arXiv AI

APIOT: Autonomous Vulnerability Management Across Bare-Metal Industrial OT Networks

arXiv AI
Jun 30

COHORT: Collaborative Orchestration for Hardening via Offensive Replay on Emulated Topologies

arXiv:2606. 30479v1 Announce Type: cross Abstract: Mitigating an observed adversary in an enterprise network typically takes weeks of expert work: an analyst derives a mitigation tailored to that adversary, validates it without breaking production, and verifies it disrupts the specific attack.

By Chen Frydman, Aviram Zilberman, Rubin Krief, Abed Showgan, Andres Murillo, Sekiya Motoyoshi, Asaf Shabtai, Yuval Elovici, Rami Puzis
arXiv AI
Sep 17

PentestChain: A Cost-Aware, MCP-Orchestrated Framework for Automated Penetration Testing with Free-Tier LLMs

PentestChain is a ten‑phase automated penetration testing framework that uses a cost‑aware AI cascade, starting with a local 7B‑parameter Ollama model (qwen2.5‑7b) and then free‑tier OpenRouter and Cerebras models, with a rule‑based fallback. It exposes the entire pipeline through a Model Context Protocol (MCP) server that includes eleven tools. The authors evaluate the framework using standard testbeds (AutoPenBench, Cybench subset, PentestGPT 182‑sub‑task benchmark) and report that the local model keeps paid‑API cost at zero while detecting 26 services and enriching 34 CVEs on legacy targets.

By Rushabh Vipulkumar Patel, Dipo Dunsin, Mohammed Almaiah, Mohamed Chahine Ghanem
arXiv AI
2d ago

PACE: Provenance-Aware Capability Enforcement for Tool-Using LLM Agents

The paper introduces PACE, a Provenance-Aware Capability Enforcement system designed to secure tool-using large language model agents by mediating every tool call before execution. PACE employs path confinement to limit influence paths and verifies effects against authenticated authority, distinguishing certified execution contracts from evaluated configurations. Experiments on eight agent‑security benchmarks show that the evaluated configuration reduces attack success in most cases while maintaining near‑native utility.

By Fengpeng Li, Qizhou Wang, Yuke Hu, Kemou Li, Jun Liu, Haiwei Wu, Jiantao Zhou, Di Wang
arXiv AI
Aug 28

PLCBench: Can Autonomous LLM Agents Turn PLC Access into Sustained Physical Impact?

PLCBench is a hardware‑in‑the‑loop framework that evaluates whether autonomous large language model agents can transform network‑reachable programmable logic controllers (PLCs) into sustained physical threats. It integrates vendor‑native PLC interaction, commercial PLC execution, closed‑loop process simulation, and deterministic diagnostics to classify episodes into usable interaction, process‑linked manipulation, and sustained physical impact. Across 240 real‑PLC episodes with five LLM families, 31.3% achieved sustained physical objectives, revealing that richer process observation improves success rates and pinpointing failure points for future defense research.

By Yitian Zhou, Jingyu Zheng, Qiliang Jiang, Linkang Du, Haoming Liu, Lichao Wu, Shiyi Zhao, Mengxiang Liu, Ruilong Deng