CSIRO Cybersecurity Seminar – The Autonomous Adversary: Red-Teaming in the Age of LLM Agents
Presentation: CSIRO Cybersecurity Seminar – The Autonomous Adversary: Red-Teaming in the Age of LLM Agents
Wednesday 29 Jul 2026 | ONLINE | Dr. Mohammad Mamun, Senior Research Officer in cybersecurity at the Digital Technology Research Centre, National Research Council Canada.
Abstract
LLM agents are emerging as a new primitive for autonomous red teaming, with the potential to support multi-step cyber operations such as attack planning, adversary emulation, and lateral movement. Recent advances in autonomous cyber evaluation, including cyber-range assessments by the UK AI Security Institute and related research on agentic AI for cybersecurity, have shifted attention from prompt-level misuse toward end-to-end operational capability in realistic environments.
This work examines the role of LLM agents as autonomous adversaries through controlled lateral-movement scenarios that capture key elements of advanced cyber operations under different levels of autonomy. The results highlight both the promise and the current limitations of LLM-based red teaming: although these systems can exhibit useful planning and adaptive behavior, reliable execution remains constrained by brittle command invocation, weak state tracking, credential-handling failures, and environmental instability. These findings underscore the need for rigorous evaluation methodologies, realistic cyber-range benchmarks, and stronger governance frameworks for increasingly capable autonomous cyber agents.
