Research · curated 15 Jul 2026

VEXA_IoT: Autonomous IoT Vulnerability EXploitation using AI Agents

Coverage timeline

15 Jul 2026arxiv.orgprimary

Single-source research — first reported, latest, and curated coincide.

Why it matters

VEXA_IoT demonstrates that LLM-driven agents can autonomously discover and exploit IoT vulnerabilities at high success rates, signaling a lowering of the barrier for scalable automated offensive operations that defenders will increasingly face.

VEXA_IoT is an autonomous multi-agent framework by Swinea et al. that uses LLM-based reasoning combined with offensive security tools (Nmap, Metasploit, bettercap) to perform reconnaissance, plan attack sequences, and exploit IoT vulnerabilities. Evaluated across IoTGoat and Metasploitable environments and ten OWASP IoT attack scenarios, it achieved a 95.0% overall success rate across 260 attack executions with execution times under two minutes.