2024/10/10 by Andrey Anurin, Jonathan Ng, Anurin, Andrey +6 · 3 citations
Business, Management and Accounting · Computer Science · Decision Sciences · #Artificial Intelligence (cs.AI) #Big Data and Business Intelligence #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Information and Cyber Security #Machine Learning (cs.LG) #Performance (cs.PF) #Scientific Computing and Data Management
paper · pdf · doi:10.48550/arxiv.2410.09114
openalex publication_date 2024/10/10 · openalex created_date 2024/10/20 · openalex updated_date 2026/07/28
LLM agents have the potential to revolutionize defensive cyber operations, but their offensive capabilities are not yet fully understood. To prepare for emerging threats, model developers and governments are evaluating the cyber capabilities of foundation models. However, these assessments often lack transparency and a comprehensive focus on offensive capabilities. In response, we introduce the Catastrophic Cyber Capabilities Benchmark (3CB), a novel framework designed to rigorously assess the real-world offensive capabilities of LLM agents. Our evaluation of modern LLMs on 3CB reveals that frontier models, such as GPT-4o and Claude 3.5 Sonnet, can perform offensive tasks such as reconnaissance and exploitation across domains ranging from binary analysis to web technologies. Conversely, smaller open-source models exhibit limited offensive capabilities. Our software solution and the corresponding benchmark provides a critical tool to reduce the gap between rapidly improving capabilities and robustness of cyber offense evaluations, aiding in the safer deployment and regulation of these powerful technologies.