Benchmarking Practices in LLM-driven Offensive Security: Testbeds, Metrics, and Experiment Design

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Happe, Andreas, Cito, Jürgen
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866912431288090624
author Happe, Andreas
Cito, Jürgen
author_facet Happe, Andreas
Cito, Jürgen
contents Large Language Models (LLMs) have emerged as a powerful approach for driving offensive penetration-testing tooling. Due to the opaque nature of LLMs, empirical methods are typically used to analyze their efficacy. The quality of this analysis is highly dependent on the chosen testbed, captured metrics and analysis methods employed. This paper analyzes the methodology and benchmarking practices used for evaluating Large Language Model (LLM)-driven attacks, focusing on offensive uses of LLMs in cybersecurity. We review 19 research papers detailing 18 prototypes and their respective testbeds. We detail our findings and provide actionable recommendations for future research, emphasizing the importance of extending existing testbeds, creating baselines, and including comprehensive metrics and qualitative analysis. We also note the distinction between security research and practice, suggesting that CTF-based challenges may not fully represent real-world penetration testing scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2504_10112
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Benchmarking Practices in LLM-driven Offensive Security: Testbeds, Metrics, and Experiment Design
Happe, Andreas
Cito, Jürgen
Cryptography and Security
Artificial Intelligence
Large Language Models (LLMs) have emerged as a powerful approach for driving offensive penetration-testing tooling. Due to the opaque nature of LLMs, empirical methods are typically used to analyze their efficacy. The quality of this analysis is highly dependent on the chosen testbed, captured metrics and analysis methods employed. This paper analyzes the methodology and benchmarking practices used for evaluating Large Language Model (LLM)-driven attacks, focusing on offensive uses of LLMs in cybersecurity. We review 19 research papers detailing 18 prototypes and their respective testbeds. We detail our findings and provide actionable recommendations for future research, emphasizing the importance of extending existing testbeds, creating baselines, and including comprehensive metrics and qualitative analysis. We also note the distinction between security research and practice, suggesting that CTF-based challenges may not fully represent real-world penetration testing scenarios.
title Benchmarking Practices in LLM-driven Offensive Security: Testbeds, Metrics, and Experiment Design
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2504.10112