Program

Date Time Event
Fri 16 Oct 2026
Holiday Inn Munich – City Center
TBD Keynote
Jürgen Cito | TU Wien, Austria

Jürgen Cito is a Full Professor of Software Engineering at TU Wien, Austria. He received his PhD from the University of Zurich and was a postdoctoral researcher at MIT CSAIL. His research focuses on program analysis and AI-based software engineering, with a particular emphasis on autonomous systems for software development and security. His recent work investigates the capabilities and limitations of large language models in offensive security, including automated penetration testing and the ethical implications of dual-use AI systems.


Language Models as Penetration Testing Agents: Surprising Capabilities and Ethical Dimensions

Large language models (LLMs) have recently shown unexpectedly strong performance in offensive security tasks. In this talk, I present our work demonstrating their effectiveness in concrete scenarios such as privilege escalation and attacks on enterprise networks (e.g., Active Directory environments). To explain these results, we hypothesize why LLMs perform well in this domain and relate these hypotheses to our empirical study of how human penetration testers reason and operate in practice. Finally, I want to discuss the ethical dimension of automated penetration testing: Dual-use concerns have always been central to security research, but become more acute with increasing levels of autonomy. We examine how these concerns manifest in the context of LLM-based penetration testing, including questions around responsible disclosure, access, and the broader implications of commoditizing offensive capabilities.


TBD More sessions to be announced...