# How Does AI-Infra-Guard Protect AI Infrastructure? A Layered Security Analysis

> AI-Infra-Guard protects AI infrastructure with multi-layered security. Discover how it defends against CVEs, misconfigurations, and prompt attacks via fingerprinting, scanning, and risk assessment.

- Repository: [Tencent/AI-Infra-Guard](https://github.com/tencent/AI-Infra-Guard)
- Tags: deep-dive
- Published: 2026-08-26

---

**AI-Infra-Guard protects AI infrastructure through a multi-layered security platform that combines static component fingerprinting, dynamic vulnerability scanning, agent risk assessment, and jailbreak evaluation to defend AI services against CVEs, misconfigurations, and prompt-level attacks.**

AI-Infra-Guard (AIG) is an open-source AI red-team platform developed by Tencent that safeguards AI services across multiple attack surfaces. Understanding how AI-Infra-Guard protects AI infrastructure requires examining its modular architecture, which systematically addresses vulnerabilities at the component, agent, and prompt layers without requiring modifications to core code when adding new detection rules.

## Component Fingerprinting and CVE Detection

At the foundation of AI-Infra-Guard's protection strategy lies **static fingerprinting** of running AI services. The platform scans active deployments—including vLLM, Ollama, ComfyUI, and NVIDIA Triton—to identify exact versions and match them against a library of over 2,000 known CVE descriptors.

The HTTP interaction layer resides in [`pkg/httpx/httpx.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/httpx/httpx.go), which provides the low-level client used by all scanners to probe target services. The core fingerprinting logic executes in [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go), where detected components are correlated against the CVE database. When you run a scan against a live endpoint, the tool fingerprints the service and prints a table of matched vulnerabilities with severity ratings and remediation links.

To detect CVEs in a running vLLM instance:

```bash

# Target a running vLLM server

ai-infra-guard scan -t http://127.0.0.1:8000

```

The command contacts the target URL, fingerprints the service via HTTP headers and response patterns, and reports any matching vulnerabilities from the integrated database.

## YAML-Based Vulnerability Rule Engine

AI-Infra-Guard implements a **plug-in architecture** that separates detection logic from core code through YAML-defined rules. The [`pkg/database/yaml_model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/yaml_model.go) file handles parsing and loading vulnerability definitions stored in the `data/vuln/` directory.

Each YAML rule specifies detection patterns, severity levels, affected versions, and remediation steps. This architecture allows security teams to add new fingerprint or vulnerability rules rapidly in response to emerging AI threats without recompiling the application. The rule engine applies these definitions to detected components, generating structured reports that include CVE links and specific fix recommendations.

## MCP and Agent Skill Security Scanning

The platform extends protection to the **Model-Context-Protocol (MCP)** layer by inspecting MCP servers and agent skill packages for 14+ security categories. The [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go) file implements the security rule plug-in loader that checks for tool poisoning, credential leakage, privilege escalation, and other agent-specific risks.

This scanning capability targets the growing ecosystem of AI agents that interact with external tools and APIs. By analyzing skill packages and server configurations, AI-Infra-Guard identifies unsafe permission grants or exposed credentials before deployment.

To scan a local MCP repository:

```bash
ai-infra-guard mcp-scan --repo ./my-mcp-server

```

## Multi-Agent Red-Team Simulation

AI-Infra-Guard executes **dynamic red-team operations** through multi-agent simulations orchestrated by [`common/agent/agent.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/agent/agent.go). This module simulates complex agent workflows—such as those running on Dify or Coze platforms—to uncover unsafe interactions, tool misuse, and loss-of-control pathways.

Unlike static scans, these simulations exercise the actual runtime behavior of agent systems, revealing vulnerabilities that only appear during multi-step interactions. The agent framework tests for scenarios where autonomous systems might bypass safety constraints or escalate privileges through chained tool invocations.

