Dynamic Risk Assessments for Offensive Cybersecurity Agents

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Wei, Boyi, Stroebl, Benedikt, Xu, Jiacen, Zhang, Joie, Li, Zhou, Henderson, Peter
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866918179564945408
author Wei, Boyi
Stroebl, Benedikt
Xu, Jiacen
Zhang, Joie
Li, Zhou
Henderson, Peter
author_facet Wei, Boyi
Stroebl, Benedikt
Xu, Jiacen
Zhang, Joie
Li, Zhou
Henderson, Peter
contents Foundation models are increasingly becoming better autonomous programmers, raising the prospect that they could also automate dangerous offensive cyber-operations. Current frontier model audits probe the cybersecurity risks of such agents, but most fail to account for the degrees of freedom available to adversaries in the real world. In particular, with strong verifiers and financial incentives, agents for offensive cybersecurity are amenable to iterative improvement by would-be adversaries. We argue that assessments should take into account an expanded threat model in the context of cybersecurity, emphasizing the varying degrees of freedom that an adversary may possess in stateful and non-stateful environments within a fixed compute budget. We show that even with a relatively small compute budget (8 H100 GPU Hours in our study), adversaries can improve an agent's cybersecurity capability on InterCode CTF by more than 40\% relative to the baseline -- without any external assistance. These results highlight the need to evaluate agents' cybersecurity risk in a dynamic manner, painting a more representative picture of risk.
format Preprint
id arxiv_https___arxiv_org_abs_2505_18384
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Dynamic Risk Assessments for Offensive Cybersecurity Agents
Wei, Boyi
Stroebl, Benedikt
Xu, Jiacen
Zhang, Joie
Li, Zhou
Henderson, Peter
Cryptography and Security
Artificial Intelligence
Foundation models are increasingly becoming better autonomous programmers, raising the prospect that they could also automate dangerous offensive cyber-operations. Current frontier model audits probe the cybersecurity risks of such agents, but most fail to account for the degrees of freedom available to adversaries in the real world. In particular, with strong verifiers and financial incentives, agents for offensive cybersecurity are amenable to iterative improvement by would-be adversaries. We argue that assessments should take into account an expanded threat model in the context of cybersecurity, emphasizing the varying degrees of freedom that an adversary may possess in stateful and non-stateful environments within a fixed compute budget. We show that even with a relatively small compute budget (8 H100 GPU Hours in our study), adversaries can improve an agent's cybersecurity capability on InterCode CTF by more than 40\% relative to the baseline -- without any external assistance. These results highlight the need to evaluate agents' cybersecurity risk in a dynamic manner, painting a more representative picture of risk.
title Dynamic Risk Assessments for Offensive Cybersecurity Agents
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2505.18384