软件工程流水线中编码代理的基于执行的安全测试
Execution-Grounded Security Testing for Coding Agents in Software Engineering Pipelines
浏览论文内容
中文总结 AI 辅助
研究针对软件工程流水线中编码代理的安全问题,提出基于执行的红队测试框架,利用沙盒证据探测安全边界,将不安全操作嵌入工作负载并借助执行预言机优化,通过实验大幅增加不安全执行验证率,凸显编码代理需更强安全测试。
中文摘要 AI 辅助
编码代理越来越多地集成到系统操作中,其工具使用可直接修改项目工件、执行环境和底层系统。例如,若编码代理在系统启动或配置脚本中插入钩子,更改可能在交互后持续,随后触发并滥用委托的用户或系统权限来修改系统。这使安全测试成为系统问题。我们提出一个基于执行的红队测试框架,利用可观察的沙盒证据探测执行层安全边界,包括工具调用、运行时跟踪和文件系统差异。我们的框架将目标不安全操作嵌入常规软件工程工作负载中,使用执行预言机在初始探测被拒绝或失败时指导优化。在多个代理框架和模型主干上,我们的红队工作负载重新制定大幅增加了已验证的不安全执行,在代码载体上达到73.61%,在文本载体上达到53.93%。这些结果表明,系统操作中的编码代理在任务伪装下仍不安全,一旦危险意图隐藏在合理的工程任务中,代理可能会对周围系统执行不安全操作。更广泛地说,系统操作中的编码代理仍需要更强的安全测试和保障措施。
英文摘要
Coding agents are increasingly integrated into system operations, where their tool use can directly modify project artifacts, execution environments, and the underlying system. For example, if a coding agent inserts a hook into a system startup or configuration script, that change can persist after the interaction, be triggered later, and abuse delegated user or system privileges to modify the system. This makes security testing a system problem: the key question is not only what the agent says, but what it actually does to the surrounding environment. We present an execution-grounded red-team testing framework for probing this execution-layer security boundary using observable sandbox evidence, including tool invocations, runtime traces, and file-system diffs. Our framework embeds target unsafe operations into routine software engineering workloads, including unit testing, regression testing, crash reproduction, and validation, and uses an execution oracle to guide refinement when an initial probe is rejected or fails. Across multiple agent frameworks and model backbones, our red-team workload reformulation substantially increases verified unsafe execution, reaching 73.61% on code carriers and 53.93% on text carriers. These results show that coding agents in system operations remain insecure under task disguise: once risky intent is hidden inside plausible engineering tasks, the agent can be induced to carry out unsafe actions on the surrounding system. More broadly, coding agents in system operations still demand stronger security testing and safeguards.
发表机构
- Nanjing University(南京大学)
- Nanyang Technological University(南洋理工大学)
- Hainan University(海南大学)
机构由 AI 辅助整理,请以论文原文为准。