arXiv:2411.13459cs.CRcs.AI2024-11被引 4

系统化梳理复合AI系统的多层攻击与防御,揭示组合攻击的威胁威力。

SoK: A Systems Perspective on Compound AI Threats and Countermeasures

  • 从系统视角整合软件与硬件层的多种攻击方式
  • 发现组合攻击可大幅降低对威胁模型的假设要求
  • 适合安全研究者与企业AI架构师参考

大型语言模型(LLMs)在企业中广泛应用,使用专有模型并处理敏感数据。以往研究已识别出训练与推理环节涉及的各类软硬件攻击向量,使机密性与完整性策略难以实施。随着复合型AI推理流水线(集成多个LLM)的发展,攻击面显著扩大。攻击者不仅针对算法,还瞄准相关软硬件组件。现有研究多孤立分析各层,但本工作发现跨层攻击结合可实现强效端到端攻击,且对威胁模型假设更少。我们系统梳理了不同层次的软件与硬件攻击,并基于MITRE ATT&CK框架对机器学习攻击进行分类,以明确其威胁定位。最后,总结了软硬件层的现有缓解措施,强调必须构建综合防御策略,以支持复合型AI系统的安全高效部署。

原文摘要 · Abstract (English)

Large language models (LLMs) used across enterprises often use proprietary models and operate on sensitive inputs and data. The wide range of attack vectors identified in prior research - targeting various software and hardware components used in training and inference - makes it extremely challenging to enforce confidentiality and integrity policies. As we advance towards constructing compound AI inference pipelines that integrate multiple large language models (LLMs), the attack surfaces expand significantly. Attackers now focus on the AI algorithms as well as the software and hardware components associated with these systems. While current research often examines these elements in isolation, we find that combining cross-layer attack observations can enable powerful end-to-end attacks with minimal assumptions about the threat model. Given, the sheer number of existing attacks at each layer, we need a holistic and systemized understanding of different attack vectors at each layer. This SoK discusses different software and hardware attacks applicable to compound AI systems and demonstrates how combining multiple attack mechanisms can reduce the threat model assumptions required for an isolated attack. Next, we systematize the ML attacks in lines with the Mitre Att&ck framework to better position each attack based on the threat model. Finally, we outline the existing countermeasures for both software and hardware layers and discuss the necessity of a comprehensive defense strategy to enable the secure and high-performance deployment of compound AI systems.

AI安全攻击分析系统防御

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。