Pith. sign in

REVIEW 2 cited by

Evaluation of Reinforcement Learning for Autonomous Penetration Testing using A3C, Q-learning and DQN

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2407.15656 v1 pith:JOROJ6QC submitted 2024-07-22 cs.CR cs.AI

classification cs.CRcs.AI
keywords scenariospenetrationperformedattacksolvetestingagentshyperparameter
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

Penetration testing is the process of searching for security weaknesses by simulating an attack. It is usually performed by experienced professionals, where scanning and attack tools are applied. By automating the execution of such tools, the need for human interaction and decision-making could be reduced. In this work, a Network Attack Simulator (NASim) was used as an environment to train reinforcement learning agents to solve three predefined security scenarios. These scenarios cover techniques of exploitation, post-exploitation and wiretapping. A large hyperparameter grid search was performed to find the best hyperparameter combinations. The algorithms Q-learning, DQN and A3C were used, whereby A3C was able to solve all scenarios and achieve generalization. In addition, A3C could solve these scenarios with fewer actions than the baseline automated penetration testing. Although the training was performed on rather small scenarios and with small state and action spaces for the agents, the results show that a penetration test can successfully be performed by the RL agent.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. VulnGym: Evaluating Vulnerability Management Strategies against Advanced Persistent Threats

    cs.CR 2026-07 conditional novelty 6.0 of 10

    A shared-network RL simulator shows importance-based patching cuts APT goal success far more than CVSS or centrality policies under limited defender budget.

  2. Attack Effect Model based Malicious Behavior Detection

    cs.CR 2025-06 conditional novelty 5.0 of 10

    FEAD derives security monitoring items from attack reports with an LLM, decomposes them across existing collectors, and applies locality-aware graph analysis, reporting an 8.23% higher F1-score than ThreaTrace with 5....

Pith tools