11 papers
The Ethics of Autonomous AI Agents for Offensive Security
Andreas Happe, Jürgen Cito, Jürgen Cito +1
LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling - deterministic, narrowly scoped, and operated by trained practitioner…
Towards Reliable Local Security Agents: Verifiable Post-Training for Linux Privilege Escalation
Philipp Normann, Andreas Happe, Jürgen Cito +1
LLM agents are becoming increasingly important in the security domain, but leading systems are often closed-source, cloud-based, hard to reproduce or use with sensitive code. This…
Recognition Without Mitigation: Ethical Frameworks in Autonomous Offensive-LLM Agent Research
Andreas Happe, Jürgen Cito
Large language models have moved from advising on offensive security to autonomously conducting it. A growing literature presents agents that execute reconnaissance, exploitation,…
Cochise: A Reference Harness for Autonomous Penetration Testing
Andreas Happe, Jürgen Cito, Jürgen Cito
Recent work on LLM-driven autonomous penetration testing reports promising results, but existing systems often bundle architectural, prompting, and tool-integration choices togethe…
Enhancing Linux Privilege Escalation Attack Capabilities of Local LLM Agents
Benjamin Probst, Andreas Happe, Jürgen Cito +1
Cloud-based Large Language Models (LLMs) can perform autonomous penetration-testing sub-tasks such as Linux privilege escalation, but raise security, privacy, and sovereignty conce…
Can LLMs Hack Enterprise Networks? -- Replicated Computational Results (RCR) Report
Andreas Happe, Jürgen Cito
This is the Replicated Computational Results (RCR) Report for the paper ``Can LLMs Hack Enterprise Networks?" The paper empirically investigates the efficacy and effectiveness of d…