Back to today's list

LLM agents security duality: a comprehensive survey of self-security and empowered cybersecurity

Yiwei Xu, Yong Zhuang, Xuanming Liu, Tian Zhang, Bowen Xiao, Xiaoyang Xu, Delong Jiang, Juan Wang, Hongxin Hu

Published Jun 30, 2026
Editorial review7.5
Relevance0.471
Freshness0.000

Why It Matters

What makes this one worth your time

As LLM agents become more integrated into systems, understanding their security implications is crucial for developing robust applications and mitigating risks.

This survey explores the dual role of LLM agents in self-security and cybersecurity enhancement.

Summary

The paper surveys the security challenges and opportunities presented by large language model (LLM) agents, focusing on their self-security and their role in enhancing cybersecurity practices.

Key contributions

  • A comprehensive overview of threats to LLM agents and corresponding mitigation strategies.
  • A proposed taxonomy of threat sources related to LLM agents.
  • The first agent-empowerment framework aligned with the full cyber offense-defense lifecycle.

Notable insights

  • The paper proposes a taxonomy organized by threat sources specific to LLM agents, which could help in systematically addressing security vulnerabilities.
  • It introduces an agent-empowerment framework that aligns with the entire cyber offense-defense lifecycle, potentially offering a new approach to cybersecurity.

Possible limitations

  • Not stated in the abstract.

Abstract

arXiv:2606.28450v1 Announce Type: cross Abstract: Large language model (LLM) agents are rapidly being integrated into real-world systems. Their autonomy and tool-use capabilities generate substantial value while simultaneously expanding the security attack surface. This survey provides a comprehensive overview of the opportunities and challenges of LLM agents in security, focusing on two core areas: (1) threats to LLM agents themselves and corresponding mitigation strategies (LLM agents self-security), and (2) the role of LLM agents in empowering the cybersecurity lifecycle across offense and defense (LLM agents empowered cybersecurity). We first examine the internal and external attack surfaces of agents, propose a taxonomy organized by threat sources, and analyze associated mitigations and evaluation frameworks. We then investigate how agent capabilities are applied in cybersecurity practice and present, to our knowledge, the first agent-empowerment framework aligned with the full cyber offense-defense lifecycle. By systematically surveying these two areas, we are the first to highlight a positive feedback synergy between LLM agents self-security and empowered cybersecurity, offering new insights for the advancement of both. We further identify current limitations and outline promising directions for future research. The insights provided aim to catalyze the coordinated development of LLM agents self-security and agent empowered cybersecurity, paving the way for more capable and robust agent applications.