paper-with-me

홈 › Papers

AutoEG: Exploiting Known Third-Party Vulnerabilities in Black-Box Web Applications

2026-04-01 · Ruozhao Yang, Mingfei Cheng, Gelei Deng, Junjie Wang, Tianwei Zhang, Xiaofei Xie arxiv

Large-scale web applications are widely deployed with complex third-party components, inheriting security risks arising from component vulnerabilities. Security assessment is therefore required to determine whether such known vulnerabilities remain practically exploitable in real applications. Penetration testing is a widely adopted approach that validates exploitability by launching concrete attacks against known vulnerabilities in real-world black-box systems. However, existing approaches often fail to automatically generate reliable exploits, limiting their effectiveness in practical security assessment. This limitation mainly stems from two issues: (1) precisely triggering vulnerabilities with correct technical details, and (2) adapting exploits to diverse real-world deployment settings. In this paper, we propose AutoEG, a fully automated multi-agent framework for exploit generation targeting black-box web applications. AutoEG has two phases: First, AutoEG extracts precise vulnerability trigger logic from unstructured vulnerability information and encapsulates it into reusable trigger functions. Second, AutoEG uses trigger functions for concrete attack objectives and iteratively refines exploits through feedback-driven interaction with the target application. We evaluate AutoEG on 104 real-world vulnerabilities with 29 attack objectives, resulting in 660 exploitation tasks and 55,440 exploit attempts. AutoEG achieves an average success rate of 82.41%, substantially outperforming state-of-the-art baselines, whose best performance reaches only 32.88%.

📄 PDF Abstract BibTeX arXiv:2604.00704

Code (0)

등록된 구현이 없습니다.

Similar Papers 제목 키워드 기반

Attacks on Third-Party APIs of Large Language Models

2024-04-24 · Wanru Zhao, Vidit Khazanchi, Haodi Xing, Xuanli He 외

Large language model (LLM) services have recently begun offering a plugin ecosystem to interact with third-party API services. This innovation enhances the capabilities of LLMs, but it also introduces risks, as these plu…

Language ModelingLanguage ModellingLarge Language Model

Mining Threat Intelligence about Open-Source Projects and Libraries from Code Repository Issues and Bug Reports

2018-08-09 · Lorenzo Neil, Sudip Mittal, Anupam Joshi

Open-Source Projects and Libraries are being used in software development while also bearing multiple security vulnerabilities. This use of third party ecosystem creates a new kind of attack surface for a product in deve…

When AI Meets the Web: Prompt Injection Risks in Third-Party AI Chatbot Plugins

2025-11-08 · Yigitcan Kaya, Anton Landerer, Stijn Pletinckx, Michelle Zimmermann 외 arxiv

Prompt injection attacks pose a critical threat to large language models (LLMs), with prior work focusing on cutting-edge LLM applications like personal copilots. In contrast, simpler LLM applications, such as customer s…

Code Generation

AutoEG: Automated Experience Grafting for Off-Policy Deep Reinforcement Learning

2020-04-22 · Keting Lu, Shiqi Zhang, Xiaoping Chen

Deep reinforcement learning (RL) algorithms frequently require prohibitive interaction experience to ensure the quality of learned policies. The limitation is partly because the agent cannot learn much from the many low-…

Deep Reinforcement Learningreinforcement-learningReinforcement LearningReinforcement Learning (RL)

Enriching Vulnerability Reports Through Automated and Augmented Description Summarization

2022-10-03 · Hattan Althebeiti, David Mohaisen

Security incidents and data breaches are increasing rapidly, and only a fraction of them is being reported. Public vulnerability databases, e.g., national vulnerability database (NVD) and common vulnerability and exposur…

Language ModelingLanguage Modelling