We tested our own WAF with frontier AI models. Here’s what we found
- ID
- 29816
- Status
- summarized
- Published
- 29 Sep 2026, 9:00 PM
- Fetched
- 29 Sep 2026, 10:55 PM
- Provider
- Cloudflare Blog
- Category
- infrastructure
- Original URL
- https://blog.cloudflare.com/adaptive-ai-waf-testing/
- Source URL
- https://blog.cloudflare.com/rss/
Summary
- Score
- 4.5
- Created
- 29 Sep 2026, 10:55 PM
- Tags
- Audience
- developersai_ml_learnerssaas_founders
What happened
Cloudflare built an LLM-driven "WAF tester" that takes known exploits and iterates on them — changing encoding, moving the payload to a different part of the HTTP request, or switching vulnerability — using only selected HTTP response data as feedback, with no visibility into source code or WAF rules. Run against an authorized customer staging environment across six attack categories, it recorded 1,107 attempts; the vast majority were blocked, and non-blocked requests were treated as leads for human review rather than confirmed exploits, feeding new detections into the WAF. The post does not publish a bypass rate or a per-category breakdown of what got through, and Cloudflare is testing its own product.
Why it matters
The concrete takeaway is Cloudflare's own framing: a payload that slips past a WAF still needs an exploitable application to succeed, so keeping your stack patched remains the stronger defense — don't let a WAF subscription stand in for dependency updates. The second takeaway is methodological: this is a vendor reporting on its own product with no bypass number published, so treat "the vast majority were blocked" as an unquantified claim when you evaluate any WAF vendor's AI-resistance messaging, Cloudflare included. There is no Malaysia-specific detail in the text.
Discussion angle
Cloudflare describes the technique (LLM mutates payloads, reads responses, picks the next variation) but not the result — no bypass count, no per-category breakdown. Ask the room: if you ran the same adaptive loop against your own staging environment this week, what would you actually measure, and would you publish the number?