<node id="692299">
  <nid>692299</nid>
  <type>news</type>
  <uid>
    <user id="36253"><![CDATA[36253]]></user>
  </uid>
  <created>1788462238</created>
  <changed>1788463231</changed>
  <title><![CDATA[Georgia Tech Researchers Share AI Cyber Challenge Lessons at USENIX Security 2026]]></title>
  <body><![CDATA[<p>What can artificial intelligence (AI) do to protect software from cyberattacks?</p><p>Georgia Tech researchers <a href="https://sites.gatech.edu/winningaixcc/">spent two years</a> helping to answer that question through <a href="https://www.darpa.mil/research/programs/ai-cyber">DARPA’s AI Cyber Challenge</a> (AIxCC), a competition designed to test whether AI could identify and fix security vulnerabilities in real-world software.</p><p>Now, they are sharing what they learned with the cybersecurity community.</p><p>Their paper, <a href="https://www.usenix.org/system/files/usenixsecurity26-zhang-cen.pdf"><em>SoK: DARPA’s AI Cyber Challenge (AIxCC): Competition Design, Architectures, and Lessons Learned</em></a>, was presented at <a href="https://www.usenix.org/conference/usenixsecurity26">USENIX Security 2026,</a> one of the world's leading cybersecurity conferences. The paper was selected as a runner-up for the conference’s distinguished paper award, placing it among 36 recognized papers from 362 accepted papers out of 3,028 submissions.</p><p>The paper examines how the seven finalist teams approached the competition and what the results reveal about the future of AI-powered cybersecurity.</p><h2>Putting AI to the Test</h2><p>AIxCC challenged teams to build Cyber Reasoning Systems (CRSs) that could operate with minimal human assistance to identify software vulnerabilities, develop fixes, and determine whether security alerts were real threats.</p><p>The teams had 143 hours to analyze 53 software projects during the final competition.</p><p>Georgia Tech’s <a href="https://team-atlanta.github.io/">Team Atlanta</a>, which won the competition, used an approach that combined multiple AI agents with traditional security tools. Other teams used different approaches, including applying AI for specific tasks or building highly autonomous AI agents.</p><p>The variety of systems provided researchers with a rare opportunity to compare different approaches to AI-powered cybersecurity.</p><h2>Lesson from the Competition</h2><p>One of the biggest lessons was that reliability matters as much as intelligence.</p><p>Some systems were highly capable but struggled to remain operational while analyzing large, complicated software projects. The strongest systems were often those that could work reliably throughout the competition.</p><p>The researchers also found that AI and traditional security tools have different strengths. Traditional tools were still effective at finding common bugs, while AI performed better at reasoning through more complex problems.</p><p>However, AI-generated fixes remain a major challenge.</p><p>Researchers found that 38% to 46% of AI-generated patches were semantically incorrect. This means a patch might stop a security problem but also break a feature or create another problem.</p><p>The results show that AI can play an important role in cybersecurity, but human experts are still needed to verify the safety of AI-generated fixes.</p><h2>Sharing the Lessons</h2><p><strong>Cen</strong> <strong>Zhang</strong>, the paper’s first author, said the research offers a unique look at the competition by combining lessons from the finalist teams, organizers, and DARPA’s data.</p><p>“This paper provides a unique angle on how AIxCC was designed, the techniques teams used, and what the scores reveal and conceal,” Zhang said.</p><p><strong>Jiho</strong> <strong>Kim</strong> presented the paper at USENIX Security 2026. He said the presentation was an opportunity to share lessons from two years of work with the broader cybersecurity community.</p><p>“Seeing the strong interest and thoughtful questions from the audience made the experience particularly rewarding,” Kim said.</p><p>The researchers say they hope the lessons from AIxCC will help guide the next generation of cybersecurity tools.</p>]]></body>
  <field_subtitle>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_subtitle>
  <field_dateline>
    <item>
      <value>2026-09-03T00:00:00-04:00</value>
      <timezone><![CDATA[America/New_York]]></timezone>
    </item>
  </field_dateline>
  <field_summary_sentence>
    <item>
      <value><![CDATA[Georgia Tech researchers spent two years helping to answer the question: What can artificial intelligence (AI) do to protect software from cyberattacks?]]></value>
    </item>
