All Products
Search
Document Center

Agent Security Center:AI assets

Last Updated:Jul 10, 2026

Automatically discovers and catalogs AI assets in the cloud, and centrally manages security risks such as vulnerabilities, public internet exposure, configuration flaws, and sensitive information leaks across the full lifecycle of development, deployment, and runtime.

Features overview

Supported AI asset inventory

  • AI component identification on servers

    • Training and inference engines: Ollama, vLLM, LM Studio, Xinference, LLaMA Factory, and more.

    • AI service applications: AI UI (Open WebUI), conversational services (NextChat, etc.), AI workflows (such as Dify), image generation (such as ComfyUI, Stable Diffusion WebUI), and more.

    • Infrastructure: Vector databases (Milvus, Qdrant), and more.

  • Multi-cloud AI product identification: Snapshots/images, Serverless services, and AI cloud products (Lingjun, Visual Intelligence Platform, etc.), covering AI products across Alibaba Cloud, Tencent Cloud, AWS, Azure, and other multi-cloud environments.

Asset categories

  • AI workloads: Includes ECS instances, Lingjun instances, Serverless, and more.

  • AI image artifacts: Includes ECS images, ECS snapshots, container images, and more.

  • Development and training: Common platforms include:

    • Alibaba Cloud: PAI

    • Huawei Cloud: ModelArts

    • Tencent Cloud: TI-ONE

    • AWS: SageMaker

    • Azure: Azure AI Service

    • Azure: Azure Machine Learning

  • AI services: Providers include DashScope, DeepSeek, and more.

  • AI tools and components: Includes Ollama, LlamaIndex, and more.

Supported AI asset risk detection

  • Detection capabilities and rule library

    • AI component vulnerabilities: Multiple vulnerability detection rules.

    • AI configuration compliance: Multiple configuration checks covering AI product security best practices.

    • AI key storage: Detects whether keys are stored in plaintext.

    • AI component exposure analysis: Multi-dimensional exposure surface analysis.

  • Core risk detection dimensions

    • Vulnerability risks: Unauthorized access vulnerabilities in key components (such as Stable Diffusion WebUI, Ollama, ComfyUI, etc.).

    • Plaintext key storage: Detects plaintext storage of AI service keys (such as OpenAI API Keys) and user credentials (such as Hugging Face Tokens).

    • Identity and access risks: Security checks for access control whitelist configurations, member permission configurations, and more.

    • Configuration risks: Checks for cloud product network access policies (such as VPC access), service operation protection, custom service configurations for VPC-internal access, and more.

    • Exposure risks: Identifies AI assets on servers that are exposed to the internet.

Billing and edition support

The AI Asset feature does not require a separate purchase. It depends on the authorization and activation of Security Center's security protection features. For information about how to purchase Security Center, see Purchase Security Center.

Subscription

Service/Edition

AI capabilities

Related feature

Enterprise or Ultimate service

Identifies AI component assets on servers.

  • Assets > Host > AI Component

  • Assets > Cloud Product

    Note

    Only AI component names, versions, software package paths, and the latest scan times are displayed on the ECS snapshot and image pages.

Identifies related vulnerabilities in AI components.

Risk Governance > Vulnerabilities > Application Vulnerability

Identifies AI application components exposed to the internet.

Risk Governance > Asset Exposure Analysis or Risk Governance > Attack Management

Container Image Scan value-added service

  • Basic security scanning: Detects AI vulnerabilities, malicious samples, and sensitive files in images, and performs security baseline checks.

  • AI-specific risk scanning: Identifies the risk of AI keys stored in plaintext in images, including but not limited to OpenAI keys and Alibaba Cloud PAI-EAS service tokens.

Protection Configuration > Container Protection > Container Image Scan

CSPM value-added service

Integrates AI security best practices from mainstream cloud providers such as Alibaba Cloud, Azure, AWS, Tencent Cloud, and Huawei Cloud, and provides automated detection of AI asset configuration risks.

Risk Governance > CSPM

Pay-as-you-go

Service

AI capabilities

Related menu

Host and Container Security

Important

The protection level bound to the server must be Host Protection or Full Protection for Hosts and Containers.

Identifies AI component assets on servers.

  • Assets > Host > AI Component

  • Assets > Cloud Product

    Note

    Only AI component names, versions, software package paths, and the latest scan times are displayed on the ECS snapshot and image pages.

Identifies related vulnerabilities in AI components.

Risk Governance > Vulnerabilities > Application Vulnerability

Identifies AI application components exposed to the internet.

Risk Governance > Asset Exposure Analysis or Risk Governance > Attack Management

Agentless Detection

Provides agentless host detection capabilities, allowing comprehensive scanning of ECS instances with AI components deployed — no client installation required. The detection scope includes:

  • Common risks: Vulnerability, Baseline Check, and Malicious Sample

  • AI-specific risks: Sensitive File Detects AI service credentials (such as OpenAI keys and Alibaba Cloud PAI-EAS service tokens).

