REVIEW 1 major objections 1 minor 45 references
Rising From the Ashes: How Agentic AI is Unblocking Challenges in Cybersecurity
T0 review · 1 major / 1 minor · reviewed 2026-06-26 · grok-4.3
Pith's one-line read Agentic AI expands the scope of feasible cybersecurity defenses by ingesting and reasoning over natural language or code.
desk verdict Position paper mapping cybersecurity bottlenecks to agentic AI with 16 untested case studies. read the letter →
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
The reading
What carries the argument
The mapping of open security problems to emergent agentic AI capabilities
What would settle it
A real-world test of agentic AI on supply chain security analysis that either cuts manual labor substantially without missing key issues or reveals new failure modes like incorrect threat assessments.
Extended reading notes
Core claim
Agentic AI has the potential to alleviate security bottlenecks by directly ingesting and reasoning over natural language or code, thereby expanding the scope of feasible defenses, as demonstrated by mapping open security problems to these capabilities and examining 16 case studies.
Load-bearing premise
The emergent capabilities of agentic AI systems will prove sufficient in practice to handle the mapped security problems without introducing unacceptable new risks or failure modes.
Editorial extensions
If this is right
- Previously inefficient security tasks become addressable.
- Defenders can tackle a wider range of problems including supply chain analysis.
- The cost of security decreases as AI handles more reasoning.
- More problems shift from unsolvable to feasible.
Reading between the lines
- Similar mappings could be applied to challenges in other fields with high manual costs.
- Successful use would require verifying that the AI does not introduce new vulnerabilities in security contexts.
- This could shift security work from direct task execution to higher-level oversight of AI agents.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper claims that many cybersecurity problems are labor-intensive bottlenecks that have historically been inefficient or unsolvable to address. It argues that agentic AI can alleviate these by directly ingesting and reasoning over natural language or code, thereby expanding feasible defenses. The central support is a mapping of open security problems to emergent agentic AI capabilities, illustrated by 16 case studies (including supply chain analysis).
Significance. If the mappings prove accurate and the case studies indicate practical pathways, the work could usefully frame research priorities at the AI-security intersection by identifying previously intractable problems that agentic systems might now make tractable. The contribution is conceptual rather than empirical; its value would lie in stimulating targeted implementations and risk analyses that build on the provided illustrations.
major comments (1)
- [Case studies section] Case studies (including supply chain analysis): The 16 illustrative case studies are presented as evidence of how agentic AI may benefit defenders, yet the manuscript reports no implementations, success metrics, ablation studies, reliability measurements, or analysis of new failure modes introduced by the agents. This directly leaves unaddressed whether the mapped tasks can be executed at acceptable reliability, which is load-bearing for the claim that agentic AI expands the scope of feasible defenses.
minor comments (1)
- [Abstract] The abstract and introduction would benefit from an explicit statement that the work is a position/mapping paper rather than an empirical evaluation, to set reader expectations for the nature of the evidence provided.
Simulated Author's Rebuttal
We thank the referee for the detailed review and for recognizing the conceptual nature of the work. We address the major comment below, clarifying the intended scope of the case studies while acknowledging the absence of empirical validation.
read point-by-point responses
-
Referee: [Case studies section] Case studies (including supply chain analysis): The 16 illustrative case studies are presented as evidence of how agentic AI may benefit defenders, yet the manuscript reports no implementations, success metrics, ablation studies, reliability measurements, or analysis of new failure modes introduced by the agents. This directly leaves unaddressed whether the mapped tasks can be executed at acceptable reliability, which is load-bearing for the claim that agentic AI expands the scope of feasible defenses.
Authors: We agree that the manuscript contains no implementations, metrics, ablations, reliability measurements, or analysis of agent-induced failure modes. The paper is explicitly positioned as a conceptual mapping of open security problems to emergent agentic AI capabilities, with the 16 case studies serving only as illustrations of potential pathways rather than as empirical demonstrations. The abstract and introduction frame the contribution as identifying previously intractable problems that agentic systems might now make tractable, without asserting that any have been solved at acceptable reliability. We will revise the manuscript to add an explicit Limitations and Scope section that states: (1) the case studies are speculative illustrations only, (2) no claims are made regarding executability or reliability, and (3) empirical validation, including reliability and new failure-mode analyses, is left to future targeted implementations. This revision will also temper language in the case-study section to emphasize 'potential' rather than 'benefit.' revision: partial
Circularity Check
No circularity; qualitative position paper with no derivations or self-referential reductions
full rationale
The paper maps open security problems to agentic AI capabilities via conceptual discussion and 16 illustrative case studies. No equations, fitted parameters, quantitative predictions, or load-bearing self-citations appear in the provided text or abstract. Claims rest on qualitative reasoning without any reduction of outputs to inputs by construction. This is the expected finding for a non-quantitative position paper.
