{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T16:27:26Z","timestamp":1784392046318,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":45,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,6]],"date-time":"2023-11-06T00:00:00Z","timestamp":1699228800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["ECCS-1847056 and BCS-2122060"],"award-info":[{"award-number":["ECCS-1847056 and BCS-2122060"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,6]]},"DOI":"10.1145\/3689933.3690831","type":"proceedings-article","created":{"date-parts":[[2024,11,7]],"date-time":"2024-11-07T18:26:07Z","timestamp":1731003967000},"page":"11-22","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":22,"title":["PenHeal: A Two-Stage LLM Framework for Automated Pentesting and Optimal Remediation"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0009-0498-2973","authenticated-orcid":false,"given":"Junjie","family":"Huang","sequence":"first","affiliation":[{"name":"New York University Shanghai, Shanghai, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0008-2953","authenticated-orcid":false,"given":"Quanyan","family":"Zhu","sequence":"additional","affiliation":[{"name":"New York University, Brooklyn, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Brown et al","author":"Tom","year":"2020","unstructured":"Tom B. Brown et al. 2020. Language models are few-shot learners. (2020). arXiv: 2005.14165."},{"key":"e_1_3_2_1_2_1","unstructured":"OpenAI et al. 2024. Gpt-4 technical report. (2024). arXiv: 2303.08774."},{"key":"e_1_3_2_1_3_1","unstructured":"Hugo Touvron et al. 2023. Llama 2: open foundation and fine-tuned chat models. (2023). arXiv: 2307.09288."},{"key":"e_1_3_2_1_4_1","unstructured":"Gemini Team et al. 2024. Gemini: a family of highly capable multimodal models. (2024). arXiv: 2312.11805."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3649449"},{"key":"e_1_3_2_1_6_1","volume-title":"Chao","author":"Li Bei","year":"2019","unstructured":"QiangWang, Bei Li, Tong Xiao, Jingbo Zhu, Changliang Li, Derek F.Wong, and Lidia S. Chao. 2019. Learning deep transformer models for machine translation. (2019). https:\/\/arxiv.org\/abs\/1906.01787 arXiv: 1906.01787 [cs.CL]."},{"key":"e_1_3_2_1_7_1","volume-title":"Pretraining-based natural language generation for text summarization. (2019). https:\/\/arxiv.org\/abs\/1902.09 243 arXiv","author":"Zhang Haoyu","year":"1902","unstructured":"Haoyu Zhang, Jianjun Xu, and Ji Wang. 2019. Pretraining-based natural language generation for text summarization. (2019). https:\/\/arxiv.org\/abs\/1902.09 243 arXiv: 1902.09243 [cs.CL]."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/W-FiCloud.2016.29"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2007.159"},{"key":"e_1_3_2_1_10_1","unstructured":"Xin Zhou Sicong Cao Xiaobing Sun and David Lo. 2024. Large language model for vulnerability detection and repair: literature review and the road ahead. (2024). arXiv: 2404.02525."},{"key":"e_1_3_2_1_11_1","volume-title":"Ferreira","author":"Shafee Samaneh","year":"2024","unstructured":"Samaneh Shafee, Alysson Bessani, and Pedro M. Ferreira. 2024. Evaluation of llm chatbots for osint-based cyber threat awareness. (2024). arXiv: 2401.15127."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"crossref","unstructured":"Marwan Omar. 2023. Detecting software vulnerabilities using language models. (2023). arXiv: 2302.11773.","DOI":"10.1109\/JEEIT58638.2023.10185860"},{"key":"e_1_3_2_1_13_1","unstructured":"Gelei Deng et al. 2023. Pentestgpt: an llm-empowered automatic penetration testing tool. (2023). arXiv: 2308.06782 [cs.SE]."