arXiv:2603.08566cs.CRcs.AI2026-03被引 2

开源可本地部署的网络安全推理框架,助力发现真实项目中的未知漏洞。

OSS-CRS: Liberating AIxCC Cyber Reasoning Systems for Real-World Open-Source Security

  • 构建可本地运行的开源框架,支持多类安全推理技术协同
  • 在8个OSS-Fuzz项目中发现10个新漏洞,含3个高危级
  • 适合安全研究者与开源维护者快速集成和验证漏洞检测能力

DARPA的AI网络安全挑战赛(AIxCC)表明,网络安全推理系统(CRS)不仅能发现漏洞,还能自主验证并修复:七支队伍在此后开源了其系统。然而,这七个开源的CRS仍基本无法在原团队之外使用,因它们依赖已不存在的比赛云环境。我们提出OSS-CRS,一个开放、可本地部署的框架,用于对真实开源项目运行并组合多种CRS技术,具备预算感知的资源管理能力。我们移植了第一名系统(Atlantis),并在8个OSS-Fuzz项目中发现了10个此前未知的漏洞,其中3个为高危级别。OSS-CRS已公开发布。

原文摘要 · Abstract (English)

DARPA's AI Cyber Challenge (AIxCC) showed that cyber reasoning systems (CRSs) can go beyond vulnerability discovery to autonomously confirm and patch bugs: seven teams built such systems and open-sourced them after the competition. Yet all seven open-sourced CRSs remain largely unusable outside their original teams, each bound to the competition cloud infrastructure that no longer exists. We present OSS-CRS, an open, locally deployable framework for running and combining CRS techniques against real-world open-source projects, with budget-aware resource management. We ported the first-place system (Atlantis) and discovered 10 previously unknown bugs (three of high severity) across 8 OSS-Fuzz projects. OSS-CRS is publicly available.

网络安全漏洞挖掘开源工具AI推理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。