Saved in:
| Main Authors: | , , , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | https://arxiv.org/abs/2509.13021 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866917438011998208 |
|---|---|
| author | Luong, Phung Duc Bao, Le Tran Gia Tam, Nguyen Vu Khai Khoa, Dong Huu Nguyen Quyen, Nguyen Huu Pham, Van-Hau Duy, Phan The |
| author_facet | Luong, Phung Duc Bao, Le Tran Gia Tam, Nguyen Vu Khai Khoa, Dong Huu Nguyen Quyen, Nguyen Huu Pham, Van-Hau Duy, Phan The |
| contents | This work introduces xOffense, an AI-driven, multi-agent penetration testing framework that shifts the process from labor-intensive, expert-driven manual efforts to fully automated, machine-executable workflows capable of scaling seamlessly with computational infrastructure. At its core, xOffense leverages a fine-tuned, mid-scale open-source LLM (Qwen3-32B) to drive reasoning and decision-making in penetration testing. The framework assigns specialized agents to reconnaissance, vulnerability scanning, and exploitation, with an orchestration layer ensuring seamless coordination across phases. Fine-tuning on Chain-of-Thought penetration testing data further enables the model to generate precise tool commands and perform consistent multi-step reasoning. We evaluate xOffense on two rigorous benchmarks: AutoPenBench and AI-Pentest-Benchmark. The results demonstrate that xOffense consistently outperforms contemporary methods, achieving a sub-task completion rate of 79.17%, decisively surpassing leading systems such as VulnBot and PentestGPT. These findings highlight the potential of domain-adapted mid-scale LLMs, when embedded within structured multi-agent orchestration, to deliver superior, cost-efficient, and reproducible solutions for autonomous penetration testing. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2509_13021 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | xOffense: An Autonomous Multi-Agent Framework for Penetration Testing with Domain-Adapted Large Language Models Luong, Phung Duc Bao, Le Tran Gia Tam, Nguyen Vu Khai Khoa, Dong Huu Nguyen Quyen, Nguyen Huu Pham, Van-Hau Duy, Phan The Cryptography and Security Artificial Intelligence This work introduces xOffense, an AI-driven, multi-agent penetration testing framework that shifts the process from labor-intensive, expert-driven manual efforts to fully automated, machine-executable workflows capable of scaling seamlessly with computational infrastructure. At its core, xOffense leverages a fine-tuned, mid-scale open-source LLM (Qwen3-32B) to drive reasoning and decision-making in penetration testing. The framework assigns specialized agents to reconnaissance, vulnerability scanning, and exploitation, with an orchestration layer ensuring seamless coordination across phases. Fine-tuning on Chain-of-Thought penetration testing data further enables the model to generate precise tool commands and perform consistent multi-step reasoning. We evaluate xOffense on two rigorous benchmarks: AutoPenBench and AI-Pentest-Benchmark. The results demonstrate that xOffense consistently outperforms contemporary methods, achieving a sub-task completion rate of 79.17%, decisively surpassing leading systems such as VulnBot and PentestGPT. These findings highlight the potential of domain-adapted mid-scale LLMs, when embedded within structured multi-agent orchestration, to deliver superior, cost-efficient, and reproducible solutions for autonomous penetration testing. |
| title | xOffense: An Autonomous Multi-Agent Framework for Penetration Testing with Domain-Adapted Large Language Models |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2509.13021 |