Cloudflare Uses AI Harness to Probe and Harden Its WAF
Cloudflare placed frontier AI models in a controlled harness to test its WAF: across 45 scenarios the system generated 1,107 attack attempts, leaving 49 findings after human triage. The work led to three changes in Cloudflare's Managed Ruleset, including two new SSRF detections.
- 45 scenarios, 1,107 attempts, 49 findings after human triage
- 48 of 49 findings involved command injection or SSRF
- Added SSRF - Obfuscated Host and SSRF - Restricted Protocol rules
- Models ran black-box, without access to WAF rules or source code
Read next
Security