Two-stage auditing finds more exploitable flaws in AI agent repositories

AgentXploit separates source-code attack-path discovery from runtime exploitation, outperforming comparison systems on two security benchmarks.

Top University
Weida Liang · Shi Qiu · Zhun Wang · Simon Sure · Xiaoyuan Liu · Tianneng Shi · +3 more

National University of Singapore · University of North Carolina at Chapel Hill · University of California, Berkeley · University of Chicago · University of California, Santa Barbara

Research Digest··2 min read
The authors built an automated white-box auditing system that analyzes an AI agent's repository for attacker-controlled paths to sensitive operations, then tests concrete exploits in a controlled runtime.

AgentXploit divides auditing between two roles.

Why this paper

From National University of Singapore and 4 others · Released code · Part of Agent Security & Attacks, now 32 papers

In one line

AgentXploit separates repository attack-path discovery from runtime exploitation, achieving 59.3% end-to-end success on 72 vulnerabilities.

What it released

Code

What we could check

  • ✓Code link in the paper (github.com)
  • ·No weights link found
  • ·No dataset link found
  • ·No compute details found
  • ✓Limitations stated by the authors
  • ✓Reports numbers on named benchmarks (2 benchmarks)

Observed from the paper text and links we have. Absence here means we did not find it, not that it does not exist.

§
newspaper

Research Digest

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.