  </field_summary_sentence>
  <field_summary>
    <item>
      <value><![CDATA[<p>What can artificial intelligence (AI) do to protect software from cyberattacks?</p><p>Georgia Tech researchers spent two years helping to answer that question through DARPA’s AI Cyber Challenge (AIxCC), a competition designed to test whether AI could identify and fix security vulnerabilities in real-world software.</p><p>Now, they are sharing what they learned with the cybersecurity community.</p>]]></value>
    </item>
  </field_summary>
  <field_media>
          <item>
        <nid>
          <node id="681067">
            <nid>681067</nid>
            <type>image</type>
            <title><![CDATA[USENIX-AIxCC-Paper-web-copy.jpg]]></title>
            <body><![CDATA[]]></body>
                          <field_image>
                <item>
                  <fid>265418</fid>
                  <filename><![CDATA[USENIX-AIxCC-Paper-web-copy.jpg]]></filename>
                  <filepath><![CDATA[/sites/default/files/2026/09/03/USENIX-AIxCC-Paper-web-copy.jpg]]></filepath>
                  <file_full_path><![CDATA[http://hg.gatech.edu//sites/default/files/2026/09/03/USENIX-AIxCC-Paper-web-copy.jpg]]></file_full_path>
                  <filemime>image/jpeg</filemime>
                  <image_740><![CDATA[]]></image_740>
                  <image_alt><![CDATA[A dark room with a man presenting from a slideshow]]></image_alt>
                </item>
              </field_image>
            
                      </node>
        </nid>
      </item>
      </field_media>
  <field_contact_email>
    <item>
      <email><![CDATA[jpopham3@gatech.edu]]></email>
    </item>
  </field_contact_email>
  <field_location>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_location>
  <field_contact>
    <item>
      <value><![CDATA[<p>John Popham</p><p>Communications Officer for the School of Cybersecurity and Privacy</p>]]></value>
    </item>
  </field_contact>
  <field_sidebar>
    <item>
      <value><![CDATA[]]></value>
    </item>
  </field_sidebar>
  <field_boilerplate>
    <item>
      <nid><![CDATA[]]></nid>
    </item>
  </field_boilerplate>
  <!--  TO DO: correct to not conflate categories and news room topics  -->
  <!--  Disquisition: it's funny how I write these TODOs and then never
         revisit them. It's as though the act of writing the thing down frees me
         from the responsibility to actually solve the problem. But what can I
         say? There are more problems than there's time to solve.  -->
  <links_related> </links_related>
  <files> </files>
  <og_groups>
          <item>47223</item>
          <item>1188</item>
          <item>660406</item>
          <item>660367</item>
      </og_groups>
  <og_groups_both>
          <item>
        <![CDATA[Artificial Intelligence]]>
      </item>
          <item>
        <![CDATA[Computer Science/Information Technology and Security]]>
      </item>
          <item>
        <![CDATA[Student Competition Winners (academic, innovation, and research)]]>
      </item>
          <item>
        <![CDATA[Student Research]]>
      </item>
      </og_groups_both>
  <field_categories>
          <item>
        <tid>194606</tid>
        <value><![CDATA[Artificial Intelligence]]></value>
      </item>
          <item>
        <tid>153</tid>
        <value><![CDATA[Computer Science/Information Technology and Security]]></value>
      </item>
          <item>
        <tid>193158</tid>
        <value><![CDATA[Student Competition Winners (academic, innovation, and research)]]></value>
      </item>
          <item>
        <tid>8862</tid>
        <value><![CDATA[Student Research]]></value>
      </item>
      </field_categories>
  <core_research_areas>
          <term tid="193655"><![CDATA[Artificial Intelligence at Georgia Tech]]></term>
          <term tid="145171"><![CDATA[Cybersecurity]]></term>
          <term tid="39501"><![CDATA[People and Technology]]></term>
      </core_research_areas>
  <field_news_room_topics>
      </field_news_room_topics>
  <links_related>
      </links_related>
  <files>
      </files>
  <og_groups>
          <item>47223</item>
          <item>1188</item>
          <item>660406</item>
          <item>660367</item>
      </og_groups>
  <og_groups_both>
          <item><![CDATA[College of Computing]]></item>
          <item><![CDATA[Research Horizons]]></item>
          <item><![CDATA[School of Cybersecurity &amp; Privacy]]></item>
          <item><![CDATA[School of Cybersecurity and Privacy]]></item>
      </og_groups_both>
  <field_keywords>
      </field_keywords>
  <field_userdata><![CDATA[]]></field_userdata>
</node>
