activity
20242026
collaborators

11 papers

cs.CR2026

SherAgent: Scaling Attack Investigation in the Wild via LLM-Empowered Iterative Query-Filter Backtracking

Zhenyuan Li, Zhengkai Wang, Ling Jiang +5

Provenance-based attack investigation enables viable automation by standardizing data and query logic; however, it is critically hindered in practice by dependency explosions and f…

cs.CR2026

Minos: A Multi-Agent Collaborative Framework for Provenance-Based Backward Tracking

Jiahui Wang, Zhenyuan Li, Zhengkai Wang +2

Sophisticated cyber attacks, particularly Advanced Persistent Threats (APTs), require effective post-intrusion forensic analysis. Provenance-based backward tracking reconstructs at…

cs.CR2026

Safety in Self-Evolving LLM Agent Systems: Threats, Amplification, and Case Studies

Ruixiao Lin, Xinhao Deng, Qingming Li +12

Self-evolving LLM agent systems, which autonomously update their model parameters, memory, tools, and architectures, introduce a qualitatively new threat landscape in which adversa…

cs.CR2026

Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems

Qizhi Cai, Yangyang Wei, Yijie Xu +4

Agentic systems increasingly orchestrate complex, tool-using workflows within agentic execution environments, where high-level goals and tool invocations at the application layer m…

cs.CR2026

From Sands to Mansions: Towards Automated Cyberattack Emulation with Classical Planning and Large Language Models

Lingzhi Wang, Zhenyuan Li, Yi Jiang +4

Evolving attacker capabilities demand realistic and continuously updated cyberattack emulation for threat-informed defense and security benchmarking. Towards automated attack emula…

cs.CR2025

Automated Penetration Testing with LLM Agents and Classical Planning

Lingzhi Wang, Xinyi Shi, Ziyu Li +8

While penetration testing plays a vital role in cybersecurity, achieving fully automated, hands-off-the-keyboard execution remains a significant research challenge. In this paper,…