你如何选择人工智能组件?关于安全人工智能集成实践的访谈研究
From Adoption to Deployment: A Qualitative Study on AI Integration in Software Development Practice
- North Carolina State University(北卡罗来纳州立大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
研究通过访谈了解从业者选择和集成人工智能组件的决策及安全考量,发现其选模型多受功能标准驱动,安全常被忽视,集成过程缺安全关注,行业重蹈早期软件依赖管理覆辙,为此给出相关建议倡导安全设计方法。
AI中文摘要:
在现代软件系统中,大语言模型作为人工智能组件的使用日益增加,给软件供应链带来了明显的安全风险。虽然传统软件供应链组件有诸多考量和安全机制,但人工智能组件和平台的快速采用却忽视了这些经验教训。本研究旨在通过探索性半结构化访谈,了解从业者在选择和集成人工智能组件时的决策过程和安全考量。对22位来自不同组织的软件开发人员、架构师和人工智能从业者进行访谈后发现,从业者选择模型主要受功能标准驱动,安全很少被视为评估标准。在人工智能组件集成过程中始终缺乏安全关注,行业在重复早期软件依赖管理的错误,将快速重用和可用性置于安全和溯源之上。最后为人工智能采用者、模型提供者和研究人员提炼出可操作的建议,倡导主动的、设计时安全的方法,将安全评估融入组件选择并贯穿软件开发生命周期。
英文摘要:
The increasing adoption of Large Language Models (LLMs) as AI components in modern software systems introduces distinct security risks to the software supply chain. While many considerations and safety mechanisms are in place for components of the traditional software supply chain, the recent rapid adoption of AI components and platforms has overlooked these hard learned lessons. Selecting and integrating AI models without clear guidance on how these choices affect system security may leave applications vulnerable to threats, such as malicious components, data leakage, and unintended behavior. The goal of this study is to understand practitioners' decision making process and security considerations in selecting and integrating AI components through an exploratory semi-structured interview study. Toward this goal, we conducted semistructured interviews with 22 software developers, architects, and AI practitioners across diverse organizations about how they integrate AI components into their software. Our analysis finds that practitioners' model selection is predominantly driven by functional criteria, including performance, accuracy, cost, and specific features, e.g., tool calling or multimodal support, while security is rarely considered as an evaluation criterion. We observe a consistent lack of security concern throughout the AI component integration process, with established software supply chain lessons overlooked or ignored. The industry is repeating the historically costly mistakes of early software dependency management, prioritizing rapid reuse and availability over security and provenance. We distill our findings into actionable recommendations for AI adopters, model providers, and researchers, advocating for a proactive, security-by-design approach that integrates security evaluation into component selection and sustains it throughout the software development lifecycle.