arXiv · 2412.02776
Hacking CTFs with Plain Agents
Abstract
We saturate a high-school-level hacking benchmark with plain LLM agent design. Concretely, we obtain 95% performance on InterCode-CTF, a popular offensive security benchmark, using prompting, tool use, and multiple attempts. This beats prior work by Phuong et al. 2024 (29%) and Abramovich et al. 2024 (72%). Our results suggest that current LLMs have surpassed the high school level in offensive cybersecurity. Their hacking capabilities remain underelicited: our ReAct&Plan prompting strategy solves many challenges in 1-2 turns without complex engineering or advanced harnessing.
Explore related subjects
Keep this discovery
Rustem Turtayev, Artem Petrov, Dmitrii Volkov, Denis Volk. 2024-12-03. Hacking CTFs with Plain Agents. https://arxiv.org/abs/2412.02776
Cite the original work for its findings. Save a collection to share your selection of sources.