AI 中文总结
本研究提出五维风险动态框架,分析前沿人工智能重塑关键基础设施系统级安全风险的机制,指出学术研究与运营约束的错配,推动系统级安全保证研究。
AI 中文摘要
前沿人工智能(FAI),涵盖大规模通用人工智能系统,包括大语言模型、多模态基础模型及智能体系统,正日益融入关键基础设施(CI)。这对长期以来的安全假设构成挑战,如行为有界性、网络分段性、组件透明性及人类节奏决策。现有AI安全文献通常按攻击类型、生命周期阶段或资产类别组织风险,但未能捕捉系统级动态,比如FAI如何塑造CI安全结果的风险产生、传播与控制机制。本知识系统化(SoK)引入五维风险动态框架,刻画FAI如何在全生命周期中重构CI安全:(i)通过FAI赋能的新攻击与防御能力实现的能力涌现;(ii)通过数据、模型及AI供应链实现的渗透路径;(iii)跨互联基础设施与依赖关系的跨系统传播;(iv)有效技术与人类控制权威的退化;(v)运行压力下机构响应能力的压力。该框架未枚举威胁,而是识别共同决定系统级风险的重复机制。我们进一步发现学术AI安全研究与CI运营约束间存在结构错配,并推导基于系统级保证标准的面向部署的研究议程。总体而言,本研究将关注点从以模型为中心的鲁棒性转向互联CI环境中以生命周期为结构的系统级保证。
英文摘要
Frontier artificial intelligence (FAI), encompassing large-scale, general-purpose AI systems, including large language models, multimodal foundation models, and agentic systems, is increasingly integrated into critical infrastructure (CI). This challenges long-standing security assumptions of bounded behavior, segmented networks, component transparency, and human-paced decision-making. Existing AI-security literature typically organizes risks by attack type, lifecycle stage, or asset class, but fails to capture the system-level dynamics, such as how risk emerges, spreads, and is controlled, through which FAI reshapes CI security outcomes. This Systematization of Knowledge (SoK) introduces a five-dimensional risk-dynamics framework that characterizes how FAI reconfigures CI security across the lifecycle: (i) Capability Emergence through new FAI-enabled attack and defense capabilities, (ii) Infiltration Pathways through data, models and AI supply chains, (iii) Cross-System Propagation across interconnected infrastructures and dependencies, (iv) degradation of effective technical and human Control Authority, and (v) strain on institutional Response Capacity under operational pressure. Rather than enumerating threats, the framework identifies recurring mechanisms that jointly determine system-level risk. We further identify a structural mismatch between academic AI-security research and CI operational constraints, and derive a deployment-oriented research agenda grounded in system-level assurance criteria. Collectively, this work shifts attention from model-centric robustness to lifecycle-structured, system-level assurance in interconnected CI environments.
Comments19 pages