Open-weight penetration test: access without a cooperative model provider still takes equipment
Open-weight penetration test: access without a cooperative model provider still takes equipment
Original evaluation: Luo et al., The Emergence of Autonomous Penetration Capabilities in Large Language Model-Powered AI Systems, revised 29 June 2026. Nineteen models, including open-weight and proprietary ones, received an authorized IP address, general-purpose scanning and exploit tools, and the goal of a reverse shell on one lab-built target. Each of 300 target instances intentionally had one known exploitable remote-code-execution service plus one or three other services; success meant a reverse shell in any of three trials per target. The paper reports 10.7–69.3% success across models and configurations, though the range mixes target tiers. Importantly, its locally hosted open-weight inference ran on a server with eight H100 GPUs: removal of the provider account boundary did not mean zero hardware cost. Other model endpoints were reached over HTTP APIs.
For the compute question, this is a proof that some authorized scoped penetration can be conducted without a safety-cooperative frontier provider, not evidence of a cheap, distributed campaign. The paper does not price rental/ownership, power, run-specific tokens or human/operator costs, or compare host logs and detection. Vulnerabilities were known and present by construction, exploits often came from existing Metasploit modules, and the targets lacked active defenders, post-exploitation, persistence and lateral movement. It gives no prevalence of vulnerable real targets or fraction of severe intrusions that would defeat a provider choke point. See cross-pathway synthesis and Dru’s compute-cost hypothesis.