hzysvilla GitHub avatar

Agent4Pentest_Survey

hzysvilla

A curated paper list and companion repository for a survey on LLM-driven penetration testing, featuring a taxonomy of 81 papers across 6 categories and a four-phase architectural evolution.

Stars

88

7-day growth

No data

Forks

2

Open issues

0

License

No data

Last updated

2026-07-11

AI repository intelligence
FR-AI / ANALYSIS

Why it is worth attention

It provides a structured, up-to-date taxonomy of the fast-growing field of AI-driven penetration testing, traces the co-evolution of benchmarks and agents, is actively maintained with community contributions, and includes a verified list of commercial systems.

Who it is for

  • Cybersecurity researchers and practitioners
  • AI and LLM agent developers
  • Penetration testers and red-team operators
  • Graduate students in cybersecurity and AI

Use cases

  • Conducting literature reviews on automated penetration testing
  • Identifying research gaps and trends in LLM-driven offensive security
  • Benchmarking new systems against the provided taxonomy and corpus
  • Evaluating commercial pentesting platforms against academic work

Strengths

  • Comprehensive corpus of 81 papers systematically categorized into 6 research categories
  • Clearly defined four-phase architectural evolution from text-only reasoning to reinforcement learning
  • Actively maintained with pull requests and additions beyond the original survey
  • Includes a verified list of 8 commercial systems for industry context

Considerations

  • Survey corpus is fixed to papers published between 2023 and June 2026, potentially missing later work
  • Not all listed papers have publicly available code or datasets
  • Taxonomy assigns each paper to a single primary category, which may oversimplify multi-faceted contributions

README quick start

A Survey of LLM-Driven Penetration Testing: Taxonomy, Co-Evolution, and Open Challenges

Agent4Pentest: A Curated Paper List and Survey Companion

English | 简体中文

Survey corpus: 81 papers · 6 research categories · 2023–June 2026

Agent4Pentest is a curated paper list for LLM-driven and agent-based penetration testing and the official companion repository for A Survey of LLM-Driven Penetration Testing: Taxonomy, Co-Evolution, and Open Challenges.

We continuously maintain this collection, add newly released work, and welcome researchers to contribute their papers, benchmarks, systems, datasets, and code through Pull Requests.

[!NOTE] The survey analyzes a fixed corpus of 81 works released between 2023 and June 2026. This repository is a living index and may grow beyond the original survey corpus as the field evolves.

Table of Contents


Research Landscape

The survey maps Agent4Pentest through a six-category taxonomy and a four-phase architectural evolution, then relates this progression to the parallel expansion of benchmark and CTF-based training infrastructure.

Four-Phase Architectural Evolution

PhaseCore shiftMain bottleneck
I. Text-only Reasoning (2023)LLMs reason over the engagement state while humans execute every command.Execution autonomy and high human dependence
II. Tool-augmented Single Agents (2023–2024)A single agent directly invokes scanners, exploit frameworks, and shells.Context management and reasoning degradation on long tasks
III. Multi-agent Coordination (2024–2025)Specialized subagents split the attack pipeline under an orchestrator, enabling structured handoffs and parallel execution.Training-data scarcity and dependence on human demonstrati

Related repositories

Similar projects matched by category, topics, and programming language.

MoonshotAI
Featured
MoonshotAI GitHub avatar

Kimi-K3

Kimi K3 is an open-weight, 2.8T-parameter native multimodal agentic model with a 1M-token context window, designed for frontier coding, knowledge work, and reasoning tasks.

AI & Machine LearningAI Agents
3,348
xuchonglang
Featured
xuchonglang GitHub avatar

investing-for-beginners

A structured investing guide for Chinese beginners covering US stocks, options, and cryptocurrency, with focus on foundational concepts and risk awareness.

Blockchain & Web3
2,739
Krishnagangwal
Featured
Krishnagangwal GitHub avatar

CS-Fundamentals

A curated collection of Computer Science fundamentals (PDFs, notes, cheatsheets, interview question banks) for placement preparation, covering seven core subjects plus general resources.

Data & DatabasesDatabases & Storage
2,326