BEGIN:VCALENDAR
VERSION:2.0
PRODID:Data::ICal 0.24
BEGIN:VEVENT
DESCRIPTION:   'Title: Better Bug Hunting on AI Products: A VRP Lead’s Pe
 rspective\n   Tags: Bug Bounty Village | Creator Talk/Panel\n   When: Satu
 rday\, Aug 8\, 12:30 - 13:30 PDT\n   Where: LVCCW Level 2 W206-207 (Bug Bo
 unty Village) - [1]Map\n\n   Description:\n\n   At Google\, we receive hun
 dreds of reports per week (not exaggerating)\n   that claim to identify vu
 lnerabilities in our AI products. However\,\n   only a tiny fraction of th
 ose (<1%!) will receive a reward. But there\n   is hope! When we break dow
 n the reasons so many reports are rejected\,\n   nearly all of them fall i
 nto a few common categories that make them\n   invalid. Join the Technical
  Lead of Google’s AI Vulnerability Reward\n   Program to walk through th
 ese common pitfalls\, learn how to bug hunt\n   more effectively on AI pro
 ducts\, and hopefully\, take home more\n   bounties for your efforts. Outl
 ine I. Introduction Self intro\, discuss\n   the interest in AI VRP\, intr
 oduce the problem of low success rates for\n   researchers II. Overview of
  Google AI VRP - Brief program history\,\n   overview of triage/reward pro
 cess - Explain VRP scope/rewards:\n   In-Scope: Security vulnerabilities (
 Rogue Actions / Sensitive Data\n   Exfiltration)\; Some AI Abuse categorie
 s Out-of-Scope: "AI slop\,"\n   simple alignment bypasses\, or jailbreaks 
 that do not result in a\n   direct security impact on user data. III. Comm
 on Mistakes -\n   Jailbreaks/Safety: Getting an LLM to generate "bad" cont
 ent is not a\n   security vulnerability we reward through the program (ple
 ase report\n   in-product!). - Self-pwns: Reports are over-reliant on soci
 al\n   engineering or have unconvincing attack scenarios - Ignoring Contex
 t:\n   Misunderstanding "sensitive data" versus expected model behavior. I
 V.\n   Better Bug Hunting - Direct and Indirect Prompt Injection: Reviewin
 g\n   (un)successful AI VRP reports - Our programs look for indirect promp
 t\n   injection attacks\; this isn’t always easy to understand - Note: T
 his\n   section will include details from a recently rewarded and disclose
 d AI\n   VRP report [details TBC pending researcher/corporate comms approv
 al] -\n   Clear and Actionable Reporting: - We want to help teams fix bugs
 \n   quickly\; you can help us do that by writing clear and actionable\n  
  reports - Reproduction can be challenging due to non-determinism V.\n   C
 onclusion / Q&A\n\n   SpeakerBio:  John Kotheimer\, Senior Security Engine
 er\, Google\n\n   John is a Senior Information Security Engineer and Techn
 ical Lead of\n   the AI Vulnerability Reward Program (AI VRP) at Google in
  New York\n   City. John has significant experience operating bug bounty\n
    programs–including a previous role as TL of the Abuse Vulnerability\n
    Reward Program at Google–as well as a background in infrastructure\n 
   security\, red teaming\, and incident response. As AI VRP lead\, John\n 
   oversees the triage of hundreds of AI bug reports submitted to the\n   p
 rogram every week. John also coordinates the panel that determines\n   rew
 ards for accepted AI bugs at Google and helps plan and run many of\n   Goo
 gle’s bugSWAT live hacking events. Before joining Google in 2019\,\n   J
 ohn was an information security consultant at Mandiant and completed\n   g
 raduate study at Carnegie Mellon University. Outside of work\, he\n   enjo
 ys travel\, craft beer\, and riichi mahjong.\n\n   '\n\n   1. #LVCCW_Level
 2_West\n\n\n
DTEND:20260808T203000Z
DTSTART:20260808T193000Z
LOCATION:Bug Bounty Village - LVCCW Level 2 W206-207 (Bug Bounty Village)
SUMMARY:Better Bug Hunting on AI Products: A VRP Lead’s Perspective
END:VEVENT
END:VCALENDAR