Assumptions & free parameters
Cite this review
Pith. "Pith review of Rising From the Ashes: How Agentic AI is Unblocking Challenges in Cybersecurity." pith.science (2026). https://pith.science/paper/NHI6YDFQ
@misc{pith2026260623138,
author = {Pith},
title = {Pith review of: Rising From the Ashes: How Agentic AI is Unblocking Challenges in Cybersecurity},
year = {2026},
howpublished = {\url{https://pith.science/paper/NHI6YDFQ}},
note = {Machine review of arXiv:2606.23138}
}
read the original abstract
Security remains a high-cost challenge, with many problems historically deemed inefficient to address or effectively unsolvable. A significant number of these problems stem from labor-intensive tasks that create bottlenecks in defensive approaches. Agentic AI has the potential to alleviate these bottlenecks by directly ingesting and reasoning over natural language or code, thereby expanding the scope of feasible defenses. In this paper, we map open security problems to emergent agentic AI capabilities. To illustrate this potential, we examine 16 case studies, including supply chain analysis, highlighting how agentic AI may benefit defenders.
Reference graph
Works this paper leans on
-
[1]
Agentic ai: Autonomous intelligence for complex goals—a comprehensive survey.IEEe Access, 13:18912–18936, 2025
Deepak Bhaskar Acharya, Karthigeyan Kuppan, and B Divya. Agentic ai: Autonomous intelligence for complex goals—a comprehensive survey.IEEe Access, 13:18912–18936, 2025
2025
-
[2]
Ciocarlie, Vinod Yegneswaran, Somesh Jha, and Xiangyu Zhang
Mohannad Alhanahnah, Shiqing Ma, Ashish Gehani, Gabriela F. Ciocarlie, Vinod Yegneswaran, Somesh Jha, and Xiangyu Zhang. autompi: Automated multiple perspective attack investigation with semantics aware execution partitioning.IEEE Transactions on Software Engineering, 49(4):2761–2775, 2023. 8
2023
-
[3]
AEG: automatic exploit generation
Thanassis Avgerinos, Sang Kil Cha, Brent Lim Tze Hao, and David Brumley. AEG: automatic exploit generation. InProceedings of the Network and Distributed System Security Symposium, NDSS 2011, San Diego, California, USA, 6th February - 9th February 2011. The Internet Society, 2011
2011
-
[4]
Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750
Guru Baran. Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750. https://cybersecuritynews.com/ 73-unique-0-day-vulnerabilities-pwn2own/
-
[5]
Wild patterns: Ten years after the rise of adversarial machine learning
Battista Biggio and Fabio Roli. Wild patterns: Ten years after the rise of adversarial machine learning. In Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pages 2154– 2156, 2018
2018
-
[6]
Assessing claude mythos preview’s cybersecurity capabilities
Nicholas Carlini, Newton Cheng, Keane Lucas, Michael Moore, Milad Nasr, Vinay Prabhushankar, Winnie Xiao, Hakeem Angulu, Jackie Bow Evyatar Ben Asher, Keir Bradwell, Ben Buchanan, David Forsythe, Daniel Freeman, Alex Gaynor, Xinyang Ge, Logan Graham, Kyla Guru, Hasnain Lakhani, Matt McNiece, Mojtaba Mehrara, Renee Nichol, Adnan Pirzada, Sophia Porter, And...
