Out of the Cage: How Stochastic Parrots Win in Cyber Security Environments
arXiv:2308.12086 · doi:10.5220/0012391800003636
Abstract
Large Language Models (LLMs) have gained widespread popularity across diverse domains involving text generation, summarization, and various natural language processing tasks. Despite their inherent limitations, LLM-based designs have shown promising capabilities in planning and navigating open-world scenarios. This paper introduces a novel application of pre-trained LLMs as agents within cybersecurity network environments, focusing on their utility for sequential decision-making processes. We present an approach wherein pre-trained LLMs are leveraged as attacking agents in two reinforcement learning environments. Our proposed agents demonstrate similar or better performance against state-of-the-art agents trained for thousands of episodes in most scenarios and configurations. In addition, the best LLM agents perform similarly to human testers of the environment without any additional training process. This design highlights the potential of LLMs to efficiently address complex decision-making tasks within cybersecurity. Furthermore, we introduce a new network security environment named NetSecGame. The environment is designed to eventually support complex multi-agent scenarios within the network security domain. The proposed environment mimics real network attacks and is designed to be highly modular and adaptable for various scenarios.
Under review. 10 pages plus appendices, 7 figures, 4 tables. Edit: fix e-mails and code repository
References in corpus (17)
- Chain-of-Thought Prompting Elicits Reasoning in Large Language Models
- Evaluating Large Language Models Trained on Code
- Large Language Models are Zero-Shot Reasoners
- ReAct: Synergizing Reasoning and Acting in Language Models
- Reflexion: Language Agents with Verbal Reinforcement Learning
- BART: Denoising Sequence-to-Sequence Pre-training for Natural Language Generation, Translation, and Comprehension
- Voyager: An Open-Ended Embodied Agent with Large Language Models
- StarCoder: may the source be with you!
- Generative Agents: Interactive Simulacra of Human Behavior
- How is ChatGPT's behavior changing over time?
- Getting pwn'd by AI: Penetration Testing with Large Language Models
- Autonomous Penetration Testing using Reinforcement Learning
- Describe, Explain, Plan and Select: Interactive Planning with Large Language Models Enables Open-World Multi-Task Agents
- Guiding Pretraining in Reinforcement Learning with Large Language Models
- Developing Optimal Causal Cyber-Defence Agents via Cyber Security Simulation
- SPRING: Studying the Paper and Reasoning to Play Games
- NASimEmu: Network Attack Simulator & Emulator for Training Agents Generalizing to Novel Scenarios