arXiv:2607.19837cs.AIcs.CR2026-07

用侦察驱动的渗透测试提升对AI代理的安全评估

Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents

论文配图:Know Your Agent: Reconnaissance-Driven Pentesting of AI Agents
图 1 · 摘自论文原文
  • 通过建模侦察过程,识别代理弱点和知识资产
  • 在真实编码代理上验证,可发现隐蔽攻击漏洞
  • 开源框架与基准,适合安全研究人员使用

传统渗透测试通过每一步的侦察来发现隐藏弱点、构建更强攻击并推进目标;我们主张AI代理同样需要此类方法。本文形式化了代理侦察过程,识别其试图提取的知识资产:这些资产是什么、如何被利用、以及如何在间接提示注入攻击中暴露代理弱点。基于此,我们提出知你代理(KYA)框架,通过黑盒探测、目标画像构建和攻击生成,实现自动化侦察驱动的渗透测试。我们在代理安全基准和一个真实世界编码代理上评估了KYA,并公开了该框架、基准数据集及基线实现以支持复现。

原文摘要 · Abstract (English)

Traditional pentesting uses reconnaissance at each step to uncover unseen weaknesses, build stronger attacks, and advance the objective; we argue that AI agents require the same treatment. We formalize agent reconnaissance by modeling the process and identifying the knowledge assets it seeks to extract: what they are, how they are used, and which agent weaknesses they exploit to give adversaries leverage in indirect prompt injection attacks. We instantiate these insights in Know Your Agent (KYA), a framework that automates black-box, reconnaissance-driven pentesting by probing agents, building target profiles, and using those profiles to craft stronger attacks. We evaluate KYA on agent-security benchmarks and a real-world coding agent, and release KYA, its benchmarks, and baseline implementations for reproducibility.

AI安全渗透测试侦察提示注入

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。