Security1 publisher2 min readPublished
Thales's own test shows its new binary protection cutting an AI agent's bug finds from eight to zero
Thales says its new Sentinel Envelope Plus binary protection cut an AI agent's finds in one test application from 8 of 10 vulnerabilities to zero. The bugs stay in the code, so software vendors would be buying time to patch, and the only measurement of that time so far comes from the seller.
The Watch · Security desk
What happened
- On the protected build the agent consumed 970 times as many tokens, then wrote its own analysis tools before recommending the analysis be dropped.
- Thales names on-premises, embedded and edge software as most exposed, because attackers can copy those binaries and analyze them offline.
- Optional license controls can be bundled with the code protection, and they are also added without touching source code.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Because the bugs stay in the code, vendors still owe customers patches; the protection only raises what each finding costs an attacker who holds the binary.
- decision Vendors shipping to customer hardware must pick which functions get the heaviest protection, trading runtime performance for analysis cost without a published overhead figure to plan against.
- exposure Teams that hold internally found bugs for the planned release, as Thales suggests, leave known flaws in fielded binaries longer, guarded by obfuscation alone.
- precedent Measuring resistance in AI tokens, 970 times more in this test, gives buyers a figure to demand from competing protection vendors and from independent testers.
Thales ran one AI agent twice against one application containing ten vulnerabilities [5][6]. On the unprotected build the agent found eight, an 80 percent hit rate, and missed two [5][1][2]. On the protected build it found none [6]. Thales did not name the agent, the model or the test application, and it did not disclose price, performance overhead or customers.
The attacker in Thales's threat case already has a copy of the binary. On-premises, embedded and edge software runs outside the vendor's security environment. An attacker can take a copy and analyze it offline, searching for vulnerabilities, proprietary algorithms and business logic [10]. Thales says AI-assisted tools have cut the specialist expertise and time that reverse engineering takes [15].
The product applies protection after compilation. It transforms and recompiles selected parts of an application, adding layers against decompilation, tampering and runtime inspection, with no source changes or special build environment [2][3]. Developers choose which parts get the strongest treatment, balancing security against performance [4]. Thales says plainly that the vulnerabilities remain in the code and only become harder to find and exploit [8]. The test result records the point where one agent, after writing its own analysis tools, recommended discontinuing the analysis [7].
Damien Bullot, Thales's vice president of software monetization, framed the gain as time [14]. "Our testing shows that the right software protection can make AI-assisted reverse engineering significantly more difficult and resource-intensive," he said [11]. He added: "For software vendors, that additional time matters. It creates a larger window to identify issues, deploy fixes and protect customers, while helping safeguard the intellectual property embedded in their applications." [12]
Thales also sells the extra time as a scheduling benefit. It says teams can handle an internally discovered vulnerability through planned release cycles instead of dropping development work [9]. Under that plan, a bug the vendor already knows about stays in binaries on customer hardware until the next scheduled release, with obfuscation standing between it and an attacker [3].
The release bundles optional license controls, added the same way without source changes [13]. On this record, one protection vendor has built a commercial defense against offline AI analysis of shipped binaries and measured it once, on its own bench [1][5][6].
What to watch
- An independent test of Sentinel Envelope Plus against a named AI agent or a human reverse engineer, with the vulnerability classes disclosed.
- Published performance overhead for the strongest protection setting on selected functions.
- Named customers in embedded or edge markets, or competing protection vendors publishing their own AI-agent benchmarks.