Fetching the paper…
Reading the bibliography…
Penetration testing, a crucial industrial practice for ensuring system security, has traditionally resisted automation due to the extensive expertise required by human professionals.
K. Barbar, “Attributed tree grammars,” Theoretical Computer Science , vol. 119, no. 1, pp. 3–22, 1993. [Online]. Available: https://www.sciencedirect.com/science/article/pii/030439759390337S
1993
Earlier work this paper cites.
B. Arkin, S. Stender, and G. McGraw, “Software penetration testing,” IEEE Security & Privacy , vol. 3, no. 1, pp. 84–87, 2005
2005
Earlier work this paper cites.
S. Mauw and M. Oostdijk, “Foundations of attack trees,” vol. 3935, 07 2006, pp. 186–198
2006
Earlier work this paper cites.
N. Antunes and M. Vieira, “Benchmarking vulnerability detection tools for web services,” in 2010 IEEE International Conference on Web Services . IEEE, 2010, pp. 203–210
2010
Earlier work this paper cites.
P. Xiong and L. Peyton, “A model-driven penetration test framework for web applications,” in 2010 Eighth International Conference on Privacy, Security and Trust . IEEE, 2010, pp. 173–180
2010
Earlier work this paper cites.
NIST and E. Aroms, “Nist special publication 800-115 technical guide to information security testing and assessment,” 2012
2012
Earlier work this paper cites.
J. Yeo, “Using penetration testing to enhance your company’s security,” Computer Fraud & Security , vol. 2013, no. 4, pp. 17–20, 2013
2013
Earlier work this paper cites.
G. Weidman, Penetration testing: a hands-on introduction to hacking . No starch press, 2014
2014
Earlier work this paper cites.
A. Applebaum, D. Miller, B. Strom, H. Foster, and C. Thomas, “Analysis of automated adversary emulation techniques,” in Proceedings of the Summer Simulation Multi-Conference . Society for Computer Simulation International, 2017, p. 16
2017
Earlier work this paper cites.
F. Abu-Dabaseh and E. Alshammari, “Automated penetration testing: An overview,” in The 4th International Conference on Natural Language Computing, Copenhagen, Denmark , 2018, pp. 121–129
2018
Earlier work this paper cites.
Sep 2018. [Online]. Available: https://forum.hackthebox.com/t/carrier/963
2018
Earlier work this paper cites.
2019
Earlier work this paper cites.
S. Rahalkar and S. Rahalkar, “Openvas,” Quick Start Guide to Penetration Testing: With NMAP, OpenVAS and Metasploit , pp. 47–71, 2019
2019
Earlier work this paper cites.
H. S. Lallie, K. Debattista, and J. Bal, “A review of attack graph and attack tree visual syntax in cyber security,” Computer Science Review , vol. 35, p. 100219, 2020. [Online]. Available: https://www.sciencedirect.com/science/article/pii/S1574013719300772
2020
Earlier work this paper cites.
MITRE, “Common Weakness Enumeration (CWE),” https://cwe.mitre.org/index.html , 2021
2021
Earlier work this paper cites.
[Online]. Available: https://picoctf.org/competitions/2021-redpwn.html
2021
Earlier work this paper cites.
E. Collins, “Lamda: Our breakthrough conversation technology,” May 2021. [Online]. Available: https://blog.google/technology/ai/lamda/
2021
Earlier work this paper cites.
J. Wang, X. Yi, R. Guo, H. Jin, P. Xu, S. Li, X. Wang, X. Guo, C. Li, X. Xu et al. , “Milvus: A purpose-built vector data management system,” in Proceedings of the 2021 International Conference on Management of Data , 2021, pp. 2614–2627
2021
Earlier work this paper cites.
2022
Cited alongside, same era.
H. Pearce, B. Ahmad, B. Tan, B. Dolan-Gavitt, and R. Karri, “Asleep at the keyboard? assessing the security of github copilot’s code contributions,” in 2022 IEEE Symposium on Security and Privacy (SP) . IEEE, 2022, pp. 754–768
2022
Cited alongside, same era.
“OWASP Juice-Shop Project,” https://owasp.org/www-project-juice-shop/ , 2022
2022
Cited alongside, same era.
B. Guimaraes and M. Stampar, “sqlmap: Automatic SQL injection and database takeover tool,” https://sqlmap.org/ , 2022
2022
Cited alongside, same era.
