acceptodds
Under review as a conference paper at ICLR 2027

TRACE: Evidence-Grounded Epistemic Control for Reliable Autonomous Penetration Testing

Abstract

Autonomous penetration-testing agents increasingly rely on large language models to reason over security observations and orchestrate heterogeneous tools. However, these environments are partially observable and dynamic, and tool outputs may be incomplete, stale, conflicting, or misleading. Such epistemic errors can propagate through long-horizon trajectories, leading to redundant probing, premature decisions, and task failure. We propose TRACE, an evidence-grounded epistemic-control framework that maintains claim-centric beliefs using evidence provenance, reliability, temporal freshness, and explicit support–contradiction relations. TRACE actively acquires evidence using prospective information gain under cost, redundancy, and operational-risk constraints, and repairs affected beliefs when prior evidence becomes invalid or contradictory. Under a controlled same-backbone evaluation, TRACE increases CVE-Bench Success@1 from 25.0% to 32.5%. In separate epistemic-control analyses, TRACE reduces the repeated-action rate from 0.273 to 0.158 relative to heuristic evidence acquisition and improves recovery over dependency-agnostic belief repair. These results demonstrate the value of explicit evidence and belief management for robust autonomous penetration testing under unreliable observations.

open until 14 Dec 2026

est. 32% chance this paper gets accepted at ICLR 2027.

Reject 68%Accept 32%

What do you think this paper will get?

All positions stay anonymous.

Related papers

Loading the map…

Discussion (0)

Sign in to comment.