Automatically discovers and catalogs AI assets in the cloud, and centrally manages security risks such as vulnerabilities, public internet exposure, configuration flaws, and sensitive information leaks across the full lifecycle of development, deployment, and runtime.
Features overview
Supported AI asset inventory
AI component identification on servers
Training and inference engines: Ollama, vLLM, LM Studio, Xinference, LLaMA Factory, and more.
AI service applications: AI UI (Open WebUI), conversational services (NextChat, etc.), AI workflows (such as Dify), image generation (such as ComfyUI, Stable Diffusion WebUI), and more.
Infrastructure: Vector databases (Milvus, Qdrant), and more.
Multi-cloud AI product identification: Snapshots/images, Serverless services, and AI cloud products (Lingjun, Visual Intelligence Platform, etc.), covering AI products across Alibaba Cloud, Tencent Cloud, AWS, Azure, and other multi-cloud environments.
Asset categories
AI workloads: Includes ECS instances, Lingjun instances, Serverless, and more.
AI image artifacts: Includes ECS images, ECS snapshots, container images, and more.
Development and training: Common platforms include:
Alibaba Cloud: PAI
Huawei Cloud: ModelArts
Tencent Cloud: TI-ONE
AWS: SageMaker
Azure: Azure AI Service
Azure: Azure Machine Learning
AI services: Providers include DashScope, DeepSeek, and more.
AI tools and components: Includes Ollama, LlamaIndex, and more.
Supported AI asset risk detection
Detection capabilities and rule library
AI component vulnerabilities: Multiple vulnerability detection rules.
AI configuration compliance: Multiple configuration checks covering AI product security best practices.
AI key storage: Detects whether keys are stored in plaintext.
AI component exposure analysis: Multi-dimensional exposure surface analysis.
Core risk detection dimensions
Vulnerability risks: Unauthorized access vulnerabilities in key components (such as Stable Diffusion WebUI, Ollama, ComfyUI, etc.).
Plaintext key storage: Detects plaintext storage of AI service keys (such as OpenAI API Keys) and user credentials (such as Hugging Face Tokens).
Identity and access risks: Security checks for access control whitelist configurations, member permission configurations, and more.
Configuration risks: Checks for cloud product network access policies (such as VPC access), service operation protection, custom service configurations for VPC-internal access, and more.
Exposure risks: Identifies AI assets on servers that are exposed to the internet.
Billing and edition support
The AI Asset feature does not require a separate purchase. It depends on the authorization and activation of Security Center's security protection features. For information about how to purchase Security Center, see Purchase Security Center.
Subscription
Service/Edition | AI capabilities | Related feature |
Enterprise or Ultimate service | Identifies AI component assets on servers. |
|
Identifies related vulnerabilities in AI components. | ||
Identifies AI application components exposed to the internet. | or | |
Container Image Scan value-added service |
| |
CSPM value-added service | Integrates AI security best practices from mainstream cloud providers such as Alibaba Cloud, Azure, AWS, Tencent Cloud, and Huawei Cloud, and provides automated detection of AI asset configuration risks. |
Pay-as-you-go
Service | AI capabilities | Related menu |
Host and Container Security Important The protection level bound to the server must be Host Protection or Full Protection for Hosts and Containers. | Identifies AI component assets on servers. |
|
Identifies related vulnerabilities in AI components. | ||
Identifies AI application components exposed to the internet. | or | |
Agentless Detection | Provides agentless host detection capabilities, allowing comprehensive scanning of ECS instances with AI components deployed — no client installation required. The detection scope includes:
| |
CSPM paid service | CSPM Integrates AI security best practices from mainstream cloud providers such as Alibaba Cloud, Azure, AWS, Tencent Cloud, and Huawei Cloud. Provides automated detection of AI asset configuration risks, comprehensively covering key security configuration items for AI platforms (PAI), various AI services, and machine learning components. | |
Serverless Asset Protection paid service | Serverless Asset Protection Supports common threat alert detection, vulnerability scanning, and baseline risk checks for Serverless AI assets. |
Install the client
To discover AI components, scan AI Application Vulnerability, identify AI asset exposure risks, and use Container Image Scan, you must install the Security Center client if Agentless Detection is not activated. Use one of the following methods:
Agentless Detection provides partial AI component and application detection capabilities without requiring a security client. For details, see Agentless detection scan risks.
