REVIEW 3 major objections 5 minor 1 cited by
The paper claims that LLM-driven autonomous agents for offensive security are indeterminate in actions, impacts, and users, and that their joint shift gives attackers a short-term advantage over existing ethical and governance frameworks.
Reviewed by Pith at T0; open to challenge. T0 means a machine referee read the full paper against a public rubric. the ladder, T0–T4 →
T0 review · deepseek-v4-flash
2026-08-01 10:19 UTC pith:DRKQA4GL
load-bearing objection Genuinely useful conceptual framing of agentic pen-testing ethics; fix the independence claim and soften the empirical overreach before I'd fully trust it. the 3 major comments →
The Ethics of Autonomous AI Agents for Offensive Security
The pith
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The central claim is that agentic offensive AI occupies a regime no prior class of offensive tooling has occupied. Traditional tools were determinate on at least one axis: a fuzzer has unbounded discovery scope but bounded users and inert impact; an exploit framework can democratize access while keeping a curated module set; a scanner used in an operational environment may have indeterminate impact but is bounded by users and rules of engagement. LLM-driven agents are indeterminate on three independent dimensions at once. Because the dimensions are independent, mitigations that previously compensated for one axis—such as bounding the action space to compensate for broadened access—no longer
What carries the argument
The key machinery is the 'indeterminacy triplet'—an analytical lens that classifies a tool along three independent dimensions: the action space (deterministic vs. non-deterministic, explainable vs. opaque), the impact scope (bounded to specified targets vs. open-ended), and the user population (restricted by skill vs. commodified). The paper uses this triplet to identify the qualitative shift: while each dimension has historical precedent, no prior offensive tool combined all three. The triplet does the argumentative work of showing why previous mitigation strategies—like keeping action spaces enumerable, relying on operator skill, or scoping impact through rules of engagement—fail when all
Load-bearing premise
The load-bearing premise is that LLM outputs are intrinsically opaque, resisting both ex-ante and ex-post explanation; if explainability tools such as mechanistic interpretability, deterministic inference, or reliable logging improve substantially in the near term, the joint-indeterminacy regime weakens and the diffuse-moral-attribution conclusion loses force.
What would settle it
A decisive test: deploy an autonomous penetration-testing agent with a perfect action log, a deterministic planning core, and an interpretability layer that enables a human operator to predict every action before execution and explain every action after it occurs. If such a system achieves the same success rate as current non-deterministic agents on the same benchmark, then the 'indeterminacy of actions' dimension is not intrinsic, and the paper's regime-shift claim fails for that dimension. A second falsifier is a time-series measure of the cost of a successful attack versus the cost of detec
If this is right
- Existing dual-use mechanisms—responsible disclosure, export controls, and know-your-customer review—assume a determinate, bounded tool; they lose traction when applied to agents whose actions, impact, and user base are all open-ended.
- Moral responsibility for harms caused by an autonomous offensive agent becomes diffuse across the user, the tool-maker, the model provider, and third parties; the paper argues no single agent has both free action and epistemic insight to bear full responsibility.
- The short-term net effect favors attackers: LLM agents industrialize offensive capability while defensive workflows remain human-intensive, as illustrated by bug-bounty programs being flooded and maintainers' review burden growing.
- Human-in-the-loop oversight, logging, and scaffold-level safety review are necessary but not sufficient; the paper recommends structured access for high-capability models and explicit threat models for scaffolds.
- In the long run, the same technology could democratize defensive practice, but only if deliberate training pipelines and governance measures are built before the market consolidates.
Where Pith is reading between the lines
- Editorial inference: If the indeterminacy of actions is a property of current stochastic LLMs rather than an irreducible feature of the technology, a future advance in mechanistic interpretability could collapse the first dimension; the paper's 'qualitatively new regime' claim would then be a statement about the present generation, not about all future agentic tools.
- Editorial inference: The offense-defense cost asymmetry may not be permanent; if defensive AI agents reach parity with offensive ones, the short-term attacker advantage could reverse. The paper treats the balance as structurally asymmetric, but the trajectory is an empirical question it does not settle.
- Editorial inference: The indeterminacy triplet can be reused as a diagnostic for other dual-use AI domains, such as automated social engineering or disinformation, where action, impact, and user base may shift similarly.