2026
-
[7]
Mihai Christodorescu, Earlence Fernandes, Ashish Hooda, Somesh Jha, Johann Rehberger, Kamalika Chaudhuri, Xiaohan Fu, Khawaja Shams, Guy Amir, Jihye Choi, Sarthak Choudhary, Nils Palumbo, Andrey Labunets, and Nishit V . Pandya. Agent security is a systems problem.arXiv preprint arxiv.org:2605.18991, 2026
work page Pith review arXiv 2026
-
[8]
Rt-fuzzer: Task driven fuzzing of real time operating system firmware
Abraham Clements, Abel Gomez Rivera, Richard Ji- ayang Liu, Kirill Levchenko, Rick Kennell, and Gabriela Ciocarlie. Rt-fuzzer: Task driven fuzzing of real time operating system firmware. InNDSS Workshop on Binary Analysis Research (BAR), 2026
2026
Show all 45 references
-
[9]
Cobos and Selcen Cakir
E. Cobos and Selcen Cakir. A review of the economic costs of cyber incidents. Report, World Bank Group, 2024
2024
-
[10]
A comprehensive symbolic analysis of tls 1.3
Cas Cremers, Marko Horvat, Jonathan Hoyland, Sam Scott, and Thyla Van Der Merwe. A comprehensive symbolic analysis of tls 1.3. InProceedings of the 2017 ACM SIGSAC conference on computer and communica- tions security, pages 1773–1788, 2017
2017
-
[11]
Transparent Computing
DARPA. Transparent Computing. https://www.darpa.mil/ research/programs/transparent-computing
-
[12]
Translating c to safer rust.Proc
Mehmet Emre, Ryan Schroeder, Kyle Dewey, and Ben Hardekopf. Translating c to safer rust.Proc. ACM Program. Lang., 5(OOPSLA), October 2021
2021
-
[13]
Problems of monetary man- agement: the uk experience
Charles AE Goodhart. Problems of monetary man- agement: the uk experience. InMonetary theory and practice: The UK experience, pages 91–121. Springer, 1984
1984
-
[14]
Grimes, Gabriela F
Howard D. Grimes, Gabriela F. Ciocarlie, Robert J. Butler, and Wayne E. Austad. Microelectronics Offer Case Study for Securing Defense-Critical Supply Chains. https://www.afcea.org/signal-media/cyber-edge/ microelectronics-offer-case-study-securing-defense- critical-supply-chains
-
[15]
NoDoze: Combatting Threat Alert Fatigue with Auto- mated Provenance Triage
Wajih Ul Hassan, Shengjian Guo, Ding Li, Zhengzhang Chen, Kangkook Jee, Zhichun Li, and Adam Bates. NoDoze: Combatting Threat Alert Fatigue with Auto- mated Provenance Triage. InProceedings 2019 Network and Distributed System Security Symposium, San Diego, CA, 2019. Internet Society
2019
-
[16]
Transparency and accountability: unpacking the real problems of explain- able ai.AI & SOCIETY, 40(7):5587–5588, 2025
Afzal Hussain and Ashfaq Hussain. Transparency and accountability: unpacking the real problems of explain- able ai.AI & SOCIETY, 40(7):5587–5588, 2025
2025
-
[17]
Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Kyu Hyung Lee, Jignesh M
Hassaan Irshad, Gabriela F. Ciocarlie, Ashish Gehani, Vinod Yegneswaran, Kyu Hyung Lee, Jignesh M. Patel, Somesh Jha, Yonghwi Kwon, Dongyan Xu, and Xiangyu Zhang. TRACE: enterprise-wide provenance tracking for real-time APT detection.IEEE Trans. Inf. Forensics Secur., 16:4363–...
