arXiv:2505.08842cs.CRcs.CL2025-05ACL被引 6

用AI智能体系统检测开源AI库隐藏漏洞,提升供应链安全

LibVulnWatch: A Deep Assessment Agent System and Leaderboard for Uncovering Hidden Vulnerabilities in Open-Source AI Libraries

  • 构建多智能体图谱系统,自动分析代码库与文档风险
  • 覆盖88%的OpenSSF评分检查项,每库发现最多19个新增风险
  • 适合开发者、安全团队和企业选型时评估开源库风险

开源AI库是现代AI系统的基础,但其在安全、许可、维护、供应链完整性和合规性方面存在显著且未被充分关注的风险。我们提出LibVulnWatch,一个利用大语言模型和智能体工作流进行深度、基于证据评估的系统。该框架基于图结构编排多个专业智能体,从代码仓库、文档和漏洞数据库中提取、验证并量化风险,生成可复现、符合治理要求的五维评分,并公开发布到公共排行榜以实现持续生态监控。应用于20个广泛使用的库(包括机器学习框架、大模型推理引擎和智能体编排工具),该方法覆盖高达88%的OpenSSF Scorecard检查项,每库额外发现最多19个风险,如关键远程执行漏洞、缺失软件物料清单(SBOM)及监管缺口。通过融合先进语言技术与实际软件风险评估需求,本工作展示了可扩展、透明的持续供应链评估机制,支持更明智的库选择决策。

原文摘要 · Abstract (English)

Open-source AI libraries are foundational to modern AI systems, yet they present significant, underexamined risks spanning security, licensing, maintenance, supply chain integrity, and regulatory compliance. We introduce LibVulnWatch, a system that leverages recent advances in large language models and agentic workflows to perform deep, evidence-based evaluations of these libraries. Built on a graph-based orchestration of specialized agents, the framework extracts, verifies, and quantifies risk using information from repositories, documentation, and vulnerability databases. LibVulnWatch produces reproducible, governance-aligned scores across five critical domains, publishing results to a public leaderboard for ongoing ecosystem monitoring. Applied to 20 widely used libraries, including ML frameworks, LLM inference engines, and agent orchestration tools, our approach covers up to 88% of OpenSSF Scorecard checks while surfacing up to 19 additional risks per library, such as critical RCE vulnerabilities, missing SBOMs, and regulatory gaps. By integrating advanced language technologies with the practical demands of software risk assessment, this work demonstrates a scalable, transparent mechanism for continuous supply chain evaluation and informed library selection.

开源安全智能体系统漏洞检测供应链风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。