Executive Summary
Facts Only
* Automatic Exploit Generation (AEG) is an area focusing on identifying vulnerabilities and constructing functional payloads.
* PwnAgent is an LLM-driven multi-agent framework for end-to-end exploit generation combining offensive knowledge with runtime introspection.
* The benchmark consists of 66 Linux x86/x86-64 ELF binaries and stack-oriented tasks.
* PwnAgent achieved a 62.12% end-to-end success rate on the benchmark using the Kimi-K2.6 backend.
* The PwnGPT baseline achieved a 31.82% success rate on the same evaluation.
* The system is designed to operate within a gray-box setting, assuming local execution privileges and GDB attachment capability.
* The knowledge base $\mathcal{K}$ is structured into four layers: Foundational Principles ($L1$), Reasoning Rule Chains ($L2$), Reference Trajectories ($L3$), and Empirical Pitfalls ($L4$).
* Cognitive sharding distributes knowledge fragments statically to specialized agents based on their role.
* The workflow involves five stages: Semantic Modeling, Exploit Strategy Selection, Dynamic Memory Probing, Exploit Code Generation, and Stratified Feedback and Remediation.
Full Take
From the original · Cybersecurity Journal (Springer)
Abstract Automatic Exploit Generation (AEG) plays an important role in proactive assessment of software threats by identifying vulnerabilities and constructing functional payloads.Read the full story at link.springer.com
