63 days after AISLE OpenSSL encrypts 2/3 of the internet 10 fixes accepted straight into production
AISLE is now the #1 source of accepted security findings in OpenClaw, the fastest-growing AI agent framework. Our AI discovered 15 vulnerabilities: 1 Critical (CVSS 9.4), 9 High, 5 Moderate. 21% of all OpenClaw security advisories globally are from us, more than anyone else ⏬
New post on what AI cybersecurity research looks like when it actually works! I wrote up what we've learned discovering 12 of 12 new OpenSSL zero-days, 5 CVEs in curl, and additional 100+ validated CVEs across critical open source infrastructure, middleware, and secure apps 🔗⏬
Thanks for sharing! Happy to answer any questions you / your followers might have. The full thread with more details is here: bsky.app/profile/stan... I'm genuinely excited and slightly worried how far we've managed to push our AI system. A CVE is one thing, but we've now industrialized the process.
Perennially excellent AI safety researcher Stanislov Fort writes about finding 12 zero days in OpenSSL with an AI scaffold. www.greaterwrong.com/posts/7aJwgb...
OpenSSL secures most of the internet's encryption. They just patched 12 new zero-day vulnerabilities. Our Al system developed by AISLE is responsible for discovering all 12/12, every single one of them. This includes a pre-auth HIGH severity one & 3 that lurked there for >25 years! 1/6
This level of ignorance is surprising but unfortunately legitimately dangerous, giving the readers a pleasant but ultimately false idea that AI is just not that good really. One doesn't have to rely on academic experts here -- just trying out using LLMs clearly shows that they are *extremely* useful
LLMs used as synthetic text extruding machines have no legitimate use cases and --- for all the reasons discussed in the stochastic parrots paper --- are prone to harmful outputs to boot. >>
Presenting *Ensemble Everything Everywhere* at NeurIPS AdvML'24 workshop today! 🔥 Come by today at 10.40-12.00 in East Ballroom C to ask me about: 1) 🏰 bio-inspired naturally robust models 2) 🎓 Interpretability & robustness 3) 🖼️ building a generator for free 4) 😵💫 attacking GPT-4, Claude & Gemini
I discovered a fatal flaw in a paper by @floriantramer.bsky.social et al claiming to break our Ensemble Everything Everywhere defense. Due to a coding error they used attacks 20x above the standard 8/255. They confirmed this but the paper is already out & quoted on OpenReview. What should we do now?
A decade ago, AlphaGo inspired me to leap from black holes to AI. Bittersweet to close my time at DeepMind, but thrilled to start a new chapter focusing directly on AI and security. Find me at NeurIPS this week or DM me here if you'd like to chat!
✨ Super excited to share our paper **Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness** arxiv.org/abs/2408.05446 ✨ Inspired by biology we 1) get adversarial robustness + interpretability for free, 2) turn classifiers into generators & 3) design attacks on GPT-4
✨ Super excited to share our paper **Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness** arxiv.org/abs/2408.05446 ✨ Inspired by biology we 1) get adversarial robustness + interpretability for free, 2) turn classifiers into generators & 3) design attacks on GPT-4
My favorite description of a large language model was accidentally written by Ray Bradbury in 1969, more than half a century ago, and it's eerie how fitting its rendition of an emergent language mind is: vvvvvvv The poem follows in the replies vvvvvv
We "rickrolled" GPT-4o by a specially crafted image of Stephen Hawking 😵💫! This is AFAIK the first case of successful transferrable image attacks on frontier models (www.youtube.com/watch?v=mf_E...) 📝Ensemble everything everywhere: Multi-scale aggregation for adversarial robustness Paper below 👇
Rickrolling the OpenAI GPT-4o by a specially modified photo of Stephen Hawking
YouTube video by Stanislav Fort
youtube.com
There is a popular piece by @washingtonpost.com claiming that GPT-4 consumes 0.14 kWh per 100 words. At $0.15/kWh this implies ~$150/1M tokens *for electricity alone* which is 10x what OpenAI charges *in total*. The WaPo estimate is therefore certainly very off and should be corrected
I have written up my argument for solving adversarial attacks in computer vision as a baby version of general AI alignment. I think that the *shape* of the problem is very similar & that we *have* to be able to solve it before tackling the A(G)I case. Blog post: www.lesswrong.com/posts/oPnFzf...