1Password's FLAWED AI Patching Paper Is a Case Study in Industry Research Malpractice
FLAWED's Flaws and What This Means for Industry Research

Suha Sabi Hussain, a former Trail of Bits researcher, dissects 1Password's FLAWED paper on AI vulnerability patching, calling it 'slop.' She highlights glaring errors—wrong diagrams, arithmetic mistakes, and only 19 citations, mostly corporate blogs and XKCD—while a concurrent academic paper cites 73. Hussain argues this isn't just sloppy; it's plagiarism by omission that crowds out rigorous, less-resourced research. She calls for a retraction and stronger research norms, warning that corporate reach shouldn't become a proxy for validity.
The purpose of rigor is to protect us from conclusions we want to accept but that are not true.