arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2607.13987cs.CR

智能体技能安全:威胁模型、攻击、防御与评估

Agent Skill Security: Threat Models, Attacks, Defenses, and Evaluation

Sanket Badhe, Priyanka Tiwari

AI总结:

研究智能体可复用技能安全,提出SkillSec-Eval框架,刻画技能生命周期并开发威胁分类法,通过对327个真实技能实证评估,发现多阶段有漏洞,强调需进行生命周期感知安全分析。

AI中文摘要:

可复用技能正成为大语言模型智能体的基本构建块,能在不同应用中打包、共享和复用。然而,现有安全研究主要集中在提示注入和运行时执行,技能生命周期中更广泛的安全风险大多未被探索。本文提出SkillSec-Eval,一个用于系统评估可复用智能体技能安全性的生命周期感知框架。首先描述技能生命周期并开发涵盖存储库准入、语义检索、规划器选择、执行和技能演化的威胁分类法。然后在SkillSec-Eval中实例化该分类法,并使用327个真实世界技能的存储库进行全面实证评估。研究表明,除执行外,多个生命周期阶段都会出现漏洞,凸显了对可复用智能体技能进行生命周期感知安全分析的必要性。

英文摘要:

Reusable skills are becoming a fundamental building block of Large Language Model (LLM) agents, enabling capabilities to be packaged, shared, and reused across diverse applications. However, existing security research primarily focuses on prompt injection and runtime execution, leaving security risks throughout the broader skill lifecycle largely unexplored. In this paper, we present SkillSec-Eval, a lifecycle-aware framework for systematically evaluating the security of reusable agent skills. We first characterize the skill lifecycle and develop a threat taxonomy spanning repository admission, semantic retrieval, planner selection, execution, and skill evolution. We then instantiate this taxonomy in SkillSec-Eval and conduct a comprehensive empirical evaluation using a repository of 327 real-world skills. Our study demonstrates that vulnerabilities arise at multiple lifecycle stages beyond execution, highlighting the need for lifecycle-aware security analysis of reusable agent skills.

↑