用AI代理模拟真实攻防,自动发现并利用漏洞
Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents
- 多智能体协作,分步完成漏洞探测与利用
- 漏洞利用成功率超60%,检测准确率提升10%以上
- 支持执行反馈和记忆复用,适合安全研究者使用
大语言模型在辅助网络安全任务方面展现出潜力,但现有方法在自动漏洞发现与利用上受限于交互不足、执行缺乏根基及经验无法复用。我们提出Co-RedTeam,一个面向安全领域的多智能体框架,通过整合安全领域知识、代码感知分析、执行接地的迭代推理以及长期记忆,模拟真实红队工作流程。该框架将漏洞分析分解为协同的发现与利用阶段,使智能体能基于真实执行反馈进行规划、执行、验证与优化,并从过往轨迹中学习。在多个挑战性安全基准上的评估表明,Co-RedTeam在不同主干模型下均显著优于强基线,漏洞利用成功率超过60%,漏洞检测准确率绝对提升超10%。消融与迭代实验进一步验证了执行反馈、结构化交互和记忆机制对构建鲁棒且泛化性强的网络安全智能体的关键作用。
原文摘要 · Abstract (English)
Large language models (LLMs) have shown promise in assisting cybersecurity tasks, yet existing approaches struggle with automatic vulnerability discovery and exploitation due to limited interaction, weak execution grounding, and a lack of experience reuse. We propose Co-RedTeam, a security-aware multi-agent framework designed to mirror real-world red-teaming workflows by integrating security-domain knowledge, code-aware analysis, execution-grounded iterative reasoning, and long-term memory. Co-RedTeam decomposes vulnerability analysis into coordinated discovery and exploitation stages, enabling agents to plan, execute, validate, and refine actions based on real execution feedback while learning from prior trajectories. Extensive evaluations on challenging security benchmarks demonstrate that Co-RedTeam consistently outperforms strong baselines across diverse backbone models, achieving over 60% success rate in vulnerability exploitation and over 10% absolute improvement in vulnerability detection. Ablation and iteration studies further confirm the critical role of execution feedback, structured interaction, and memory for building robust and generalizable cybersecurity agents.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。