发表机构
Anaconda(安纳康达)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
提出智能体事件登记册(AIR),通过来源关联目录记录AI智能体事件,支持案例检索与评估范围审计,以帮助防止重复失败。
AI 中文摘要
AI智能体日益通过工具和委派权限行事,但通用事件库很少捕获比较公开失败与智能体安全评估所需的机制。我们提出了智能体事件登记册(Agent Incident Registry, AIR),这是一个来源关联的目录,包含从\Yfirst{}到\Ylast{}披露的\N{}条智能体相关事件记录。每条记录包括支持证据、稳定标识符,以及针对因果角色、披露类别、机制和结果的无缺失感知标签。在智能体行动的\Nprimary{}条生成式系统记录中,\Rprimary{}条涉及已实现的危害(\Pprimary\\%)。已实现的结果集中在野外和安全失败记录中,而负责任披露和研究演示绝大多数是演示性的;因此,总体份额反映的是集合构成而非部署风险。初始筛选后,第二位人工审阅者检查了所有\N{}条记录及其现有标签的完整性和正确性。在部署模拟审计中,InjecAgent的\NInjecAgentCases{}个案例占据AIR的十二个表面中的三个,且全部为攻击者触发,而AIR包含\Nsafety{}个无对手安全失败。AIR支持基于来源的案例检索和评估范围审计,而非失败率或控制效能估计。
英文摘要
AI agents increasingly act through tools and delegated authority, but general incident repositories rarely capture the mechanisms needed to compare public failures with agent-security evaluations. We present the Agent Incident Registry (AIR) (Project page: https://enkryptai.com/air), a source-linked catalog containing 487 records of agent-related events disclosed from 2022 through 2026. Each record includes supporting evidence, a stable identifier, and missingness-aware labels for causal role, disclosure class, mechanism, and outcome. Among the 336 generative-system records in which the agent acted, 81 involved realized harm (24\%). Realized outcomes concentrate in in-the-wild and safety-failure records, while responsible disclosures and research demonstrations are overwhelmingly demonstrated; the aggregate share therefore characterizes collection composition rather than deployment risk. After initial curation, a second human reviewer checked all 487 records and their existing labels for completeness and correctness. In a deployment-analogue audit, InjecAgent's 1,054 cases occupy three of AIR's twelve surfaces and are all attacker-triggered, whereas AIR contains 92 no-adversary safety failures. AIR supports source-grounded case retrieval and evaluation-scope auditing, not failure-rate or control-efficacy estimation.