Применение общедоступных больших языковых моделей для проведения автоматизированного тестирования на проникновение
Ключевые слова:
большие языковые модели, искусственный интеллект, наступательный искусственный интеллектАннотация
В работе исследуется возможность применения общедоступных больших языковых моделей для проведения кибератаки путем автоматизированного тестирования на проникновение в систему. Тестирование проводилось с использованием большой языковой модели DeepSeek-R1. Эксперимент был проведен на лабораторном стенде, состоящим из двух виртуальных машин с операционными системами: Kali Linux и Metasploitable2. Полученные результаты показали возможность применения большой языковой модели для проведения пентеста, но с некоторыми ограничениями.
Библиографические ссылки
[1] Williams, S. Cybersecurity teams are preparing for a surge in global CVE vulnerabilities in 2026 // SecurityBrief Asia. — 2026. — Режим доступа: https://securitybrief.asia/story/cybersecurity-teams-brace-for-surge-in-global-cves-in-2026.
[2] Singer, B., Lucas, K., Adiga, L., Jain, M., Bauer, L., Sekar, V. (2025). Incalmo: An Autonomous LLM-Based System for Red Teaming in Multi-Component Networks. arXiv.org. DOI: 10.1007/s10207-024-00868-2
[3] Mirsky, Y., Demontis, A., Kotak, J., Shankar, R., Gelei, D., Yang, L., Zhang, X., Pintor, M., Lee, W., Elovici, Y., Biggio, B. (2023). The Threat of Offensive Artificial Intelligence to Organizations. Computers & Security.: https://www.sciencedirect.com/science/article/abs/pii/S0167404822003984
[4] Gupta, M., Gupta, M. (2025). Measuring AI Cybersecurity: A Comprehensive Framework for Understanding Offensive and Adversarial AI. AI and Ethics, 5, 883–910. DOI: 10.1007/s43681-024-00427-4
[5] Hu, Z., Beuran, R., Tan, Y. (2020). Automated Penetration Testing Using Deep Reinforcement Learning. In: Proceedings of the 2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), Genoa, Italy, pp. 2–10. DOI: 10.1109/EuroSPW51379.2020.00010
[6] Nguyen, T. T., Reddi, V. J. (2021). Deep Reinforcement Learning for Cybersecurity. arXiv.org.: https://arxiv.org/abs/1906.05799
[7] CVE-2025-26210: Cross-Site Scripting (XSS) Vulnerability in DeepSeek AI Products (2025). Feedly.: https://feedly.com/cve/CVE-2025-26210
[8] Kelly, D. J., Long, J., Mylonas, A., Pitropakis, N., Buchanan, W. J. (2024). A Systematic Review of Research Using Artificial Intelligence for Open Source Intelligence (OSINT) Applications. International Journal of Information Security, 23, 2911–2938. DOI: 17487/RFC8377
[9] IBM aThink (2023). AI vs Human Deceit: Unravelling New-Age Phishing Tactics.: https://www.ibm.com/think/x-force/ai-vs-human-deceit-unravelling-new-age-phishing-tactics
[10] Инфобезопасность.ру (2025). ИИ вооружил киберпреступников — число атак в России выросло на треть.: https://infobezopasnost.ru/blog/news/ii-vooruzhil-kiberprestupnikov-chislo-atak-v-rossii-vyroslo-na-tret
[11] Как реклама с дипфейками в Instagram приводит к потере денег. (2025): https://www.kaspersky.ru/blog/scam-with-deepfakes-in-instagram-facebook-whatsapp/40221
[12] Zhang, Z., Wang, C., Wang, Y., Shi, E., Ma, Y., Zhong, W., Chen, J., Mao, M., Zheng, Z. (2025). LLM Hallucinations in Practical Code Generation: Phenomena, Mechanisms, and Mitigation. Proceedings of ISSTA 2025. DOI: 10.1145/3728894
[13] LLM they cannot cope with the search and exploitation of vulnerabilities // Infosecurity Magazine.: https://www.infosecurity-magazine.com/news/llms-fall-vulnerability-discovery
[14] Todd, D. (2025). DeepSeek and AI-Generated Malware Pose New Cybersecurity Threat. SecureWorld.: https://www.secureworld.io/industry-news/deepseek-ai-generated-malware
[15] Alger, J. (Managing Editor) (2025). DeepSeek Can Develop Malware: Cyber Experts Share the Risks. Security Magazine.: https://www.securitymagazine.com/articles/101470-deepseek-can-develop-malware-cyber-experts-are-sharing-the-risks
Загрузки
Опубликован
Выпуск
Раздел
Лицензия
Copyright (c) 2026 Системная инженерия и инфокоммуникации

Это произведение доступно по лицензии Creative Commons «Attribution-ShareAlike» («Атрибуция — На тех же условиях») 4.0 Всемирная.