General installation method: For detailed instructions, see Install the agent.
Install when purchasing ECS: When purchasing an Alibaba Cloud ECS instance, select Free Security Reinforcement to automatically install the client. After selection, the ECS instance loads the basic security components, which provide website vulnerability checks, cloud product security configuration checks, and abnormal host login alerts. All can be managed through Security Center.
Sync AI assets
Automatic sync
When you activate and perform operations such as Investigate asset fingerprints, Host baseline check, Use agentless detection, Container image security scanning, CSPM configuration check, Vulnerability scanning, or Serverless asset scanning, the system automatically syncs and records AI assets and their associated risk information.
Automatic daily sync is available only for Enterprise Edition and higher.
Manual sync
Go to Security Center console > Agent Security Center > AI Assets. At the top left of the page, select the region where the assets to protect are located: Chinese Mainland or Outside Chinese Mainland.
On the Asset List tab, click Synchronize Assets.
NoteThe sync operation takes some time. Please wait patiently.
Asset and risk overview
On the Overview tab of Agent Security Center > AI Assets, you can view the AI assets and primary risk information for each module, including the following:
At-Risk AI Assets: Displays the total number of AI assets at risk under the current account, along with the corresponding risk trend.
AI Risk Asset Distribution: Shows the classification of current AI assets and the quantity changes compared to the previous day.
Top 5 AI Risk Configurations: Displays the top 5 risk counts for AI-SPM-related check items. Click a check item name to go to the CSPM page for details.
Top 5 AI Vulnerabilities: Displays the top 5 AI component vulnerability data in vulnerability management. Click a vulnerability name to go to the vulnerability details page.
AI Asset Internet Exposure: Displays asset exposure analysis data. You can view the exposure trend over the last 7 days, the last 30 days, or a custom time period.
Top 5 Keys Stored in Plaintext: Displays the top 5 AI plaintext key storage risks discovered by agentless detection.
View the AI asset list and risks
Navigate to the Asset List tab of .
Check the Risky Assets / Total Assets in the asset list. If the number of at-risk assets is greater than 0, click View in the Actions column.
On the asset details page, click View in the Actions column of the target asset to view the asset and its risks. Common asset risks and handling instructions are as follows:
NoteRefer to the console display for the actual content.
Vulnerability Details: View and handle AI Application Vulnerability detected on the current asset. Associated Urgent Vulnerability and Linux Software Vulnerability/Windows System Vulnerability are also displayed.
WarningAI application vulnerabilities require manual remediation and do not support one-click remediation in the console.
Remediation may affect your business. We recommend that you create a server snapshot or image backup before proceeding. For more information, see Manage vulnerabilities.
Alert: View and handle alerts detected on the current AI asset. For more operations, see Respond to security alerts.
Agentless Detection: View and handle vulnerability risks, baseline check risks, malicious samples, and sensitive file information scanned by agentless detection. For more operations, see Use agentless detection.
CSPM: View and handle risk information identified by configuration checks. For more operations, see Configure and run check policies and Handle failed check items.
Key: View AI-related API key plaintext storage risks detected by agentless detection and container image scanning.
Billing
AI asset discovery: Security Center automatically discovers and tag AI assets. This process does not incur additional charges.
Risk detection billing: The detection and remediation costs for related risks are attributed to the dependent Security Center feature modules and follow their respective billing rules. For billing details, see Billing description.
Application vulnerabilities: Counted against the host security protection authorization quota.
AI configuration risk checks: Billed based on the Cloud Security Posture Management (CSPM) authorization quota.
Image security scanning: Billed based on the image scanning authorization quota or number of scans.
Agentless detection: Billed based on the scanning capacity (GB) of agentless detection.