Critical systems and supply chains across the U.S. face a continuous, accelerating barrage of cyberattacks. Threat actors are hungry for sensitive data, or simply want to disrupt systems and processes and cause chaos.

In hopes of fighting back and bolstering the nation’s cyber defenses, the Biden-Harris Administration announced the “AI Cyber Challenge” (AIxCC) today at Black Hat USA. The competition will pit security teams from across the country against each other as they race to build cutting-edge artificial intelligence (AI) tools that can identify and fix software vulnerabilities in the country’s essential infrastructure and systems.

The challenge is led by the Defense Advanced Research Projects Agency (DARPA) in collaboration with top AI companies including Anthropic, Google, Microsoft and OpenAI. DARPA has committed $18.5 million in prize money for the competition, with $4 million as the top prize.

The agency is also offering to support up to seven small businesses with up to $1 million each so they can participate in the competition’s initial phase.

“If we're successful, I hope to see AIxCC not only produce the next generation of cybersecurity tools in this space, but show how AI can be used to better society by defending its political underpinnings,” Perri Adams, program manager in the information innovation office at DARPA, said in a prebriefing.

“By automatically defending critical software at scale, we can have the greatest impact for cybersecurity across the country, and the world,” she said.

Prize-winning tools to be released as open source

Officials explained that this challenge is about using AI to develop software security tools that can find and fix vulnerabilities in software, as well as rapidly defend infrastructure against attacks.

Challengers will participate in a qualifying event in spring 2024. Up to 20 of the top-scoring teams will then be invited to participate in the semifinal competition at DEF CON 2024 in August. Of those, up to five will be selected for monetary prizes and an invitation to the final phase of the competition at DEF CON 2025.

The top three winners will receive additional monetary prizes and will be asked to open source their system so it can be used by everyone “from volunteer open-source developers to commercial industry,” Adams explained.

[caption id="attachment_133320" align="alignnone" width="824"] Image source: DARPA.[/caption]

Also to this end, the Open Source Security Foundation (OpenSSF), a Linux Foundation project, will serve as an advisor to help ensure the winning software is put to use right away.

“Open-source software is an essential and core part of our nation’s critical infrastructure,” said Omkhar Arasaratnam, OpenSSF GM, in a statement. “Finding new and innovative ways to ensure our open-source software supply chain is secure by construction is in everyone's best interest.”

A ‘daunting maze’ of technology

Adams noted that while software enables modern life, it also creates an expanding attack surface for malicious actors. This includes critical infrastructure, which is especially vulnerable to cyberattack given the challenges of securing sprawling software systems.

“Cyber defenders are tasked with protecting a really daunting maze of technology,” she said.

Adams called the challenge a “first-of-its-kind collaboration” to create AI-driven systems to address cybersecurity. Anne Neuberger, deputy national security advisor for cyber and emerging technology, agreed, saying with this challenge, teams will have the “power of modern AI” to work through complicated problems to support national security.

“Because fundamentally, there is no national security without cyber security,” Neuberger said. “And in cybersecurity, there's always a race between offense and defense. Defense always has to be one step ahead. We see the promise of AI in enabling defense to be one step ahead.”

A partnership between public and private sectors

Industry experts say the initiative holds promise and has the potential to build on existing AI research.

“Government funding for research into solving security issues in and with emerging technologies has the potential to help push forward the boundary of our understanding and capabilities in very meaningful ways,” said Thomas Atkinson, managing security consultant at NCC Group.

“Hopefully this funding will help invigorate research in this space and create meaningful innovations,” he said. “There is definitely some great potential to be had from this initiative and it’s great to see the U.S. government supplying funding at a potentially pivotal time in our lives.”

DARPA has issued these types of challenges for nearly two decades to attract a “wide raft of talented people” to solve “staggeringly hard problems,” said Arati Prabhakar, director of the White House Office of Science and Technology Policy.

“This is one of the ways that public and private sectors work together to do good to change how the future unfolds,” she said.

As Prabhakar put it: “This competition will be a clarion call for all kinds of creative people and organizations to bolster the security of critical software that American families and businesses and all of our society relies on.”

Administrative commitment to AI and cybersecurity

The challenge underscores the Administration's emphasis and broader work on AI, Prabhakar noted.

“The President has been completely clear that we have got to get AI right for the American people,” she said. “He has made AI an important urgent priority here at the White House and across the entire administration.”

Last month, the Administration announced it had secured voluntary commitments from seven leading AI companies to manage risks posed by the technology. These include Amazon, Anthropic, Google, Inflection, Meta, Microsoft and OpenAI.

Those companies have committed to public transparency and will perform red teaming of their systems and make the results of those tests public. Furthermore, an independent, public evaluation of large language models (LLMs) — the first-ever public assessment — will take place this week at DEF CON 2023.