- Editorial inference: A testable extension would be to measure the actual cost ratio of launching an autonomous attack versus defending against the same attack across a fixed benchmark; if the ratio is not large, or if it falls over time, the paper's claim that attackers have a short-term advantage would need revision.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. This paper offers a conceptual and normative analysis of LLM-driven autonomous agents used for offensive security. It argues that, unlike traditional deterministic penetration-testing tools, agentic tools exhibit indeterminacy along three purportedly independent dimensions: opacity/non-determinism of actions, open-ended impact, and democratized user access. The paper claims that their simultaneous occurrence constitutes a qualitatively new regime that existing dual-use and AI-ethics frameworks cannot handle, and that the resulting offense-defense cost asymmetry favors attackers in the short term. It then applies multiple ethical frameworks (deontology, consequentialism, virtue ethics, value sensitive design, moral agency theory) to analyze diffuse moral attribution across users, tool-makers, model-makers, and third parties, and concludes with stakeholder-specific recommendations.
Significance. If the joint-indeterminacy thesis is correct, the paper identifies a genuinely new configuration in cybersecurity ethics and gives useful, action-oriented guidance for researchers, model-makers, and regulators. The multi-framework approach is a strength, as is the paper's explicit caution about vendor benchmarks (footnote 3) and its acknowledgment of colliding ethical traditions. However, the central 'three independent dimensions' claim contains internal tensions that need repair, and the empirical basis for the headline 'net short-term effect favors attackers' is thinner than the abstract suggests. The work is nonetheless a valuable contribution to an emerging area, provided the load-bearing conceptual claims are clarified.
major comments (3)
- [Abstract and §4.1] The claimed independence of the three indeterminacy dimensions is internally inconsistent. The Abstract states that impact is 'open-ended due to the non-deterministic actions, agency of utilized models, and opaque LLM supply-chains,' and §4.1 concludes that agents are 'indeterminate in scope and capabilities' directly from non-determinism and supply-chain opacity. If impact indeterminacy is a downstream consequence of action indeterminacy, then the dimensions are not independent, and the 'qualitatively different regime' claim—which the paper explicitly rests on the simultaneous shift of three independent dimensions—is weakened. Please either justify genuine independence with a non-causal notion of 'independence,' or revise the claim to describe three distinct but causally coupled aspects of indeterminacy.
- [Abstract and §8.1] There is a tension between the claim that LLM outputs 'resist both ex-ante and ex-post explanation' and the recommendation in §8.1 to 'incorporate logging tools, facilitating traceability and ex-post incident analysis.' If logging can provide ex-post traceability, then ex-post opacity is not an intrinsic property of agentic tools but is contingent on current tooling and deployment choices. Because the diffuse-moral-attribution argument relies on this opacity, the paper should either specify what remains opaque even with logging, or restrict the opacity claim to current default deployments. As written, the two statements are in direct conflict.
- [Abstract and §7.1 / footnote 3] The empirical claim that 'the net short-term effect favors attackers' is load-bearing for the paper's risk assessment, but the evidence marshaled in §7.1 is mixed. The cURL case shows both overwhelming low-quality reports and later high-quality LLM-assisted reports that maintainers found useful; Mozilla and Linux CVE numbers are framed as defender-side benefits. The paper's own footnote 3 concedes that vendor-published benchmarks are 'not independently reproducible.' The claim may be defensible on structural cost-asymmetry grounds, but the paper should either provide a more explicit argument for why offense-side industrialization dominates the observed defender-side benefits, or soften the abstract's assertive phrasing.
minor comments (5)
- [Section 2.1, footnote 3; §8.1] Several capability claims, including the cochise factor-of-16–25x improvement (ref. 25), cite the authors' own preprints or prototypes. The disclosure in the back matter is good, but the main text should explicitly flag author-affiliated results as self-reported capability evidence, particularly because footnote 3 already cautions about benchmark reproducibility.
- [Section 8.1] The recommendation for model-makers is internally abrupt: 'We advocate for open-weight models for accessibility and transparency reasons. Yet, if you are creating LLMs with offensive cybersecurity capabilities, we recommend keeping them closed-weight.' This is a reasonable capability-specific exception, but it needs a transition sentence explaining the general/exception structure to avoid reading as a contradiction.
- [Section 7.2] Minor grammar issue: 'does not only poses a direct, but also an indirect threat' should be 'does not only pose a direct threat, but also an indirect one.'
- [References] Reference [53] is cited as 'Daniel Sternber blog' but should be 'Daniel Stenberg's blog.' Also, some arXiv preprints lack version identifiers; this is acceptable but inconsistent formatting should be harmonized.
