← Back to feed
2026-07-10agentsreasoninginfra

VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents

Katherine Swinea, Kshitiz Aryal, Lopamudra Praharaj, Maanak Gupta

PDF preview for VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents
Read on arXiv →

Key claim

VEXAIoT automates IoT vulnerability assessment with high success rates.

In plain English

IoT systems face significant security challenges due to their constrained hardware and insecure configurations. Current methods for vulnerability testing are often manual and limited in scope. This paper introduces VEXAIoT, an autonomous framework that uses AI agents to discover and exploit vulnerabilities in IoT environments. Builders might care because it automates the security testing process, achieving high success rates in identifying and exploiting vulnerabilities.

Novelty
8.0/10

Introduces a novel multi-agent framework for IoT vulnerability exploitation using LLMs.

Reliability
7.5/10

Demonstrates solid experimental results across multiple attack scenarios with clear metrics.

Deep reliability assessment

The methodology supports the claim that LLM-driven agents can automate IoT vulnerability assessment in controlled environments, but it may overclaim generalizability to real-world IoT systems with more dynamic and heterogeneous conditions.

Reproducibility

No open source code or dataset is mentioned in the paper.

Key figure

Figure 1 illustrates the VEXAIoT framework, showing the separation of vulnerability analysis and exploit execution into two independent agents.

Benchmark results

~IoTGoat and Metasploitable2attack success rate: 95vs None specifiedN/A