arXiv · 2502.15506
Construction and Evaluation of LLM-based agents for Semi-Autonomous penetration testing
Abstract
With the emergence of high-performance large language models (LLMs) such as GPT, Claude, and Gemini, the autonomous and semi-autonomous execution of tasks has significantly advanced across various domains. However, in highly specialized fields such as cybersecurity, full autonomy remains a challenge. This difficulty primarily stems from the limitations of LLMs in reasoning capabilities and domain-specific knowledge. We propose a system that semi-autonomously executes complex cybersecurity workflows by employing multiple LLMs modules to formulate attack strategies, generate commands, and analyze results, thereby addressing the aforementioned challenges. In our experiments using Hack The Box virtual machines, we confirmed that our system can autonomously construct attack strategies, issue appropriate commands, and automate certain processes, thereby reducing the need for manual intervention.
Explore related subjects
Keep this discovery
Masaya Kobayashi, Masane Fuchi, Amar Zanashir, Tomonori Yoneda, Tomohiro Takagi. 2025-02-21. Construction and Evaluation of LLM-based agents for Semi-Autonomous penetration testing. https://arxiv.org/abs/2502.15506
Cite the original work for its findings. Save a collection to share your selection of sources.