12 papers
The Ethics of Autonomous AI Agents for Offensive Security
Andreas Happe, Jürgen Cito, Jürgen Cito +1
LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling - deterministic, narrowly scoped, and operated by trained practitioner…
Reducing Token Usage of State-in-Context Agents using Minification
Nicolas Hrubec, Jürgen Cito
This paper presents a replication and extension of the recently introduced state-in-context agent framework. We independently re-implement the DirectSolve variant and evaluate it o…
Recognition Without Mitigation: Ethical Frameworks in Autonomous Offensive-LLM Agent Research
Andreas Happe, Jürgen Cito
Large language models have moved from advising on offensive security to autonomously conducting it. A growing literature presents agents that execute reconnaissance, exploitation,…
Enhancing Linux Privilege Escalation Attack Capabilities of Local LLM Agents
Benjamin Probst, Andreas Happe, Jürgen Cito +1
Cloud-based Large Language Models (LLMs) can perform autonomous penetration-testing sub-tasks such as Linux privilege escalation, but raise security, privacy, and sovereignty conce…
LLMs as Hackers: Autonomous Linux Privilege Escalation Attacks
Andreas Happe, Aaron Kaplan, Juergen Cito
Penetration-testing is crucial for identifying system vulnerabilities, with privilege-escalation being a critical subtask to gain elevated access to protected resources. Language M…
Adversarial Bug Reports as a Security Risk in Language Model-Based Automated Program Repair
Piotr Przymus, Andreas Happe, Jürgen Cito
Large Language Model (LLM) - based Automated Program Repair (APR) systems are increasingly integrated into modern software development workflows, offering automated patches in resp…