arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

将智能体安全重新思考为一个网络问题

Rethinking Agent Security as a Networking Problem

Van Tran, Taveesh Sharma, Tajveer Singh Dhesi, Nick Feamster

arXiv 2608.12172首次发表:更新:

AI 中文总结

该研究针对现有以智能体为中心的安全防御无法可靠防范AI智能体风险的问题,借鉴网络领域原则,提出结合确定性执行与语义策略的AI智能体安全系统设计思路。

AI 中文摘要

AI智能体正变得越来越强大并被广泛部署,有望大幅提升生产力并催生新类型的应用。然而,它们日益增强的自主性也带来了重大的隐私和安全风险。现有的防御措施主要以智能体为中心,依赖智能体自身来检测威胁并执行隐私和安全策略。这种方法存在根本性局限,因为它将策略执行权交给了由大语言模型(LLM)驱动的AI智能体,其行为具有内在不确定性,且易受提示注入等攻击的操纵。因此,当前的防御措施无法可靠地防范隐私和安全威胁,凸显出亟需一种新的解决方案来保障AI智能体系统的安全。网络领域长期以来一直在应对类似挑战,提供了可借鉴的深刻原则,包括集中控制与分布式执行、基于能力的敏感资源请求访问中介、以及通过零信任执行实现最小权限。历史上,这些原则为网络系统提供了强大的确定性保障。但仅靠这些原则不足以保障AI智能体的安全,因为智能体行动的安全性和适当性往往取决于静态规则无法表达的语义上下文。基于这些原则,我们倡导一种系统的AI智能体安全方法,将提供强安全保障的确定性执行机制与支持细致决策的语义上下文感知策略相结合。随后,我们提出了一种参考架构,并确定了关键研究问题和未来方向,以指导安全且隐私保护的AI智能体系统的设计。

英文摘要

AI agents are rapidly becoming more capable and widely deployed, promising substantial gains in productivity and enabling new classes of applications. However, their growing autonomy also introduces significant privacy and security risks. Existing defenses are predominantly agent-centric, relying on the agent itself to detect threats and enforce privacy and security policies. This approach is fundamentally limited because it entrusts policy enforcement to AI agents whose LLM-driven behavior is inherently nondeterministic and vulnerable to manipulation through attacks such as prompt injection. As a result, current defenses cannot reliably prevent privacy and security threats, highlighting a critical need for a new solution to securing AI agent systems. The networking community has long grappled with similar challenges and offers insightful principles we can borrow to design a more secure AI agent system. These include centralized control with distributed enforcement, capability-based access for mediating requests to sensitive resources, and least privilege through zero-trust enforcement. Historically, these principles have provided strong deterministic guarantees for networked systems. However, these principles alone are insufficient for AI agents because the safety and appropriateness of an agent's actions often depend on semantic context beyond the expressiveness of static rules. Building on these principles, we advocate for a systematic approach to AI agent security that combines deterministic enforcement mechanisms, which provide strong security guarantees, with semantic, context-aware policies that enable nuanced decision-making. We then present a reference architecture and identify key research questions and future directions to guide the design of secure and privacy-preserving AI agent systems.

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