Off-by-1 Labs: Why AI-generated vulnerability patches still require expert human review
Summary
Off-by-1 Labs finds that AI generated vulnerability patches for recently disclosed CVEs often contain defects, with a low rate of patches fully fixing issues without altering behavior and a substantial risk of introducing new vulnerabilities. The research provides tooling, datasets, and a paper to help defenders assess AI patching effectiveness, emphasizing that domain experts must review patches before deployment.