Hugging Face Daily Papers · · 5 min read

Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming

Mirrored from Hugging Face Daily Papers for archival readability. Support the source by reading on the original site.

The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that \\emph{layer-paradigm matching} can serve as a practical foundation for agent security and a shared base for the community to build on.</p>\n","updatedAt":"2026-07-06T04:28:30.645Z","author":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","fullname":"Zonghao Ying","name":"Zonghao2025","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":1,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.9080268740653992},"editors":["Zonghao2025"],"editorAvatarUrls":["/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2606.31227","authors":[{"_id":"6a471e766ee372f6920de2da","name":"Yong Yang","hidden":false},{"_id":"6a471e766ee372f6920de2db","name":"Xing Zheng","hidden":false},{"_id":"6a471e766ee372f6920de2dc","name":"Huiyu Wu","hidden":false},{"_id":"6a471e766ee372f6920de2dd","name":"Huangsheng Cheng","hidden":false},{"_id":"6a471e766ee372f6920de2de","name":"Xiaorong Shi","hidden":false},{"_id":"6a471e766ee372f6920de2df","name":"Jing Guo","hidden":false},{"_id":"6a471e766ee372f6920de2e0","name":"Bo Yang","hidden":false},{"_id":"6a471e766ee372f6920de2e1","name":"Yi Zhou","hidden":false},{"_id":"6a471e766ee372f6920de2e2","name":"Xiangfan Wu","hidden":false},{"_id":"6a471e766ee372f6920de2e3","user":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user","name":"Zonghao2025"},"name":"Zonghao Ying","status":"claimed_verified","statusLastChangedAt":"2026-07-05T21:10:22.133Z","hidden":false}],"publishedAt":"2026-06-30T00:00:00.000Z","submittedOnDailyAt":"2026-07-06T00:00:00.000Z","title":"Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming","submittedOnDailyBy":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user","name":"Zonghao2025"},"summary":"The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that layer-paradigm matching can serve as a practical foundation for agent security and a shared base for the community to build on.","upvotes":8,"discussionId":"6a471e776ee372f6920de2e4","ai_summary":"AI-Infra-Guard is an open-source framework that addresses AI infrastructure security through layered detection paradigms spanning infrastructure, protocol, agent behavior, and model layers.","ai_keywords":["AI red teaming","Model Context Protocol","LLM-driven agentic auditing","black-box agent red teaming","jailbreak harness","supply-chain auditing","layer-paradigm matching"],"ai_summary_model":"Qwen/Qwen2.5-Coder-32B-Instruct","organization":{"_id":"66543b6e420092799d2f625c","name":"tencent","fullname":"Tencent","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/5dd96eb166059660ed1ee413/Lp3m-XLpjQGwBItlvn69q.png"}},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user"},{"_id":"6a2da6c8ca070ee12c6e396c","avatarUrl":"/avatars/0355287dcabaa67dbc7f0b10b87451f9.svg","isPro":false,"fullname":"Joe Mama","user":"JoeMama123123123","type":"user"},{"_id":"698f8de8ae185b257313a76c","avatarUrl":"/avatars/488cad3f610f749a5631371fb2f019b8.svg","isPro":false,"fullname":"V9y2j9w0e","user":"v9y2j9w0e","type":"user"},{"_id":"63ac5701c21e60a3e9b58aa7","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63ac5701c21e60a3e9b58aa7/g6EX7diOpuA94R2ab-rZC.png","isPro":true,"fullname":"Dipankar Sarkar","user":"dipankarsarkar","type":"user"},{"_id":"6a36a73bb3bb7023bc7c5df3","avatarUrl":"/avatars/8675271edcb0d86be5a144a24941383f.svg","isPro":false,"fullname":"Blair DuCray-Oppat","user":"blairducrayoppat","type":"user"},{"_id":"69bcead8685c38830c6381ca","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/noauth/9zRy-q7Of6x3IH6aGkbQm.jpeg","isPro":false,"fullname":"佐藤莉子","user":"miladavis","type":"user"},{"_id":"64612660933afb0106a9dee3","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/noauth/Ea83e0zR_2m8foWy6J0AF.jpeg","isPro":false,"fullname":"Xingyu Zheng","user":"Xingyu-Zheng","type":"user"},{"_id":"6270324ebecab9e2dcf245de","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/6270324ebecab9e2dcf245de/cMbtWSasyNlYc9hvsEEzt.jpeg","isPro":false,"fullname":"Kye Gomez","user":"kye","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"organization":{"_id":"66543b6e420092799d2f625c","name":"tencent","fullname":"Tencent","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/5dd96eb166059660ed1ee413/Lp3m-XLpjQGwBItlvn69q.png"},"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2606/2606.31227.md","query":{}}">
Papers
arxiv:2606.31227

Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming

Published on Jun 30
· Submitted by
Zonghao Ying
on Jul 6
Authors:
,
,
,
,
,
,
,
,
,

Abstract

AI-Infra-Guard is an open-source framework that addresses AI infrastructure security through layered detection paradigms spanning infrastructure, protocol, agent behavior, and model layers.

The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that layer-paradigm matching can serve as a practical foundation for agent security and a shared base for the community to build on.

Community

Paper author Paper submitter about 22 hours ago

The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that \emph{layer-paradigm matching} can serve as a practical foundation for agent security and a shared base for the community to build on.

Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images

· Sign up or log in to comment

Get this paper in your agent:

hf papers read 2606.31227
Don't have the latest CLI?
curl -LsSf https://hf.co/cli/install.sh | bash

Models citing this paper 0

No model linking this paper

Cite arxiv.org/abs/2606.31227 in a model README.md to link it from this page.

Datasets citing this paper 0

No dataset linking this paper

Cite arxiv.org/abs/2606.31227 in a dataset README.md to link it from this page.

Spaces citing this paper 0

No Space linking this paper

Cite arxiv.org/abs/2606.31227 in a Space README.md to link it from this page.

Collections including this paper 1

Discussion (0)

Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.

Sign in →

No comments yet. Sign in and be the first to say something.

More from Hugging Face Daily Papers