## Jailbreak and Prompt Security Testing

At the application layer, AI-Infra-Guard evaluates **prompt-level security** through curated jailbreak datasets. The `AIG-PromptSecurity/` directory contains the testing framework that runs adversarial prompts against LLM endpoints to measure resistance to injection attacks and other prompt-level exploits.

Security teams configure target models through the web interface, select testing datasets, and initiate evaluations that report per-prompt success rates. This capability specifically targets the unique risks of large language models, where carefully crafted inputs can override safety guidelines or extract sensitive training data.

To configure jailbreak testing via the Web UI:

1. Navigate to **Settings → Model Config** and enter your LLM endpoint details
2. Select a jailbreak dataset from the curated library
3. Click **Start Evaluation** to view real-time success rates and cross-model comparison charts

## Unified API and Real-Time Monitoring

All scanning capabilities expose through a **unified RESTful API** (`/api/v1/*`) and a modern web interface powered by [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go). This architecture enables one-click execution of complex security assessments, real-time progress monitoring via WebSocket connections, and detailed JSON reporting.

The WebSocket bridge facilitates live updates during long-running scans, allowing security teams to monitor multi-agent simulations or large-scale fingerprinting operations as they progress. The REST API supports CI/CD integration, enabling automated security gates in AI deployment pipelines.

## Summary

AI-Infra-Guard delivers comprehensive AI infrastructure protection through six integrated layers:

- **Component Fingerprinting**: Identifies 2,000+ CVEs across popular AI serving frameworks via [`pkg/vulstruct/scanner.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/vulstruct/scanner.go)
- **YAML Rule Engine**: Supports rapid threat response through declarable vulnerability definitions in [`pkg/database/yaml_model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/yaml_model.go)
- **MCP Security**: Inspects agent skills and Model-Context-Protocol implementations for credential leaks and privilege escalation via [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go)
- **Red-Team Simulation**: Executes dynamic multi-agent testing against platforms like Dify and Coze through [`common/agent/agent.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/agent/agent.go)
- **Prompt Security**: Evaluates jailbreak resistance and injection vulnerabilities via the `AIG-PromptSecurity` framework
- **Unified Interface**: Provides RESTful APIs and WebSocket real-time updates through [`common/websocket/server.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/common/websocket/server.go)

## Frequently Asked Questions

### What types of AI services can AI-Infra-Guard fingerprint and detect?

AI-Infra-Guard supports fingerprinting of major AI serving frameworks including vLLM, Ollama, ComfyUI, and NVIDIA Triton. The [`pkg/httpx/httpx.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/httpx/httpx.go) HTTP client probes these services to extract version information and running configuration, matching findings against a database of over 2,000 known CVE descriptors covering common AI infrastructure components.

### How does AI-Infra-Guard detect vulnerabilities in MCP servers without executing the code?

The platform analyzes Model-Context-Protocol servers through static analysis of skill packages and configuration files. The [`internal/mcp/plugins.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/internal/mcp/plugins.go) loader inspects 14+ security categories—including tool poisoning vectors and credential leakage patterns—by parsing YAML definitions and manifest files rather than executing arbitrary agent code, ensuring safe inspection of third-party components.

### Can AI-Infra-Guard perform automated jailbreak testing against proprietary LLM endpoints?

Yes. The `AIG-PromptSecurity` module accepts custom endpoint configurations through the web UI or API, allowing security teams to test proprietary models against curated jailbreak datasets. The framework measures per-prompt success rates and generates cross-model comparison charts, validating prompt injection resistance without requiring access to the model's underlying weights or training data.

### What is the plug-in architecture for adding new vulnerability detection rules?

AI-Infra-Guard implements a YAML-based rule system defined in [`pkg/database/yaml_model.go`](https://github.com/Tencent/AI-Infra-Guard/blob/main/pkg/database/yaml_model.go) that loads detection patterns from the `data/vuln/` directory. Security researchers add new rules by creating YAML files specifying detection signatures, affected versions, and remediation steps, enabling immediate protection against emerging threats without modifying the core Go codebase or recompiling the binary.