Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

DEF CON 31’s AI red-team exercise was announced in May 2023 as a public assessment of AI models at the AI Village, tied to a White House initiative on AI security risks. The conference later took place in Las Vegas from August 10–13, 2023. The available coverage describes the plan and the organizers’ rationale, but does not establish how many people took part or publish a tally of what they found.

What was the DEF CON 31 AI red-team exercise?

In a May 4, 2023 preview, CyberScoop reported that a group of AI companies had committed to make models available for red-teaming at DEF CON 31. The event was to be hosted at the AI Village, where researchers would probe systems for security and safety weaknesses. CyberScoop expected thousands of security researchers; that was a forecast, not a verified attendance figure. CyberScoop’s announcement coverage

DEF CON 31 subsequently ran in Las Vegas from August 10 through August 13, 2023. The later archived DEF CON 31 program describes the AI Village as hosting talks, workshops, demonstrations, and a generative AI red-team exercise.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Which companies were named?

The provider lists differ between the May preview and the later archived program. They should be read as accounts published at different times, not combined into a single definitive roster.

Source and timing Companies named
CyberScoop preview, May 4, 2023 Anthropic, Google, Hugging Face, Microsoft, NVIDIA, OpenAI, and Stability AI
Archived AI Village program Anthropic, Google, Hugging Face, Meta, NVIDIA, OpenAI, and Stability

The difference is Microsoft in the preview versus Meta in the archived description; the latter also calls the company Stability rather than Stability AI. The records do not explain the discrepancy.

How was the testing supposed to work?

According to the preview, Scale AI developed the evaluation platform, and participants would be given laptops to use during the exercise. The report said identified bugs would be disclosed according to industry-standard responsible-disclosure practices. It did not name the platform, provide detailed contest rules, or link to a public disclosure repository.

The AI Village’s archived description frames AI as a distinct attack surface. Its organizers said the work went beyond prompt injection and jailbreaks: because AI systems can behave stochastically, both bug hunting and the way results are reported may need to adapt. That is the organizers’ explanation of the challenge, not a published account of specific test results. Archived DEF CON 31 program

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What risks were researchers meant to examine?

CyberScoop described several concerns that motivated evaluation. They were reasons to test models, not findings attributed to the DEF CON exercise:

  • Misuse: models might help generate disinformation, malware, or phishing material.
  • Harmful knowledge: a system could provide information that enables harm.
  • Bias: some forms of bias can be difficult to identify and test systematically.
  • Unexpected properties: model behavior may produce risks developers or users did not anticipate.
  • Hallucinations: a model may give confident answers that are not grounded in reality.

These concerns cover different kinds of risk: malicious use, harmful outputs, unfair behavior, and reliability failures. A red-team exercise can probe for weaknesses, but the available event coverage does not show which risks were found or how often.

Why invite public red-teamers?

AI Village founder Sven Cattell argued that broader participation was necessary to address the range of problems. As quoted by CyberScoop, he said: “The diverse issues with these models will not be resolved until more people know how to red team and assess them.” The exercise’s public format reflected that emphasis on expanding who could learn to assess AI systems.

The archived Friday program called the exercise the largest live AI hacking event to that point. That is the organizer’s characterization; the available sources do not supply comparative attendance or testing figures to independently measure it. Archived DEF CON 31 Friday program

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known—and not known—about the outcome?

The sources establish the announcement, the broad setup, the concerns behind the exercise, and the AI Village’s later description of its program. They do not establish actual participant numbers, a complete inventory of model versions tested, or a public count of findings. The May 2023 preview’s expectation of “thousands” should therefore not be treated as the event’s final attendance, and the stated risks should not be presented as vulnerabilities discovered there.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.