{"692299":{"#nid":"692299","#data":{"type":"news","title":"Georgia Tech Researchers Share AI Cyber Challenge Lessons at USENIX Security 2026","body":[{"value":"\u003Cp\u003EWhat can artificial intelligence (AI) do to protect software from cyberattacks?\u003C\/p\u003E\u003Cp\u003EGeorgia Tech researchers \u003Ca href=\u0022https:\/\/sites.gatech.edu\/winningaixcc\/\u0022\u003Espent two years\u003C\/a\u003E helping to answer that question through \u003Ca href=\u0022https:\/\/www.darpa.mil\/research\/programs\/ai-cyber\u0022\u003EDARPA\u2019s AI Cyber Challenge\u003C\/a\u003E (AIxCC), a competition designed to test whether AI could identify and fix security vulnerabilities in real-world software.\u003C\/p\u003E\u003Cp\u003ENow, they are sharing what they learned with the cybersecurity community.\u003C\/p\u003E\u003Cp\u003ETheir paper, \u003Ca href=\u0022https:\/\/www.usenix.org\/system\/files\/usenixsecurity26-zhang-cen.pdf\u0022\u003E\u003Cem\u003ESoK: DARPA\u2019s AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned\u003C\/em\u003E\u003C\/a\u003E, was presented at \u003Ca href=\u0022https:\/\/www.usenix.org\/conference\/usenixsecurity26\u0022\u003EUSENIX Security 2026,\u003C\/a\u003E one of the world\u0027s leading cybersecurity conferences. The paper was selected as a runner-up for the conference\u2019s distinguished paper award, placing it among 36 recognized papers from 362 accepted papers out of 3,028 submissions.\u003C\/p\u003E\u003Cp\u003EThe paper examines how the seven finalist teams approached the competition and what the results reveal about the future of AI-powered cybersecurity.\u003C\/p\u003E\u003Ch2\u003EPutting AI to the Test\u003C\/h2\u003E\u003Cp\u003EAIxCC challenged teams to build Cyber Reasoning Systems (CRSs) that could operate with minimal human assistance to identify software vulnerabilities, develop fixes, and determine whether security alerts were real threats.\u003C\/p\u003E\u003Cp\u003EThe teams had 143 hours to analyze 53 software projects during the final competition.\u003C\/p\u003E\u003Cp\u003EGeorgia Tech\u2019s \u003Ca href=\u0022https:\/\/team-atlanta.github.io\/\u0022\u003ETeam Atlanta\u003C\/a\u003E, which won the competition, used an approach that combined multiple AI agents with traditional security tools. Other teams used different approaches, including applying AI for specific tasks or building highly autonomous AI agents.\u003C\/p\u003E\u003Cp\u003EThe variety of systems provided researchers with a rare opportunity to compare different approaches to AI-powered cybersecurity.\u003C\/p\u003E\u003Ch2\u003ELesson from the Competition\u003C\/h2\u003E\u003Cp\u003EOne of the biggest lessons was that reliability matters as much as intelligence.\u003C\/p\u003E\u003Cp\u003ESome systems were highly capable but struggled to remain operational while analyzing large, complicated software projects. The strongest systems were often those that could work reliably throughout the competition.\u003C\/p\u003E\u003Cp\u003EThe researchers also found that AI and traditional security tools have different strengths. Traditional tools were still effective at finding common bugs, while AI performed better at reasoning through more complex problems.\u003C\/p\u003E\u003Cp\u003EHowever, AI-generated fixes remain a major challenge.\u003C\/p\u003E\u003Cp\u003EResearchers found that 38% to 46% of AI-generated patches were semantically incorrect. This means a patch might stop a security problem but also break a feature or create another problem.\u003C\/p\u003E\u003Cp\u003EThe results show that AI can play an important role in cybersecurity, but human experts are still needed to verify the safety of AI-generated fixes.