Analysis · curated 3 Aug 2026

LLM-Based Intelligent Agents for Cybersecurity: A Tutorial and Survey of Automated Vulnerability Discovery - University of Arizona

Coverage timeline

3 Aug 2026arizona.edu

Single-source analysis — first reported, latest, and curated coincide.

Why it matters

LLM-driven autonomous agents capable of web app testing, code auditing, fuzzing, and exploit generation represent a rising offensive-capability class that defenders must understand as these tools mature.

A peer-reviewed IEEE Access survey and tutorial from University of Arizona researchers reviews LLM-based autonomous agents for automated vulnerability discovery and penetration testing, synthesizing 155 sources (2022–early 2026) and walking through four phases: mission scoping/prompt engineering, autonomous exploration and tool selection, vulnerability hypothesis formation, and payload generation. It covers multi-agent architectures, reasoning-class models, the Model Context Protocol ecosystem, autonomous bug-bounty agents, and agentic security benchmarks.