How to Update Detection Rules in AI-Infra-Guard Without Recompiling
You can update detection rules in AI-Infra-Guard without recompiling by editing the plain YAML files in the data/ directory and triggering a hot-reload via the WebSocket-based Update API, management UI, or command-line tools—no binary rebuild or server restart required.
Tencent's AI-Infra-Guard maintains its security intelligence (fingerprints, CVE definitions, MCP plugins, and jailbreak evaluations) as discrete YAML files that the Go server reads dynamically at runtime. This architecture, implemented in pkg/vulstruct/scanner.go, allows security teams to iterate on detection logic instantly without rebuilding the Go binary or redeploying containers.
Understanding the YAML-Based Rule Architecture
AI-Infra-Guard decouples detection logic from the compiled binary by storing all rules as structured YAML files in specific subdirectories under data/.
Directory Structure and Rule Locations
The server expects rule files in the following locations:
data/fingerprints/— Service fingerprint templates for AI infrastructure componentsdata/vuln/anddata/vuln_en/— CVE and vulnerability definitions (multi-language support)data/mcp/— Model Context Protocol security pluginsdata/eval/— Jailbreak and safety evaluation sets
Each subdirectory contains independent *.yaml files. According to the source code in internal/options/options.go, the default fingerprint path is configurable via the --fps flag (defaulting to data/fingerprints), allowing operators to mount custom rule volumes without modifying the container image.
Runtime Rule Parsing
When the server starts (or receives a reload signal), pkg/vulstruct/scanner.go unmarshals each YAML file into Fingerprint or Vulnerability structs and compiles the rule expressions using the internal parser. Because this parsing happens at runtime, the binary contains no embedded rule data—only the engine logic required to interpret the YAML definitions.
Three Methods to Update Detection Rules Without Recompiling
Once you modify or add YAML rule files, you must refresh the in-memory cache using one of three supported interfaces. None of these methods require recompilation or process restarts.
Method 1: Management UI Hot-Reload
The React-based frontend provides a one-click reload mechanism. In frontend/src/components/management/FingerprintTabContent.tsx, the Update Data button initiates a WebSocket call to the backend reload endpoint.
- Edit the YAML file in
data/fingerprints/or another rule directory - Navigate to the Knowledge-Base page in the UI
- Click Update Data
- The frontend sends a request to
/api/v1/update, and the server rescans alldata/subdirectories
Method 2: Direct HTTP API Calls
For automation or headless environments, invoke the Update API directly using common/websocket/update_api.go. This endpoint reads the directories listed in dataDirsDefault and refreshes the rule cache atomically.
Trigger a reload via curl:
curl -X POST http://127.0.0.1:8088/api/v1/update
A response code of 0 indicates success. The server immediately uses the updated rule set for subsequent scans.
Method 3: Command-Line Synchronization
Tencent provides a Python utility for syncing rule files from upstream repositories. Located at skills/aig-agent-redteam/scripts/aig_data.py, this script downloads the latest rule definitions and places them in the correct data/ subdirectories.
Run the sync command from the repository root:
python skills/aig-agent-redteam/scripts/aig_data.py sync \
--download \
--dest data \
--include fingerprints,vuln,eval,mcp
After the script reports Sync completed, trigger the hot-reload via the HTTP API call shown above to apply the changes without restarting the service.
Advanced Rule Management via REST API
Beyond bulk reloading, you can perform CRUD operations on individual rule files through the Knowledge-Base REST API defined in common/websocket/server.go. This allows granular updates without filesystem access to the server.
Retrieving Current Rules
curl http://127.0.0.1:8088/api/v1/knowledge/fingerprints/my_new_service | jq .
Updating a Rule In-Place
Send a PUT request to overwrite a specific fingerprint definition:
curl -X PUT http://127.0.0.1:8088/api/v1/knowledge/fingerprints/my_new_service \
-H "Content-Type: application/json" \
-d '{"file_content":"name: my_new_service\nmethod: GET\npath: /api/v1/status\nmatch:\n - \"MyNewService\"\nrule: \"contains(body, \\\"MyNewService\\\")\"\nreferences:\n - https://github.com/example/my_new_service\nauthor: Jane Doe"}'
After modifying rules via the Knowledge-Base API, invoke the Update endpoint (/api/v1/update) to refresh the scanner's in-memory cache.
Configuring Custom Rule Paths
If your organization stores detection rules in a separate Git repository or configuration management system, specify an alternative path using the --fps command-line flag defined in internal/options/options.go:
./ai-infra-guard server --fps /etc/aig-custom-rules/fingerprints
The server will load YAML files from the custom directory while maintaining the same hot-reload capabilities via the Update API.
Summary
- Rule Storage: AI-Infra-Guard stores all detection logic as YAML files in
data/fingerprints/,data/vuln/,data/mcp/, anddata/eval/ - Zero-Downtime Updates: The
pkg/vulstruct/scanner.goparser loads these files at runtime, eliminating the need for binary recompilation - Hot-Reload Options: Trigger updates via the UI Update Data button, a
POSTto/api/v1/update, or theaig_data.pysync script - Custom Directories: Use the
--fpsflag to point to external rule repositories without rebuilding the application
Frequently Asked Questions
Do I need to restart the AI-Infra-Guard server after editing YAML files?
No. The server maintains an in-memory cache of parsed rules that can be refreshed on demand. Call the /api/v1/update endpoint or click Update Data in the management UI to reload rules without restarting the process or recompiling the binary.
Can I store detection rules in a custom directory outside of data/?
Yes. Use the --fps command-line flag (defined in internal/options/options.go) to specify an alternative path for fingerprint templates. You can mount external volumes or configuration maps to this path, and the hot-reload mechanism will continue to function normally.
What file format does AI-Infra-Guard use for detection rules?
All detection rules use plain YAML format. The pkg/vulstruct/scanner.go module unmarshals these files into Go structs at runtime. Each rule file contains fields like name, method, path, match, and rule (the expression logic), making them human-readable and version-control friendly.
How do I add completely new rule categories to AI-Infra-Guard?
Create a new subdirectory under data/ (for example, data/custom_checks/) and add your YAML rule files there. Ensure the files follow the same schema as existing fingerprint or vulnerability definitions. Then trigger a reload via the Update API. The scanner in pkg/vulstruct/scanner.go dynamically discovers and parses all valid YAML files in the configured directories.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →