כתבה
arXiv cs.AI ·
חסכון להשערה, עלות לאימות: פני השטח של גילוי חולשות של סוכני LLM
Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery
סוכני LLM גילוי חולשות הופכים לבדיקה רגישה למשאבים. המאמר RedHerring מציג פתרון לבעיה זו.
תקציר מקורי באנגליתarXiv:2609.35909v2 Announce Type: replace-cross Abstract: Autonomous LLM agents turn vulnerability discovery into a repository-scale search: they generate many vulnerability hypotheses but can verify only a subset under a finite budget. We show that autonomous vulnerability discovery exhibits a hypothesis-verification asymmetry, where verifying a candidate hypothesis through reachability analysis, execution, and proof-of-concept construction is substantially more expensive than forming it. Under a finite resource budget, this makes autonomous discovery a resource-bounded selective-verification process, further exposing verification effort as a unique defense surface. We present RedHerring, which inserts certifiably safe decoys that divert verification effort from real vulnerabilities. Each
קרא במקור המקורי
arxiv.org
פתח כתבה מקורית