Policy & safetyIncidentSafety & Alignment1 source · Sep 29, 2026

We tested our own WAF with frontier AI models. Here’s what we found

“Is your WAF ready for frontier AI models?” We keep hearing this question from our customers, so we decided to find out.

Proof1 independent outlet

Key points

  • When it comes to exploiting applications, what LLMs are really good at is iterating and mutating attack payloads faster than any human hacker could do.
  • LLMs can use real-time responses to iterate and change their techniques by, for example, testing different encodings, sending the payload in a different part of the HTTP request, or moving to the next vulnerability to test.
  • For the project described in this blog post, we took a dynamic approach: making the LLM act as if it was a hacker to evaluate whether a WAF is doing its job.
  • We built a WAF tester that starts from known exploits and then iterates by changing how it is encoded or delivered, sends it again, and uses the response to choose the next variation.

Sources (1)

  • [1]We tested our own WAF with frontier AI models. Here’s what we found
    Cloudflare Blog: AI · Sep 29, 01:00 PM
    “Is your WAF ready for frontier AI models?” We keep hearing this question from our customers, so we decided to find out.
    When it comes to exploiting applications, what LLMs are really good at is iterating and mutating attack payloads faster than any human hacker could do.

Extractive summary: sentences quoted from the sources.

Before this

  1. Sep 29, 2026Yzmblog/DMAD: DMAD: Distribution Matching as Adversarial Distillation for Fast Visual Generation
  2. Sep 29, 2026ml-explore/mlx v0.32.3
  3. Sep 28, 2026Next.js applications, powered by Vite: introducing Vinext 1.0
  4. Sep 28, 2026The road to the agentic browser: A Kitesurf update
  5. Sep 28, 2026FengZhenfei/carrel: Ontology-Augmented Generation for AI agents.
  6. Sep 27, 2026Cloudflare’s 2026 Annual Founders’ Letter

Related