Google Mandiant AVDH 多智能体漏洞发现框架全拆解
- URL: https://mp.weixin.qq.com/s/bKchk0auNV9i0PWruyjoDg
- Date Saved: 2026-09-07
- Source: WeChat (安全牛)
- Tags: ai-engineering, security-privacy
Summary
Deep analysis of Google Mandiant’s internal AVDH (Agentic Vulnerability Discovery Harness) framework — a multi-agent AI system for code security auditing that’s been running ~10 months in production.
Key results:
- Found 100+ verified high-severity vulns in a stolen enterprise codebase in just 2 days
- Scanned tens of millions of lines of code, producing tens of thousands of findings
- Discovered dozens of CVE-worthy vulns in web extensions & OSS projects (12 CVEs assigned)
6-stage pipeline (not a single prompt):
- Threat modeling — AI understands codebase architecture, human reviews before proceeding
- Entry point discovery — maps attack surface (web routes, APIs, IPC, message queues)
- Context enrichment — auto-gathers scattered auth checks, input filters, related control code
- Vulnerability hypothesis generation — specialized agents for different vuln classes (access control vs dangerous data flows)
- Hypothesis verification — multiple agents with high temperature challenge each hypothesis from different angles; a synthesizer agent classifies as confirmed/disproven/rejected
- Human verification — experts reproduce with PoC; AI confirmation ≠ vulnerability confirmation
Key design principles:
- Multi-agent adversarial verification (agents actively try to disprove hypotheses, not just confirm)
- Expert rules organized by language/framework/vuln-type for knowledge reuse
- Synthetic code benchmarks to avoid training data contamination in evaluations
- Human-in-the-loop at strategic control points (threat model review, final PoC verification)
6 recommendations for enterprises:
- Design vuln discovery as a pipeline, not a single prompt
- Map attack surface before hunting vulns
- Let AI verify AI — don’t trust first output
- Encode expert knowledge into framework rules, not just model weights
- Require human verification for high-risk conclusions
- Build eval benchmarks immune to training set contamination
Takeaway: The competitive edge isn’t the base model — it’s security knowledge engineering + workflow design + verification systems. AI reallocates human time from tedious context-gathering to high-judgment tasks.