AWS introduced Deception Benchmark, a public evaluation suite designed to test whether AI models can distinguish genuinely exploitable vulnerabilities from code that only appears vulnerable. The benchmark contains 14,822 purpose-built samples spanning 16 programming languages and more than 70 CWE categories, including scenarios in which environmental or infrastructure controls prevent exploitation.
Testing of 12 general-purpose models found that no evaluated configuration kept both false-positive and false-negative rates below AWS's 10% threshold for production use. Direct vulnerability-detection prompts generally found more flaws but produced excessive false alarms, while prompts requiring proof of exploitation lowered false positives at the expense of missing real vulnerabilities. The benchmark releases samples and an evaluation workflow while withholding labels to preserve verified scoring and limit memorization, complementing broader language-model cybersecurity evaluation efforts such as Cybench.

Track how attackers are adapting to this technology.
1 event from the most recent confirmed update back to the earliest known activity.
AWS publicly released the Deception Benchmark, comprising purpose-built vulnerable and safe code/deployment scenarios to evaluate whether AI models can distinguish exploitable vulnerabilities from deceptive false alarms. Its evaluation of 12 general-purpose models found no tested model-and-prompting configuration kept both false-positive and false-negative rates below 10%.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourceaws.amazon.com
Open sourcearxiv.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.