arXiv:2605.27042cs.CRcs.AI2026-05中稿 · SAGAI 2026

对两款私有AI代理系统渗透测试,发现安全漏洞仍普遍

Lessons from Penetration Tests on Large-Scale Agent Systems

论文配图:Lessons from Penetration Tests on Large-Scale Agent Systems
图 1 · 摘自论文原文
  • 通过真实渗透测试检验私有AI代理系统安全性
  • 发现多类与过往系统相同的重复性安全弱点
  • 揭示即使严格开发流程也难避免深层安全缺陷

随着AI系统自主性和执行能力不断增强,已发现的安全漏洞数量持续上升。然而,这些漏洞大多并非根本性创新,而是长期存在于以往计算系统中的典型弱点。具备执行能力的AI代理本质上是无边界、可自我修改的程序,广泛交互于计算栈的多个层级,给开发者带来巨大安全挑战,需推理并防护复杂的跨层行为。以往研究主要关注开源代理及其框架中的漏洞,而私有代理系统——在更严格的编码标准和正式审查流程下开发——是否同样存在类似安全弱点仍不明确。本文报告了2025年对两款私有代理产品开展的两次渗透测试结果,并评估自该评估以来AI代理系统的安全状况是否有所改善。

原文摘要 · Abstract (English)

As AI systems gain increasing autonomy and execution capability, the number of discovered security vulnerabilities continues to rise. However, many of these vulnerabilities are not fundamentally novel, but instead reflect recurring classes of weaknesses long observed in prior computing systems. Execution-capable AI agents are effectively unbounded, self-modifying programs that interact extensively with multiple layers of the computing stack. This broad interaction surface imposes a significant security burden on developers, who must reason about and secure complex cross-layer behaviors. Prior research has primarily focused on vulnerabilities in open-source agents and agent frameworks. In contrast, it remains unclear whether proprietary agent systems -- developed under stricter coding standards and formal review processes -- exhibit similar security weaknesses. In this paper, we present findings from two penetration tests conducted in 2025 against proprietary agent products and evaluate whether the security posture of AI agents has improved since these assessments.

AI安全渗透测试代理系统

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。