arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.12996cs.CR

ATOBench:当目标证据存在时,追踪自主渗透测试代理如何验证漏洞

ATOBench: Tracing How Autonomous Penetration-Testing Agents Verify Vulnerabilities When Target Evidence Lies

Qiyang Chen, Yixi Li, Fengwei Zhang, Junlin Liu

首次发表
浏览论文内容

中文总结 AI 辅助

研究人员提出ATOBench框架,通过注入响应转换实现自主渗透测试代理验证过程的可观测性,经450回合评估发现,活动增加会掩盖断裂的验证链,成功恢复依赖于找到并保留可用证据。

中文摘要 AI 辅助

自主渗透测试代理依赖目标响应,这些响应既指导后续行动,也决定最终报告。因此,欺骗性响应会改变攻击轨迹和代理的验证过程。然而,最终报告几乎无法体现代理如何解读冲突证据、调整方向、决定停止,或如何将观察结果转化为漏洞声明。我们推出ATOBench,这一评估框架可让该验证过程变得可观测。ATOBench在运行时注入已注册的响应转换,并将每个转换后的回合与同一环境下的原生回合配对,每对在第一个受影响的响应处对齐,随后通过源关联重构后续行动、证据恢复、停止及报告支持。三类固定的观察合约涵盖漏洞证明、资源所有权及可复用工件。我们在450个回合上评估了五条模型路径,分析显示:活动增加会掩盖断裂的验证链,而成功的恢复取决于找到可用证据并在报告中保留它。ATOBench将欺骗性目标观察转化为自主渗透测试中证据处理的可复现探针,这种过程级视图将攻击性渗透测试代理的评估从最终结果扩展,揭示不可信观察如何塑造行动、验证及报告。

英文摘要

Autonomous penetration-testing agents rely on target responses. These responses guide both subsequent actions and the final report. A deceptive response can therefore redirect both the attack trajectory and the agent's verification process. However, final reports reveal little about how an agent interprets conflicting evidence, changes course, decides to stop, or turns observations into a vulnerability claim. We introduce ATOBench, an evaluation framework that makes this verification process observable. ATOBench injects registered response transformations at runtime and pairs each transformed episode with a native episode under the same environment. Each pair is aligned at the first affected response. A source-linked reconstruction then follows later actions, evidence recovery, stopping, and report support. Three frozen observation contracts cover exploit proof, resource ownership, and reusable artifacts. We evaluate five model routes over 450 episodes. The analysis shows that increased activity can mask a broken verification chain, while successful recovery depends on finding usable evidence and preserving it through reporting. ATOBench turns deceptive target observations into a reproducible probe of evidence handling in autonomous penetration testing. This process-level view extends offensive pentest agent evaluation beyond final outcomes by revealing how untrusted observations shape actions, verification, and reporting.

↑