返回全部动态

谷歌开源 Mantis:AI 代理框架减少漏洞扫描误报

原标题:Google Mantis: An Agentic Vulnerability Scanning Harness for Reducing False Positives

InfoQ AI ML and Data Engineering开源质量 75

AI 摘要

谷歌开源了 Mantis,这是一个用于自动化软件漏洞生命周期的 AI 代理框架,旨在解决传统 AI 代码扫描中误报率高和幻觉漏洞的问题。Mantis 结合了批评者和审查者代理等智能体技术,并在沙盒环境中复现漏洞以提供证据,同时通过分析仓库历史和架构,将文件摘要为层次树,减少 85% 的 token 使用。该框架支持多种模型,并建议针对不同任务使用不同规模的模型,以提高效率和准确性。Mantis 已在 GitHub 上开源。

以上摘要由 AI 生成,可能存在误差。事实请以原文为准。

正文节选

Google has open-sourced Mantis, an AI-agent framework designed to automate the software vulnerability lifecycle, from identifying and validating vulnerabilities to reproducing and fixing them. Google says it developed Mantis to address the high rate of false positives and hallucinated vulnerabilities produced by conventional AI-powered code scanning. While sloppiness in AI code scanning frequently leads to hallucinated bugs and weak true-positive rates under 7%, we designed Mantis to be effectiv


发布时间:2026-09-06 20:00
抓取时间:2026-09-06 20:25
来源机构:InfoQ
阅读原文infoq.com