SysEvolve reports LLM agents stall after initial access and collapse when decoys are deployed
A co-evolutionary attack-defense system built from three components — a range builder that orchestrates 257 CVEs into 1,148 multi-host ranges at 2.1% overhead, an attack planner that improves success over 25% versus baseline LLMs, and a real-time defender claiming 10x to 1000x greater precision than prior systems, deployed against real APT activity at Huawei and Sangfor. The agent-capability findings matter more than the system: multi-step composition and larger topologies expose gaps that single-step evaluations hide, the bottleneck sits after initial access in post-compromise state utilization, and deploying decoy endpoints triples agent timeouts and eliminates downstream completion while initial-access success rates stay unchanged.
Source
↳ Follow the thread