A curated, annotated directory
Links worth opening on autonomous attackers, cyber deception, and quantum cognition
I open every page before I describe it, and every description says what the thing is and why you would bother. Nothing here is original research. The value is the selection, the annotations, and the flags on the entries I do not entirely trust.
-
Autonomous cyber attackers
AI agents and multi-agent systems used for offensive cyber operations, the benchmarks that measure them, and the defensive research responding to it.
62 links
-
Cyber deception
Honeypots, honeytokens, decoys, denial-and-deception doctrine, and the empirical work measuring whether any of it changes attacker behaviour.
58 links
-
Quantum cognition
Quantum probability theory as a model of human judgment and decision making, including the critical literature arguing that it fails.
30 links
14 entries sit across more than one topic. Those are collected on Intersections, which is also where the gaps are most visible.
Start here
The first few steps of each topic's reading path, in order. Paths has the full sequences and says why each step comes where it does.
-
Staying ahead of threat actors in the age of AI
The first joint Microsoft and OpenAI disclosure, naming five state-linked groups using models for reconnaissance, scripting and social engineering, and finding no novel AI-enabled attack. The baseline everything since is measured against.
vendor-authored# -
LLM Agents can Autonomously Exploit One-day Vulnerabilities
Reports GPT-4 exploiting 87% of 15 one-day CVEs when handed the CVE description, dropping to 7% without it. The headline number is widely cited; the caveat that it needs the writeup is the part most citations omit.
-
Cybench: A Framework for Evaluating Cybersecurity Capabilities and Risks of Language Models
Forty professional CTF tasks from four competitions, each decomposed into subtasks so partial progress is measurable. The benchmark most frequently cited when labs and AI safety institutes report offensive cyber capability.
-
CVE-Bench: A Benchmark for AI Agents' Ability to Exploit Real-World Web Application Vulnerabilities
Sandboxed reproductions of critical-severity web CVEs with automated success checks. State-of-the-art agent frameworks resolved up to 13%. That figure is the most defensible number currently available for end-to-end autonomous exploitation, and it is a long way below what the threat reporting implies.
-
Imposing a Cyber Penalty Against Attackers with Cyber Deception
Readable summary of the Tularosa findings for practitioners: 52% of attacker commands targeted decoys, and exploit failures doubled under deception. Read this before the two formal papers.
-
Deception Techniques in Computer Security: A Research Perspective
Classifies deception along four orthogonal axes: goal, unit, layer, and deployment mode. The cleanest taxonomy in the literature; the ACM version is paywalled, so the authors' copy is linked first.
-
MITRE's adversary engagement framework: prepare, operate and understand phases over a goal/approach/activity matrix, with a starter kit. Successor to MITRE Shield, and the common vocabulary most deception programmes end up using.
-
Hosted honeytoken generator, free: files, URLs, credentials, cloud keys that alert when touched.
-
Quantum cognition: a new theoretical approach to psychology
Short, readable introduction aimed at psychologists rather than mathematicians. The author's copy is free; the Elsevier version is paywalled. Ten pages, and the fastest way into the vocabulary.
-
Free-to-read review covering contextual inference, belief updating and interference effects, with an explicit section on limitations. The single best orientation piece if you read only one thing here.
-
Quantum-like models cannot account for the conjunction fallacy
The strongest published attack on the programme: experiments on question-order effects produce results the quantum account of the conjunction fallacy predicts wrongly. Read it before citing any quantum explanation of Linda.
-
An overview of the quantum cognition research program
The most current open-access survey, covering judgment fallacies, concept combination, order effects and memory, and engaging directly with replication failures such as Boyer-Kassem's order-effect results.
Recently added
The ten most recent additions to the directory.
-
Intelligent interactive honeypots: A systematization of AI-driven cyber deception
Systematizes forty studies on AI-driven interactive honeypots, mapping interaction level to attack stage and calling out unstandardised datasets and evaluation as the field's main weaknesses. Carries a 2027 issue date.
-
A 4-Month Dataset of SSH Botnet Interactions and Command Payloads
145,425 events from an SSH honeypot over four months. Command payloads, credential patterns, attack sequences. CC BY 4.0.
-
A Review of Honeypots: Fingerprinting Techniques, Detection, and Evasion Mechanisms
The counter-deception side: how attackers fingerprint honeypots through behavioural and protocol tells, and how weak existing anti-fingerprinting defences are. The corrective to optimistic deployment literature.
-
A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes
Covers both directions of agentic AI in security and names systemic risks specific to agents: collusion between them, cascading failure, oversight evasion and memory poisoning. Preprint, with working prototypes included.
preprint# -
AI as tradecraft: How threat actors operationalize AI
Two years on from the 2024 baseline: AI embedded across phishing, malware development and post-compromise work, while humans keep targeting decisions. Notes DPRK use of fabricated identities for employment fraud.
vendor-authored# -
Takes the parameter-free QQ equality from quantum cognition and applies it to model log-probabilities, finding most item pairs saturate into near-determinism and so cannot support a distribution-level test. The only direct link between these two literatures found.
preprint# -
Big Enough to Break Out: Tracking the Rising Capability of LLM Penetration-Testing Agents
Compares a human-in-the-loop pentest harness against a newer autonomous one across three public targets, arguing that planning rather than memory is the current bottleneck. Small sample, September 2026 preprint.
preprint# -
Detecting and countering misuse of AI: September 2026
Case studies of actors disrupted between December 2025 and August 2026 across seven harm categories, including cyber espionage and influence operations. Vendor-authored, and covers only misuse of one company's models.
vendor-authored# -
Foundations of Cyber Deception: Modeling, Analysis, Design, Human Factors, and Their Convergence
Twelve chapters across theory, human factors and application domains including ICS and UAV networks. Pitched at students entering the area.
paywalled# -
GTIG AI Threat Tracker: From Prompting to Autonomy - The Evolution of Adversarial AI
September 2026 tracker documenting a shift from prompt-assisted work to agentic workflows, including a cloud compromise and mass credential harvesting completed in under six hours. Names specific actors and malware families.
vendor-authored#