Chinese AI lab says its new coding model got scarily good at finding security flaws, almost by accident

Started by StoneCold_99, Yesterday at 07:29 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Chinese AI lab says its new coding model got scarily good at finding security flaws, almost by accident   Views(Read 44 times)
Active members in this topic:
StoneCold_99(1)

StoneCold_99

Chinese AI developer Zhipu has launched GLM-5.3, a coding focused model the company says developed unexpectedly strong cybersecurity capabilities as a side effect of training it to be a better programmer. On CyberGym, a benchmark testing vulnerability identification, GLM-5.3 scored 84.5%, edging out Anthropic's Mythos 5 at 83.8% and OpenAI's GPT-5.6 Sol at 83.6%. It trails both by a much wider margin on ExploitBench, which tests actually exploiting a found vulnerability, scoring 54.4% against 78% and 76.5% respectively.

Zhipu says the model moved beyond spotting isolated bugs to forming coherent plans for complete exploitation chains, and attributes the jump specifically to scaling post training, reinforcement learning across increasingly complex simulated work environments, rather than building an entirely new base model. The company's ExploitBench score more than doubled from GLM-5.2's 24.4%, and on a separate benchmark testing sustained task completion, GLM-5.3 finished 105 exploitation tasks within two hours versus 29 for its predecessor.

Working with security teams in China, Zhipu ran the model against real world codebases and says it identified 2,436 vulnerabilities across 269 projects after expert review and deduplication, including 1,097 medium to high severity issues spanning system kernels, browser engines, and network protocols. The oldest flaw found dated back to 1981, and vulnerabilities in the dataset had sat undiscovered in code for an average of 26.6 years.

Neil Shah of Counterpoint Research frames the underlying issue plainly, saying the same reasoning an AI uses to test code and fix bugs is exactly what an attacker uses to find a weak spot and break through it, meaning offensive cyber capability is becoming an inherent byproduct of training a genuinely good coding model rather than something that has to be deliberately built in. That's a real problem specifically because Zhipu plans to release GLM-5.3's model weights openly about two weeks after launch, meaning any safety guardrails built in during training could potentially be stripped out once the weights are public.

So the honest tension here is real. The same capability that lets the model find and help fix thousands of genuine security flaws in existing software is functionally identical to the capability that could let a bad actor find and exploit them, and once the weights are open, that capability is available to absolutely anyone regardless of intent
Question everything. Especially this.

Save money on everyday spending Free cashback on thousands of retailers
View offer