Yandex will pay up to a million rubles for vulnerabilities in its neural networks

Yandex is expanding its vulnerability hunting program and inviting researchers to participate in a new area of “Bug Hunting” that now covers generative neural networks. For the first time, white-hat hackers are targeting YandexGPT, YandexART and all the infrastructure associated with their operation.
Yandex is willing to pay up to 1 million rubles for the identification of serious technical vulnerabilities, depending on their criticality and complexity.
What exactly neural networks are looking for
In the new phase of the Hunt, researchers will be able to focus on technical glitches and logical vulnerabilities that could affect the performance or learning of models. Specifically:
- Induce incorrect model behavior
- Cause it to fail or malfunction
- Gain access to internal configuration or service data
- Disrupt other Yandex services through interaction with the model
Maximum payout is provided for vulnerabilities that allow sensitive information such as technical system promt, model configurations, or data from protected infrastructure partitions.
Important: only technical reports are accepted under this program. Complaints about incorrect responses from the Alice voice assistant or failed images in Masterpiece will not be considered.

Neural networks already in 20+ Yandex services
The YandexGPT and YandexART models are being actively implemented in the Yandex ecosystem. More than 20 user and business services are based on them, including:
- Alice
- Search with Neural Network
- Yandex Direct
- Yandex Cloud
- API integrations for third-party developers
The appearance of neural networks in the list of Bug Hunt targets is a step towards open and independent security verification that meets the strict requirements that Yandex declares when developing new products.
Security is at the heart of the approach
The company emphasizes that it builds its technologies with the principles of secure development in mind. Security is checked at all stages – from architecture to implementation. Yandex investigates potential vulnerabilities before release and implements protection against AI attacks.
- Yandex Antirobot – protection from DDoS attacks
- Monitoring Center – threat detection and analysis of suspicious activity
- Regular internal audits – assess the level of system security
Now the verification of AI systems is supplemented by another tool – open verification by external experts.