\u003C\/p\u003E\u003Ch2\u003ESharing the Lessons\u003C\/h2\u003E\u003Cp\u003E\u003Cstrong\u003ECen\u003C\/strong\u003E \u003Cstrong\u003EZhang\u003C\/strong\u003E, the paper\u2019s first author, said the research offers a unique look at the competition by combining lessons from the finalist teams, organizers, and DARPA\u2019s data.\u003C\/p\u003E\u003Cp\u003E\u201cThis paper provides a unique angle on how AIxCC was designed, the techniques teams used, and what the scores reveal and conceal,\u201d Zhang said.\u003C\/p\u003E\u003Cp\u003E\u003Cstrong\u003EJiho\u003C\/strong\u003E \u003Cstrong\u003EKim\u003C\/strong\u003E presented the paper at USENIX Security 2026. He said the presentation was an opportunity to share lessons from two years of work with the broader cybersecurity community.\u003C\/p\u003E\u003Cp\u003E\u201cSeeing the strong interest and thoughtful questions from the audience made the experience particularly rewarding,\u201d Kim said.\u003C\/p\u003E\u003Cp\u003EThe researchers say they hope the lessons from AIxCC will help guide the next generation of cybersecurity tools.\u003C\/p\u003E","summary":"","format":"limited_html"}],"field_subtitle":"","field_summary":[{"value":"\u003Cp\u003EWhat can artificial intelligence (AI) do to protect software from cyberattacks?\u003C\/p\u003E\u003Cp\u003EGeorgia Tech researchers spent two years helping to answer that question through DARPA\u2019s AI Cyber Challenge (AIxCC), a competition designed to test whether AI could identify and fix security vulnerabilities in real-world software.\u003C\/p\u003E\u003Cp\u003ENow, they are sharing what they learned with the cybersecurity community.\u003C\/p\u003E","format":"limited_html"}],"field_summary_sentence":[{"value":"Georgia Tech researchers spent two years helping to answer the question: What can artificial intelligence (AI) do to protect software from cyberattacks?"}],"uid":"36253","created_gmt":"2026-09-03 19:03:58","changed_gmt":"2026-09-03 19:20:31","author":"John Popham","boilerplate_text":"","field_publication":"","field_article_url":"","location":"Atlanta, GA","dateline":{"date":"2026-09-03T00:00:00-04:00","iso_date":"2026-09-03T00:00:00-04:00","tz":"America\/New_York"},"extras":[],"hg_media":{"681067":{"id":"681067","type":"image","title":"USENIX-AIxCC-Paper-web-copy.jpg","body":null,"created":"1788463126","gmt_created":"2026-09-03 19:18:46","changed":"1788463126","gmt_changed":"2026-09-03 19:18:46","alt":"A dark room with a man presenting from a slideshow","file":{"fid":"265418","name":"USENIX-AIxCC-Paper-web-copy.jpg","image_path":"\/sites\/default\/files\/2026\/09\/03\/USENIX-AIxCC-Paper-web-copy.jpg","image_full_path":"http:\/\/hg.gatech.edu\/\/sites\/default\/files\/2026\/09\/03\/USENIX-AIxCC-Paper-web-copy.jpg","mime":"image\/jpeg","size":1074015,"path_740":"http:\/\/hg.gatech.edu\/sites\/default\/files\/styles\/740xx_scale\/public\/2026\/09\/03\/USENIX-AIxCC-Paper-web-copy.jpg?itok=473Fyfwp"}}},"media_ids":["681067"],"groups":[{"id":"47223","name":"College of Computing"},{"id":"1188","name":"Research Horizons"},{"id":"660406","name":"School of Cybersecurity \u0026 Privacy"},{"id":"660367","name":"School of Cybersecurity and Privacy"}],"categories":[{"id":"194606","name":"Artificial Intelligence"},{"id":"153","name":"Computer Science\/Information Technology and Security"},{"id":"193158","name":"Student Competition Winners (academic, innovation, and research)"},{"id":"8862","name":"Student Research"}],"keywords":[],"core_research_areas":[{"id":"193655","name":"Artificial Intelligence at Georgia Tech"},{"id":"145171","name":"Cybersecurity"},{"id":"39501","name":"People and Technology"}],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[{"value":"\u003Cp\u003EJohn Popham\u003C\/p\u003E\u003Cp\u003ECommunications Officer for the School of Cybersecurity and Privacy\u003C\/p\u003E","format":"limited_html"}],"email":["jpopham3@gatech.edu"],"slides":[],"orientation":[],"userdata":""}}}