Voices ML

Models That Speak Back

Breaking News
Free Weights

Cloudflare Uses AI to Test and Harden Web Application Firewall

By Poppy Ashworth October 7, 2026
Cloudflare Uses AI to Test and Harden Web Application Firewall - cloudflare firewall ai
The system ran 45 scenarios, producing 1,107 attack attempts across all tests.

Cloudflare has utilized artificial intelligence to test and strengthen its Web Application Firewall, exposing it to thousands of attack variations generated by frontier models. The process began with attack payloads the WAF had already blocked, then fed those into AI models to create refined variations. These models had no access to Cloudflare’s internal rules or source code, making the test a black-box evaluation.

The system ran 45 scenarios, producing 1,107 attack attempts across all tests. After human review, 49 findings were flagged for further action—48 of them related to command injection or server-side request forgery. The AI’s role was limited to proposing mutations, while a Python harness managed request construction, response logging, and scenario control.

A single SSRF test shows how the feedback loop worked. The AI repeatedly altered how a cloud metadata address was formatted, shifting between decimal, octal, and trailing-dot representations. When a decimal version was blocked, the next attempt used a trailing-dot format, which triggered a redirect instead. Cloudflare logged the result for review rather than treating it as a successful bypass.

Of the 1,107 total attempts, 607 produced actionable results: 558 were blocked by the WAF, while the remaining 49 required deeper investigation. Human reviewers confirmed whether requests reached their targets, remained malicious, and could be safely reproduced. Only those meeting all criteria were considered for rule updates.

The process led to three changes in Cloudflare’s Managed Ruleset: two new detections, SSRF – Obfuscated Host and SSRF – Restricted Protocol, alongside an improvement to the existing SSRF – Cloud rule. The approach mirrors other security tools, like Google Mandiant’s Agentic Vulnerability Discovery Harness, which chains specialized AI agents through hypothesis generation and validation before human review.

For defenders, the method highlights how AI can automate parts of security testing without replacing human judgment. The 49 findings from 1,107 attempts suggest the AI’s ability to uncover subtle attack variations; but only when paired with rigorous triage. Without human oversight, the risk of false positives or missed edge cases would rise sharply. The result is a faster, more targeted way to harden defenses, provided the AI’s output is treated as a starting point, not a final answer.

Leave a Reply

Your email address will not be published. Required fields are marked *

© 2026 Voices ML. All rights reserved.