智能体安全:LLM驱动渗透测试的工具、失效模式与设计法则体系化研究
Agentic Security: A Systematization of Tools, Failure Modes, and Design Laws for LLM-Driven Penetration Testing
浏览论文内容
中文总结 AI 辅助
该研究对LLM驱动渗透测试的智能体安全相关工具、失效模式等体系化,推导定量规律与设计法则,实现Inspectra平台验证。
中文摘要 AI 辅助
智能体安全利用大语言模型(LLM)智能体规划、调度和解释安全工具。随着这类系统从演示阶段转向部署产品,从业者反复遇到相同的操作失效问题。我们通过对10种广泛使用的静态、动态、云、编排和AI红队工具进行无人值守流水线的实操评估,将这些失效问题体系化。我们引入四维集成摩擦指数,将一次性工程成本与重复性的组织、法律和维护成本区分开。随后,我们推导解释重复性失效模式的定量规律:将智能体安全系统建模为确定性中介封装的随机LLM策略,我们发现长期会话会随阶段计数丢失驻留证据,而短期子智能体则会根据原始证据与其摘要之间的压缩比扩展可用范围;我们表明,两阶段裁决级联会倍增评分者似然比,但当评分者误差相关时收益甚微;我们表明,将无法评估的结果视为攻击失败会使下游测量偏向规避性和严重响应;我们将规划器-工作者模型路由表述为背包问题,并推导重尾工具的闭式执行上限η*=αv/c;最后,我们解释为何范围和预算执行无法委托给系统提示:提示无法约束实际执行的内容。我们实现的平台Inspectra作为实例,其机制标记为已部署、部分部署或计划中,包括那些未奏效的机制。
英文摘要
Agentic security uses large-language-model (LLM) agents to plan, dispatch, and interpret security tools. As these systems move from demonstrations to deployed products, practitioners repeatedly encounter the same operational failures. We systematize these failures through a hands-on evaluation of ten widely used static, dynamic, cloud, orchestration, and AI red-teaming tools for unattended pipelines. We introduce a four-dimensional Integration Friction Index that separates one-time engineering cost from recurring organisational, legal, and maintenance cost. We then derive quantitative regularities that explain recurring failure modes. Modelling an agentic security system as stochastic LLM policies wrapped by a deterministic mediator, we show that long-lived sessions lose resident evidence with phase count, while short-lived sub-agents extend the usable horizon according to the compression ratio between raw evidence and its summary. We show that a two-stage verdict cascade multiplies scorer likelihood ratios, but provides little benefit when scorer errors correlate. We show that treating unevaluable outcomes as attack failures biases downstream measurements toward evasive and severe responses. We formulate planner-versus-worker model routing as a knapsack problem and derive a closed-form execution cap for heavy-tailed tools, eta* = alpha v/c. Finally, we show why scope and budget enforcement cannot be delegated to system prompts: prompts do not constrain what actually executes. Inspectra, our implemented platform, serves as a worked instantiation, with mechanisms labelled shipped, partial, or planned, including those that did not work.
发表机构
- Ahsanullah University of Science and Technology(阿赫桑乌拉科技大学)
- BRAC University(BRAC大学)
- North South University(北南大学)
- Missouri State University(密苏里州立大学)
- Multimedia University(多媒体大学)
- American International University-Bangladesh(孟加拉国美国国际大学)
机构由 AI 辅助整理,请以论文原文为准。