Hugging Face talk says cyber models still miss the key reasoning leap
AI Engineer · youtube · 2026-07-24
A Hugging Face talk argues that frontier models still miss the reasoning leap a skilled hacker makes, even when they can do reconnaissance.
- The demo uses a real access-control flaw in a chain of Keycloak, Vault, and a broker.
- The model is started as a low-privileged user and asked to reach production code, but it fails to make the crucial inference: an admin check validates by name in one place and by ID in another, so renaming oneself to the admin account would escalate privileges.
- The speakers’ thesis is optimistic: cyber defense could improve if we build better training data and benchmarks for these logic jumps.
- Arithmetic creates cyber data by having human vulnerability researchers discover their own zero days in open-source software, then wrapping them in black-box environments where discovery and exploitation are deterministically graded.
- The benchmark focuses on access control, which the talk frames as the top vulnerability class, and the current version is extremely hard: exactly one solve at K1.
- The broader bet is that if open-source models become fast and reliable at these reasoning-heavy attacks, defenders may gain a durable edge instead of the advantage being concentrated in a few frontier labs.
More from Embodied
- Unitree’s As2-W quadruped is shown climbing a steep rock face — blaawker · 2026-07-24
- FLUX 3 unifies image, video, audio and action prediction in one model — robrombach · 2026-07-24
- China is testing robotic traffic cones that deploy themselves around crash sites — lukas_m_ziegler · 2026-07-24
- Robotics VLA inference work surfaces latency and action-chunking tradeoffs — SoyGema · 2026-07-24
- Uber Founder Kalanick's Pitch to CS Grads: Automate Heavy Machinery, Skip the App Store — Portable_Solar_ZA · 2026-07-24
- TIME puts Unitree on its new cover as the humanoid-robot wave accelerates — chris_j_paxton · 2026-07-24