BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: LLMs at the Forefront: Pioneering the Future of Fuzz
  Testing\n   in a Rapidly Changing World\n   When: Sunday\, Aug 13\, 12:00
  - 12:45 PDT\n   Where: Caesars Forum - Academy - 407-410 - Track 4 - [1]M
 ap\n\n   SpeakerBio:X \, Hacker\n   X is a seasoned security researcher an
 d programming language\n   enthusiast with an impressive track record in r
 esearch\, vulnerability\n   discovery\, and fuzz testing. From the moment 
 he laid hands on a\n   Blueberry-colored Apple iBook G3 provided by his el
 ementary school\, X\n   developed a slight obsession with technology.\n\n 
   He is a urban cycling enthusiast that needs to wear his helmet more\n   
 often\, a techno and bass aficionado\, and tree wizard.\n\n   Before findi
 ng vulnerabilities for a living he developed scientific\n   computing soft
 ware. See his Clojure-based Sequoia database fuzzer for\n   an ideal repre
 sentation of X's skill set and interests.\n\n\n   Description:\n   Large L
 anguage Models are already revolutionizing the software\n   development la
 ndscape. As hackers we can only do what we've always\n   done\, embrace th
 e machine and use it to do our bidding.\n\n   There are many valid critici
 sms of GPT models for writing code like\n   the tendency to hallucinate fu
 nctions\, not being able to reason about\n   architecture\, training done 
 on amateur code\, limited context due to\n   token length\, and more. None
  of which are particularly important when\n   writing fuzz tests. This pre
 sentation will delve into the integration\n   of LLMs into fuzz testing\, 
 providing attendees with the insights and\n   tools necessary to transform
  and automate their security assessment\n   strategies.\n\n   The presenta
 tion will kick off with an introduction to LLMs\; how they\n   work\, the 
 potential use cases and challenges for hackers\, prompt\n   writing tips\,
  and the deficiencies of current models. We will then\n   provide a high l
 evel overview explaining the purpose\, goals\, and\n   obstacles of fuzzin
 g\, why this research was undertaken\, and why we\n   chose to start with 
 'memory safe' Python. We will then explore\n   efficient usage of LLMs for
  coding\, and the primary benefits LLMs\n   offer for security work\, pavi
 ng the way for a comprehensive\n   understanding of how LLMs can automate 
 tasks traditionally performed\n   by humans in fuzz testing engagements.\n
 \n   We will then introduce FuzzForest\, an open source tool that harnesse
 s\n   the power of LLMs to automatically write\, fix\, and triage fuzz tes
 ts\n   on Python code. A thorough discussion on the workings of FuzzForest
 \n   will follow\, with a focus on the challenges faced during development
 \n   and our solutions. The highlight of the talk will showcase the result
 s\n   of running the tool on the 20 most popular open-source Python\n   li
 braries which resulted in identifying dozens of bugs.\n\n   We will end th
 e talk with an analysis of efficacy and question if\n   we'll all be repla
 ced with a SecurityGPT model soon.\n\n   To maximize the benefits of this 
 talk\, attendees should possess a\n   fundamental understanding of fuzz te
 sting\, programming languages\, and\n   basic AI concepts. However\, a hig
 h-level refresher will be provided to\n   ensure a smooth experience for a
 ll participants.\n\n   REFERENCES\n         My original blog post that spa
 rked the idea: [2]https://infiniteforest.org/LLMs+to+Write+Fuzzers\n\n   B
 logs \n         [3]https://comby.dev/blog/2022/04/11/comby-decomposer-comp
 iler-fuzzing\n         [4]https://martinfowler.com/articles/2023-chatgpt-x
 u-hao.html\n\n   Research Papers:\n   [5]https://arxiv.org/abs/2212.14834\
 n   [6]https://embed.cs.utah.edu/csmith/\n   [7]https://www.usenix.org/sys
 tem/files/sec23fall-prepub-446-fu.pdf\n\n   Tools \n         [8]https://gi
 thub.com/google/atheris [9]https://github.com/mpaepper/llm_agents\n\n   Pr
 ompt Course:\n   [10]https://www.deeplearning.ai/short-courses/chatgpt-pro
 mpt-engineering-for-developers/\n\n   '\n\n   1. #CaesarsAcademyBR\n   2. 
 https://infiniteforest.org/LLMs+to+Write+Fuzzers\n   3. https://comby.dev/
 blog/2022/04/11/comby-decomposer-compiler-fuzzing\n   4. https://martinfow
 ler.com/articles/2023-chatgpt-xu-hao.html\n   5. https://arxiv.org/abs/221
 2.14834\n   6. https://embed.cs.utah.edu/csmith/\n   7. https://www.usenix
 .org/system/files/sec23fall-prepub-446-fu.pdf\n   8. https://github.com/go
 ogle/atheris\n   9. https://github.com/mpaepper/llm_agents\n   10. https:/
 /www.deeplearning.ai/short-courses/chatgpt-prompt-engineering-for-develope
 rs/\n\n\n
DTEND:20230813T194500Z
DTSTART:20230813T190000Z
LOCATION:DC - Caesars Forum - Academy - 407-410 - Track 4
SUMMARY:LLMs at the Forefront: Pioneering the Future of Fuzz Testing in a R
 apidly Changing World
END:VEVENT
END:VCALENDAR
