Information and Communications Technology and Policy

Information and Communications Technology and Policy

Information and Communications Technology and Policy ›› 2026, Vol. 52 ›› Issue (8): 74-81.doi: 10.12267/j.issn.2096-5931.2026.08.011

Previous Articles     Next Articles

A novel agent security software testing scheme driven by large language model

HAN Han1, WANG Jingyao2, CHANG Tianen2   

  1. 1 Zensmart Technology Co., Ltd., Beijing 100083, China
    2 CTTL Terminal Labs, China Academy of Information and Communications Technology, Beijing 100191, China
  • Received:2026-06-20 Online:2026-08-25 Published:2026-09-02

Abstract:

With the large-scale deployment of autonomous AI Agents in low-altitude intelligent network, industrial control, financial services and urban governance, new security vulnerabilities such as prompt injection, unauthorized tool calling, context poisoning and multi-agent trust hijacking continue to break out. Traditional testing methods including static code scanning, dynamic payload blasting and manual red team penetration suffer from low vulnerability detection accuracy, high false positive rate, inability to cover emergent risks in long link tasks and insufficient efficiency of test case generation. A hierarchical agent security testing scheme driven by retrieval-augmented large language model is proposed to meet the full-lifecycle security verification requirements of AI Agents. The scheme can effectively identify emergent security defects in multi-step chains that cannot be captured by traditional testing solutions, providing a complete technical path for standardized security testing of agent software.

Key words: agent, security testing, large language model, retrieval-augmented generation, vulnerability detection

CLC Number: