智能体集成软件的安全性:当人类操作与智能体行为共存时
Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist
- State Key Laboratory for Novel Software Technology, Nanjing University(南京大学软件新技术国家重点实验室)
- Technical University of Munich(慕尼黑工业大学)
机构由 AI 辅助整理,请以论文原文为准。
中文总结 AI 辅助
本文提出从整个系统层面评估智能体集成软件的安全性,将共存问题分为四类,并指出信息溯源、策略执行、授权维持和效果恢复等研究方向。
中文摘要 AI 辅助
智能体集成软件(Agent-Integrated Software, AIS)将智能体嵌入传统应用程序中,同时支持人类操作和智能体行为。人类操作使用户能够进行精确更改并检查结果,而智能体行为则执行常规或多步骤任务。这些互补的角色使得共存成为许多软件系统长期可能具备的特征。人类操作和智能体行为影响相同的软件状态,并且可以利用彼此的结果。因此,安全策略必须在两条路径上保持有效。我们认为,AIS的安全性必须在整个软件系统的层面上进行评估。单独保护智能体和传统软件核心并不能确保它们在一起时是安全的。为了指导对AIS整体安全性的分析,我们将这种共存引发的问题归纳为四类:上下文误用、授权违规、执行控制和效果完整性。利用这些类别,我们考察了当前实践如何解决AIS中的安全问题,以及其保护在哪些方面仍然有限。基于这一分析,我们确定了在保留信息溯源、跨操作路径执行策略、随时间维持有效授权以及管理持久效果和恢复方面的研究机会。由此产生的视角为理解和改进AIS的安全性提供了一个概念框架。
英文摘要
Agent-Integrated Software (AIS) embeds an intelligent agent in a conventional application, supporting both human operations and agent actions. Human operations let users make precise changes and inspect results, while agent actions carry out routine or multi-step tasks. These complementary roles make coexistence a likely long-term feature of many software systems. Human operations and agent actions affect the same software state and can use one another's results. Therefore, security policies must remain effective across both paths. We argue that AIS security must be assessed at the level of the whole software system. Protecting the agent and the conventional software core separately does not establish that they are secure together. To guide security analysis of AIS as a whole, we organize the problems arising from this coexistence into four categories: context misuse, authorization violation, execution control, and effect integrity. Using these categories, we examine how current practices address the security problems in AIS and where their protection remains limited. Building on this analysis, we identify research opportunities in preserving information provenance, enforcing policy across operation paths, maintaining valid authorization over time, and managing persistent effects and recovery. This resulting perspective provides a conceptual framework for understanding and improving the security of AIS.