ai.hackcv
论文精选 60arXiv

VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents

Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptions of Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred to as Vulnerability EXploitation using AI Agents (VEXAIoT), for vulnerability discovery and exploitation in IoT environments using LLM-based reasoning and offensive security tools. The framework combines a vulnerability detection agent and an attack execution agent to perform reconnaissance, plan attack sequences, and execute exploits against vulnerable IoT services. The system is evaluated in IoTGoat and Metasploitable environments across ten attack scenarios mapped to OWASP IoT vulnerabilities. Experimental results show attack success rate of up to 100% with low token overhead and average execution times under two minutes for most attacks. Across 260 attack executions, VEXAIoT achieves a 95.0% overall success rate, including 94.5% success in IoTGoat and 96.7% success in Metasploitable2. These results demonstrate the potential for LLM-driven agents to automate IoT vulnerability assessment and offensive security workflows in controlled environments

AI 解读论文

AI 自主框架 VEXAIoT 在 IoT 环境中自动发现和利用漏洞。

核心方法
结合 LLM 理解能力和安全工具,通过多代理框架实现漏洞检测和攻击执行的自动化,包括侦察、规划攻击序列和执行攻击。
适合谁读
研究者 / 工程师
要解决的问题
IoT 系统由于硬件限制、过时的固件和不安全的默认配置而容易受到攻击,需要可扩展和适应性强的安全测试方法。
关键实验
在 IoTGoat 和 Metasploitable 环境中测试了 10 个针对 OWASP IoT 漏洞的攻击场景,260 次攻击中整体成功率为 95.0%。
主要贡献
提出了首个利用 LLM 在 IoT 环境中自动发现和利用特定漏洞的多代理框架 VEXAIoT,展示了高成功率和快速执行。
意义与局限
意义在于提高 IoT 安全测试的效率和自动化程度,但目前仅限于受控环境,实际应用中可能面临挑战。
领域:cs.CR作者:Katherine Swinea、Kshitiz Aryal、Lopamudra Praharaj
相关推荐

本站内容由 LLM 精选聚合,原文版权归 arXiv 所有 · 摘录仅供参考