The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that \\emph{layer-paradigm matching} can serve as a practical foundation for agent security and a shared base for the community to build on.</p>\n","updatedAt":"2026-07-06T04:28:30.645Z","author":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","fullname":"Zonghao Ying","name":"Zonghao2025","type":"user","isPro":false,"isHf":false,"isHfAdmin":false,"isMod":false,"followerCount":1,"isUserFollowing":false}},"numEdits":0,"identifiedLanguage":{"language":"en","probability":0.9080268740653992},"editors":["Zonghao2025"],"editorAvatarUrls":["/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg"],"reactions":[],"isReport":false}}],"primaryEmailConfirmed":false,"paper":{"id":"2606.31227","authors":[{"_id":"6a471e766ee372f6920de2da","name":"Yong Yang","hidden":false},{"_id":"6a471e766ee372f6920de2db","name":"Xing Zheng","hidden":false},{"_id":"6a471e766ee372f6920de2dc","name":"Huiyu Wu","hidden":false},{"_id":"6a471e766ee372f6920de2dd","name":"Huangsheng Cheng","hidden":false},{"_id":"6a471e766ee372f6920de2de","name":"Xiaorong Shi","hidden":false},{"_id":"6a471e766ee372f6920de2df","name":"Jing Guo","hidden":false},{"_id":"6a471e766ee372f6920de2e0","name":"Bo Yang","hidden":false},{"_id":"6a471e766ee372f6920de2e1","name":"Yi Zhou","hidden":false},{"_id":"6a471e766ee372f6920de2e2","name":"Xiangfan Wu","hidden":false},{"_id":"6a471e766ee372f6920de2e3","user":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user","name":"Zonghao2025"},"name":"Zonghao Ying","status":"claimed_verified","statusLastChangedAt":"2026-07-05T21:10:22.133Z","hidden":false}],"publishedAt":"2026-06-30T00:00:00.000Z","submittedOnDailyAt":"2026-07-06T00:00:00.000Z","title":"Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming","submittedOnDailyBy":{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user","name":"Zonghao2025"},"summary":"The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that layer-paradigm matching can serve as a practical foundation for agent security and a shared base for the community to build on.","upvotes":8,"discussionId":"6a471e776ee372f6920de2e4","ai_summary":"AI-Infra-Guard is an open-source framework that addresses AI infrastructure security through layered detection paradigms spanning infrastructure, protocol, agent behavior, and model layers.","ai_keywords":["AI red teaming","Model Context Protocol","LLM-driven agentic auditing","black-box agent red teaming","jailbreak harness","supply-chain auditing","layer-paradigm matching"],"ai_summary_model":"Qwen/Qwen2.5-Coder-32B-Instruct","organization":{"_id":"66543b6e420092799d2f625c","name":"tencent","fullname":"Tencent","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/5dd96eb166059660ed1ee413/Lp3m-XLpjQGwBItlvn69q.png"}},"canReadDatabase":false,"canManagePapers":false,"canSubmit":false,"hasHfLevelAccess":false,"upvoted":false,"upvoters":[{"_id":"650fc649dc509ae7d7d58215","avatarUrl":"/avatars/7bb8d9048ff604cf7475e52c33ec780e.svg","isPro":false,"fullname":"Zonghao Ying","user":"Zonghao2025","type":"user"},{"_id":"6a2da6c8ca070ee12c6e396c","avatarUrl":"/avatars/0355287dcabaa67dbc7f0b10b87451f9.svg","isPro":false,"fullname":"Joe Mama","user":"JoeMama123123123","type":"user"},{"_id":"698f8de8ae185b257313a76c","avatarUrl":"/avatars/488cad3f610f749a5631371fb2f019b8.svg","isPro":false,"fullname":"V9y2j9w0e","user":"v9y2j9w0e","type":"user"},{"_id":"63ac5701c21e60a3e9b58aa7","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/63ac5701c21e60a3e9b58aa7/g6EX7diOpuA94R2ab-rZC.png","isPro":true,"fullname":"Dipankar Sarkar","user":"dipankarsarkar","type":"user"},{"_id":"6a36a73bb3bb7023bc7c5df3","avatarUrl":"/avatars/8675271edcb0d86be5a144a24941383f.svg","isPro":false,"fullname":"Blair DuCray-Oppat","user":"blairducrayoppat","type":"user"},{"_id":"69bcead8685c38830c6381ca","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/noauth/9zRy-q7Of6x3IH6aGkbQm.jpeg","isPro":false,"fullname":"佐藤莉子","user":"miladavis","type":"user"},{"_id":"64612660933afb0106a9dee3","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/noauth/Ea83e0zR_2m8foWy6J0AF.jpeg","isPro":false,"fullname":"Xingyu Zheng","user":"Xingyu-Zheng","type":"user"},{"_id":"6270324ebecab9e2dcf245de","avatarUrl":"https://cdn-avatars.huggingface.co/v1/production/uploads/6270324ebecab9e2dcf245de/cMbtWSasyNlYc9hvsEEzt.jpeg","isPro":false,"fullname":"Kye Gomez","user":"kye","type":"user"}],"acceptLanguages":["en"],"dailyPaperRank":0,"organization":{"_id":"66543b6e420092799d2f625c","name":"tencent","fullname":"Tencent","avatar":"https://cdn-avatars.huggingface.co/v1/production/uploads/5dd96eb166059660ed1ee413/Lp3m-XLpjQGwBItlvn69q.png"},"markdownContentUrl":"https://huggingface.co/buckets/huggingchat/papers-content/resolve/2606/2606.31227.md","query":{}}">
Securing the AI Agent: A Unified Framework for Multi-Layer Agent Red Teaming
Authors: ,
,
,
,
,
,
,
,
,
Abstract
AI-Infra-Guard is an open-source framework that addresses AI infrastructure security through layered detection paradigms spanning infrastructure, protocol, agent behavior, and model layers.
The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that layer-paradigm matching can serve as a practical foundation for agent security and a shared base for the community to build on.
Community
The fast growth of open-source AI infrastructure, from model serving engines and agent platforms to the Model Context Protocol (MCP) ecosystem and the language models themselves, has outpaced the security tooling available to defend it. We present AI-Infra-Guard, an open-source framework that organizes AI red teaming around a single observation: the attack surface of an AI agent is stratified across layers (infrastructure, protocol/tool, agent behavior, and model), and no single detection paradigm fits all of them. The framework therefore matches a paradigm to each layer, from deterministic rule matching over 75+ AI components and 1{,}400+ vulnerability rules, through LLM-driven agentic auditing of MCP servers and agent-skill packages and multi-turn black-box agent red teaming, to a jailbreak harness with 26+ attack operators over sixteen datasets. To our knowledge it is the only open-source framework to span all of these, including supply-chain auditing of the agent skills that increasingly extend AI agents. We release AI-Infra-Guard as open source so that \emph{layer-paradigm matching} can serve as a practical foundation for agent security and a shared base for the community to build on.
Upload images, audio, and videos by dragging in the text input, pasting, or clicking here.
Tap or paste here to upload images
Cite arxiv.org/abs/2606.31227 in a model README.md to link it from this page.
Cite arxiv.org/abs/2606.31227 in a dataset README.md to link it from this page.
Cite arxiv.org/abs/2606.31227 in a Space README.md to link it from this page.
Discussion (0)
Sign in to join the discussion. Free account, 30 seconds — email code or GitHub.
Sign in →No comments yet. Sign in and be the first to say something.