发表机构
LaunchSafe(LaunchSafe)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
介绍用于自主网络攻击的自进化智能操作系统SE-AOS,以Mako为首个实例,在XBOW验证基准上实现全套件覆盖,提出自主攻击定律,运行自进化循环,因研究有双重用途,公布科学成果但保留操作细节等。
AI 中文摘要
我们介绍了自进化智能操作系统(SE-AOS):一种新型人工智能智能体,它将攻击能力视为可变的、有版本的内核,在运行时进行扩展,观察自身失败,合成新能力,在实时目标上进行验证,并将其热加载回自身。Mako是用于安全研究的首个SE-AOS实例,是LaunchSafe中开发的自主网络攻击引擎。在公共XBOW验证基准上,Mako在包含三个难度级别的26个漏洞类别的104个容器化CTF风格的Web应用程序上实现了全套件覆盖。我们的核心成果是自主攻击定律:一旦某种能力存在且可发现,难度就会降低;稀缺的是能力而非推理。Mako还运行一个门控自进化循环,在适应性不退化时对自身智能体和规则提出、沙盒化并提交改进。我们故意不公布操作结果、有效载荷、攻击链和工具来源,因为将全谱网络攻击简化为可重复、机器速度的管道的系统是具有双重用途的研究关注点。我们公布科学;我们保留武器。
英文摘要
We introduce the Self-Evolving Agentic Operating System (SE-AOS): a new class of AI agent that treats exploit capability as a mutable, versioned kernel it extends at runtime, observing its own failures, synthesising new capabilities, proving them against a live target, and hot-loading them back into itself. Mako is the first SE-AOS instance for security research and the autonomous web exploitation engine developed within LaunchSafe. LaunchSafe builds autonomous security agents for continuous offensive testing and agent-driven security research; Mako is the core engine behind that platform. On the public XBOW validation-benchmarks, 104 containerised, CTF-style web applications spanning 26 vulnerability classes across three difficulty tiers, Mako achieves full-suite coverage: it drives every one of the 104 targets to emit a cryptographically fresh, per-build flag, under a verification regime that makes fabricated or memorised results impossible. Our central result is a law of autonomous exploitation: once a capability exists and is discoverable, difficulty collapses; capability, not reasoning, is what is scarce, together with an architecture and formalism that turn that law into a self-improving system. Mako further runs a gated self-evolution loop that proposes, sandboxes, and commits improvements to its own agents and rules when fitness does not regress. We deliberately withhold the operational results, payloads, exploit chains, and tool source, because a system that reduces full-spectrum web exploitation to a repeatable, machine-speed pipeline is dual-use research of concern. We publish the science; we withhold the weapon.
Comments13 pages, 10 figures, 8 tables