SysEvolve: An AI-native, safe, autonomous adversarial attack-defense co-evolutionary system
| Source: arXiv AI
Tags: SysEvolve, cybersecurity, LLM agents, adversarial AI, APT detection, red team
SysEvolve builds a self-evolving attack-defense system where AI agents autonomously drive each other's improvement — improving attack success 25%+ over baseline LLMs while achieving 10-1000x greater detection precision, with real APT detection validated at Huawei and Sangfor in production.
Details
LLM capabilities are accelerating offensive cybersecurity faster than they are improving defense, creating an asymmetry where attacks trend toward autonomous execution while defense remains human-intensive. SysEvolve proposes co-evolution as the solution: attack and defense AI agents autonomously drive each other's improvement through adversarial confrontation. The system has three components: SysField constructs realistic multi-host cyber ranges, orchestrating 257 CVEs into 1,148 ranges with 2.1% overhead. SySpear generates efficient attack schemes, improving attack success by over 25% above baseline LLMs. SysArmor performs real-time, interpretable defense, achieving 10–1,000x greater precision than prior systems — and has been validated detecting real APT attacks in production at Huawei and Sangfor. Evaluation reveals three important findings about LLM agent capability. First, multi-step composition and larger topologies expose capability gaps hidden by single-step evaluations. Second, the bottleneck lies in post-compromise state utilization, not initial access. Third, decoy endpoints are remarkably effective against AI agents: deploying decoys in the range triples agent timeouts and eliminates downstream task completion despite leaving initial access success rates unchanged. This production deployment context distinguishes SysEvolve from purely academic cybersecurity research and makes it directly relevant to enterprise security teams evaluating AI-driven threat detection.