17–19 Sept 2025
Tehnical University of Moldova
Europe/Bucharest timezone

Can Chatbots Build CTFs? A Preliminary Assessment of LLMs in Jeopardy-Style Challenge Generation

19 Sept 2025, 14:30
15m
Room 1

Room 1

Paper presentation Networking in Education and Research Open Source Education and Research

Speaker

Mihai Chiroiu (University POLITEHNICA of Bucharest)

Description

Jeopardy-style Capture-The-Flag (CTF) challenges play a central role in cybersecurity education and training; however, their creation remains a resource-intensive and technically demanding process. This paper investigates the capability of general-purpose large language models (LLMs)—specifically ChatGPT, Gemini, Copilot, Claude and DeepSeek—to automate the generation of CTF challenges. We prompt each model to create full tasks, including titles, descriptions, artifacts, and solution write-ups, across core categories such as web exploitation, cryptography, and reverse engineering. The generated challenges are evaluated using criteria including technical correctness, solvability, clarity, creativity, and write-up quality. Our results highlight significant variability in the outputs, reflecting differences in how well each model interprets prompts, handles technical nuance, and structures complete scenarios. This preliminary study demonstrates both the potential and current limitations of using LLMs in CTF design, providing a foundation for more specialized tools aimed at automated cybersecurity challenge generation.

Authors

Ghita Alexandru-Andrei (University POLITEHNICA of Bucharest) Mihai Chiroiu (University POLITEHNICA of Bucharest) Prof. Răzvan Victor RUGHINIȘ (National University of Science and Technology POLITEHNICA Bucharest)

Presentation materials

There are no materials yet.