},{"key":"e_1_3_2_1_14_1","unstructured":"Jiacen Xu Jack W. Stokes Geoff McDonald Xuesong Bai David Marshall Siyue Wang Adith Swaminathan and Zhou Li. 2024. Autoattacker: a large language model guided system to implement automatic cyber-attacks. (2024). arXiv: 2403.01038."},{"key":"e_1_3_2_1_15_1","volume-title":"Penetration Testing: A Hands-On Introduction to Hacking","author":"Weidman Georgia","year":"2014","unstructured":"Georgia Weidman. 2014. Penetration Testing: A Hands-On Introduction to Hacking. No Starch Press, 528. isbn: 9781593275648."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW51379.2020.00010"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2018.00244"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS48642.2020.9162301"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/3540250.3549098"},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3387940.3392200"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE52982.2021.00031"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1109\/tse.2022.3147265"},{"key":"e_1_3_2_1_23_1","volume-title":"Learning to repair software vulnerabilities with generative adversarial networks. (2018). arXiv","author":"Harer Jacob","year":"1805","unstructured":"Jacob Harer, Onur Ozdemir, Tomo Lazovich, Christopher P. Reale, Rebecca L. Russell, Louis Y. Kim, and Peter Chin. 2018. Learning to repair software vulnerabilities with generative adversarial networks. (2018). arXiv: 1805.07475."},{"key":"e_1_3_2_1_24_1","volume-title":"Common Vulnerabilities and Exposures (CVE). Accessed: 2024-06--21","author":"MITRE Corporation","unstructured":"MITRE Corporation. 2021. Common Vulnerabilities and Exposures (CVE). Accessed: 2024-06--21. The MITRE Corporation. https:\/\/cve.mitre.org."},{"key":"e_1_3_2_1_25_1","volume-title":"FIRST","author":"CVSS","year":"2021","unstructured":"2021. CVSS v3.1 Specification Document. https:\/\/www.first.org\/cvss\/v3.1\/spec ification-document. Accessed: 2024-06--21. FIRST, (2021)."},{"key":"e_1_3_2_1_26_1","unstructured":"Ashish Vaswani Noam Shazeer Niki Parmar Jakob Uszkoreit Llion Jones Aidan N. Gomez Lukasz Kaiser and Illia Polosukhin. 2023. Attention is all you need. (2023). arXiv: 1706.03762."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICASSP39728.2021.9413810"},{"key":"e_1_3_2_1_28_1","unstructured":"Patrick Lewis et al. 2021. Retrieval-augmented generation for knowledgeintensive nlp tasks. (2021). arXiv: 2005.11401."},{"key":"e_1_3_2_1_29_1","doi-asserted-by":"crossref","unstructured":"Aobo Kong Shiwan Zhao Hao Chen Qicheng Li Yong Qin Ruiqi Sun Xin Zhou Enzhi Wang and Xiaohang Dong. 2024. Better zero-shot reasoning with role-play prompting. (2024). arXiv: 2308.07702.","DOI":"10.18653\/v1\/2024.naacl-long.228"},{"key":"e_1_3_2_1_30_1","unstructured":"Zhiheng Xi et al. 2023. The rise and potential of large language model based agents: a survey. (2023). arXiv: 2309.07864."},{"key":"e_1_3_2_1_31_1","unstructured":"Yujia Qin et al. 2023. Toolllm: facilitating large language models to master 16000 real-world apis. (2023). arXiv: 2307.16789."},{"key":"e_1_3_2_1_32_1","volume-title":"Sean Paul Bergeron, and Konstantin Berlin","author":"V\u00f6r\u00f6s Tam\u00e1s","year":"2023","unstructured":"Tam\u00e1s V\u00f6r\u00f6s, Sean Paul Bergeron, and Konstantin Berlin. 2023. Web content filtering through knowledge distillation of large language models. (2023). arXiv: 2305.05027."},{"key":"e_1_3_2_1_33_1","volume-title":"Danial Khosh Kholgh, and Panos Kostakos","author":"Kaheh Mehrdad","year":"2023","unstructured":"Mehrdad Kaheh, Danial Khosh Kholgh, and Panos Kostakos. 2023. Cyber sentinel: exploring conversational agents in streamlining security tasks with gpt-4. (2023). https:\/\/arxiv.org\/abs\/2309.16422 arXiv: 2309.16422 [cs.CR]."