What's in the SOSS? An OpenSSF Podcast

AIxCC Part 4 – Cyber Reasoning Systems: The Real-World Journey After AIxCC

9 snips
Feb 10, 2026
Jeff Diecks, OpenSSF technical lead on the AI Cyber Challenge with 20+ years in open source, discusses how AI-powered vulnerability detectors moved from competition to real-world use. He covers real bug findings in the Linux kernel and CUPS. He explains the OSS-CRS standard infrastructure for mixing system components and shares lessons on responsibly reporting AI-generated security findings to maintainers.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Competition Drove Open Research And Real Impact

  • The AIxCC aimed to create systems that both find and fix vulnerabilities in critical open source software.
  • Competitors were required to open-source their work, accelerating real-world adoption and collaboration.
ANECDOTE

Different Teams, Different Strengths

  • Team Theory used pure LLMs rather than fuzzing, showing different viable technical approaches.
  • Another team generated excellent patches but lost competition credit due to a late architectural change.
ANECDOTE

Polling LLMs For Verdicts

  • One team submitted potential findings to multiple LLMs for verdicts, effectively polling models for consensus.
  • The hosts joked it was like getting "eight out of nine dentists" to agree before submission.
Get the Snipd Podcast app to discover more snips from this episode
Get the app