A recent analysis by VulnCheck has raised questions about the accuracy and reconciliation of Anthropic's Project Glasswing bug disclosure ledger. The analysis found a significant discrepancy between Anthropic's claimed number of discovered vulnerabilities and those actually recorded in its public ledger, with only a small fraction marked as fixed. Furthermore, the ledger itself contains internal inconsistencies regarding the number of fixed vulnerabilities. The report also highlights a notable difference in severity ratings between Anthropic's AI and human maintainers, with the AI frequently flagging issues as critical or high severity, potentially leading to alert fatigue for maintainers. AI
IMPACT Highlights the need for verifiable data in AI's defensive capabilities, impacting policy arguments for frontier model development.
RANK_REASON Analysis of a company's public disclosure ledger regarding AI-found vulnerabilities. [lever_c_demoted from research: ic=1 ai=1.0]
Read on dev.to — Anthropic tag →
AI-generated summary · Google Gemini · from 1 sources. How we write summaries →