← Latest papers
🤖 AI

AgentCyberRange: Benchmarking Frontier AI Systems in Realistic Cyber Ranges

The paper introduces AgentCyberRange, an open, multi-host infrastructure designed to benchmark frontier AI systems' autonomous offensive capabilities across realistic web exploitation and post-exploitation scenarios, revealing that while current models show limited success, they can still discover unknown vulnerabilities and bypass defenses under realistic conditions.

Original authors: Fengyu Liu, Jiarun Dai, Yihe Fan, Wuyuao Mai, Ziao Li, Bofei Chen, Jie Zhang, Zheng Lou, Bocheng Xiang, Qiyi Zhang, Xudong Pan, Geng Hong, Yuan Zhang, Min Yang

Published 2026-06-15
📖 4 min read☕ Coffee break read

Original authors: Fengyu Liu, Jiarun Dai, Yihe Fan, Wuyuao Mai, Ziao Li, Bofei Chen, Jie Zhang, Zheng Lou, Bocheng Xiang, Qiyi Zhang, Xudong Pan, Geng Hong, Yuan Zhang, Min Yang

Original paper licensed under CC BY 4.0 (http://creativecommons.org/licenses/by/4.0/). This is an AI-generated explanation of the paper below. It is not written or endorsed by the authors. For technical accuracy, refer to the original paper. Read full disclaimer

The Big Picture: Testing AI in a "Digital Dojo"

Imagine you want to know if a new, super-smart robot is dangerous. You can't just ask it, "Are you dangerous?" because it might lie. You also can't just give it a math test, because being good at math doesn't mean it can break into a house.

To really know if this robot can cause trouble, you need to put it in a simulated neighborhood (a "Cyber Range") where it has to try to break in, just like a real burglar would.

This paper introduces AGENTCYBERRANGE, which is exactly that: a giant, open-source "digital dojo" designed to test how well the world's smartest AI systems can perform realistic cyber attacks.

The Problem: The "Video Game" vs. The "Real World"

Before this paper, testing AI security was like playing a video game where you only have to solve one puzzle at a time.

  • Old Tests: "Here is a locked door. Pick the lock." (This is called Vulnerability Reproduction).
  • The Reality: A real hacker doesn't just pick one lock. They first have to walk around the neighborhood to find the back door, sneak in, find the master key in the hallway, and then unlock every room in the house.

The authors argue that previous tests were too simple. They didn't test the AI's ability to connect the dots from "finding the door" to "taking over the whole house."

The Solution: A Two-Stage Heist

The AGENTCYBERRANGE benchmark sets up two main challenges for the AI, mimicking a real heist:

  1. Web Exploitation (The Front Door): The AI has to look at a real website (like a bank or a blog) and find a hidden back door or a weak window. It has to figure out where to look without being told.
  2. Post-Exploitation (The Inside Job): Once the AI gets in through that one door, it has to stay there. It needs to climb the ladder to get "Root" (the boss key), sneak past security guards (antivirus), and move from one computer to another until it controls the entire network.

To make this fair and repeatable, they built a tool called CAGE. Think of CAGE as the referee and the stage manager. It sets up the fake houses, lets the AI robots run, watches what they do, and automatically checks if they actually succeeded or if they just got lucky.

The Experiment: Who is the Best Burglar?

The researchers tested six of the world's most advanced AI systems (including versions of GPT, Claude, and others) in this digital dojo. They gave them a "budget" of steps (like a time limit) to try and break in.

The Results:

  • The Winner: The AI system GPT-5.5 (paired with a coding tool called Codex) was the best.
  • The Score: Even the best AI only succeeded in about 16% of the "Front Door" challenges and 32% of the "Inside Job" challenges.
  • The Takeaway: These AIs are getting scary good. They aren't just solving puzzles; they are actually breaking into real software and moving through networks. But, they are still far from being perfect, reliable hackers. They often get lost, miss hidden doors, or get caught by security alarms.

The "Surprise" Findings

The paper found two interesting things that weren't part of the original test plan:

  1. They found new secrets: While trying to break into the test websites, the AIs accidentally discovered brand new, unknown vulnerabilities (Zero-days) in popular software that even the human developers didn't know about yet.
  2. They are adaptable: When the test environment tried to stop them (like an antivirus program), the AIs sometimes changed their "tools" or "methods" to bypass the defense, showing they can think on their feet.

The Conclusion: We Need a New Mirror

The authors conclude that we can no longer just test AI on simple puzzles. Because these systems are starting to show the ability to chain together complex attacks (finding a door, breaking in, and taking over), we need realistic, end-to-end testing environments like AGENTCYBERRANGE.

We need to see exactly how they fail and how they succeed in a safe, controlled "dojo" so we can understand the risks before they are used in the real world. The paper emphasizes that while these AIs are powerful, they are not yet "reliable" attackers, but their potential is growing fast enough that we need to watch them closely.

In short: The paper built a realistic simulation to test if super-AIs can hack like humans. They found that the smartest AIs can already break into real systems and find new holes, but they still make a lot of mistakes. We need these tests to keep our digital world safe.

Drowning in papers in your field?

Get daily digests of the most novel papers matching your research keywords — with technical summaries, in your language.

Try Digest →