ABRACADABRA Labs / resource directory

A curated, annotated directory

Research worth reading on autonomous attackers, cyber deception, and quantum cognition

A curated list of links on autonomous attackers, cyber deception, and quantum cognition. Each entry comes with a short note on what it is and why it's worth a look.

14 entries sit across more than one topic. Those are collected on Intersections, which is also where the gaps are most visible.

Start here

Four readings per topic, in order. Each group is the start of a reading path; Paths continues it and says why each step comes where it does.

Autonomous cyber attackers

  1. Staying ahead of threat actors in the age of AI

    The first joint Microsoft and OpenAI disclosure, naming five state-linked groups using models for reconnaissance, scripting and social engineering, and finding no novel AI-enabled attack. The baseline everything since is measured against.

    vendor-authored
  2. LLM Agents can Autonomously Exploit One-day Vulnerabilities

    Reports GPT-4 exploiting 87% of 15 one-day CVEs when handed the CVE description, dropping to 7% without it. The headline number is widely cited; the caveat that it needs the writeup is the part most citations omit.

    contestedpreprint
  3. Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models

    Forty professional CTF tasks from four competitions, each decomposed into subtasks so partial progress is measurable. The benchmark most frequently cited when labs and AI safety institutes report offensive cyber capability.

  4. CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities

    Sandboxed reproductions of critical-severity web CVEs with automated success checks. State-of-the-art agent frameworks resolved up to 13%. That figure is the most defensible number currently available for end-to-end autonomous exploitation, and it is a long way below what the threat reporting implies.

    open version

Cyber deception

  1. Imposing a Cyber Penalty Against Attackers with Cyber Deception

    Readable summary of the Tularosa findings for practitioners: 52% of attacker commands targeted decoys, and exploit failures doubled under deception. Read this before the two formal papers.

  2. Deception Techniques in Computer Security: A Research Perspective

    Classifies deception along four orthogonal axes: goal, unit, layer, and deployment mode. The cleanest taxonomy in the literature; the ACM version is paywalled, so the authors' copy is linked first.

    seminalopen version
  3. MITRE Engage

    MITRE's adversary engagement framework: prepare, operate and understand phases over a goal/approach/activity matrix, with a starter kit. Successor to MITRE Shield, and the common vocabulary most deception programs end up using.

    open version
  4. Canarytokens

    Hosted honeytoken generator, free: files, URLs, credentials, cloud keys that alert when touched.

    livingvendor-authored

Quantum cognition

  1. Quantum cognition: a new theoretical approach to psychology

    Short, readable introduction aimed at psychologists rather than mathematicians. The author's copy is free; the Elsevier version is paywalled. Ten pages, and the fastest way into the vocabulary.

    open version
  2. Quantum Cognition

    Free-to-read review covering contextual inference, belief updating and interference effects, with an explicit section on limitations. The single best orientation piece if you read only one thing here.

    open version
  3. Quantum-like models cannot account for the conjunction fallacy

    The strongest published attack on the program: experiments on question-order effects produce results the quantum account of the conjunction fallacy predicts wrongly. Read it before citing any quantum explanation of Linda.

    contestedseminalopen version
  4. An overview of the quantum cognition research program

    The most current open-access survey, covering judgment fallacies, concept combination, order effects and memory, and engaging directly with replication failures such as Boyer-Kassem's order-effect results.

Recently added

The ten most recent additions to the directory.