- [Section 2.3] The observation that 'corporations prefer fully autonomous solutions and will therefore forgo HITL-oversight' is asserted without citation. It is plausible but should be framed as an assumption rather than an established fact, since it supports later HITL-related recommendations.
Circularity Check
No circularity: the paper is a conceptual ethical analysis, not a derivation from fitted inputs or self-citation chains.
full rationale
This paper is a conceptual and normative analysis, not an empirical derivation. It contains no equations, no fitted parameters, no predictions computed from data, and no uniqueness theorem invoked to force a conclusion. The central claim—that LLM agents differ from traditional pen-testing tools along action, impact, and user indeterminacy—is argued from described technical properties (non-deterministic sampling, general-purpose scaffolds, commodified access) rather than derived from those properties by construction. Self-citations (e.g., cochise [24], [25]) are used as illustrative capability evidence and are explicitly qualified in footnote 3 as indicative landscape descriptions, not as the normative foundation. The apparent tension that impact indeterminacy is said to be 'due to' non-deterministic actions while the three dimensions are claimed to be 'not derivable from one another' is a possible internal-consistency issue, but it is not a circular reduction: the paper does not define action indeterminacy in terms of impact indeterminacy or vice versa. No circular step can be exhibited, so score 0.
Axiom & Free-Parameter Ledger
axioms (5)
- domain assumption Traditional pen-testing tools are deterministic, enumerable, and operator-bounded.
- domain assumption LLM-driven agents are non-deterministic and opaque, resisting ex-ante and ex-post explanation.
- domain assumption The offense-defense cost asymmetry is structural.
- domain assumption Moral responsibility requires freedom and epistemic competence.
- domain assumption Vendor-published and preprint capability claims are indicative of the current landscape.
invented entities (1)
-
Joint indeterminacy regime
no independent evidence
read the original abstract
LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling -- deterministic, narrowly scoped, and operated by trained practitioners -- agentic security tools exhibit \textit{indeterminacy} along three independent dimensions. First, their actions are drawn from a non-deterministic policy whose outputs resist both ex-ante and ex-post explanation, frustrating incident attribution and pre-deployment safety review. Second, their impact is open-ended due to the non-deterministic actions, agency of utilized models, and opaque LLM supply-chains. Third, their user population is indeterminate in both size and required skill: the operating skill floor for using or developing offensive capabilities has dropped sharply. These three properties are linked thematically, but are not derivable from one another. Combined with the structural cost asymmetry between offense and defense, they enable the industrialization of offensive capability. The net short-term effect favors attackers, even if the same technology may, in the long run, democratize access to defensive practice. Existing dual-use cybersecurity and AI-ethics frameworks were not designed for this combination. Our work analyzes how moral attribution becomes diffuse between users, tool-makers, and third parties when employing autonomous AI agents for offensive security. We also examine the stakeholder impact of this technology and provide stratified recommendations.
Forward citations
Cited by 1 Pith paper
-
Cyber-Capable AI Agents: Vulnerabilities, Evaluation Containment, and Defensive Response
A structured review organizes cyber-capable-agent risks into five vulnerability classes and argues that evaluation environments must be treated as operational security systems rather than background.
