December 2025Unreviewed
Autopwn: Automatic Code-Reuse Exploit Generation Framework with Agentic AI
Kaleb Bacztub, Dylan Christensen, Arun Ravindran, Meera Sridhar
2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)
Abstract
This paper presents AutoPwn, an AI-enabled framework for automatic code-reuse exploit generation. AutoPwn leverages agentic large language models to orchestrate the classical stages of exploitation—gadget discovery, semantic analysis, chain construction, and payload integration—within a closed-loop workflow. Our focus is on IoT network management services, where limited defenses make return-oriented programming (ROP) and jump-oriented programming (JOP) attacks particularly relevant. As a case st
Categories
Cite
@inproceedings{bacztub2025autopwn,
title = {{Autopwn: Automatic Code-Reuse Exploit Generation Framework with Agentic AI}},
author = {Kaleb Bacztub and Dylan Christensen and Arun Ravindran and Meera Sridhar},
year = {2025},
month = dec,
booktitle = {2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)},
doi = {10.1109/ACSACW69556.2025.00065},
url = {https://www.semanticscholar.org/paper/6e203aec72715114d99237dd566e0cb96ad06dfa}
}