2021
-
[18]
Analyz- ing integrity protection in the selinux example policy
Trent Jaeger, Reiner Sailer, and Xiaolan Zhang. Analyz- ing integrity protection in the selinux example policy. In Usenix Security, 2003
2003
-
[19]
Ghosh, Vipin Swarup, Cliff Wang, and X
Sushil Jajodia, Anup K. Ghosh, Vipin Swarup, Cliff Wang, and X. Sean Wang, editors.Moving Target Defense: Creating Asymmetric Uncertainty for Cyber Threats, volume 54 ofAdvances in Information Security. Springer New York, New York, NY , 2011
2011
-
[20]
A survey on large language models for code generation.ACM Transactions on Software Engineering and Methodology, 35(2):1–72, 2026
Juyong Jiang, Fan Wang, Jiasi Shen, Sungju Kim, and Sunghun Kim. A survey on large language models for code generation.ACM Transactions on Software Engineering and Methodology, 35(2):1–72, 2026
2026
-
[21]
Kephart and D.M
J.O. Kephart and D.M. Chess. The vision of autonomic computing.Computer, 36(1):41–50, 2003
2003
-
[22]
King and Peter M
Samuel T. King and Peter M. Chen. Backtracking intrusions. InProceedings of the Nineteenth ACM Sym- posium on Operating Systems Principles, SOSP ’03, page 223–236, New York, NY , USA, 2003. Association for Computing Machinery
2003
-
[23]
sel4: Formal verification of an os kernel
Gerwin Klein, Kevin Elphinstone, Gernot Heiser, June Andronick, David Cock, Philip Derrin, Dhammika Elka- duwe, Kai Engelhardt, Rafal Kolanski, Michael Norrish, et al. sel4: Formal verification of an os kernel. In Proceedings of the ACM SIGOPS 22nd symposium on Operating syste...
2009
-
[24]
Rapid: Real-time alert investigation with context-aware prioritization for efficient threat discovery
Yushan Liu, Xiaokui Shu, Yixin Sun, Jiyong Jang, and Prateek Mittal. Rapid: Real-time alert investigation with context-aware prioritization for efficient threat discovery. InProceedings of the 38th Annual Computer Security Applications Conference, ACSAC ’22, page 827–840, New ...
2022
-
[25]
Locasto, Angelos Stavrou, Gabriela F
Michael E. Locasto, Angelos Stavrou, Gabriela F. Cretu, and Angelos D. Keromytis. From stem to sead: specula- tive execution for automated defense. In2007 USENIX Annual Technical Conference on Proceedings of the USENIX Annual Technical Conference, ATC’07, USA,
-
[26]
Integrating flexible support for security policies into the linux operating system
Peter Loscocco and Stephen Smalley. Integrating flexible support for security policies into the linux operating system. In2001 USENIX Annual Technical Conference (USENIX ATC 01), Boston, MA, June 2001. USENIX 9 Association
2001
-
[27]
MPI: Multiple per- spective attack investigation with semantic aware execu- tion partitioning
Shiqing Ma, Juan Zhai, Fei Wang, Kyu Hyung Lee, Xiangyu Zhang, and Dongyan Xu. MPI: Multiple per- spective attack investigation with semantic aware execu- tion partitioning. In26th USENIX Security Symposium (USENIX Security 17), pages 1111–1128, Vancouver, BC, August 2017. USE...
2017
-
[28]
Adversarial robustness of deep neural networks: A survey from a formal verification perspective.IEEE Transactions on Dependable and Secure Computing, 2022
Mark Huasong Meng, Guangdong Bai, Sin Gee Teo, Zhe Hou, Yan Xiao, Yun Lin, and Jin Song Dong. Adversarial robustness of deep neural networks: A survey from a formal verification perspective.IEEE Transactions on Dependable and Secure Computing, 2022
2022
-
[29]
Debloating software through Piece-Wise compilation and loading
Anh Quach, Aravind Prakash, and Lok Yan. Debloating software through Piece-Wise compilation and loading. In27th USENIX Security Symposium (USENIX Secu- rity 18), pages 869–886, Baltimore, MD, August 2018. USENIX Association
2018
-
[30]
Language models are unsupervised multitask learners.OpenAI blog, 2019
Alec Radford, Jeffrey Wu, Rewon Child, David Luan, Dario Amodei, Ilya Sutskever, et al. Language models are unsupervised multitask learners.OpenAI blog, 2019
2019
-
[31]
Attributing cyber attacks.Journal of Strategic Studies, 38(1-2):4–37, 2015
Thomas Rid and Ben Buchanan. Attributing cyber attacks.Journal of Strategic Studies, 38(1-2):4–37, 2015
2015
-
[32]
Sabelfeld and A.C
