July 2026Unreviewed
VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents
Katherine Swinea, Kshitiz Aryal, Lopamudra Praharaj, Maanak Gupta
Abstract
Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptions of Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred
Categories
Cite
@misc{swinea2026vexaiot,
title = {{VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents}},
author = {Katherine Swinea and Kshitiz Aryal and Lopamudra Praharaj and Maanak Gupta},
year = {2026},
month = jul,
eprint = {2607.09653},
archivePrefix = {arXiv},
url = {https://arxiv.org/abs/2607.09653}
}