Autonomous Cyberattack with Security-Augmented Generative Artificial Intelligence

Jonathan Gregory, Qi Liao · 2024

Ethical hacking and penetration testing is a vital task by cybersecurity professionals to find and exploit possible vulnerabilities in a system before malicious actors do. However, system hacking has a high barrier to entry that necessitates years of experiential learning and formal education. The rapid development of generative artificial intelligence (AI) may potentially lower the barrier to entry. This research experiments with automatic penetration testing via large language models (LLMs) augmented with security information. This research uses a locally hosted Mistral 7B model with Low-Rank Adaptation (LoRA) fine-tuning and Retrieval-Augmented Generation (RAG) to improve penetration testing. When the LLMs are fine tuned with limited and unstructured security data such as privilege escalation articles from a few public web sites, the system succeeds in achieving privilege escalation on Linux hosts. The results of this research suggest that no-cost LLM-assisted penetration testing is possible even on ordinary PCs using locally hosted models. Future research is needed to achieve more diversified attacks and discover zero-day vulnerabilities, perhaps with better prompt engineering, models, and security data.

Read the paper · More papers on PaperTik