arXiv:2606.19390cs.SEcs.AI2026-06被引 1

用可复现框架自动生成智能体AI安全通告,提升漏洞利用性判断准确率。

Execution-bound advisory automation for agentic AI: a reproducible AIBOM-driven CSAF-VEX framework

  • 通过SBOM与AIBOM绑定运行环境,实现静态与动态证据融合
  • 在1万组件规模的模拟智能体工作负载中验证,支持50至5000个组件
  • 生成可加密签名的CSAF-VEX通告,适合安全团队和开发方使用

提出一种协议驱动的框架,将软件物料清单(SBOM)与人工智能物料清单(AIBOM)关联到确定性环境捕获和结构化运行时遥测。漏洞可利用性基于声明的构件、观测到的激活条件和执行策略进行计算。结合静态与运行时证据生成CSAF VEX安全通告,经加密签名并可通过确定性回放验证。评估基于约10000个组件条目,在包含50至5000组件的合成智能体AI工作负载上进行,整合OSV、GitHub Advisory、KEV和EPSS数据集。

原文摘要 · Abstract (English)

A protocol driven framework is presented that binds SBOM and AIBOM artefacts to deterministic environment capture and structured runtime telemetry. Exploitability is computed from declared artefacts, observed activation conditions, and enforced execution policies. CSAF VEX advisories are generated from combined static and runtime evidence, cryptographically signed, and validated through deterministic replay. Evaluation uses approximately 10000 component entries across synthetic Agentic AI workloads 50 to 5000 components, incorporating OSV, GitHub Advisory, KEV, and EPSS datasets.

智能体安全漏洞评估可复现性CSAF-VEX

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。