Talk: "From Fuzzers to Agents: Building a Cyber Reasoning System for AIxCC"

Speakers: Mischa Meier, Annika Kuntze

Published: December 29, 2025

DARPA’s AI Cyber Challenge (AIxCC) aimed to push the boundaries of autonomous cybersecurity: Can AI systems identify, verify, and fix software vulnerabilities independently, in real time, and without human assistance? Over two years, teams worldwide built “Cyber Reasoning Systems” (CRS) that can analyze complex open-source software, generate reproducers to confirm reported bugs are real, and ultimately synthesize patches. Our team participated in the challenge and built our own CRS from scratch. In this talk, we share insights into the competition: how LLM-driven vulnerability detection works in practice, which design choices matter, and how the finalist teams approached the problem.

Recording on media.ccc.de