Security agents lose evidence support when available telemetry changes

APTInvestBench shows that autonomous investigations can appear stable in aggregate while losing support for many individual attack actions.

Academic
Yu Wang · Shuhao Li · Tao Yin · Ziyang Li · Xueying Zhao · Peishuai Sun · +1 more

Zhongguancun Laboratory

Research Digest··2 min read
The authors introduce APTInvestBench, a benchmark that tests whether LLM agents can investigate advanced persistent threats when the available security logs change.

The benchmark contains 370 investigation cases spanning seven SOC-inspired telemetry conditions, including full, endpoint-only and network-only views.

Why this paper

From Zhongguancun Laboratory · Part of Agent Security & Attacks, now 45 papers

In one line

When telemetry changes, LLM agents lose citation support for 35.5% of previously covered attack actions even though the actions remain recoverable.

What we could check

  • ·No code link found
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ·No stated limitations found
  • ✓Reports numbers on named benchmarks

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.