Reference graph
Works this paper leans on
-
[1]
Llm rankings by market share,https://openrouter.ai/rankings#market-share
-
[2]
aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capab ilities(April 2026), accessed: 2026-05-01
AISI: Our evaluation of claude mythos preview’s cyber capabilities.https://www. aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capab ilities(April 2026), accessed: 2026-05-01
2026
-
[3]
AISI: Our evaluation of openai’s gpt-505 cyber capabilities.https://www.aisi.g ov.uk/blog/our-evaluation-of-openais-gpt-5-5-cyber-capabilities(April 2026), accessed: 2026-05-01
2026
-
[4]
Alden, D.: A flood of useful security reports.https://lwn.net/Articles/10665 81/(April 2026), accessed: 2026-05-01
2026
-
[5]
Amazon: Aws security agent on-demand penetration testing is now generally avail- able.https://aws.amazon.com/about-aws/whats-new/2026/03/aws-securit y-agent-ondemand-penetration/(March 2026), accessed: 2026-05-03
2026
-
[6]
Anthropic: Detecting and countering malicious uses of claude: March 2025.https: //www.anthropic.com/news/detecting-and-countering-malicious-uses-of-c laude-march-2025(April 2025), accessed: 2025-06-19
2025
-
[7]
Anthropic: Project glasswing: Securing critical software for the ai era.https: //www.anthropic.com/glasswing(April 2026), accessed: 2026-05-01
2026
-
[8]
Advances in Neural Information Processing Systems37, 136037–136083 (2024)
Arditi, A., et al.: Refusal in language models is mediated by a single direction. Advances in Neural Information Processing Systems37, 136037–136083 (2024)
2024
-
[9]
In: Analysis, design and evaluation of man– machine systems, pp
Bainbridge, L.: Ironies of automation. In: Analysis, design and evaluation of man– machine systems, pp. 129–135. Elsevier (1983)
1983
-
[10]
Brian Grinstead, Christian Holler, F.B.: Behind the scenes hardening firefox with claude mythos preview.https://hacks.mozilla.org/2026/05/behind-the-sce nes-hardening-firefox/(May 2026), accessed: 2026-05-13
2026
-
[11]
Brockmeier, J.: Open source security in spite of ai.https://lwn.net/Articles/1 058266/(Februar 2026), accessed: 2026-05-01 Ethics of Autonomous AI Agents for Offensive Security 19
2026
-
[12]
Brown, A.: Building the leading open-source pentesting agent: Architecture lessons from xbow benchmark.https://medium.com/data-science-collective/buildi ng-the-leading-open-source-pentesting-agent-architecture-lessons-fro m-xbow-benchmark-f6874f932ca4(October 2025), accessed: 2026-05-03
2025
-
[13]
npj Artificial Intelligence2(1), 7 (2026)
Buyl, M., Rogiers, A., et al.: Large language models reflect the ideology of their creators. npj Artificial Intelligence2(1), 7 (2026)
2026
-
[14]
Collingridge, D.: The social control of technology (1980)
1980
-
[15]
In: USENIX Security 24
Deng, G., et al.:{PentestGPT}: Evaluating and harnessing large language models for automated penetration testing. In: USENIX Security 24. pp. 847–864 (2024)
2024
-
[16]
Denning,D.E.:InformationWarfareandSecurity.ACMPressandAddison-Wesley, New York and Reading, Mass. (1999)
1999
-
[17]
AI & SOCIETY40(4), 3019–3044 (2025)
Emery-Xu, N., Jordan, R., Trager, R.: International governance of advancing arti- ficial intelligence. AI & SOCIETY40(4), 3019–3044 (2025)
2025
-
[18]
Computers & Security109, 102382 (June 2021)
Formosa, P., Wilson, M., Richards, D.: A principlist framework for cybersecurity ethics. Computers & Security109, 102382 (June 2021). https://doi.org/10.1016/j.cose.2021.102382,https://www.sciencedirect.com/ science/article/pii/S0167404821002030
arXiv 2021
-
[19]
interactions3(6), 16–23 (1996)
Friedman, B.: Value-sensitive design. interactions3(6), 16–23 (1996)
1996
-
[20]
Societies15(1), 6 (2025)
Gerlich, M.: Ai tools in society: Impacts on cognitive offloading and the future of critical thinking. Societies15(1), 6 (2025)
2025
-
[21]
Group, G.T.I.: Adversarial misuse of generative ai.https://cloud.google.com /blog/topics/threat- intelligence/adversarial- misuse- generative- ai (January 2025), accessed: 2025-06-19
