3 papers
cs.CR2026
AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications
Ruozhao Yang, Mingfei Cheng, Gelei Deng +3
Large-scale web applications are widely deployed with complex third-party components, inheriting security risks arising from component vulnerabilities. Security assessment is there…
cs.CR2026
What Makes a Good LLM Agent for Real-world Penetration Testing?
Gelei Deng, Yi Liu, Yuekang Li +5
LLM-based agents show promise for automating penetration testing, yet reported performance varies widely across systems and benchmarks. We analyze 28 LLM-based penetration testing…
cs.SE2025
PentestEval: Benchmarking LLM-based Penetration Testing with Modular and Stage-Level Design
Ruozhao Yang, Mingfei Cheng, Gelei Deng +3
Penetration testing is essential for assessing and strengthening system security against real-world threats, yet traditional workflows remain highly manual, expertise-intensive, an…