COAPT: Bridging Semantic-Operational Divide in Autonomous Penetration Testing Through LLM-Driven Cognitive Planning

0Citations
Citations of this article
12Readers
Mendeley users who have this article in their library.
Get full text

Abstract

The automation of penetration testing has long been constrained by the semantic-operational divide between human expert cognition and machine-executable workflows. We present COAPT, a novel architecture that bridges this gap through large language model (LLM) driven cognitive planning, enabling autonomous execution of full-cycle penetration testing aligned with the penetration testing execution standard (PTES) and MITRE adversarial tactics, techniques, and common knowledge (ATT&CK) framework. COAPT introduces three key innovations: (1) A cognitive planning architecture combining retrieval-augmented generation with chain-of-thought reasoning, grounding decisions in verified cybersecurity knowledge; (2) Formal semantic interfaces that translate strategic intent into executable commands for security tools through machine-actionable contracts; (3) Hierarchical rnulti-agent coordination that maintains tactical consistency across reconnaissance, exploitation, privilege escalation, and defense recommendation phases. Evaluated across diverse penetration testing scenarios, COAPT demonstrates superior performance over state-of-the-art tools in vulnerability exploitation success rates and operational efficiency, while significantly reducing LLM hallucination risks through its knowledge-grounded reasoning approach. The architecture's ability to autonomously chain multi-stage attacks and generate ATT&CK-mapped defense strategies establishes a new paradigm for cybersecurity automation that preserves human expert workflows at machine execution scales.

Cite

CITATION STYLE

APA

Zhang, H., Lu, H., Chen, Y., He, Y., & Tian, Z. (2026). COAPT: Bridging Semantic-Operational Divide in Autonomous Penetration Testing Through LLM-Driven Cognitive Planning. Big Data Mining and Analytics, 9(3), 788–804. https://doi.org/10.26599/BDMA.2025.9020078

Register to see more suggestions

Mendeley helps you to discover research relevant for your work.

Already have an account?

Save time finding and organizing research with Mendeley

Sign up for free