AI-driven testing shows Cloudflare WAF still blocks most frontier model attacks
Cloudflare used large language models to act like a hacker and probe a staged web app. Out of 1,107 attempts, most attacks were blocked, but the exercise uncovered dozens of SSRF and command‑injection leads that helped improve the service.
Cloudflare recently ran a test where a large language model (LLM) acted as an attacker against a customer’s staging environment protected by the company’s web‑application firewall (WAF). The AI generated 1,107 request variations across six common attack categories, and the WAF blocked the vast majority of them. After human review, 49 findings remained, most of which involved command‑injection or server‑side request forgery (SSRF) attempts that required deeper analysis.
Why AI‑generated attacks matter for your site
Frontier AI models excel at iterating payloads faster than a human could. According to the Cloudflare Blog, the LLM was able to mutate attack vectors by changing encodings, moving the payload to different parts of the HTTP request, and trying alternate representations of the same target address. This kind of rapid, automated fuzzing can reveal gaps that static code scans or manual pen tests might miss. For small‑business owners and nonprofit teams, the takeaway is simple: the tools attackers use are getting smarter, so defenses need to keep pace.
What the test covered
The Cloudflare team built a custom tester that started with known exploits and let the LLM propose the next variation based on the response it received. The test spanned six attack categories:
- Cross‑site scripting (XSS)
- SQL injection (SQLi)
- Command injection (CMDi)
- Server‑side request forgery (SSRF)
- Path traversal or local file inclusion (LFI)
- Log4j style remote code execution
Each scenario tried different encodings (decimal, octal, trailing‑dot IP forms) and placed the payload in various request locations such as query strings, form bodies, or headers. The WAF configuration used in the test included Cloudflare’s Managed Ruleset, the OWASP Core Ruleset at Paranoia Level 3, and an attack‑score threshold that blocks anything scoring 30 or below.
Key findings from the AI run
After filtering out malformed or duplicate requests, the team found that most attack categories received near‑full coverage, meaning the WAF blocked almost every attempt. However, the AI uncovered 49 items that required manual triage, with 48 relating to command injection or SSRF. One illustrative case involved an SSRF payload that used a trailing‑dot representation of the metadata IP address (169.254.169.254.). The WAF blocked the standard dotted form but let the trailing‑dot version pass, resulting in a redirect rather than a block page. This nuance highlighted a potential parsing difference that could be tightened in future rule updates.
Practical steps to harden your own web applications
If you run a WordPress site, a custom PHP app, or any public‑facing service, consider the following actions:
- Enable a managed WAF rule set. Cloudflare’s Managed Ruleset and the OWASP Core Ruleset provide broad coverage for the attack types tested.
- Set an appropriate attack‑score threshold. A score of 30 or lower blocked the majority of attempts in the test; adjust the setting based on your risk tolerance.
- Regularly patch your software stack. The blog stresses that a payload that bypasses the WAF still needs a vulnerable backend, so keeping frameworks, plugins, and server packages up‑to‑date is a strong line of defense.
- Run automated tests that include AI‑generated payloads. While the Cloudflare test used a custom harness, open‑source tools can drive similar fuzzing with LLM‑generated strings.
- Review and tune rule exceptions. If you have custom allow‑lists or bypasses, verify they do not unintentionally open gaps for encoded variations.
- Monitor logs for unusual encoding patterns. Requests that use octal, integer, or trailing‑dot IP formats can be a sign of automated probing.
For teams that need hands‑on help, you can reach out to a Formidable Masterminds developer for advice on configuring your WAF or testing your WordPress site. Running WordPress or Formidable Forms? Get help from a Formidable Masterminds developer.
How AI testing fits into a broader security program
The adaptive loop described by Cloudflare shows that an AI model can propose a mutation, see the response, and then decide the next move, without ever seeing the WAF’s rule set or internal IDs. This mirrors a real‑world attacker who observes firewall responses and adapts in real time. Incorporating such testing into your security lifecycle helps you discover edge cases early, before a malicious actor does.
- Integrate AI‑driven fuzzing into CI/CD pipelines. Run a limited set of payload variations on staging environments before each release.
- Pair AI testing with manual review. Automated tools generate noise; human triage filters the signals that matter, as Cloudflare’s 49 findings illustrate.
- Update your WAF rules based on findings. Cloudflare used the bypasses to create new detections that now protect all customers.
By treating AI as a partner in testing rather than a threat, you can stay ahead of the rapid mutation capabilities that modern language models bring to the attacker’s toolbox.
What to watch for moving forward
The Cloudflare experiment is an early look at how frontier AI can be used for offensive testing. As the models become more capable, they will likely generate even more subtle variations, such as multi‑stage payloads that combine encoding tricks with timing attacks. Organizations should:
- Keep an eye on vendor updates to WAF rule sets that address AI‑generated techniques.
- Conduct periodic reviews of WAF logs for patterns that differ from typical user traffic.
- Consider threat‑modeling sessions that explicitly include AI‑assisted attackers.
In short, the test shows that a well‑configured WAF remains a reliable barrier, but it also proves that continuous testing, now with AI assistance, is essential to maintain that confidence.
The information in this briefing is based on the Cloudflare Blog post titled “We tested our own WAF with frontier AI models. Here’s what we found.”
Sources
- We tested our own WAF with frontier AI models. Here’s what we found The Cloudflare Blog
This post was drafted with AI from the reporting linked above and published by Jones Web Designs. For full details, read the original sources.