arXiv:2501.01435cs.CRcs.AI2025-01

通用AI模型部署面临安全风险,需借鉴网络安全经验应对

Fundamental Risks in the Current Deployment of General-Purpose AI Models: What Have We (Not) Learnt From Cybersecurity?

  • 将通用AI比作操作系统,分析其自主性与权限带来的安全隐患
  • 指出当前评估体系不足,需建立更系统的安全检测框架
  • 适合关注AI安全、系统设计的开发者和研究者参考

通用人工智能(如大语言模型)已广泛应用于各类场景,从基础语言处理到聊天机器人,甚至逐步具备类似“操作系统”的能力,可控制应用决策与逻辑。工具调用、微软Copilot及Office集成、OpenAI的Altera等实例体现了其日益增强的自主性、数据访问与执行能力。这些特性也带来了诸多网络安全挑战。本文总结了我们在安全评估方面的研究成果,并展望未来机遇与挑战。

原文摘要 · Abstract (English)

General Purpose AI - such as Large Language Models (LLMs) - have seen rapid deployment in a wide range of use cases. Most surprisingly, they have have made their way from plain language models, to chat-bots, all the way to an almost ``operating system''-like status that can control decisions and logic of an application. Tool-use, Microsoft co-pilot/office integration, and OpenAIs Altera are just a few examples of increased autonomy, data access, and execution capabilities. These methods come with a range of cybersecurity challenges. We highlight some of the work we have done in terms of evaluation as well as outline future opportunities and challenges.

AI安全大模型系统风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。