arXiv AI By Carolina Fern\'andez-Mart\'inez, Shuaib Siddiqui, Vanesa Daza

A Knowledge-Based Multi-Agent Framework for Security Control Recommendation

Read the original on arXiv AI →

arXiv:2607. 09954v1 Announce Type: cross Abstract: Hardening IT on-premises environments can be a daunting task for teams without access to adequate cybersecurity expertise.

Machine-generated by The Flow from the publisher's headline and feed description — not written or checked by a human. The full article lives at arXiv AI.

arXiv AI
Sep 11

Dont Just Teach, Explain! A Gamified 20Q Recommender for Cybersecurity Education

The paper presents a gamified 20Q-style recommender for cybersecurity education that uses reinforcement learning and explainable AI to guide learners through interactive questioning. By acting as a knowledgeable questioner, the system narrows down user-described security scenarios, identifies the underlying threat, and transparently explains its reasoning. The authors detail the system architecture, algorithmic foundations, and provide case studies covering attack vectors such as the Cyber Kill Chain, phishing, ransomware, and web application vulnerabilities.

By Mary Nusrat, Sarfuddin Bhuiyan, Gahangir Hossain
arXiv AI
Aug 24

Structured but Fragile: On the Limits of LLMs in Cybersecurity Decision-Making

The paper investigates whether large language models (LLMs) can perform structured security reasoning in cybersecurity decision-making. By testing LLMs on defense selection over attack graphs from real-world threat scenarios, the study finds that LLMs can produce coherent strategies when the attack-graph structure is explicitly provided, yet their performance is fragile, highly sensitive to prompt framing, and deteriorates with increasing graph complexity. Additionally, LLM-generated solvers recover the correct high-level formulation but scale poorly compared to specialized solvers.

By Pasquale Malacaria, Yunxiao Zhang
arXiv AI
Jun 12

The Emergence of Autonomous Penetration Capabilities in Large Language Model-Powered AI Systems

arXiv:2606. 13079v1 Announce Type: cross Abstract: Nowadays, the autonomous execution of cyberattacks capable of causing substantial real-world harm is widely regarded as one of the critical red lines that frontier AI systems must not cross.

By Jiaqi Luo, Jiarun Dai, Zhile Chen, Jia Xu, Weibing Wang, Yawen Duan, Brian Tse, Geng Hong, Xudong Pan, Yuan Zhang, Min Yang