[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"doc-detail-82447-en":3,"doc-seo-82447-105":30,"detail-sidebar-cat-0-en-105":91},{"code":4,"msg":5,"data":6},0,"success",{"doc_id":7,"user_id":8,"nickname":9,"user_avatar":10,"doc_module":4,"category_id":11,"category_name":12,"doc_title":13,"doc_description":14,"doc_content":15,"file_id":16,"file_url":17,"file_type":18,"file_size":19,"view_count":20,"is_deleted":4,"is_public":21,"is_downloadable":21,"audit_status":21,"page_count":22,"language":23,"language_code":24,"site_id":25,"html_lang":24,"table_of_contents":26,"faqs":27,"seo_title":13,"seo_description":14,"update_tm":28,"read_time":29},82447,7971461741311,"Ophelia","https://ap-avatar.wpscdn.com/avatar/74000253aff267980c6?x-image-process=image/resize,m_fixed,w_180,h_180&k=1779345379180704826",8,"Research & Report","VEXAIoT Autonomous IoT Vulnerability EXploitation using AI Agents","Internet of Things (IoT) systems face persistent security weaknesses from constrained hardware, legacy firmware, and unsafe default settings, creating demand for scalable, adaptive testing. Although LLM-based agent workflows have shown value in penetration testing and CTF settings, IoT-specific vulnerability exploitation remains insufficiently explored. VEXAIoT introduces an autonomous multi-agent framework combining vulnerability detection and attack execution using LLM reasoning and offensive tools, evaluated on IoTGoat and Metasploitable across OWASP-mapped scenarios with strong success rates.","VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents  \nKatherine Swinea∗ , Kshitiz Aryal†, Lopamudra Praharaj‡, Maanak Gupta∗  \n∗ Department of Computer Science, Tennessee Tech University, TN, USA.  \n†School of Interdisciplinary Informatics, University of Nebraska Omaha, NE, USA.‡Dept. of Mathematics & Computer Science, University of North Carolina at Pembroke, NC, USA.  \nCorresponding [e-mail: mgupta@tntech.edu](e-mail: mgupta@tntech.edu)  \narXiv :2607 .09653v 1 [ cs .CR] 10 Jul 2026  \nAbstract—Internet of Things (IoT) systems are inherently vulnerable due to constrained hardware, outdated firmware, and insecure default configurations, creating a need for scalable and adaptive security testing approaches. While recent adoptionsof Large Language Model (LLM) agents have demonstrated promise in penetration testing and Capture-the-Flag (CTF) environments, their application to IoT specific vulnerabilities remains unexplored. This paper presents an autonomous multi-agent framework, referred to as Vulnerability EXploitation using AI Agents (VEXAIoT), for vulnerability discovery and exploitation in IoT environments using LLM-based reasoning and offensive security tools. The framework combines a vulnerability detection agent and an attack execution agent to perform reconnaissance, plan attack sequences, and execute exploits against vulnerable IoT services. The system is evaluated in IoTGoat and Metasploitable environments across ten attack scenarios mapped to OWASP IoT vulnerabilities. Experimental results show attack success rate of up to 100% with low token overhead and average execution times under two minutes for most attacks. Across 260 attack executions, VEXAIoT achieves a 95.0% overall success rate, including 94.5% success in IoTGoat and 96.7% success in Metasploitable2. These results demonstrate the potential for LLM-driven agents to automate IoT vulnerability assessment and offensive security workflows in controlled environments.  \nIndex Terms—IoT Security, Large Language Models, Autonomous Agents, Penetration Testing  \nI. INTRODUCTION  \nInternet of Things (IoT) devices have been largely integrated into modern society with the widespread adoption of smart devices in homes, healthcare, manufacturing, and industrial environments. The number of connected IoT devices continues to grow rapidly, reaching 18.5 billion devices in 2024 and increasing by 14% in 2025 [1] . The connected IoT devices are projected to exceed 39 billion by 2030 . While this rapid growth has improved automation and connectivity, it has also expanded the attack surface across a large number of interconnected and often vulnerable devices [2] .  \nIoT devices have many known vulnerabilities that are difficult to address due to the constrained hardware limitations, limited computational capabilities, and infrequent firmware updates. Many devices often lack strong encryption methods as secure algorithms can be computationally intensive and resource-heavy [3] . This can lead to problems such as unauthorized access to stored information or eavesdropping on communications that include sensitive information like credentials. Additionally, many IoT devices rely on hardcoded  \nor default credentials that are publicly known or easily extracted from firmware images [4] . These weaknesses can allow attackers to gain unauthorized access to the device with minimal effort. Even when vulnerabilities are identified, patching them remains difficult because update mechanisms themselves may lack integrity verification or authentication safeguards, enabling malicious firmware modifications or unauthorized updates [5] . Together, these examples show how IoT devices can be easily compromised and that the issues are often intertwined making them persistent across IoT ecosystems.  \nTo better understand these vulnerabilities and develop effective defenses, researchers commonly use IoT testbeds and intentionally vulnerable environments to simulate real-world attack scenario","cbCaiimzWbky2KXI","https://ap.wps.com/l/cbCaiimzWbky2KXI","pdf",972694,2,1,11,"English","en",105,"# Introduction\n## Motivation: IoT security challenges\n## Background: existing scanning and AI approaches\n## Gap: autonomous IoT vulnerability exploitation","[{\"question\":\"What problem does VEXAIoT address in IoT security testing?\",\"answer\":\"VEXAIoT targets the need for scalable and adaptive security testing that can autonomously identify and exploit vulnerabilities in diverse IoT environments, where conventional scanning often requires significant manual effort.\"},{\"question\":\"How does VEXAIoT work internally?\",\"answer\":\"The framework uses two LLM-driven agents: a vulnerability detection agent for reconnaissance and planning, and an attack execution agent that runs exploits against vulnerable IoT services.\"},{\"question\":\"What were the evaluation results and where were they tested?\",\"answer\":\"Experiments on IoTGoat and Metasploitable across ten OWASP IoT-mapped attack scenarios achieved up to 100% success in some cases, with an overall success rate of 95.0% across 260 executions.\"}]",1784180419,28,{"code":4,"msg":31,"data":32},"ok",{"site_id":25,"language":24,"slug":33,"title":13,"keywords":34,"description":14,"schema_data":35,"social_meta":86,"head_meta":88,"extra_data":90,"updated_unix":28},"vexaiot-autonomous-iot-vulnerability-exploitation-using-ai-agents","",{"@graph":36,"@context":85},[37,53,68],{"@type":38,"itemListElement":39},"BreadcrumbList",[40,44,47,50],{"item":41,"name":42,"@type":43,"position":21},"https://docshare.wps.com","Home","ListItem",{"item":45,"name":46,"@type":43,"position":20},"https://docshare.wps.com/document/","Document",{"item":48,"name":12,"@type":43,"position":49},"https://docshare.wps.com/document/research-report/",3,{"item":51,"name":13,"@type":43,"position":52},"https://docshare.wps.com/document/vexaiot-autonomous-iot-vulnerability-exploitation-using-ai-agents/82447/",4,{"url":51,"name":13,"@type":54,"author":55,"headline":13,"publisher":57,"fileFormat":60,"inLanguage":24,"description":14,"dateModified":61,"datePublished":62,"encodingFormat":60,"isAccessibleForFree":63,"interactionStatistic":64},"DigitalDocument",{"name":9,"@type":56},"Person",{"url":41,"name":58,"@type":59},"DocShare","Organization","application/pdf","2026-07-20","2026-07-16",true,{"@type":65,"interactionType":66,"userInteractionCount":20},"InteractionCounter",{"@type":67},"ViewAction",{"@type":69,"mainEntity":70},"FAQPage",[71,77,81],{"name":72,"@type":73,"acceptedAnswer":74},"What problem does VEXAIoT address in IoT security testing?","Question",{"text":75,"@type":76},"VEXAIoT targets the need for scalable and adaptive security testing that can autonomously identify and exploit vulnerabilities in diverse IoT environments, where conventional scanning often requires significant manual effort.","Answer",{"name":78,"@type":73,"acceptedAnswer":79},"How does VEXAIoT work internally?",{"text":80,"@type":76},"The framework uses two LLM-driven agents: a vulnerability detection agent for reconnaissance and planning, and an attack execution agent that runs exploits against vulnerable IoT services.",{"name":82,"@type":73,"acceptedAnswer":83},"What were the evaluation results and where were they tested?",{"text":84,"@type":76},"Experiments on IoTGoat and Metasploitable across ten OWASP IoT-mapped attack scenarios achieved up to 100% success in some cases, with an overall success rate of 95.0% across 260 executions.","https://schema.org",{"og:url":51,"og:type":87,"og:title":13,"og:site_name":58,"og:description":14},"article",{"robots":89,"canonical":51},"index,follow",{"doc_id":7,"site_id":25},{"code":4,"msg":5,"data":92},[93,97,101,105,110,115,120,123,128,131,135],{"id":21,"doc_module":4,"doc_module_name":46,"category_name":94,"show_sort_weight":95,"slug":96},"Story & Novel",90,"story-novel",{"id":20,"doc_module":4,"doc_module_name":46,"category_name":98,"show_sort_weight":99,"slug":100},"Literature",80,"literature",{"id":52,"doc_module":4,"doc_module_name":46,"category_name":102,"show_sort_weight":103,"slug":104},"Exam",70,"exam",{"id":106,"doc_module":4,"doc_module_name":46,"category_name":107,"show_sort_weight":108,"slug":109},5,"Comic",60,"comic",{"id":111,"doc_module":4,"doc_module_name":46,"category_name":112,"show_sort_weight":113,"slug":114},6,"Technology",50,"technology",{"id":116,"doc_module":4,"doc_module_name":46,"category_name":117,"show_sort_weight":118,"slug":119},7,"Healthcare",40,"healthcare",{"id":11,"doc_module":4,"doc_module_name":46,"category_name":12,"show_sort_weight":121,"slug":122},30,"research-report",{"id":124,"doc_module":4,"doc_module_name":46,"category_name":125,"show_sort_weight":126,"slug":127},9,"Religion & Spirituality",20,"religion-spirituality",{"id":126,"doc_module":4,"doc_module_name":46,"category_name":129,"show_sort_weight":126,"slug":130},"World Cup","world-cup",{"id":132,"doc_module":4,"doc_module_name":46,"category_name":133,"show_sort_weight":132,"slug":134},10,"Lifestyle","lifestyle",{"id":136,"doc_module":4,"doc_module_name":46,"category_name":137,"show_sort_weight":106,"slug":138},19,"General","general"]