R. Guo, X. Luan, L. Xiang, X. Yan, X. Yi, J. Luo, Q. Cheng, W. Xu, J. Luo, F. Liu et al. , “Manu: a cloud native vector database management system,” Proceedings of the VLDB Endowment , vol. 15, no. 12, pp. 3548–3561, 2022
2023
Closest in time.
J. Wei, X. Wang, D. Schuurmans, M. Bosma, B. Ichter, F. Xia, E. Chi, Q. Le, and D. Zhou, “Chain-of-thought prompting elicits reasoning in large language models,” 2023
2023
Closest in time.
H. Sun, X. Li, Y. Xu, Y. Homma, Q. Cao, M. Wu, J. Jiao, and D. Charles, “Autohint: Automatic prompt optimization with hint generation,” 2023
2023
Closest in time.
2023
Closest in time.
alphaXiv searches the wider corpus for related work and actual follow-ups.
alphaXiv is searching for related work…
2022
Cited alongside, same era.
2023
Cited alongside, same era.
2023
Cited alongside, same era.
V. Mayoral-Vilches, G. Deng, Y. Liu, M. Pinzger, and S. Rass, “Exploitflow, cyber security exploitation routes for game theory and ai research in robotics,” 2023
2023
Cited alongside, same era.
Y. Zhang, W. Song, Z. Ji, Danfeng, Yao, and N. Meng, “How well does llm generate security tests?” 2023
2023
Cited alongside, same era.
“Models - openai api,” https://platform.openai.com/docs/models/ , (Accessed on 02/02/2023)
2023
Cited alongside, same era.
“Gpt-4,” https://openai.com/research/gpt-4 , (Accessed on 06/30/2023)
2023
Cited alongside, same era.
2023
Cited alongside, same era.
Y. Liu, Y. Yao, J.-F. Ton, X. Zhang, R. Guo, H. Cheng, Y. Klochkov, M. F. Taufiq, and H. Li, “Trustworthy llms: a survey and guideline for evaluating large language models’ alignment,” 2023
2023
Closest in time.
2023
Closest in time.
2023
Closest in time.
Z. He, Z. Li, S. Yang, A. Qiao, X. Zhang, X. Luo, and T. Chen, “Large language models for blockchain security: A systematic literature review,” 2024
2024
Closest in time.
G. Wang, Y. Li, Y. Liu, G. Deng, T. Li, G. Xu, Y. Liu, H. Wang, and K. Wang, “Metmap: Metamorphic testing for detecting false vector matching problems in llm augmented generation,” 2024
2024
Closest in time.
Y. Li, Y. Liu, G. Deng, Y. Zhang, W. Song, L. Shi, K. Wang, Y. Li, Y. Liu, and H. Wang, “Glitch tokens in large language models: Categorization taxonomy and effective detection,” 2024
2024
Closest in time.
N. Li, Y. Li, Y. Liu, L. Shi, K. Wang, and H. Wang, “Halluvault: A novel logic programming-aided metamorphic testing framework for detecting fact-conflicting hallucinations in large language models,” 2024
2024
Closest in time.
G. Deng, Y. Liu, Y. Li, K. Wang, Y. Zhang, Z. Li, H. Wang, T. Zhang, and Y. Liu, “Masterkey: Automated jailbreaking of large language model chatbots,” in Proceedings 2024 Network and Distributed System Security Symposium , ser. NDSS 2024. Internet Society, 2024. [Online]. Available: http://dx.doi.org/10.14722/ndss.2024.24188
2024
Closest in time.
Y. Liu, G. Deng, Y. Li, K. Wang, Z. Wang, X. Wang, T. Zhang, Y. Liu, H. Wang, Y. Zheng, and Y. Liu, “Prompt injection attack against llm-integrated applications,” 2024
2024
Closest in time.
J. Li, Y. Liu, C. Liu, L. Shi, X. Ren, Y. Zheng, Y. Liu, and Y. Xue, “A cross-language investigation into jailbreak attacks in large language models,” 2024
2024
Closest in time.
G. Deng, Y. Liu, K. Wang, Y. Li, T. Zhang, and Y. Liu, “Pandora: Jailbreak gpts by retrieval augmented generation poisoning,” 2024
2024
Closest in time.
H. Li, G. Deng, Y. Liu, K. Wang, Y. Li, T. Zhang, Y. Liu, G. Xu, G. Xu, and H. Wang, “Digger: Detecting copyright content mis-usage in large language model training,” 2024
2024
Closest in time.
Z. Chang, M. Li, Y. Liu, J. Wang, Q. Wang, and Y. Liu, “Play guessing game with llm: Indirect jailbreak attack with implicit clues,” 2024
2024
Closest in time.