VAITP GPT

Ask about Python vulnerabilities, CVEs, exploit patterns, and secure coding.

Checking…
Frequently Asked Questions
Why is VAITP slow?

VAITP runs on limited GPU resources. Response time depends on model size and current load.

Why can’t I send multiple messages?

Currently limited to one message at a time due to resource constraints. Multi-turn conversations coming soon.

What is VAITP Premium?

Premium users get more daily requests and access to larger models. Support us on Patreon.

AI-based

Inject1on & Attack

Open-source, cross-platform software for Python vulnerability injection and attack using AI, with a comprehensive, community reviewed, dataset with vulnerabilities and corresponding patches.

VAITP Taxonomy Banner
What is VAITP?

AI-based Offensive Security

VAITP is a cross-platform software that uses AI models to inject and attack realistic vulnerabilities in Python scripts.

1,787

Catalogued vulnerabilities

53

Vulnerability types injected

67%

Peak exploitation success rate

11

Fine-tuned models released

What we are building

The VAITP framework

VAITP is now a four-phase framework. It finds candidate weaknesses, plans an injection, generates the vulnerable code, and then proves the result is genuinely exploitable by attacking it inside a container. We are continuing to develop, test and deploy it, and to train and evaluate local models against it โ€” including model families we have not tried yet โ€” before integrating it into the VAITP GUI.

Phase 0 โ€” Discovery

Autonomous zero-day discovery in real repositories: attack-surface mapping, taint analysis, built-in checks and LLM-driven hypothesis testing.

Phase 1 โ€” Planning

A reasoning model reads the target code alongside similar cases retrieved from the VAITP dataset, and writes a structured injection plan for a coder model to carry out.

Phase 2 โ€” Generation

The vulnerable variant is generated and measured โ€” Bandit, Semgrep and DeVAIC for static analysis, BLEU-4, CodeBLEU and ROUGE-L for similarity to the original.

Phase 3 โ€” Verification

The attack is executed in an isolated Docker container. A vulnerability counts only once it has been exploited and proven, with a self-correcting feedback loop when it has not.

How it started

The models we began with

BoW

Our first classifiers represented code as a bag of words, counting token occurrences while disregarding semantics, grammar and order. Cheap to train, and a useful baseline for everything that came after.

CNN

One-dimensional convolutional networks came next, learning local patterns over token sequences without us having to hand-design the features.

LSTM

Long Short-Term Memory networks carried context across a sequence, which mattered for defects whose cause and effect sit far apart in a file.

Research

The researcher and the papers

Frรฉdรฉric Bogaerts

VAITP is the doctoral research of Frรฉdรฉric Bogaerts, a PhD student and researcher at the University of Coimbra since September 2022 and an assistant professor at ESTGOH, supervised by Naghmeh Ivaki (University of Coimbra) and Josรฉ Fonseca (Instituto Politรฉcnico da Guarda). The work is carried out at CISUC, in the Department of Informatics Engineering.

Full profile and preprints on ResearchGate · LinkedIn.

  • Autonomous Exploitation of Python Vulnerabilities with AI Agents
    ISSRE โ€” IEEE International Symposium on Software Reliability Engineering, 2026
  • Controlled Vulnerability Injection with Large Language Models
    QRS โ€” IEEE International Conference on Software Quality, Reliability and Security, 2026
  • A Taxonomy for Python Vulnerabilities
    IEEE Open Journal of the Computer Society, vol. 5, pp. 368โ€“379, 2024
  • Injecting and Attacking Vulnerabilities in Python Code using Artificial Intelligence
    DSN Doctoral Symposium โ€” IEEE/IFIP International Conference on Dependable Systems and Networks, 2023

VAITP TOKEN

VAITP Banner

Join the VAITP community!

Contribute to our dataset and receive VAITP Token rewards!

Based on the Ethereum Blockchain, VAITP Token provides secure and decentralized transactions!

The VAITP WordPress Rewards Plugin allows administrators to reward users based on their actions directly on the VAITP Blockchain!