WeChat (安全牛)
ai-engineeringsecurity-privacy
Original source

Google Mandiant AVDH 多智能体漏洞发现框架全拆解

Summary

Deep analysis of Google Mandiant’s internal AVDH (Agentic Vulnerability Discovery Harness) framework — a multi-agent AI system for code security auditing that’s been running ~10 months in production.

Key results:

  • Found 100+ verified high-severity vulns in a stolen enterprise codebase in just 2 days
  • Scanned tens of millions of lines of code, producing tens of thousands of findings
  • Discovered dozens of CVE-worthy vulns in web extensions & OSS projects (12 CVEs assigned)

6-stage pipeline (not a single prompt):

  1. Threat modeling — AI understands codebase architecture, human reviews before proceeding
  2. Entry point discovery — maps attack surface (web routes, APIs, IPC, message queues)
  3. Context enrichment — auto-gathers scattered auth checks, input filters, related control code
  4. Vulnerability hypothesis generation — specialized agents for different vuln classes (access control vs dangerous data flows)
  5. Hypothesis verification — multiple agents with high temperature challenge each hypothesis from different angles; a synthesizer agent classifies as confirmed/disproven/rejected
  6. Human verification — experts reproduce with PoC; AI confirmation ≠ vulnerability confirmation

Key design principles:

  • Multi-agent adversarial verification (agents actively try to disprove hypotheses, not just confirm)
  • Expert rules organized by language/framework/vuln-type for knowledge reuse
  • Synthetic code benchmarks to avoid training data contamination in evaluations
  • Human-in-the-loop at strategic control points (threat model review, final PoC verification)

6 recommendations for enterprises:

  1. Design vuln discovery as a pipeline, not a single prompt
  2. Map attack surface before hunting vulns
  3. Let AI verify AI — don’t trust first output
  4. Encode expert knowledge into framework rules, not just model weights
  5. Require human verification for high-risk conclusions
  6. Build eval benchmarks immune to training set contamination

Takeaway: The competitive edge isn’t the base model — it’s security knowledge engineering + workflow design + verification systems. AI reallocates human time from tedious context-gathering to high-judgment tasks.