2024ReviewedOpen access
LLM Agents Can Autonomously Exploit One-day Vulnerabilities
Richard Fang, Rohan Bindu, Akul Gupta, Daniel Kang
arXiv preprint
Abstract
Shows that LLM agents (GPT-4) can autonomously exploit real-world one-day vulnerabilities given CVE descriptions, achieving 87% success rate.
Categories
#autonomous-exploit#CVE#one-day#offensive
Framework mappings
OWASP Top 10 for LLM Applications
- LLM06Excessive Agency
OWASP Top 10 for Agentic Applications
- ASI03Agent Identity & Privilege Abuse
- ASI10Rogue Agents
Cite
@misc{fang2024llmb,
title = {{LLM Agents Can Autonomously Exploit One-day Vulnerabilities}},
author = {Richard Fang and Rohan Bindu and Akul Gupta and Daniel Kang},
year = {2024},
eprint = {2404.08144},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2404.08144}
}