arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.22930cs.AIcs.SE

智能体AI编码的安全概念与Terok环境

Concepts for Securing Agentic AI Coding and the Terok Environment

Jiří Vyskočil, Franz Pöschel, Andreas Knüpfer

首次发表
浏览论文内容

中文总结 AI 辅助

本文针对智能体AI编码的IT安全风险,提出风险评估、无损失缓解概念及实现概述,助力社区安全评估该技术的应用潜力。

中文摘要 AI 辅助

智能体AI是软件开发领域极具吸引力的新型工具,与“传统”AI辅助编码相比是巨大进步,而传统AI辅助编码本身也是此前的重大突破。基于大语言模型(LLM)的AI支持是一个新兴且发展极快的领域:传统(非智能体)类型在2025年初(约18个月前)已具备实用性与生产力,智能体类型则在2025年秋季(约9个月前)跟进问世。尽管智能体AI有诸多益处与潜力,但它也带来了一些根本性的IT安全风险,且智能体方法新增了极为严峻的风险,同时使其他风险变得更加危险。在探索这一极具吸引力的新型工具的动力驱动下,我们不应忽视这些风险,而应积极应对。本文提出三项内容:(I)对IT安全风险的评估;(II)在不破坏其益处的前提下缓解风险的概念;(III)我们所提出概念的实现概述。在这个高度动态的领域中,这可能不是所识别问题的最终且一劳永逸的解决方案,但仍是在负责任地将智能体AI应用于软件开发方面迈出的重要一步,也将为社区做出贡献,使人们能够尽早且积极地评估智能体AI在软件开发中的潜力,同时避免遭受其隐含的IT安全风险。

英文摘要

Agentic AI is a fascinating new tool for software development. It is a huge step forward compared to "conventional" AI assisted coding, which in turn was a considerable breakthrough earlier. AI support through LLMs is a young and very fast-moving field. The "conventional" (non-agentic) flavor became useful and productive in early 2025 (around 18 months ago) and the agentic flavor followed in fall 2025 (approximately 9 months ago). Besides all its benefits and potential, it also carries some fundamental risks for IT security. And the agentic approach added very severe risks while making others much more dangerous. With all the motivation to explore this fascinating new tool we should not ignore the risks but actively address them. We present (I) an assessment of the IT security risks, (II) a concept for mitigating them without breaking its benefits, and (III) an overview about an implementation of our concept. In this very dynamic field this is likely not the final and once-and-for-all answer to the identified issues but still a substantial step forward in responsible usage of Agentic AI for software development. It should also be a contribution to the community to allow early and eager evaluation of the potential of agentic AI for software development without actually suffering from its implied IT security risks.

发表机构

  • Center for Advanced Systems Understanding (CASUS)(高级系统理解中心(CASUS))
  • Helmholtz-Zentrum Dresden-Rossendorf (HZDR)(德累斯顿-罗森多夫亥姆霍兹中心(HZDR))

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