A new benchmark finds AI attackers keep a foothold in a compromised machine in 28% to 45% of attempts, and far less when defences are on
CyberPersistBench tests what most cyber evaluations skip: whether an agent can stay inside a system after it gets in. Active defence cut success to between 5.5% and 13.3%.
Most cyber tests of AI agents stop once the agent gets in. A paper submitted to arXiv on 29 September, “CyberPersistBench: Evaluating LLM-Based Cyber Attackers on Installation and Persistence”, by Sujin Chen, Lijun Li, Xuhong Wang and Jing Shao, measures what comes next: whether an attacker built on a language model can install itself and keep its foothold on a compromised host.
The benchmark has 203 core tasks across seven categories of persistence technique. Across five frontier agents, the abstract reports persistence rates of 27.6% to 44.8%. On tasks with defences turned on, the range falls to 5.5% to 13.3%.
The two readings matter. The authors present the undefended rates as limited, and for a model working on its own they are. For a defender, though, a third to nearly half of footholds surviving is not reassuring, and the drop with active defence is the practical lesson: monitoring and response still work against these attackers.
It lands on the same day as Anthropic's finding that an open-weight model can now build working exploits almost as often as its own restricted model. Taken together, getting in is becoming easier and staying in is not yet routine. This is a preprint, not a peer-reviewed result, and the per-model table and the abstract did not agree on one read, so only the abstract's ranges are given here.
- Confirmed Persistence succeeded in 27.6% to 44.8% of cases across five frontier agents, and 5.5% to 13.3% with defences on. arXiv 2609.36573
- Confirmed The benchmark has 203 core tasks across seven categories. arXiv 2609.36573
Science & researchSafety, security & governance
Today in the September 30, 2026 edition · front page