SearcharxivSearch

arXiv subjects

Fikri Pitsuwan

Publications and source records attributed to Fikri Pitsuwan.

3 recordsLinked to original sources

Artificial Bugs for Crowdsearch

Bug bounty programs, where external agents are invited to search and report vulnerabilities (bugs) in exchange for rewards (bounty), have become a major tool for companies to improve their systems. We suggest augmenting such programs by inserting artificial bugs to increase the incentives to search for real (organic) bugs. Using a model of crowdsearch, we identify the efficiency gains by artificial bugs, and we show that for this, it is sufficient to insert only one artificial bug. Artificial bugs are particularly beneficial, for instance, if the designer places high valuations on finding organic bugs or if the budget for bounty is not sufficiently high. We discuss how to implement artificial bugs and outline their further benefits.

econ.TH

Crowdsearch

A common economic process is crowdsearch, wherein a group of agents is invited to search for a valuable physical or virtual object, e.g. creating and patenting an invention, solving an open scientific problem, or identifying vulnerabilities in software. We study a binary model of crowdsearch in which agents have different abilities to find the object. We characterize the types of equilibria and identify which type of crowd maximizes the likelihood of finding the object. Sometimes, however, an unlimited crowd is not sufficient to guarantee that the object is found. It even can happen that inviting more agents lowers the probability of finding the object. We characterize the optimal prize and show that offering only one prize (winner-takes-all) maximizes the probability of finding the object but is not necessarily optimal for the crowdsearch designer.

econ.TH

Decentralized Attack Search and the Design of Bug Bounty Schemes

Systems and blockchains often have security vulnerabilities and can be attacked by adversaries, with potentially significant negative consequences. Therefore, infrastructure providers increasingly rely on bug bounty programs, where external individuals probe the system and report any vulnerabilities (bugs) in exchange for rewards (bounty). We develop a simple contest model of bug bounty. A group of individuals of arbitrary size is invited to undertake a costly search for bugs. The individuals differ with regard to their abilities, which we capture by different costs to achieve a certain probability to find bugs if any exist. Costs are private information. We study equilibria of the contest and characterize the optimal design of bug bounty schemes. In particular, the designer can vary the size of the group of individuals invited to search, add a paid expert, insert an artificial bug with some probability, and pay multiple prizes.

econ.TH