可信凭证,不可信行为:高性能计算中语言模型代理安全性基准测试
Trusted Credentials, Untrusted Behavior: Benchmarking LLM-Agent Security in High-Performance Computing
浏览论文内容
中文总结 AI 辅助
研究高性能计算中语言模型代理安全性,定义其威胁模型,识别攻击面及当前控制不足,提出研究议程和TaskBound实证基准测试计划,以应对代理按用户凭证运行时可能出现的劫持授权代理问题。
中文摘要 AI 辅助
大语言模型(LLM)代理开始在高性能计算(HPC)中承担日常工作,如监控Slurm作业、诊断构建失败、检查模拟输出和协调科学工作流程。代理通常以用户凭证运行并继承其对文件和调度器的访问权限,这产生了普通账户级控制无法捕捉的故障模式。日志、工具描述、共享文件或对等代理消息中的对抗性指令可能使代理偏离用户分配的任务,即劫持授权代理问题。现有代理安全研究解释了相关机制,但多在网络、企业或个人助理环境中评估。HPC安全有成熟的身份和隔离控制,但通常不体现特定任务意图。本文定义了HPC环境中的威胁模型,识别了调度器、共享存储、多项目账户和科学工作流程产生的攻击面,审视了当前控制的不足,最后给出了研究议程和实证基准测试TaskBound计划。
英文摘要
Large language model (LLM) agents are starting to take on routine work in high-performance computing (HPC), including monitoring Slurm jobs, diagnosing failed builds, inspecting simulation output, and coordinating scientific workflows. To do this work, an agent commonly acts under its user's credentials and inherits the user's access to files and the scheduler. This arrangement creates a failure mode that ordinary account-level controls do not capture. Adversarial instructions in a log, tool description, shared file, or peer-agent message may redirect the agent beyond the task the user assigned, even though every resulting command is authenticated and permitted for that account. We refer to this as the hijacked authorized agent problem. Existing agent-security studies explain relevant mechanisms, such as indirect prompt injection and tool misuse, but generally evaluate them in web, enterprise, or personal-assistant settings. HPC security, by contrast, has mature controls for identity and isolation but does not ordinarily represent the intent of a particular task. This paper defines the threat model in the HPC setting, identifies attack surfaces created by schedulers, shared storage, multi-project accounts, and scientific workflows, and examines where current controls fall short. It concludes with a research agenda and a plan for an empirical benchmark, TaskBound.
发表机构
- Texas Tech University(德克萨斯技术大学)
机构由 AI 辅助整理,请以论文原文为准。