2025
-
[22]
In: Proc
Happe, A., Cito, J.: Getting pwn’d by ai: Penetration testing with large language models. In: Proc. 31st ACM ESEC/FSE. pp. 2082–2086 (2023)
2082
-
[23]
In: Proc
Happe, A., Cito, J.: Understanding hackers’ work: An empirical study of offensive security practitioners. In: Proc. 31st ACM ESEC/FSE. pp. 1669–1680 (2023)
2023
-
[24]
arXiv preprint arXiv:2502.04227 (2025)
Happe, A., Cito, J.: Can llms hack enterprise networks? autonomous as- sumed breach penetration-testing active directory networks. arXiv preprint arXiv:2502.04227 (2025)
Pith/arXiv arXiv 2025
-
[25]
Happe, A., Cito, J.: Cochise: A reference harness for autonomous penetration test- ing (2026),https://arxiv.org/abs/2605.11671
Pith/arXiv arXiv 2026
-
[26]
Happe, A., Cito, J.: Ethics statements in autonomous penetration-testing agent research (2026),https://arxiv.org/abs/2506.08693
Pith/arXiv arXiv 2026
-
[27]
ISC2: 2025 isc2 cybersecurity workforce study.https://www.isc2.org/insig hts/2025/12/2025-ISC2-Cybersecurity-Workforce-Study(December 2025), accessed: 2026-05-02
2025
-
[28]
International Journal of En- gineering Science and Technology3(5), 3–758 (2011)
Jamil, D., Khan, M.N.A.: Is ethical hacking ethical. International Journal of En- gineering Science and Technology3(5), 3–758 (2011)
2011
-
[29]
arXiv preprint arXiv:2501.13411 (2025)
Kong,H.,Hu,D.,etal.:Vulnbot:Autonomouspenetrationtestingforamulti-agent collaborative framework. arXiv preprint arXiv:2501.13411 (2025)
Pith/arXiv arXiv 2025
-
[30]
removal.https://www.phoronix.com/news/Linux-7.1-Removes-Old -Net(April 2026), accessed: 2026-05-02
Larabel, M.: Farewell isdn, ham radio & old network drivers: Linus torvalds merges 138k l.o.c. removal.https://www.phoronix.com/news/Linux-7.1-Removes-Old -Net(April 2026), accessed: 2026-05-02
2026
-
[31]
Lebedev, K., Moix, A., Klein, J.: Operating multi-client influence networks across platforms.https://cdn.sanity.io/files/4zrzovbb/website/45bc6adf0398488 41ed9e47051fb1209d6bb2b26.pdf(April 2025), accessed: 2025-06-19
2025
-
[32]
In: Proceedings of the 2025 CHI
Lee, H.P., et al.: The impact of generative ai on critical thinking: Self-reported reductions in cognitive effort and confidence effects from a survey of knowledge workers. In: Proceedings of the 2025 CHI. pp. 1–22 (2025) 20 A. Happe et al
2025
-
[33]
Lindsay, J.: X post.https://x.com/Jack_W_Lindsey/status/2041588505701388 648?s=20(April 2026), accessed: 2026-05-06
arXiv 2026
-
[34]
Ma, A.: Regulation in pursuit of artificial intelligence sovereignty: China’s mix of restrictive and facilitative modalities. AJIC (34), 1–16 (2024). https://doi.org/10.23962/ajic.i34.20103
-
[35]
arXiv preprint arXiv:2508.13588 (2025)
Mayoral-Vilches, V., Wachter, J., et al.: Cai fluency: A framework for cybersecurity ai fluency. arXiv preprint arXiv:2508.13588 (2025)
arXiv 2025
-
[36]
McMillian, R., et al.: White house opposes anthropic’s plan to expand access to mythos model.https://www.wsj.com/tech/ai/white- house- opposes- ant hropics-plan-to-expand-access-to-mythos-model-dc281ab5(April 2026), accessed: 2026-05-03
2026
-
[37]
arXiv preprint arXiv:2601.03788 (2026)
Mojica-Hanke, A., et al.: Criminal liability of generative artificial intelli- gence providers for user-generated child sexual abuse material. arXiv preprint arXiv:2601.03788 (2026)
arXiv 2026
-
[38]
Nimmo, B., Flossman, M.: Influence and cyber operations: an update.https: //cdn.openai.com/threat-intelligence-reports/influence-and-cyber-ope rations-an-update\_October-2024.pdf(October 2024), accessed: 2025-06-13
2024
-
[39]
openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-o ur-models-february-2025-update.pdf(February 2025), accessed: 2025-06-18
Nimmo, B., et al.: Disrupting malicious uses of ai: February 2025.https://cdn. openai.com/threat-intelligence-reports/disrupting-malicious-uses-of-o ur-models-february-2025-update.pdf(February 2025), accessed: 2025-06-18
2025
-
[40]
