Lessons Learned Running Two Agentic RE Workshops at DEF CON 34
A small model on a laptop found the bug. The system around it is what told the real one from the thirty that looked just as convincing.

I taught two four-hour workshops at DEF CON 34, both built around one question: how close can local AI models get to frontier-level reverse engineering, and what do I have to build around them to close the gap?
Both workshops came at that question from opposite ends and landed in the same place. The model is rarely what decides whether you find the bug. What decides it is everything around the model: how you feed it evidence, which tools it can reach, where you make it stop, and whether or not you can validate the result.


