View a PDF of the paper titled OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security, by Andrew Chin and 9 other authors
Abstract:DARPA’s AI Cyber Challenge (AIxCC) showed that cyber reasoning systems (CRSs) can go beyond vulnerability discovery to autonomously confirm and patch bugs: seven teams built such systems and open-sourced them after the competition. Yet all seven open-sourced CRSs remain largely unusable outside their original teams, each bound to the competition cloud infrastructure that no longer exists. We present OSS-CRS, an open, locally deployable framework for running and combining CRS techniques against real-world open-source projects, with budget-aware resource management. We ported the first-place system (Atlantis) and discovered 10 previously unknown bugs (three of high severity) across 8 OSS-Fuzz projects. OSS-CRS is publicly available.
Submission history
From: Andrew Chin [view email]
[v1]
Mon, 9 Mar 2026 16:26:33 UTC (1,078 KB)
[v2]
Wed, 25 Mar 2026 15:18:19 UTC (994 KB)
Deep Insight Think Deeper. See Clearer