4 papers
MazeRunner: Nonlinear Task and Clue Orchestration for LLM-driven Black-Box Automated Penetration Testing
Zhenyuan Li, Yi Jiang, Junjie Cheng +3
Penetration testing is essential yet resource-intensive. Although large language models (LLMs) show promise for automating security auditing, existing agents mainly execute end-to-…
SherAgent: Scaling Attack Investigation in the Wild via LLM-Empowered Iterative Query-Filter Backtracking
Zhenyuan Li, Zhengkai Wang, Ling Jiang +5
Provenance-based attack investigation enables viable automation by standardizing data and query logic; however, it is critically hindered in practice by dependency explosions and f…
Cross-Layer Semantic Flow Reconstruction for Attack Detection in Agentic Systems
Qizhi Cai, Yangyang Wei, Yijie Xu +4
Agentic systems increasingly orchestrate complex, tool-using workflows within agentic execution environments, where high-level goals and tool invocations at the application layer m…
Towards Scalable and Interpretable Mobile App Risk Analysis via Large Language Models
Yu Yang, Zhenyuan Li, Xiandong Ran +4
Mobile application marketplaces are responsible for vetting apps to identify and mitigate security risks. Current vetting processes are labor-intensive, relying on manual analysis…