CRAIJun 26

LLM agents security duality: a comprehensive survey of self-security and empowered cybersecurity

arXiv:2606.28450
Originality Synthesis-oriented
AI Analysis

For researchers and practitioners in AI security, this survey provides a structured overview and framework that unifies two previously separate areas, though it is a survey without new empirical results.

This survey comprehensively reviews the dual role of LLM agents in security: threats to agents themselves with mitigations, and their use in cybersecurity offense/defense. It proposes taxonomies and a first agent-empowerment framework aligned with the cyber lifecycle, highlighting a positive feedback synergy between self-security and empowered cybersecurity.

Large language model (LLM) agents are rapidly being integrated into real-world systems. Their autonomy and tool-use capabilities generate substantial value while simultaneously expanding the security attack surface. This survey provides a comprehensive overview of the opportunities and challenges of LLM agents in security, focusing on two core areas: (1) threats to LLM agents themselves and corresponding mitigation strategies (LLM agents self-security), and (2) the role of LLM agents in empowering the cybersecurity lifecycle across offense and defense (LLM agents empowered cybersecurity). We first examine the internal and external attack surfaces of agents, propose a taxonomy organized by threat sources, and analyze associated mitigations and evaluation frameworks. We then investigate how agent capabilities are applied in cybersecurity practice and present, to our knowledge, the first agent-empowerment framework aligned with the full cyber offense-defense lifecycle. By systematically surveying these two areas, we are the first to highlight a positive feedback synergy between LLM agents self-security and empowered cybersecurity, offering new insights for the advancement of both. We further identify current limitations and outline promising directions for future research. The insights provided aim to catalyze the coordinated development of LLM agents self-security and agent empowered cybersecurity, paving the way for more capable and robust agent applications.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes