面向大型语言模型系统的安全导向生命周期模型
A Security-Oriented Lifecycle Model for Large Language Model Systems
浏览论文内容
中文总结 AI 辅助
本文针对LLM系统生命周期框架重效率轻安全、治理与生命周期阶段脱节的问题,提出含32个阶段的安全导向生命周期模型,整合多监管框架发现治理证据分布不均的结构特性。
中文摘要 AI 辅助
大型语言模型正以前所未有的规模被集成到关键基础设施和企业工作流程中,但管控其开发与运营的生命周期框架是为运营效率而非安全分析设计的。因此,数据来源验证、制品签名、智能体权限控制及退役等与安全相关的活动常被隐含处理,或被认为会得到妥善关注。反过来,治理框架围绕风险等级或管理流程组织需求,却未明确关联其适用的生命周期阶段。本文解决这两个缺陷,提出一种面向LLM系统的生命周期模型,该模型围绕与安全相关的边界而非工作流程优化构建,以支持安全分析。该模型包含四个核心流水线层(数据、模型、分发、应用)的32个阶段,由12阶段的LLMOps支柱和9类治理支柱提供支撑。其中13个阶段作为独立单元被引入,因为它们暴露出现有框架未明确区分的独特安全问题。一项整合NIST AI RMF、欧盟AI法案及ISO/IEC 42001的治理映射揭示了当前监管格局的结构特性:治理证据集中在面向部署的阶段(系统对监管机构可见),而最具影响力的决策(数据选择、对齐策略及能力边界)则在面向开发的阶段(监管可见性最低)做出。
英文摘要
Large language models are being integrated into critical infrastructure and enterprise workflows at unprecedented scale,yet the lifecycle frameworks governing their development and operations were designed for operational efficiency rather than security analysis. As a result, security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit or assumed to receive due care. Governance frameworks, in turn, organise requirements around risk levels or management processes without clearly linking them to the lifecycle stages where they apply. This paper addresses both deficiencies. We propose a lifecycle model for LLM systems that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation. The model comprises 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar. Thirteen stages are introduced here as separate units because they expose distinct security concerns that existing frameworks do not clearly distinguish. A governance mapping synthesising the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages, where systems are visible to regulators, while the most consequential decisions, data selection, alignment strategy, and capability boundaries, are made at development-facing stages, where regulatory visibility is lowest.
发表机构
- Democritus University of Thrace(德谟克利特色雷斯大学)
- Athena Research Center(雅典娜研究中心)
机构由 AI 辅助整理,请以论文原文为准。