How to Update Detection Rules in AI-Infra-Guard Without Recompiling

You can update detection rules in AI-Infra-Guard without recompiling by editing the plain YAML files in the data/ directory and triggering a hot-reload via the WebSocket-based Update API, management UI, or command-line tools—no binary rebuild or server restart required.

Tencent's AI-Infra-Guard maintains its security intelligence (fingerprints, CVE definitions, MCP plugins, and jailbreak evaluations) as discrete YAML files that the Go server reads dynamically at runtime. This architecture, implemented in pkg/vulstruct/scanner.go, allows security teams to iterate on detection logic instantly without rebuilding the Go binary or redeploying containers.

Understanding the YAML-Based Rule Architecture

AI-Infra-Guard decouples detection logic from the compiled binary by storing all rules as structured YAML files in specific subdirectories under data/.

Directory Structure and Rule Locations

The server expects rule files in the following locations:

  • data/fingerprints/ — Service fingerprint templates for AI infrastructure components
  • data/vuln/ and data/vuln_en/ — CVE and vulnerability definitions (multi-language support)
  • data/mcp/ — Model Context Protocol security plugins
  • data/eval/ — Jailbreak and safety evaluation sets

Each subdirectory contains independent *.yaml files. According to the source code in internal/options/options.go, the default fingerprint path is configurable via the --fps flag (defaulting to data/fingerprints), allowing operators to mount custom rule volumes without modifying the container image.

Runtime Rule Parsing

When the server starts (or receives a reload signal), pkg/vulstruct/scanner.go unmarshals each YAML file into Fingerprint or Vulnerability structs and compiles the rule expressions using the internal parser. Because this parsing happens at runtime, the binary contains no embedded rule data—only the engine logic required to interpret the YAML definitions.

Three Methods to Update Detection Rules Without Recompiling

Once you modify or add YAML rule files, you must refresh the in-memory cache using one of three supported interfaces. None of these methods require recompilation or process restarts.

Method 1: Management UI Hot-Reload

The React-based frontend provides a one-click reload mechanism. In frontend/src/components/management/FingerprintTabContent.tsx, the Update Data button initiates a WebSocket call to the backend reload endpoint.

  1. Edit the YAML file in data/fingerprints/ or another rule directory
  2. Navigate to the Knowledge-Base page in the UI
  3. Click Update Data
  4. The frontend sends a request to /api/v1/update, and the server rescans all data/ subdirectories

Method 2: Direct HTTP API Calls

For automation or headless environments, invoke the Update API directly using common/websocket/update_api.go. This endpoint reads the directories listed in dataDirsDefault and refreshes the rule cache atomically.

Trigger a reload via curl:

curl -X POST http://127.0.0.1:8088/api/v1/update

A response code of 0 indicates success. The server immediately uses the updated rule set for subsequent scans.

Method 3: Command-Line Synchronization

Tencent provides a Python utility for syncing rule files from upstream repositories. Located at skills/aig-agent-redteam/scripts/aig_data.py, this script downloads the latest rule definitions and places them in the correct data/ subdirectories.

Run the sync command from the repository root:

python skills/aig-agent-redteam/scripts/aig_data.py sync \
       --download \
       --dest data \
       --include fingerprints,vuln,eval,mcp

After the script reports Sync completed, trigger the hot-reload via the HTTP API call shown above to apply the changes without restarting the service.

Advanced Rule Management via REST API

Beyond bulk reloading, you can perform CRUD operations on individual rule files through the Knowledge-Base REST API defined in common/websocket/server.go. This allows granular updates without filesystem access to the server.

Retrieving Current Rules

curl http://127.0.0.1:8088/api/v1/knowledge/fingerprints/my_new_service | jq .

Updating a Rule In-Place

Send a PUT request to overwrite a specific fingerprint definition:

curl -X PUT http://127.0.0.1:8088/api/v1/knowledge/fingerprints/my_new_service \
     -H "Content-Type: application/json" \
     -d '{"file_content":"name: my_new_service\nmethod: GET\npath: /api/v1/status\nmatch:\n  - \"MyNewService\"\nrule: \"contains(body, \\\"MyNewService\\\")\"\nreferences:\n  - https://github.com/example/my_new_service\nauthor: Jane Doe"}'

After modifying rules via the Knowledge-Base API, invoke the Update endpoint (/api/v1/update) to refresh the scanner's in-memory cache.

Configuring Custom Rule Paths

If your organization stores detection rules in a separate Git repository or configuration management system, specify an alternative path using the --fps command-line flag defined in internal/options/options.go:

./ai-infra-guard server --fps /etc/aig-custom-rules/fingerprints

The server will load YAML files from the custom directory while maintaining the same hot-reload capabilities via the Update API.

Summary

  • Rule Storage: AI-Infra-Guard stores all detection logic as YAML files in data/fingerprints/, data/vuln/, data/mcp/, and data/eval/
  • Zero-Downtime Updates: The pkg/vulstruct/scanner.go parser loads these files at runtime, eliminating the need for binary recompilation
  • Hot-Reload Options: Trigger updates via the UI Update Data button, a POST to /api/v1/update, or the aig_data.py sync script
  • Custom Directories: Use the --fps flag to point to external rule repositories without rebuilding the application

Frequently Asked Questions

Do I need to restart the AI-Infra-Guard server after editing YAML files?

No. The server maintains an in-memory cache of parsed rules that can be refreshed on demand. Call the /api/v1/update endpoint or click Update Data in the management UI to reload rules without restarting the process or recompiling the binary.

Can I store detection rules in a custom directory outside of data/?

Yes. Use the --fps command-line flag (defined in internal/options/options.go) to specify an alternative path for fingerprint templates. You can mount external volumes or configuration maps to this path, and the hot-reload mechanism will continue to function normally.

What file format does AI-Infra-Guard use for detection rules?

All detection rules use plain YAML format. The pkg/vulstruct/scanner.go module unmarshals these files into Go structs at runtime. Each rule file contains fields like name, method, path, match, and rule (the expression logic), making them human-readable and version-control friendly.

How do I add completely new rule categories to AI-Infra-Guard?

Create a new subdirectory under data/ (for example, data/custom_checks/) and add your YAML rule files there. Ensure the files follow the same schema as existing fingerprint or vulnerability definitions. Then trigger a reload via the Update API. The scanner in pkg/vulstruct/scanner.go dynamically discovers and parses all valid YAML files in the configured directories.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →