February 2024ReviewedOpen access
LLM Agents Can Autonomously Hack Websites
Richard Fang, Rohan Bindu, Akul Gupta, Qiusi Zhan, Daniel Kang
arXiv preprint
Abstract
Demonstrates that LLM agents can autonomously perform web hacking tasks including SQL injection, XSS, and CSRF attacks without human guidance.
Categories
#autonomous-hacking#web-security#agent-misuse
Framework mappings
OWASP Top 10 for LLM Applications
- LLM06Excessive Agency
OWASP Top 10 for Agentic Applications
- ASI03Agent Identity & Privilege Abuse
- ASI10Rogue Agents
Cite
@misc{fang2024llma,
title = {{LLM Agents Can Autonomously Hack Websites}},
author = {Richard Fang and Rohan Bindu and Akul Gupta and Qiusi Zhan and Daniel Kang},
year = {2024},
month = feb,
eprint = {2402.06664},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2402.06664}
}