Skip to content
Search
paperDecember 2025Unreviewed

Autopwn: Automatic Code-Reuse Exploit Generation Framework with Agentic AI

Kaleb Bacztub, Dylan Christensen, Arun Ravindran, Meera Sridhar

2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)

Abstract

This paper presents AutoPwn, an AI-enabled framework for automatic code-reuse exploit generation. AutoPwn leverages agentic large language models to orchestrate the classical stages of exploitation—gadget discovery, semantic analysis, chain construction, and payload integration—within a closed-loop workflow. Our focus is on IoT network management services, where limited defenses make return-oriented programming (ROP) and jump-oriented programming (JOP) attacks particularly relevant. As a case st

Categories

Cite

@inproceedings{bacztub2025autopwn,
  title = {{Autopwn: Automatic Code-Reuse Exploit Generation Framework with Agentic AI}},
  author = {Kaleb Bacztub and Dylan Christensen and Arun Ravindran and Meera Sridhar},
  year = {2025},
  month = dec,
  booktitle = {2025 Annual Computer Security Applications Conference Workshops (ACSAC Workshops)},
  doi = {10.1109/ACSACW69556.2025.00065},
  url = {https://www.semanticscholar.org/paper/6e203aec72715114d99237dd566e0cb96ad06dfa}
}