AgentSnare Traps Autonomous Pentest Agents in a Grown Decoy: Zero Real-Target Exploits Across 45 Attacker-CVE Pairs
AgentSnare (arXiv 2607.26998, 2026-07-29) flips the LLM pentest agent's observation-action loop against it, replacing static planted honeytokens with a trajectory-adaptive policy model that constructs new decoy artifacts conditioned on the agent's interaction history and incrementally folds validated ones into a factually consistent fake environment. Evaluated on 15 CVE-Bench applications against three attacker models, it absorbs 46.8% of tool calls, retains 55.9% of post-entry actions inside the decoy, and induces 90.0% of completion reports to be grounded in decoy evidence — with zero successful real-target exploitations across all 45 attacker-CVE pairs at pass@3. Making the agent confidently report a fake success is a materially different defense goal than blocking it.
↳ Follow the thread