},{"key":"e_1_3_2_1_34_1","volume-title":"Multi-Agent Security Workshop @ NeurIPS'23","author":"Yang John","year":"2023","unstructured":"John Yang, Akshara Prabhakar, Shunyu Yao, Kexin Pei, and Karthik R Narasimhan. 2023. Language agents as hackers: evaluating cybersecurity skills with capture the flag. In Multi-Agent Security Workshop @ NeurIPS'23. https:\/\/openreview.n et\/forum?id=KOZwk7BFc3."},{"key":"e_1_3_2_1_35_1","volume-title":"Choon Meng Seah, and Ee-Chien Chang.","author":"Tann Wesley","year":"2023","unstructured":"Wesley Tann, Yuancheng Liu, Jun Heng Sim, Choon Meng Seah, and Ee-Chien Chang. 2023. Using large language models for cybersecurity capture-the-flag challenges and certification questions. (2023). arXiv: 2308.10443."},{"key":"e_1_3_2_1_36_1","unstructured":"Minghao Shao Boyuan Chen Sofija Jancheska Brendan Dolan-Gavitt Siddharth Garg Ramesh Karri and Muhammad Shafique. 2024. An empirical evaluation of llms for solving offensive security challenges. (2024). arXiv: 2402 .11814."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/3611643.3613083"},{"key":"e_1_3_2_1_38_1","unstructured":"Andreas Happe Aaron Kaplan and J\u00fcrgen Cito. 2024. Llms as hackers: autonomous linux privilege escalation attacks. (2024). arXiv: 2310.11409."},{"key":"e_1_3_2_1_39_1","unstructured":"2024. Vulnhub. Retrieved 2024-06--20 from https:\/\/www.vulnhub.com\/."},{"key":"e_1_3_2_1_40_1","unstructured":"[n. d.] HacktheBox: Hacking training for the best. http:\/\/www.hackthebox.com\/. Accessed: 2024-06--20. ()."},{"key":"e_1_3_2_1_41_1","unstructured":"National Institute of Standards and Technology (NIST). 2024. Nvd - vulnerabilities. National Vulnerability Database (NVD). Accessed: 2024-06--21. (2024). https:\/\/nvd.nist.gov\/developers\/vulnerabilities."},{"key":"e_1_3_2_1_42_1","unstructured":"Red Hat Product Security. 2024. Python cvss calculator. GitHub repository. Accessed: 2024-06--21. (2024). https:\/\/github.com\/RedHatProductSecurity\/cvss."},{"key":"e_1_3_2_1_43_1","unstructured":"Rapid7. [n. d.] Metasploitable 2. https:\/\/docs.rapid7.com\/metasploit\/metasploit able-2. Accessed: 2024-06--20. ()."},{"key":"e_1_3_2_1_44_1","unstructured":"LangChain Contributors. 2023. Langchain: an open-source library for building language models. Available on GitHub. Accessed: 2023-09--30. (2023). https:\/\/gi thub.com\/LangChain\/langchain."},{"key":"e_1_3_2_1_45_1","volume-title":"Bypass Firewalls, and Exploit Complex Environments with the Most Widely Used Penetration Testing Framework","author":"Jaswal Nipun","year":"2018","unstructured":"Nipun Jaswal, Daniel Teixeira, Abhinav Singh, and Monika Agarwal. 2018. Metasploit Penetration Testing Cookbook: Evade Antiviruses, Bypass Firewalls, and Exploit Complex Environments with the Most Widely Used Penetration Testing Framework. (3rd ed.). Packt Publishing, (Feb. 2018). isbn: 9781788623179.","edition":"3"}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","location":"Salt Lake City UT USA","acronym":"CCS '24","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the Workshop on Autonomous Cybersecurity"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689933.3690831","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3689933.3690831","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T18:42:22Z","timestamp":1755974542000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3689933.3690831"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,6]]},"references-count":45,"alternative-id":["10.1145\/3689933.3690831","10.1145\/3689933"],"URL":"https:\/\/doi.org\/10.1145\/3689933.3690831","relation":{},"subject":[],"published":{"date-parts":[[2023,11,6]]},"assertion":[{"value":"2024-11-07","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}