AI 幻覺洗版惹禍,Google 不堪其擾宣布暫停開源漏洞獎勵計畫
Google 於 10 月 1 日起暫停「開源軟體漏洞獎勵計畫」(OSS VRP)中的產品漏洞提交。主因是近期湧入大量由 AI 生成的無效報告,導致工程師與開源維護者耗費大量時間逐一驗證,已不堪其擾。
Google 透過官方 X 帳號說明,這項調整為暫時性措施,承諾將在 2027 年第一季前完成機制調整並發布更新。在此過渡期間,官方提供以下配套與例外:
不受影響的項目:10 月 1 日前提交的產品漏洞,以及 OSS VRP 的軟體供應鏈(Supply Chain)漏洞回報均持續運作。
替代通報管道:部分 Google Cloud 倉庫漏洞仍可透過 Cloud VRP 進行通報,官方也鼓勵研究人員轉向參與旗下的其他 VRP 計畫。
📢 PSA for open-source bug hunters
We are temporarily no longer accepting OSS VRP product vulnerability submissions. This does not impact OSS VRP supply chain reports, or any outstanding reports. As an alternative, we encourage you to find impact across our other VRP programs and submit there instead, or pursue the Patch Rewards Program.
Why is this happening? This pause is due to a significant rise in automated submissions, the vast majority of which are not valid. We will continue to reformat and work on this aspect of the OSS VRP and commit to giving an update in Q1 2027.
https://t.co/nQEkHVfbHS
— Google VRP (Google Bug Hunters) (@GoogleVRP) October 1, 2026
OSS VRP 設立的初衷,是為了鼓勵獨立研究人員發掘並通報 Google 開源生態系中的程式碼缺陷、邏輯錯誤與設計問題。然而,隨著大型語言模型與自動化 AI 掃描工具的普及,通報門檻與成本大幅降低。Google 團隊近期被成千上萬份品質低落的報告淹沒,這些所謂的「漏洞」多數是無法利用或根本不存在的 AI「幻覺」,嚴重排擠了維護者修復真正高風險漏洞的寶貴時間。
這類 AI 濫用問題已成為科技業界的共同挑戰。Linux 核心維護者先前便公開表示,AI 驅動的漏洞挖掘機制讓通報量暴增,令他們完全無法負荷。此外,Intel 近期同樣無預警暫停了旗下的漏洞獎勵計畫,外界普遍推測這也與 AI 生成的無效報告氾濫息息相關。
(首圖來源:Unsplash)