Frontier AI systems are increasingly capable of cybersecurity tasks, including codebase inspection, vulnerability detection, and exploitation. However, evaluating their offensive capabilities remains constrained by limited access to open, reproducible, multi-host cyber ranges. Existing public benchmarks capture isolated skills such as CTF solving, vulnerability reproduction, and exploit generation, but often abstract away realistic intrusion workflows: discovering exposed services, gaining a foothold, collecting internal information, and expanding compromise across hosts. This gap makes it difficult to observe emerging risks early, because frontier AI systems are rarely evaluated under realistic attack conditions. We introduce AgentCyberRange, the first open, multi-range infrastructure for measuring autonomous cyber attack capability in realistic cyber ranges. It combines 110 vulnerabilities across 15 real web applications and 8 enterprise-like cyber ranges with 156 internal hosts, plus Cage, a toolchain for execution, orchestration, result collection, and verification. The benchmark covers two core stages: web exploitation, where agents explore exposed applications and validate vulnerabilities, and post exploitation, where agents turn an initial foothold into broader internal compromise. We evaluate six frontier AI systems under matched prompts and budgets. GPT-5.5 with Codex performs best, solving 16.1% of web exploitation tasks and 31.7% of post-exploitation tasks; with more concrete hints, these rates increase to 33.0% and 46.3%. We also observe out-of-benchmark findings, including unknown vulnerabilities in popular projects, and payload mutation that bypasses host defenses. These results show that open cyber-range evaluation is necessary for observing emerging offensive capabilities under realistic and reproducible conditions.


翻译:前沿AI系统在网络安全任务中的能力日益增强,包括代码库审计、漏洞检测与利用。然而,由于缺乏开放、可复现的多主机网络靶场,对其攻击能力的评估仍受限于现有公开基准。当前基准测试多聚焦于CTF解题、漏洞复现与利用生成等孤立技能,却往往剥离了真实的入侵工作流:发现暴露服务、建立立足点、收集内部信息、跨主机扩大攻击面。这种缺失导致难以早期观测到新兴风险,因为前沿AI系统极少在真实攻击条件下接受评估。我们提出AgentCyberRange——首个用于在真实网络靶场中测量自主网络攻击能力的开放多靶场基础设施。该基准整合了横跨15个真实Web应用与8个企业级网络靶场(含156个内部主机)的110个漏洞,并配备Cage工具链实现执行、编排、结果采集与验证。基准测试覆盖两个核心阶段:Web利用阶段(智能体探索暴露应用并验证漏洞)与后利用阶段(智能体将初始立足点转化为更深层的内部入侵)。我们在匹配提示词与预算的条件下评估了六种前沿AI系统。配备Codex的GPT-5.5表现最佳,完成16.1%的Web利用任务与31.7%的后利用任务;在增加具体提示后,完成率分别提升至33.0%与46.3%。此外,我们还观察到基准范围外的发现,包括热门项目中的未知漏洞,以及可绕过主机防御的有效载荷变异。这些结果表明,开放网络靶场评估对于在真实且可复现条件下观测新兴攻击能力至关重要。

0
下载
关闭预览

相关内容

《人工智能在网络防御中的机遇》
专知会员服务
12+阅读 · 6月8日
AI 智能体系统:体系架构、应用场景及评估范式
前沿人工智能趋势报告(Frontier AI Trends Report)
专知会员服务
40+阅读 · 2025年12月20日
国防领域边缘计算:将智能推向行动前沿
专知会员服务
29+阅读 · 2025年4月6日
【新书】利用生成式人工智能进行网络防御策略
专知会员服务
33+阅读 · 2024年10月18日
边缘AI行业深度:边缘AI硬件,引领硬件创新时代
专知会员服务
52+阅读 · 2024年4月18日
《人工智能安全测评白皮书》,99页pdf
专知
36+阅读 · 2022年2月26日
AI综述专栏 | 基于深度学习的目标检测算法综述
人工智能前沿讲习班
12+阅读 · 2018年12月7日
【知识图谱】知识图谱+人工智能=新型网络信息体系
产业智能官
14+阅读 · 2018年11月18日
讲透RCNN, Fast-RCNN, Faster-RCNN,将CNN用于目标检测
数据挖掘入门与实战
18+阅读 · 2018年4月20日
深度学习在推荐系统上的应用
架构文摘
13+阅读 · 2018年2月22日
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
21+阅读 · 2012年12月31日
Arxiv
14+阅读 · 2023年8月7日
VIP会员
最新内容
《无人机脆弱性利用:网络空间力量的新域》
专知会员服务
2+阅读 · 今天4:08
美空军如何将人工智能从战场部署至后方机关
专知会员服务
11+阅读 · 7月31日
《史诗怒火行动:多域前瞻评估》49页报告
专知会员服务
7+阅读 · 7月31日
《英国防部:未来空战系统数字化战略》33页
专知会员服务
5+阅读 · 7月31日
《面向自主飞行网络的智能体人工智能架构》
专知会员服务
7+阅读 · 7月31日
“史诗怒火”行动:现代多域作战的重要节点
专知会员服务
8+阅读 · 7月30日
《下一代无线网络中的多无人机通信资源管理》
相关基金
国家自然科学基金
4+阅读 · 2017年12月31日
国家自然科学基金
0+阅读 · 2017年12月31日
国家自然科学基金
6+阅读 · 2017年12月31日
国家自然科学基金
2+阅读 · 2015年12月31日
国家自然科学基金
19+阅读 · 2015年12月31日
国家自然科学基金
1+阅读 · 2015年12月31日
国家自然科学基金
0+阅读 · 2015年12月31日
国家自然科学基金
21+阅读 · 2012年12月31日
Top
微信扫码咨询专知VIP会员