Abstract

Autonomous LLM agents turn vulnerability discovery into a repository-scale search: they generate many vulnerability hypotheses but can verify only a subset under a finite budget. We show that autonomous vulnerability discovery exhibits a hypothesis-verification asymmetry, where verifying a candidate hypothesis through reachability analysis, execution, and proof-of-concept construction is substantially more expensive than forming it. Under a finite resource budget, this makes autonomous discovery a resource-bounded selective-verification process, further exposing verification effort as a unique defense surface. We present RedHerring, which inserts certifiably safe decoys that divert verification effort from real vulnerabilities. Each decoy combines a CVE-derived vulnerability chain that attracts verification with a false bridge that keeps its dangerous sink unreachable. A private certificate lets the defender verify this property efficiently, while establishing the same fact from the released repository requires solving a computationally hard problem. RedHerring further adapts each decoy to the target repository so that it reads as ordinary program logic. Across 33 OSS-Fuzz projects, 70 evaluation instances, and five models under matched budgets, RedHerring reduces real vulnerabilities discovered by 38.7-60.4%. Trajectory analysis shows that agents spend 30.6-51.5% of completion tokens and an estimated 32.5-49.9% of runtime verifying decoys, showing that RedHerring redirects a substantial fraction of the fixed search budget toward decoys. When explicitly informed that decoys may be present, the agent adapts its search strategy, yet RedHerring still reduces vulnerabilities discovered by 37.2% relative to an informed Baseline, showing that its effectiveness does not depend on decoy secrecy.

Keywords

Subject

Publication details

Journal
Not available
Open access
Green open access

Cite this article

APA 7

Zhang, K., Zhang, Z., Xie, Y., Liu, Z., Yao, S., Zhang, Z., & She, D. (2026). Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery. https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery

MLA 9

Zhang, Kaikai, et al. "Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery." https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery.

Chicago (author–date)

Zhang, Kaikai, Zihan Zhang, Yuchong Xie, Zesen Liu, Shuangjie Yao, Zhixiang Zhang, and Dongdong She. 2026. "Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery." https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery.

Harvard

Zhang, K., Zhang, Z., Xie, Y., Liu, Z., Yao, S., Zhang, Z. and She, D. (2026) 'Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery', Available at: https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery.

Vancouver

Zhang K, Zhang Z, Xie Y, Liu Z, Yao S, Zhang Z, et al. Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery. https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery

IEEE

K. Zhang, Z. Zhang, Y. Xie, Z. Liu, S. Yao, Z. Zhang, and D. She, "Cheap to Hypothesize, Costly to Verify: The Defense Surface of Agentic Vulnerability Discovery," https://omanscience.com/en/articles/cheap-to-hypothesize-costly-to-verify-the-defense-surface-of-agentic-vulnerability-discovery.