Cloudflare built an AI-driven tester that adapts each attack request based on how a web application firewall responds. Rather than replay a fixed list, the system changes encodings, request locations and techniques as it searches for variants the firewall may not block.
The company ran 1,107 attempts across six attack categories in an authorized customer staging environment. The model could see selected HTTP response data but not application source code or firewall rules. Most attacks were blocked. Human reviewers removed malformed, benign, duplicate and out-of-scope results from the requests that passed, using the remaining cases to create new detections.
A passed request was treated as a lead, not proof of a working exploit. That distinction limits false alarms and keeps an adaptive model from making security decisions alone. The experiment shows defenders can use the same rapid variation that makes AI useful to attackers, provided testing stays authorized and every apparent bypass receives technical validation.