ARTEX Wins Baidu's Security Challenge Using Linked Graphs to Coordinate AI Hacking Agents

ARTEX, winner of Baidu's agent+ challenge, open sources a Go-based multi-agent pentest system built on a dual-graph architecture.

·
·
·
ARTEX Wins Baidu's Security Challenge Using Linked Graphs to Coordinate AI Hacking AgentsPRO
  • ARTEX is an open source autonomous pentest system that won Baidu's agent+ offense/defense challenge.
  • Go backend with embedded Next.js frontend, PostgreSQL, and the norma agent SDK.
  • Dual-graph design separates a global asset graph from per-task exploration graphs, linked by anchors.
  • Planner keeps a shared todolist across wakeups to run multi-step attack chains in order without race conditions.
  • Workers can search other workers' step-level execution traces to avoid redoing discovery work.
  • AGPL-3.0 licensed and restricted by the author to local study only, see the repo.

ARTEX uses linked graphs to coordinate autonomous security agents

ARTEX is a source-available reference design for autonomous penetration testing agents. Its repository became public after the project won Baidu’s Agent+ Offense and Defense Challenge. The repository advertises AGPL-3.0, although separate use restrictions create a licensing conflict discussed below.

The stack combines a monolithic Go backend, an embedded Next.js frontend, PostgreSQL, and agent capabilities from the norma SDK. Its main architectural contribution is persistent coordination: multiple agents can pursue a long attack chain, share discoveries, preserve dependencies, and produce an inspectable record of their decisions.

ARTEX dashboard showing security tasks and findings
The ARTEX dashboard tracks tasks, assets, agents, and findings.

Linked graphs keep state legible

ARTEX stores the target inventory and the agents’ reasoning in separate graphs, then joins them through database anchors. This separation gives stable identities to assets and preserves the lineage of each test.

Graph Scope Nodes Purpose
Asset Graph Company-wide and shared across tasks root_domain, subdomain, ip, service, app, and endpoint Maintains the target inventory, parent-child relationships, and stable asset identities.
Exploration Graph One graph per task goal, intent, fact, finding, and hint Records what agents planned, observed, inferred, and proved.

Application code computes asset deduplication keys, removing that choice from model output. Exploration edges such as spawns, derived_from, yields, and proves preserve the path from an initial goal to supporting evidence and confirmed findings.

The exploration_anchors table connects intents, facts, and findings to specific assets. A developer can inspect which assets an exploration path touched or select an asset and retrieve every intent that tested it during the current task. ARTEX also derives coverage from these links across the represented in-scope surface; that metric describes graph coverage, with exhaustive security testing remaining a broader question.

Pro article

This story is for Pro members

You've reached the end of the free preview. Upgrade to AlphaSignal Pro to read the full article - and everything else behind the paywall.

Trending
  • No trending articles

Comments

avatar

Next Reads