Log in
Scope:
all Yandex services that use generative neural networks
Your goal is to identify vulnerabilities that can occur in systems and apps that use generative neural networks. This includes both issues within the ML models themselves and misconfigurations in the infrastructure that maintains their operation.
We don't consider ethical issues in this Bug Bounty category. The complete list of exceptions is available in the «Exceptions» section.
Vulnerabilities that don’t affect AI/ML functionality will be assessed in accordance with the Main scope category.
Category | Example | Reward |
---|---|---|
Attacks on the data collection, processing, and model training processes: supply chain attacks, attacks on the model training process, and data poisoning |
| $2,000 — $11 ,000 |
Information disclosure: technical and sensitive data |
| $1,500 — $11,000
Sensitive data
up to $2,000 ₽ Technical data |
Attacks on the model's business decision-making: adversarial attacks, attacks affecting decision-making algorithms |
| $500 — $3,300 |
Infrastructure attacks: modifying the system's behavior for other users, changing the system’s technical characteristics/capabilities |
| up to $5,500 |
Other attacks: plugin vulnerabilities, bypassing technical restrictions, attacks compromising the confidentiality and integrity of our systems |
| up to $2,500 |
We understand that no system is perfect, and that ethical violations may occur despite our best efforts. That's why we encourage users to report any ethical violations they encounter. You can submit your reports through the following channels: