CoSec:社区中智能体安全性的基准测试
CoSec: Benchmarking Agent Security in Communities
浏览论文内容
中文总结 AI 辅助
CoSec是一个包含208个场景的可执行基准,用于评估LLM智能体在社区内外的隐私与授权执行,发现任务效用不等于合规,社区授权仍是未解的安全挑战。
中文摘要 AI 辅助
LLM智能体在涉及多用户、社区、记忆、文件和工具的持久协作环境中运行。社区边界可能保持固定,或随成员、角色、组成和关系的变化而演变。智能体必须完成合法任务,并防止受保护信息的未授权披露。现有评估未能全面检验智能体系统中的这些风险。我们引入了CoSec,一个可执行的基准测试,用于评估在社区内部及跨社区运行的LLM智能体系统中的隐私和授权执行情况。CoSec包含208个典型场景,涵盖固定和演变的边界、属于智能体所有者或其他参与者的受保护信息,以及通过对话、环境内容、持久记忆和组合工作流进行的攻击。CoSec执行具有持久会话、记忆、文件和工具的完整智能体系统,并通过执行轨迹和工件验证信息流是否符合当前授权状态。在各种框架和模型配置下,智能体经常完成良性任务,但违反隐私和授权边界。隐私行为因框架、攻击面和社区状态而异,揭示了记忆、文件、工具和工作流如何将受保护信息携带至其授权范围之外。这些发现表明,任务效用并不等同于隐私或授权合规性,且社区环境中的授权问题对于持久LLM智能体而言仍是一个未解决的安全挑战。
英文摘要
LLM agents operate in persistent collaborative environments involving multiple users, communities, memories, files, and tools. Community boundaries may remain fixed or evolve with changes in membership, roles, composition, and relationships. Agents must complete legitimate tasks and prevent unauthorized disclosure of protected information. Existing evaluations do not fully examine these risks in agent systems. We introduce \textbf{CoSec}, an executable benchmark for evaluating privacy and authorization enforcement in LLM agent systems operating within and across communities. CoSec contains 208 canonical scenarios spanning fixed and evolving boundaries, protected information belonging to the agent owner or other participants, and attacks through dialogue, environmental content, persistent memory, and composed workflows. CoSec executes complete agent systems with persistent sessions, memory, files and tools. It verifies information flows against the active authorization state using execution traces and artifacts. Across harness and model configurations, agents frequently complete benign tasks but violate privacy and authorization boundaries. Privacy behavior varies across harnesses, attack surfaces, and community states, revealing how memory, files, tools, and workflows can carry protected information beyond its authorized scope. These findings show that task utility does not imply privacy or authorization compliance and that authorization in community settings remains an unresolved security challenge for persistent LLM agents.
发表机构
- Nanjing University(南京大学)
- Xi’an Jiaotong University(西安交通大学)
- Beihang University(北京航空航天大学)
- Zhejiang University(浙江大学)
- Zhejiang Sci-Tech University(浙江理工大学)
- Tsinghua University(清华大学)
- Southeast University(东南大学)
- Tongji University(同济大学)
- Sun Yat-sen University(中山大学)
机构由 AI 辅助整理,请以论文原文为准。