Skip to content
Search
paperJuly 2026Unreviewed

VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents

Katherine Swinea, Kshitiz Aryal, Lopamudra Praharaj, Maanak Gupta

Abstract

Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptions of Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred

Categories

Cite

@misc{swinea2026vexaiot,
  title = {{VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents}},
  author = {Katherine Swinea and Kshitiz Aryal and Lopamudra Praharaj and Maanak Gupta},
  year = {2026},
  month = jul,
  eprint = {2607.09653},
  archivePrefix = {arXiv},
  url = {https://arxiv.org/abs/2607.09653}
}