VEXAIoT: Autonomous IoT Vulnerability EXploitation using AI Agents
This work addresses the urgent need for efficient and scalable automated security testing of Internet of Things (IoT) devices, which are widely vulnerable due to resource constraints, outdated firmware, and insecure default configurations. The paper proposes the first large language model (LLM)-based multi-agent framework that orchestrates vulnerability detection and exploitation agents to perform end-to-end autonomous penetration testing—from environmental reconnaissance and attack planning to actual exploitation. The system integrates mainstream scanning and exploitation toolchains and demonstrates high efficacy on IoTGoat and Metasploitable platforms, achieving a 95.0% success rate across 260 attacks with an average execution time under two minutes and low token consumption, highlighting its strong adaptability and practical utility.