超越可预测路径:重新定义AI智能体安全事件报告
Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents
浏览论文内容
中文总结 AI 辅助
本文比较AI系统与智能体,基于23位专家意见,提出智能体安全事件报告所需信息要素,并指出开放研究问题与隐私要求,旨在推动安全可信部署。
中文摘要 AI 辅助
AI智能体正在快速部署,伴随而来的是日益增多的针对AI的特定攻击及相应事件。随着事件报告在法律合规、治理、问责和安全方面变得越来越重要,现有框架必须适应AI智能体的独特特征。本文中,两位编辑作者比较了AI系统和AI智能体,并借鉴来自学术界和工业界的23位专家的意见,确定了在AI智能体安全受到损害时报告事件所需的信息。潜在的报告要素包括,例如,智能体记忆及记忆访问、实际和潜在的自主水平,以及工具使用情况。基于这些发现,我们确定了几个开放的研究问题,包括如何高效记录事件,以及如何确定漏洞和事件是否具有普遍性。专家反馈还强调了潜在的报告弱点,例如数据泄露风险和针对报告基础设施本身的攻击,这产生了额外的研究需求。最后,我们总结了隐私要求,并概述了AI智能体安全可信部署的研究方向。
英文摘要
AI agents are being deployed rapidly, accompanied by a growing number of AI-specific attacks and corresponding incidents. As incident reporting becomes increasingly important for legal compliance, governance, accountability, and security; current frameworks must be adapted to the unique characteristics of AI agents. In this paper, two editorial authors compare AI systems and AI agents and, drawing on input from 23 experts in academia and industry, identify the information required for reporting incidents where the security of AI agents is harmed. %involving AI agents. Potential reporting elements include, for example, agent memory and memory accesses, actual and potential levels of autonomy, and tool usage. Based on these findings, we identify several open research questions, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback also highlighted potential reporting weaknesses, such as risks of data leakage and attacks targeting the reporting infrastructure itself, creating additional research needs. Lastly, we summarize privacy requirements and outline research directions for the secure and trustworthy deployment of AI agents.
发表机构
- SBA Research(SBA研究院)
- University of Massachusetts Amherst(马萨诸塞大学阿默斯特分校)
- Snyk(Snyk公司)
- Universita degli studi di Cagliari(卡利亚里大学)
- ZHAW(苏黎世应用科学大学)
- Huawei(华为)
- Veraitech(Veraitech公司)
- Virginia Tech(弗吉尼亚理工大学)
- Responsible AI collaborative(负责任人工智能协作组织)
- Carnegie Mellon University(卡内基梅隆大学)
- University of Wisconsin(威斯康星大学)
- Trustora Digital(Trustora数字公司)
- Northeastern University(东北大学)
- UL Research Institutes(UL研究院)
- Microsoft Security Response Center (MSRC)(微软安全响应中心)
- Qualcomm(高通公司)
- TU Vienna(维也纳工业大学)
- Deep Cyber/OWASP GenAI Security Project(深度网络/OWASP生成式人工智能安全项目)
- IBM Research Europe–Zurich(IBM欧洲研究院-苏黎世)
机构由 AI 辅助整理,请以论文原文为准。