arXiv:2601.23092cs.CRcs.AI2026-01被引 1

用受控生成式AI辅助无线渗透测试,提升效率与安全性

WiFiPenTester: Advancing Wireless Ethical Hacking with Governed GenAI

  • 将大语言模型用于无线安全评估的侦察与决策阶段
  • 目标选择准确率与整体评估效率显著提升
  • 强调人类控制与治理机制,适合安全研究者使用

无线伦理黑客攻击高度依赖专业人员手动分析侦察结果,并执行复杂、时间敏感的命令序列以识别脆弱目标、捕获认证握手并评估密码强度;这一过程劳动密集、难以扩展,且易受主观判断和人为错误影响。为解决上述问题,我们提出WiFiPenTester,一个实验性、受控且可复现的生成式AI赋能无线伦理黑客系统。该系统将大语言模型集成至无线安全评估的侦察与决策支持阶段,实现智能目标排序、攻击可行性评估与策略推荐,同时保持严格的人类在环控制与预算感知执行。我们阐述了系统架构、威胁模型、治理机制及提示工程方法,并在多个无线环境中进行了实证实验。结果表明,生成式AI辅助提升了目标选择准确率与整体评估效率,同时维持可审计性与伦理保障。这表明WiFiPenTester是迈向实用、安全、可扩展的生成式AI辅助无线渗透测试的重要一步,也强化了在伦理黑客中部署生成式AI时,必须具备有限自主性、人类监督与严格治理机制的必要性。

原文摘要 · Abstract (English)

Wireless ethical hacking relies heavily on skilled practitioners manually interpreting reconnaissance results and executing complex, time-sensitive sequences of commands to identify vulnerable targets, capture authentication handshakes, and assess password resilience; a process that is inherently labour-intensive, difficult to scale, and prone to subjective judgement and human error. To help address these limitations, we propose WiFiPenTester, an experimental, governed, and reproducible system for GenAI-enabled wireless ethical hacking. The system integrates large language models into the reconnaissance and decision-support phases of wireless security assessment, enabling intelligent target ranking, attack feasibility estimation, and strategy recommendation, while preserving strict human-in-the-loop control and budget-aware execution. We describe the system architecture, threat model, governance mechanisms, and prompt-engineering methodology, and empirical experiments conducted across multiple wireless environments. The results demonstrate that GenAI assistance improves target selection accuracy and overall assessment efficiency, while maintaining auditability and ethical safeguards. This indicates that WiFiPenTester is a meaningful step toward practical, safe, and scalable GenAI-assisted wireless penetration testing, while reinforcing the necessity of bounded autonomy, human oversight, and rigorous governance mechanisms when deploying GenAI in ethical hacking.

生成式AI渗透测试无线安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。