11 papers
SherAgent: Scaling Attack Investigation in the Wild via LLM-Empowered Iterative Query-Filter Backtracking
Zhenyuan Li, Zhengkai Wang, Ling Jiang +5
Provenance-based attack investigation enables viable automation by standardizing data and query logic; however, it is critically hindered in practice by dependency explosions and f…
Minos: A Multi-Agent Collaborative Framework for Provenance-Based Backward Tracking
Jiahui Wang, Zhenyuan Li, Zhengkai Wang +2
Sophisticated cyber attacks, particularly Advanced Persistent Threats (APTs), require effective post-intrusion forensic analysis. Provenance-based backward tracking reconstructs at…
Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies
Ruixiao Lin, Xinhao Deng, Qingming Li +12
Self-evolving LLM agent systems, which autonomously update their model parameters, memory, tools, and architectures, introduce a qualitatively new threat landscape in which adversa…
Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems
Qizhi Cai, Yangyang Wei, Yijie Xu +4
Agentic systems increasingly orchestrate complex, tool-using workflows within agentic execution environments, where high-level goals and tool invocations at the application layer m…
From Sands to Mansions: Towards Automated Cyberattack Emulation with Classical Planning and Large Language Models
Lingzhi Wang, Zhenyuan Li, Yi Jiang +4
Evolving attacker capabilities demand realistic and continuously updated cyberattack emulation for threat-informed defense and security benchmarking. Towards automated attack emula…
Automated Penetration Testing with LLM Agents and Classical Planning
Lingzhi Wang, Xinyi Shi, Ziyu Li +8
While penetration testing plays a vital role in cybersecurity, achieving fully automated, hands-off-the-keyboard execution remains a significant research challenge. In this paper,…