A. Sabelfeld and A.C. Myers. Language-based information-flow security.IEEE Journal on Selected Areas in Communications, 21(1):5–19, 2003
2003
-
[33]
Quickest detection of advanced persistent threats: A semi-markov game approach
Dinuka Sahabandu, Joey Allen, Shana Moothedath, Linda Bushnell, Wenke Lee, and Radha Poovendran. Quickest detection of advanced persistent threats: A semi-markov game approach. In2020 ACM/IEEE 11th International Conference on Cyber-Physical Systems (IC- CPS), pages 9–19, 2020
2020
-
[34]
Dift games: Dynamic information flow tracking games for advanced persistent threats
Dinuka Sahabandu, Baicen Xiao, Andrew Clark, Sangho Lee, Wenke Lee, and Radha Poovendran. Dift games: Dynamic information flow tracking games for advanced persistent threats. In2018 IEEE Conference on Decision and Control (CDC), pages 1136–1143, 2018
2018
-
[35]
Stolfo.A Survey of Insider Attack Detection Research, pages 69–90
Malek Ben Salem, Shlomo Hershkop, and Salvatore J. Stolfo.A Survey of Insider Attack Detection Research, pages 69–90. Springer US, Boston, MA, 2008
2008
-
[36]
Automatic reverse engineering of malware emulators
Monirul Sharif, Andrea Lanzi, Jonathon Giffin, and Wenke Lee. Automatic reverse engineering of malware emulators. In2009 30th IEEE Symposium on Security and Privacy, pages 94–109, 2009
2009
-
[37]
Long-span program behavior modeling and attack detection.ACM Trans
Xiaokui Shu, Danfeng (Daphne) Yao, Naren Ramakr- ishnan, and Trent Jaeger. Long-span program behavior modeling and attack detection.ACM Trans. Priv. Secur., 20(4), September 2017
2017
-
[38]
On adaptive attacks to adversarial example defenses.Advances in neural information pro- cessing systems, 33:1633–1645, 2020
Florian Tramer, Nicholas Carlini, Wieland Brendel, and Aleksander Madry. On adaptive attacks to adversarial example defenses.Advances in neural information pro- cessing systems, 33:1633–1645, 2020
2020
-
[39]
Jon Vadillo, Roberto Santana, and Jose A Lozano. Ad- versarial attacks in explainable machine learning: A survey of threats against models and humans.Wiley Interdisciplinary Reviews: Data Mining and Knowledge Discovery, 15(1):e1567, 2025
2025
-
[40]
Advanced code evolution techniques and computer virus generator kits
John von Neumann. Advanced code evolution techniques and computer virus generator kits
-
[41]
The honeynet project: Data collection tools, infrastructure, archives and analy- sis
David Watson and Jamie Riden. The honeynet project: Data collection tools, infrastructure, archives and analy- sis. In2008 WOMBAT Workshop on Information Security Threats Data Collection and Sharing, pages 24–30, 2008
2008
-
[42]
Research directions in software supply chain security.ACM Transactions on Software Engineering and Methodology, 34(5):1–38, 2025
Laurie Williams, Giacomo Benedetti, Sivana Hamer, Ranindya Paramitha, Imranur Rahman, Mahzabin Tamanna, Greg Tystahl, Nusrat Zahan, Patrick Morrison, Yasemin Acar, et al. Research directions in software supply chain security.ACM Transactions on Software Engineering and Methodo...
2025
-
[43]
Secv: Secure code partitioning via multi- language secure values
Peterson Yuhala, Pascal Felber, Hugo Guiroux, Jean- Pierre Lozi, Alain Tchana, Valerio Schiavoni, and Ga ¨el Thomas. Secv: Secure code partitioning via multi- language secure values. InProceedings of the 24th International Middleware Conference, Middleware ’23, page 207–219, N...
2023
-
[44]
Dorner, and Moritz Hardt
Guanhua Zhang, Florian E. Dorner, and Moritz Hardt. How benchmark prediction from fewer data misses the mark. InThe Thirty-ninth Annual Conference on Neural Information Processing Systems, 2025
2025
-
[45]
Webarena: A realistic web environment for building autonomous agents
Shuyan Zhou, Frank F Xu, Hao Zhu, Xuhui Zhou, Robert Lo, Abishek Sridhar, Xianyi Cheng, Tianyue Ou, Yonatan Bisk, Daniel Fried, et al. Webarena: A realistic web environment for building autonomous agents. In International Conference on Learning Representations, volume 2024, pa...
2024
Reviewed June 26, 2026 · model on record in the stance chip above.
Discussion (0). Sign in to comment.