about
Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction (arxiv.org)
57 points by root-parent 129 days ago | hide | past | pdf | 9 comments on HN

In plain words: A team of AI agents scans C/C++ code for bugs and proves each one with a test input that crashes the program. Unlike usual AI reports that often turn out wrong, it found 29 previously unknown bugs in real projects, all confirmed and fixed.

Abstract · FuzzingBrain V2: A Multi-Agent LLM System for Automated Vulnerability Discovery and Reproduction

Software vulnerabilities pose critical security threats, with nearly 50,000 CVEs reported in 2025. While Large Language Models (LLMs) show promise for automated vulnerability detection, three key challenges remain. First, LLM-generated vulnerability reports suffer from high false positive rates and lack reproducible verification. Second, existing LLM-based approaches use suboptimal granularities for vulnerability localization: function-level analysis overlooks bugs when context becomes extensive, while line-level analysis lacks sufficient context. Third, existing approaches have difficulty reasoning about vulnerabilities with complex cross-function dependencies and triggering conditions. We present FuzzingBrain V2, a multi-agent system that addresses these gaps through four key contributions: (1) fully automated vulnerability analysis built on Google's OSS-Fuzz, ensuring all reported vulnerabilities are fuzzer-reproducible; (2) Suspicious Point, a novel control-flow-based abstraction for precise vulnerability localization at the optimal granularity; (3) logic-driven hierarchical function analysis with dual-layer fuzzing enhancing function coverage under resource constraints; (4) MCP-based static and dynamic analysis tools with context engineering enhancing complex vulnerability reasoning. On the AIxCC 2025 Final Competition C/C++ dataset, FuzzingBrain V2 achieved 90% detection rate (36 of 40 vulnerabilities). In real-world deployment, FuzzingBrain V2 discovered 29 zero-day vulnerabilities across 12 open-source projects, all confirmed and fixed by maintainers, with 2 assigned CVE IDs.

Ze Sheng, Zhicheng Chen, Qingxiao Xu, Kewen Zhu, Jeff Huang
arXiv:2605.21779 · cs.CR, cs.SE · submitted May 20, 2026
abstract · pdf · html

add comment on HN

I wonder if at some point someone will build a SciFi style countermeasure agent.

Essentially, when intrusion detection triggers, an offensive AI is unleashed against the attacker, trying in turn to hack it back.

It would be fun and interesting (in the ancient Chinese curse sense).

Every defensive primitive you deploy is a potential offensive primitive for an attacker. Like the perennial denial of service issues in fail2ban type tools. You want to ban bots scanning your service, but that becomes a way for attackers to ban you from your service.

An AI which can respond offensively to a perceived attack will be abused by adversaries to reflect attacks onto their target. They will find a way to spoof attacks as seeming to come from their target and you will attack an innocent target.

Cyber security is always a cat and mouse game. Always was and always will, just with AI now as another tool in the arsenal of defenders and attackers. I think that we might see a shift though where the winner will be the one with most compute advantage
But it could be a third party with no access other than the intrusion signal.

You run the intrusion detection, and then your hired goons start attacking the attacker.

That sort of countermeasure system could be done without AI as well. The problem is that it's illegal. No Castle Doctrine in cybersecurity afaik.

Interesting variation on that could be AI that builds out some sort of on the fly honeypot after identifying the attacker. Basically creating the "attack" within their own premises.

The illegal part could be fixed, there's "stand your ground" for humans, I would guess for software would be less controversial.
Calling vulnerabilities detected in code as part of a responsible disclosure program a "zero-day vulnerability" seems like marketing fluff. 0-days vulnerabilities would seem to imply this vulnerability is actively exploited in the wild, and if that's true, you weren't the first one to discover it...
The common definition of zero day vulnerability is: A zero-day vulnerability is a software security flaw that is unknown to the vendor or developers responsible for fixing it. Because they have had "zero days" to address it, no patch or fix exists at the time the flaw becomes known to attackers.
سلام