acceptodds
Under review as a conference paper at ICLR 2027

CyberCraft: Scaling Agentic Synthesis of Repository-Level Vulnerability Environments for Security Agent Training

Abstract

Training agents to discover and repair software vulnerabilities requires executable environments in which both a vulnerability and its remediation can be verified. However, real vulnerabilities are scarce. Synthesizing vulnerabilities is a scalable alternative, but existing methods either operate on isolated functions without an executable context or inject repository-level vulnerabilities with limited diversity. We introduce CyberCraft, an agentic framework that synthesizes diverse, verifiable repository-level vulnerability environments at scale. An injector agent, guided by an atlas of vulnerability mechanisms mined from real-world CVEs, introduces vulnerabilities into real repositories. The atlas encourages the agent to explore beyond common patterns while grounding injections in real-world mechanisms, improving diversity. The resulting environments support verified teacher demonstrations and student reinforcement learning with execution-based rewards, while the injector co-evolves with the student by targeting its failures in new environments. We construct 7,979 verified environments across 713 C/C++ projects, hold out part of them as CyberCraft-Bench, and evaluate transfer to SEC-bench, PatchEval, and CyberGym-E2E. Training on these environments substantially improves Qwen3.5-9B on the three benchmarks.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.