Protection Configuration > Host Protection > Agentless Detection

CSPM paid service

CSPM Integrates AI security best practices from mainstream cloud providers such as Alibaba Cloud, Azure, AWS, Tencent Cloud, and Huawei Cloud. Provides automated detection of AI asset configuration risks, comprehensively covering key security configuration items for AI platforms (PAI), various AI services, and machine learning components.

Risk Governance > CSPM

Serverless Asset Protection paid service

Serverless Asset Protection Supports common threat alert detection, vulnerability scanning, and baseline risk checks for Serverless AI assets.

Assets > Serverless Asset

Install the client

To discover AI components, scan AI Application Vulnerability, identify AI asset exposure risks, and use Container Image Scan, you must install the Security Center client if Agentless Detection is not activated. Use one of the following methods:

Note

Agentless Detection provides partial AI component and application detection capabilities without requiring a security client. For details, see Agentless detection scan risks.

  • General installation method: For detailed instructions, see Install the agent.

  • Install when purchasing ECS: When purchasing an Alibaba Cloud ECS instance, select Free Security Reinforcement to automatically install the client. After selection, the ECS instance loads the basic security components, which provide website vulnerability checks, cloud product security configuration checks, and abnormal host login alerts. All can be managed through Security Center.

Sync AI assets

Automatic sync

When you activate and perform operations such as Investigate asset fingerprints, Host baseline check, Use agentless detection, Container image security scanning, CSPM configuration check, Vulnerability scanning, or Serverless asset scanning, the system automatically syncs and records AI assets and their associated risk information.

Note

Automatic daily sync is available only for Enterprise Edition and higher.

Manual sync

  1. Go to Security Center console > Agent Security Center > AI Assets. At the top left of the page, select the region where the assets to protect are located: Chinese Mainland or Outside Chinese Mainland.

  2. On the Asset List tab, click Synchronize Assets.

    Note

    The sync operation takes some time. Please wait patiently.

Asset and risk overview

On the Overview tab of Agent Security Center > AI Assets, you can view the AI assets and primary risk information for each module, including the following:

  • At-Risk AI Assets: Displays the total number of AI assets at risk under the current account, along with the corresponding risk trend.

  • AI Risk Asset Distribution: Shows the classification of current AI assets and the quantity changes compared to the previous day.

  • Top 5 AI Risk Configurations: Displays the top 5 risk counts for AI-SPM-related check items. Click a check item name to go to the CSPM page for details.

  • Top 5 AI Vulnerabilities: Displays the top 5 AI component vulnerability data in vulnerability management. Click a vulnerability name to go to the vulnerability details page.

  • AI Asset Internet Exposure: Displays asset exposure analysis data. You can view the exposure trend over the last 7 days, the last 30 days, or a custom time period.

  • Top 5 Keys Stored in Plaintext: Displays the top 5 AI plaintext key storage risks discovered by agentless detection.

View the AI asset list and risks

  1. Navigate to the Asset List tab of Agent Security > AI Asset.

  2. Check the Risky Assets / Total Assets in the asset list. If the number of at-risk assets is greater than 0, click View in the Actions column.

  3. On the asset details page, click View in the Actions column of the target asset to view the asset and its risks. Common asset risks and handling instructions are as follows:

    Note

    Refer to the console display for the actual content.

    • Vulnerability Details: View and handle AI Application Vulnerability detected on the current asset. Associated Urgent Vulnerability and Linux Software Vulnerability/Windows System Vulnerability are also displayed.

      Warning
      • AI application vulnerabilities require manual remediation and do not support one-click remediation in the console.

      • Remediation may affect your business. We recommend that you create a server snapshot or image backup before proceeding. For more information, see Manage vulnerabilities.

    • Alert: View and handle alerts detected on the current AI asset. For more operations, see Respond to security alerts.

    • Agentless Detection: View and handle vulnerability risks, baseline check risks, malicious samples, and sensitive file information scanned by agentless detection. For more operations, see Use agentless detection.

    • CSPM: View and handle risk information identified by configuration checks. For more operations, see Configure and run check policies and Handle failed check items.

    • Key: View AI-related API key plaintext storage risks detected by agentless detection and container image scanning.

Billing

  • AI asset discovery: Security Center automatically discovers and tag AI assets. This process does not incur additional charges.

  • Risk detection billing: The detection and remediation costs for related risks are attributed to the dependent Security Center feature modules and follow their respective billing rules. For billing details, see Billing description.

    • Application vulnerabilities: Counted against the host security protection authorization quota.

    • AI configuration risk checks: Billed based on the Cloud Security Posture Management (CSPM) authorization quota.

    • Image security scanning: Billed based on the image scanning authorization quota or number of scans.

    • Agentless detection: Billed based on the scanning capacity (GB) of agentless detection.