Saved in:
Bibliographic Details
Main Authors: Dong, Tian, Chen, Yanjun, Zhang, Shoufeng, Zhang, Huaien, Lyu, Yunlong, Lian, Keke, Zhang, Dong, Li, Shaofeng, Chen, Hao
Format: Preprint
Published: 2026
Subjects:
Online Access:https://arxiv.org/abs/2605.20051
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910236828237824
author Dong, Tian
Chen, Yanjun
Zhang, Shoufeng
Zhang, Huaien
Lyu, Yunlong
Lian, Keke
Zhang, Dong
Li, Shaofeng
Chen, Hao
author_facet Dong, Tian
Chen, Yanjun
Zhang, Shoufeng
Zhang, Huaien
Lyu, Yunlong
Lian, Keke
Zhang, Dong
Li, Shaofeng
Chen, Hao
contents AI infra has become a shared execution layer for model training, deployment, and agent orchestration. Because many projects reimplement similar model-centric workflows, a vulnerability disclosed in one repository can recur as a variant in another repository with a related design. Yet the prevalence and detectability of these variants remain poorly understood. This paper presents a measurement study of vulnerability variants in AI infra. Analyzing 688 GitHub repositories and 251 publicly disclosed vulnerabilities, we find that AI infra projects frequently share overlapping functionality and recurrent vulnerable patterns, creating a concrete basis for cross-repository variants. Building on this finding, we study how to automatically identify such variants from known disclosures. We propose INFRASCOPE, a reference-driven multi-agent framework that extracts transferable vulnerability semantics from known cases and uses them to locate and validate variants in new repositories. Evaluating INFRASCOPE on 20 real-world AI infra repositories, we uncover over 20 vulnerabilities, including 11 acknowledged cases and 4 cases that have been assigned CVEs so far.
format Preprint
id arxiv_https___arxiv_org_abs_2605_20051
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Hunting Vulnerability Variants in AI Infra: Measurement and Reference-Driven Detection
Dong, Tian
Chen, Yanjun
Zhang, Shoufeng
Zhang, Huaien
Lyu, Yunlong
Lian, Keke
Zhang, Dong
Li, Shaofeng
Chen, Hao
Cryptography and Security
AI infra has become a shared execution layer for model training, deployment, and agent orchestration. Because many projects reimplement similar model-centric workflows, a vulnerability disclosed in one repository can recur as a variant in another repository with a related design. Yet the prevalence and detectability of these variants remain poorly understood. This paper presents a measurement study of vulnerability variants in AI infra. Analyzing 688 GitHub repositories and 251 publicly disclosed vulnerabilities, we find that AI infra projects frequently share overlapping functionality and recurrent vulnerable patterns, creating a concrete basis for cross-repository variants. Building on this finding, we study how to automatically identify such variants from known disclosures. We propose INFRASCOPE, a reference-driven multi-agent framework that extracts transferable vulnerability semantics from known cases and uses them to locate and validate variants in new repositories. Evaluating INFRASCOPE on 20 real-world AI infra repositories, we uncover over 20 vulnerabilities, including 11 acknowledged cases and 4 cases that have been assigned CVEs so far.
title Hunting Vulnerability Variants in AI Infra: Measurement and Reference-Driven Detection
topic Cryptography and Security
url https://arxiv.org/abs/2605.20051