Share your thoughts, 1 month free Claude Pro on usSee more
WorkDL logo mark

A Red Teaming Framework for Evaluating Robustness of AI-enabled Security Orchestration, Automation, and Response Systems

About

AI-enabled Security Orchestration, Automation, and Response (SOAR) systems increasingly employ autonomous agents for cyber defense, yet their resilience to adaptive adversaries is underexplored. We introduce an autonomous red teaming framework that integrates large language models (LLMs) with reinforcement learning (RL) to generate adaptive, multi-stage attack campaigns against autonomous defenders in enterprise networks. A hierarchical design combines an LLM-based planner for strategic intent with an RL controller for tactical execution, supported by reward shaping aligned with kill-chain progression. Evaluation in a high-fidelity enterprise simulation demonstrates the effectiveness of the proposed approach, while also showing that standalone LLM agents fail to sustain multi-stage attack campaigns and that domain-specific cybersecurity models achieve only limited levels of compromise, highlighting the necessity for hybrid LLM-RL approaches to red teaming.

Ayan Javeed Shaikh, Nathaniel D. Bastian, Ankit Shah• 2026

Related benchmarks

TaskDatasetResultRank
Red Teaming EvaluationCAGE 200 episodes 4--
6
Cyber Red TeamingCAGE 4 (200 episodes)
AHD9.86
4
Showing 2 of 2 rows

Other info

Follow for update