ARTEX Wins Baidu Security Challenge With AI Agent Graphs
Open-source offensive AI framework ARTEX has won Baidu's security challenge by using dual-graph architecture to coordinate autonomous hacking agents across complex attack chains.

ARTEX, a source-available autonomous penetration testing system, has won Baidu's Agent+ Offense and Defense Challenge. Built using a monolithic Go backend, an embedded Next.js frontend, PostgreSQL, and the norma agent SDK, the framework offers a reference design for coordinating autonomous security agents across complex, multi-step cyber operations. The project repository was published following the competition under an AGPL-3.0 license, accompanied by author-specified restrictions limiting its application to local research and study.
The core architectural advancement in ARTEX is a persistent coordination mechanism utilizing dual-graph structures joined by database anchors. The system separates the static target inventory from the dynamic reasoning process of its agents. A global asset graph tracks inventory entities—including root_domain, subdomain, ip, service, app, and endpoint—to establish stable asset identities. Concurrently, task-specific exploration graphs record goal, intent, fact, finding, and hint nodes, connected by edges like spawns, derived_from, yields, and proves to trace findings back to initial goals.
To manage execution across multiple agents without race conditions, ARTEX uses a central planner that maintains a shared task list across system wakeups. Autonomous worker agents can search step-level execution traces generated by other workers, ensuring agents do not repeat past discovery work. Rather than relying on unreliable model output to manage target data, the system's application code directly computes asset deduplication keys.
By linking task intents, facts, and findings to target assets inside an exploration_anchors table, ARTEX provides practitioners with inspectable decision records and quantifiable surface coverage metrics. Security developers can trace every path an agent attempted against specific infrastructure, establishing a clear lineage for automated red teaming workflows.
This is our own summary of reporting by AlphaSignal



