arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

了解你的智能体:基于侦察的人工智能智能体渗透测试

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents

Or Zion Eliav, Eyal Lenga, Shir Bernstien, Yisroel Mirsky

arXiv 2607.19837首次发表:更新:

AI 中文总结

研究针对人工智能智能体的渗透测试,提出通过形式化智能体侦察,在KYA框架中利用探测、构建配置文件等实现黑盒侦察驱动的渗透测试自动化,并进行评估与发布,以提升智能体安全性。

AI 中文摘要

传统渗透测试在每一步都利用侦察来发现潜在弱点、构建更强攻击并推进目标,我们认为人工智能智能体也需要同样的方式。我们通过对过程建模并识别其试图提取的知识资产来形式化智能体侦察,包括资产内容、使用方式以及利用智能体弱点进行间接提示注入攻击的手段。我们在“了解你的智能体”(KYA)框架中实现了这些见解,该框架通过探测智能体、构建目标配置文件并利用这些文件进行更强攻击,实现黑盒、基于侦察的渗透测试自动化。我们在智能体安全基准测试和一个真实世界的编码智能体上评估了KYA,并发布了KYA、其基准测试和基线实现以确保可重复性。

英文摘要

Traditional pentesting uses reconnaissance at each step to uncover unseen weaknesses, build stronger attacks, and advance the objective; we argue that AI agents require the same treatment. We formalize agent reconnaissance by modeling the process and identifying the knowledge assets it seeks to extract: what they are, how they are used, and which agent weaknesses they exploit to give adversaries leverage in indirect prompt injection attacks. We instantiate these insights in Know Your Agent (KYA), a framework that automates black-box, reconnaissance-driven pentesting by probing agents, building target profiles, and using those profiles to craft stronger attacks. We evaluate KYA on agent-security benchmarks and a real-world coding agent, and release KYA, its benchmarks, and baseline implementations for reproducibility.

CommentsAccepted to 2026 IEEE Annual Computer Security Applications Conference (ACSAC)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