LATIDIA · Ciberseguridad
CyberPersistBench: Evaluating LLM-Based Cyber Attackers on Installation and Persistence
arXiv: 2609.36573v1 Tipo de anuncio: nuevo Resumen: Si bien los atacantes basados en LLM muestran una creciente competencia en la explotación de vulnerabilidades, la mayoría de los puntos de referencia de ciberseguridad existentes sufren un truncamiento de una sola etapa, prematuramente
WhatsApp ↗Telegram ↗
La noticia
arXiv:2609.36573v1 Announce Type: new Abstract: While LLM-based attackers exhibit growing proficiency in vulnerability exploitation, most existing cybersecurity benchmarks suffer from single-stage truncation, prematurely terminating evaluation upon initial access. In practice, initial footholds are exceptionally fragile across operational disruptions such as service restarts and host reboots. Whether LLM-based attackers can establish and maintain durable footholds beyond initial compromise remains a central blind spot in cybersecurity evaluation. To bridge this gap, we introduce CyberPersistBench, the first benchmark dedicated to post-compromise installation and persistence. Decoupled from upfront exploitation, CyberPersistBench frames persistence as an adversarial survival task in which agents use native host mechanisms to maintain footholds across staged system disruptions. Deterministic checks support