{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T03:10:29Z","timestamp":1778728229451,"version":"3.51.4"},"reference-count":48,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,9,1]],"date-time":"2026-09-01T00:00:00Z","timestamp":1788220800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,5,4]],"date-time":"2026-05-04T00:00:00Z","timestamp":1777852800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Systems and Software"],"published-print":{"date-parts":[[2026,9]]},"DOI":"10.1016\/j.jss.2026.112918","type":"journal-article","created":{"date-parts":[[2026,4,28]],"date-time":"2026-04-28T06:56:17Z","timestamp":1777359377000},"page":"112918","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Multi-agent deep reinforcement learning for penetration testing of IoT devices through their mobile companion app"],"prefix":"10.1016","volume":"239","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1485-0068","authenticated-orcid":false,"given":"Francesco","family":"Pagano","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7325-0316","authenticated-orcid":false,"given":"Mariano","family":"Ceccato","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2272-2376","authenticated-orcid":false,"given":"Alessio","family":"Merlo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3088-0339","authenticated-orcid":false,"given":"Paolo","family":"Tonella","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.jss.2026.112918_b1","series-title":"2019 IEEE Symposium on Security and Privacy (Sp)","first-page":"1362","article-title":"Sok: Security evaluation of home-based iot deployments","author":"Alrawi","year":"2019"},{"key":"10.1016\/j.jss.2026.112918_b2","series-title":"Appium","author":"appium.io","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b3","series-title":"Arm","author":"arm.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b4","series-title":"NDSS","article-title":"IoTFuzzer: Discovering memory corruptions in IoT through app-based fuzzing.","author":"Chen","year":"2018"},{"key":"10.1016\/j.jss.2026.112918_b5","first-page":"1","article-title":"Towards automated dynamic analysis for linux-based embedded firmware.","volume":"vol. 1","author":"Chen","year":"2016"},{"key":"10.1016\/j.jss.2026.112918_b6","series-title":"23rd USENIX Security Symposium (USENIX Security 14)","first-page":"95","article-title":"A {large-scale} analysis of the security of embedded firmwares","author":"Costin","year":"2014"},{"key":"10.1016\/j.jss.2026.112918_b7","series-title":"CVE-2018\u201319986","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b8","series-title":"CVE-2018\u201319987","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b9","series-title":"CVE-2018\u201319988","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b10","series-title":"CVE-2018\u201319989","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b11","series-title":"CVE-2018\u201319990","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b12","series-title":"CVE routers","author":"cve.mitre.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b13","series-title":"CWE-94: Improper control of generation of code (\u2019code injection\u2019)","author":"cwe.mitre.org","year":"2023"},{"issue":"2","key":"10.1016\/j.jss.2026.112918_b14","doi-asserted-by":"crossref","first-page":"392","DOI":"10.1145\/3296957.3177157","article-title":"Firmup: Precise static detection of common vulnerabilities in firmware","volume":"53","author":"David","year":"2018","journal-title":"SIGPLAN Not.","ISSN":"https:\/\/id.crossref.org\/issn\/0362-1340","issn-type":"print"},{"key":"10.1016\/j.jss.2026.112918_b15","unstructured":"Davidson, Drew, Moench, Benjamin, Ristenpart, Thomas, Jha, Somesh, 2013. {FIE} on firmware: Finding vulnerabilities in embedded systems using symbolic execution. In: 22nd USENIX Security Symposium (USENIX Security 13). pp. 463\u2013478."},{"key":"10.1016\/j.jss.2026.112918_b16","series-title":"Android developer","author":"developer.android.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b17","series-title":"Intent","author":"developer.android.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b18","series-title":"Dlink","author":"dlink.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b19","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2022.102889","article-title":"AflIot: Fuzzing on linux-based IoT device with binary-level instrumentation","volume":"122","author":"Du","year":"2022","journal-title":"Comput. Secur."},{"key":"10.1016\/j.jss.2026.112918_b20","series-title":"Number of IoT devices (2024)","author":"explodingtopics.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b21","doi-asserted-by":"crossref","unstructured":"Feng, Xiaotao, Sun, Ruoxi, Zhu, Xiaogang, Xue, Minhui, Wen, Sheng, Liu, Dongxi, Nepal, Surya, Xiang, Yang, 2021. Snipuzz: Black-box fuzzing of iot firmware via message snippet inference. In: Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security. pp. 337\u2013350.","DOI":"10.1145\/3460120.3484543"},{"key":"10.1016\/j.jss.2026.112918_b22","series-title":"14th USENIX Workshop on Offensive Technologies (WOOT 20)","article-title":"AFL++ : Combining incremental steps of fuzzing research","author":"Fioraldi","year":"2020"},{"key":"10.1016\/j.jss.2026.112918_b23","series-title":"Frida","author":"frida.re","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b24","series-title":"International Conference on Machine Learning","first-page":"1587","article-title":"Addressing function approximation error in actor-critic methods","author":"Fujimoto","year":"2018"},{"key":"10.1016\/j.jss.2026.112918_b25","series-title":"Emba","author":"github.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b26","series-title":"PHP-parser","author":"github.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b27","series-title":"Stable baseline","author":"github.