AI 中文总结
该研究提出由小型语言模型(SLM)驱动的智能体远程访问木马(agentic RAT),经实验验证其架构可行,虽操作可靠性不足,但预示着AI驱动自主网络威胁的近现实风险。
AI 中文摘要
智能体人工智能引发了新的安全担忧:无需持续人工指导即可在本地进行推理、行动和适应的网络威胁。我们通过智能体远程访问木马(agentic RAT)研究这一威胁:一种由本地部署的小型语言模型(SLM)增强的远程访问木马。SLM可解释主机和网络观测结果、选择行动、从失败步骤中恢复,并减少对外部操作员的依赖。我们在由Kali Linux、Metasploitable2目标、LM Studio以及本地80亿参数的Dolphin系列模型构建的受控、网络隔离实验室中实现了这一概念。随后我们测试如此小型的模型是否能支持自主网络决策。从架构角度来看,这在当今是可行的。在无云服务、无操作员参与的商用硬件上,SLM完成了完整的观测-决策-行动循环:它解释控制器提供的经排序的侦察证据、选择行动,并在真实易受攻击的服务上获得了经验证的root-shell访问权限。然而,它在操作层面尚不可靠。同一模型出现命令幻觉、误读输出、从失败中恢复不一致的情况,仅完成了10.9%的严格检查清单。这一差距反映了当今小型模型的局限性,而非该概念的上限。随着SLM的改进,智能体端点系统可能变得更实用、更自主且更难被检测,给现有的监控、遏制和政策执行机制带来压力。2025-2026年的真实事件已显示AI驱动的入侵正从概念走向实践,这使我们研究的本地、自包含变体成为合理的近期方向,而非假设。
英文摘要
Agentic artificial intelligence raises a new security concern: cyber threats that reason, act, and adapt locally without continuous human direction. We examine this threat through an Agentic Remote Access Trojan (agentic RAT): a Remote Access Trojan augmented with a locally deployed Small Language Model (SLM). The SLM interprets host and network observations, selects actions, recovers from failed steps, and reduces reliance on an external operator. We implement the concept in a controlled, network-isolated lab built from Kali Linux, a Metasploitable2 target, LM Studio, and a local 8-billion-parameter Dolphin-family model. We then test whether a model this small can support autonomous cyber decision-making. This is architecturally feasible today. On commodity hardware, with no cloud service and no operator in the loop, the SLM closed the full observe-decide-act cycle: it interpreted ranked reconnaissance evidence supplied by the controller, selected actions, and obtained verified root-shell access on real vulnerable services. However, it is not yet operationally reliable. The same model hallucinated commands, misread output, and recovered from failure inconsistently, completing 10.9% of a deliberately strict checklist. That gap reflects the limits of today's small models, not a ceiling on the concept. As SLMs improve, agentic endpoint systems may become more practical, more autonomous, and harder to detect, straining existing monitoring, containment, and policy-enforcement mechanisms. Real-world incidents in 2025-2026 already show AI-driven intrusions moving from concept toward practice. That makes the local, self-contained variant we study a plausible near-term direction, not a hypothetical one.
Comments6 pages, 5 figures, 1 table. Formatted in Springer LNCS style