Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

AI Bug Finding

AI is revolutionizing multiple areas of software development including writing computer software and finding bugs in both AI and conventional software. For example, modern frontier AI models can autonomously analyze massive codebases and identify subtle vulnerabilities and potential exploits. Because systems with this level of capability pose significant security risks, leading AI labs enforce strict access controls on them. Despite these advancements, there remains a critical need for more capable AI-based bug finders, as current models are still unable to find many complex vulnerabilities. In addition, there is a need for cost-efficient bug finders that software vendors can use. NIST is developing test material to measure the efficacy of AI-based bug finders to support the training, understanding and responsible use of the tools for more secure software.

Duties

  • Developing and enhancing a generic framework for creating high-quality security vulnerability datasets using AI agentic systems by adopting expert knowledge.
  • Enhancing vulnerability detection and injection through a novel adversarial agentic based technique.
  • Building new datasets for agentic security research and evaluation.
  • Producing high-quality publications based on research and results; presenting at internal and external meetings and conferences.

Required Skills, Expertise, and Qualifications

Knowledge, skills, and interest in the research and evaluation of AI-based bug finders and software vulnerabilities.

  • US citizenship is preferred.
  • M.S. or Ph.D. in Computer Science
  • 3 years of experience in AI and cyber security
  • Experience building AI models, fine tuning LLMs, understanding of transformers and other deep learning architectures, data collection, preparing datasets for AI, creating security oriented agentic systems and workflows
  • Experience designing and building deployable complex software solutions to perform vulnerability injection
  • Knowledge of C/C++, PyTorch, Python, Java, JavaScript, Docker/Podman
  • Strong oral and written communication skills and strong presentation skills.

Employment Terms

This opportunity is to be an associate researcher in the NIST Software Security Group for a term of 2 years, with options to renew and/or pursue longer term federal employment. Associate researchers are NOT Federal Employees, but they will work alongside NIST researchers. Relocation expenses will not be provided.

How to Express Interest

Candidates who meet all of the required qualifications are invited to express their interest in the position by sending an updated CV to daisy.barba [at] nist.gov (daisy[dot]barba[at]nist[dot]gov) and vadim.okun [at] nist.gov (vadim[dot]okun[at]nist[dot]gov).

Was this page helpful?