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b28","series-title":"VirtualApp","author":"github.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b29","series-title":"International Conference on Machine Learning","first-page":"1861","article-title":"Soft actor-critic: Off-policy maximum entropy deep reinforcement learning with a stochastic actor","author":"Haarnoja","year":"2018"},{"key":"10.1016\/j.jss.2026.112918_b30","doi-asserted-by":"crossref","unstructured":"Kim, Mingeun, Kim, Dongkwan, Kim, Eunsoo, Kim, Suryeon, Jang, Yeongjin, Kim, Yongdae, 2020. Firmae: Towards large-scale emulation of iot firmware for dynamic analysis. In: Proceedings of the 36th Annual Computer Security Applications Conference. pp. 733\u2013745.","DOI":"10.1145\/3427228.3427294"},{"key":"10.1016\/j.jss.2026.112918_b31","unstructured":"Kumar, Deepak, Shen, Kelly, Case, Benton, Garg, Deepali, Alperovich, Galina, Kuznetsov, Dmitry, Gupta, Rajarshi, Durumeric, Zakir, 2019. All things considered: An analysis of {IoT} devices on home networks. In: 28th USENIX Security Symposium (USENIX Security 19). pp. 1169\u20131185."},{"key":"10.1016\/j.jss.2026.112918_b32","series-title":"2024 IEEE Symposium on Security and Privacy","first-page":"130","article-title":"LABRADOR: Response guided directed fuzzing for black-box IoT devices","author":"Liu","year":"2024","ISSN":"https:\/\/id.crossref.org\/issn\/2375-1207","issn-type":"print"},{"key":"10.1016\/j.jss.2026.112918_b33","series-title":"Asynchronous methods for deep reinforcement learning","author":"Mnih","year":"2016"},{"issue":"11","key":"10.1016\/j.jss.2026.112918_b34","doi-asserted-by":"crossref","first-page":"13677","DOI":"10.1007\/s10489-022-04105-y","article-title":"A review of cooperative multi-agent deep reinforcement learning","volume":"53","author":"Oroojlooy","year":"2023","journal-title":"Appl. Intell."},{"key":"10.1016\/j.jss.2026.112918_b35","series-title":"Detect frida for android","author":"preemptive.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b36","series-title":"Raspberry pi 5","author":"raspberrypi.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b37","series-title":"2021 IEEE Symposium on Security and Privacy","first-page":"484","article-title":"Diane: Identifying fuzzing triggers in apps to generate under-constrained inputs for IoT devices","author":"Redini","year":"2021"},{"key":"10.1016\/j.jss.2026.112918_b38","series-title":"2020 IEEE Symposium on Security and Privacy","first-page":"1544","article-title":"Karonte: Detecting insecure multi-binary interactions in embedded firmware","author":"Redini","year":"2020"},{"issue":"4","key":"10.1016\/j.jss.2026.112918_b39","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3502868","article-title":"Deep reinforcement learning for black-box testing of android apps","volume":"31","author":"Romdhana","year":"2022","journal-title":"ACM Trans. Softw. Eng. Methodol. (TOSEM)"},{"key":"10.1016\/j.jss.2026.112918_b40","doi-asserted-by":"crossref","DOI":"10.1016\/j.cose.2023.103311","article-title":"Assessing the security of inter-app communications in android through reinforcement learning","volume":"131","author":"Romdhana","year":"2023","journal-title":"Comput. Secur.","ISSN":"https:\/\/id.crossref.org\/issn\/0167-4048","issn-type":"print"},{"key":"10.1016\/j.jss.2026.112918_b41","series-title":"Trust region policy optimization","author":"Schulman","year":"2015"},{"key":"10.1016\/j.jss.2026.112918_b42","series-title":"Proximal policy optimization algorithms","author":"Schulman","year":"2017"},{"key":"10.1016\/j.jss.2026.112918_b43","first-page":"1","article-title":"Firmalice-automatic detection of authentication bypass vulnerabilities in binary firmware","volume":"vol. 1","author":"Shoshitaishvili","year":"2015"},{"key":"10.1016\/j.jss.2026.112918_b44","series-title":"International Conference on Machine Learning","first-page":"387","article-title":"Deterministic policy gradient algorithms","author":"Silver","year":"2014"},{"key":"10.1016\/j.jss.2026.112918_b45","series-title":"Travel routers, NAS devices among easily hacked IoT devices","author":"threatpost.com","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b46","series-title":"Learning from delayed rewards","author":"Watkins","year":"1989"},{"key":"10.1016\/j.jss.2026.112918_b47","series-title":"Yocto","author":"yoctoproject.org","year":"2023"},{"key":"10.1016\/j.jss.2026.112918_b48","series-title":"28th USENIX Security Symposium (USENIX Security 19)","first-page":"1099","article-title":"FIRM-AFL: High-throughput greybox fuzzing of IoT firmware via augmented process emulation","author":"Zheng","year":"2019"}],"container-title":["Journal of Systems and Software"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0164121226001512?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S0164121226001512?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T02:49:48Z","timestamp":1778726988000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S0164121226001512"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,9]]},"references-count":48,"alternative-id":["S0164121226001512"],"URL":"https:\/\/doi.org\/10.1016\/j.jss.2026.112918","relation":{"has-preprint":[{"id-type":"doi","id":"10.36227\/techrxiv.174114576.61410228\/v1","asserted-by":"object"}]},"ISSN":["0164-1212"],"issn-type":[{"value":"0164-1212","type":"print"}],"subject":[],"published":{"date-parts":[[2026,9]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Multi-agent deep reinforcement learning for penetration testing of IoT devices through their mobile companion app","name":"articletitle","label":"Article Title"},{"value":"Journal of Systems and Software","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jss.2026.112918","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Authors. Published by Elsevier Inc.","name":"copyright","label":"Copyright"}],"article-number":"112918"}}