快播成人

Faculty, staff or current student? Take the UW Climate Survey

Informatics students help Google improve bug reporting

By Shanzay Shabi Thursday, June 6, 2024

Google, like many other companies, utilizes manual and automated processes to investigate security vulnerabilities (otherwise known as bugs or threats) detected by users of its products and services. Given the influx of user- and AI-generated bug reports, many of them are duplicates, rendering 90% of bug reports unactionable.

With insufficient quality control in place, Google鈥檚 internal review team wastes time trying to triage and find the answer to a pre-existing bug. Meanwhile, users waste time submitting bug reports as well.

For their Capstone project at the Information School, five Informatics students, (pictured, from left) Hitanshu Prajapati, Kyle Raychel, Eddy Peng, Harold Pham and Sami Foell partnered with Google to explore how AI could be used to create a deduplication tool that addresses this issue and improves the accuracy of bug reports. 

鈥淓ssentially we鈥檙e streamlining the process of review for security threat reports and are hoping to increase efficiency for Google鈥檚 researchers and bug reporters,鈥 said Pham, the back-end lead on the project. 鈥淎 lot of what we鈥檙e doing right now is experimental and testing the capabilities of AI in the deduplication process.鈥

The Capstone team created the deduplication tool specifically for Google鈥檚 Android-focused reporting form called the Vulnerability Reward Program, which allows users to report a bug and potentially receive financial compensation. For example, multiple users might report the same authentication or authorization flaw in Google Cloud.

The students have built 鈥淰edette,鈥 an AI assistant, and integrated it into the existing Google bug report form. Vedette analyzes the reports鈥 content for similarity to historical reports and provides analytics. The team鈥檚 goal for the assistant was to increase transparency and provide quantifiable metrics to improve the reporting process by automating manual analyses.

鈥淢anual deduplication can take several days, but this tool could theoretically conduct those processes in a few seconds,鈥 said Peng, the project manager and product designer. 鈥淥ur project is trying to champion efficiency while maintaining accuracy and speed throughout.鈥

By using cutting-edge technology to elevate the bug reporting process, the students are helping Google鈥檚 Android Security save time, effort and resources to investigate novel security threats.

Capstone sponsor and Google security team member Greg Wroblewski was thrilled with the students鈥 work, which won an Innovation Award at the annual Capstone Gala on May 30. 鈥淚鈥檓 very impressed by the level of professionalism these students exhibited throughout the project,鈥 he said. 鈥淭hey continued to surprise me with their knowledge of AI and have given an outstanding performance. I鈥檓 very proud of all of them.鈥

By the end of the project, the students will have created two key deliverables: a landing page that conveys the process behind their project (with interactive and video demonstrations attached), and a functional solution solely disclosed to Google.

鈥淭his is just the beginning of what AI can do in security,鈥 said Foell, who served as research lead and product designer. 鈥淏ecause we鈥檙e maintaining a morally and ethically sound position throughout our project, I hope that we can set a precedent for automation to assist and empower people, not replace them.鈥 

As they have experimented with the possibilities of AI in security, the Informatics students have also developed a strong bond.

鈥淢y experience has been absolutely great. You know, I love these guys. They're insanely hard-working and I鈥檓 so glad to have met them through Capstone,鈥 said Prajapati, the project鈥檚 full-stack engineer.

鈥淭his has been amazing. Experimenting with AI and seeing how its capabilities measure up to human reviewers has been incredibly fulfilling," said Raychel, the AI and data engineer. 鈥淚鈥檓 excited to see the growth and opportunities that will emerge from our discoveries.鈥