arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.13718cs.CRcs.AI

智能体如何请求许可:人工智能智能体的用户权限,从接口到执行

How Agents Ask for Permission: User Permissions for AI Agents, from Interfaces to Enforcement

  • University of Washington(华盛顿大学)

机构由 AI 辅助整理,请以论文原文为准。

Alexandra E. Michael, Franziska Roesner

AI总结:

研究人工智能智能体系统中用户级权限处理问题,通过调查21个提案构建分类法,分析五个商业智能体并与文献系统比较,确定主题与空白,为智能体权限系统研究提供参考。

AI中文摘要:

随着人工智能智能体的普及,用户越来越多地面临此类系统带来的风险。提示注入攻击和幻觉可能导致智能体向第三方泄露私人信息。作为自主系统,智能体还存在未经用户意图或授权执行敏感任务(如银行交易)的更严重风险。认识到这一挑战,智能体安全社区已为安全智能体系统提出了众多建议。这项工作大多集中在产品级方法上,即智能体系统开发者为所有用户确定并应用相同的安全策略和权限。然而,不同用户有不同需求和偏好,因此智能体人工智能系统需要支持用户级权限策略。为了解人工智能智能体系统中用户级权限是如何处理的,我们调查了21个智能体权限系统提案。通过这项综述,我们构建了一个分类法,用于说明不同系统如何在用户界面和内部指定用户级权限策略;从用户输入中推导内部策略;并在运行时执行这些策略。然后,我们分析了五个著名的商业智能体,并将它们的权限处理与文献中的智能体权限系统进行比较。我们确定了文献和商业智能体中的几个高层次主题,以及未来工作需要填补的多个空白。

英文摘要:

As AI agents gain prevalence, users are increasingly exposed to the risks such systems entail. Prompt injection attacks, as well as hallucination, can cause agents to leak private information to third parties. As autonomous systems, agents also present the more active danger of performing sensitive tasks, such as bank transactions, without the user's intent or authorization. Recognizing this challenge, the agentic security community has developed numerous proposals for secure agentic systems. Much of this work has focused on product-level approaches, where agentic system developers determine and apply the same security policies and permissions to all users. Yet different users have different needs and preferences, necessitating support for user-level permissions policies in agentic AI systems. To understand how user-level permissions are handled in AI agent systems, we survey 21 proposals for agent permissions systems. From this review, we construct a taxonomy of how different systems specify user-level permissions policies, both at the user interface and internally; derive internal policies from user input; and enforce those policies at run-time. We then analyze five prominent commercial agents and compare their permissions handling to agentic permissions systems in the literature. We identify several high-level themes across the literature and commercial agents, as well as multiple gaps where future work is needed.

补充信息

↑