Nimmo, B., et al.: Disrupting malicious uses of ai: June 2025.https://openai .com/global-affairs/disrupting-malicious-uses-of-ai-june-2025/(June 2025), accessed: 2025-06-13
2025
-
[41]
arXiv preprint arXiv:2603.17673 (2026)
Normann, P., Happe, A., et al.: Post-training local llm agents for linux privilege escalation with verifiable rewards. arXiv preprint arXiv:2603.17673 (2026)
Pith/arXiv arXiv 2026
-
[42]
OpenAI: Disrupting malicious uses of ai by state-affiliated threat actors.https: //openai.com/index/disrupting-malicious-uses-of-ai-by-state-affiliate d-threat-actors/(February 2024), accessed: 2025-06-19
2024
-
[43]
PNAS Nexus5(2), pgag013 (02 2026),10.1093/pnasnexus/pgag013
Pan, J., Xu, X.: Political censorship in large language models originating from china. PNAS Nexus5(2), pgag013 (02 2026),10.1093/pnasnexus/pgag013
-
[44]
Journal of International Tech- nology and Information Management22(4), 4 (2013)
Pike, R.E.: The “ethics” of teaching ethical hacking. Journal of International Tech- nology and Information Management22(4), 4 (2013)
2013
-
[45]
robert oppenheimer
Polenberg, R.: The ethical responsibilties of the scientist: the case of j. robert oppenheimer. In: The Achievement of American Liberalism: The New Deal and Its Legacies, pp. 129–160. Columbia University Press (2002)
2002
-
[46]
arXiv preprint arXiv:2604.27143 (2026)
Probst, B., Happe, A., Cito, J.: Enhancing linux privilege escalation attack capa- bilities of local llm agents. arXiv preprint arXiv:2604.27143 (2026)
Pith/arXiv arXiv 2026
-
[47]
arXiv preprint arXiv:2509.05372 (2025)
Przymus,P.,Happe,A.,etal.:Adversarialbugreportsasasecurityriskinlanguage model-based automated program repair. arXiv preprint arXiv:2509.05372 (2025)
Pith/arXiv arXiv 2025
-
[48]
Righetti, L., Boulanin, V.: Navigating the dual-use dilemma.https://spectrum.i eee.org/navigating-the-dual-use-dilemma(June 2025), accessed: 2026-05-02
2025
-
[49]
Journal of Information Technology & Politics16(2), 169–186 (2019)
Ruohonen, J., Kimppa, K.K.: Updating the Wassenaar debate once again: Surveil- lance, intrusion software, and ambiguity. Journal of Information Technology & Politics16(2), 169–186 (2019). https://doi.org/10.1080/19331681.2019.1616646
arXiv 2019
-
[50]
Proceedings of the IEEE63(9), 1278–1308 (1975)
Saltzer, J.H., Schroeder, M.D.: The protection of information in computer systems. Proceedings of the IEEE63(9), 1278–1308 (1975)
1975
-
[51]
arXiv preprint arXiv:2201.05159 (2022)
Shevlane, T.: Structured access: an emerging paradigm for safe ai deployment. arXiv preprint arXiv:2201.05159 (2022)
Pith/arXiv arXiv 2022
-
[52]
arXiv preprint arXiv:2501.16466 (2025) Ethics of Autonomous AI Agents for Offensive Security 21
Singer, B., et al.: Incalmo: An autonomous llm-assisted system for red teaming multi-host networks. arXiv preprint arXiv:2501.16466 (2025) Ethics of Autonomous AI Agents for Offensive Security 21
arXiv 2025
-
[53]
Stenberg, D.: Daniel sternber blog.https://daniel.haxx.se/blog/(Mai 2026), accessed: 2026-05-27
2026
-
[54]
Tennant, L.: Ctfs in the ai era.https://blog.includesecurity.com/2026/04/c tfs-in-the-ai-era/(April 2026), accessed: 2026-05-03
2026
-
[55]
Vassilev, A., et al.: Adversarial machine learning: A taxonomy and terminology of attacks and mitigations. Tech. Rep. NIST AI 100-2e2025, NIST (2025)
2025
-
[56]
(eds.) Work- shop on Generation, Evaluation and Metrics
Wachter, J., et al.: Are LLMs (really) ideological? In: Arviv, O., et al. (eds.) Work- shop on Generation, Evaluation and Metrics. pp. 99–120. ACL, Vienna (Jul 2025)
2025
-
[57]
Basic Books, 3rd edn
Walzer, M.: Just and Unjust Wars: A Moral Argument with Historical Illustrations. Basic Books, 3rd edn. (2000)
2000
-
[58]
Wu, B., Chen, G., et al.: Autopt: How far are we from the end2end automated web penetration testing? arXiv preprint arXiv:2411.01236 (2024)
Pith/arXiv arXiv 2024
-
[59]
Ziegler, A., Buckley, S.: Gpt-5.5: Mythos-like hacking, open to all.https://xbow.c om/blog/mythos-like-hacking-open-to-all(April 2026), accessed: 2026-05-01
2026
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.