构建AI攻击链评估框架,识别关键风险环节并指导防御优先级。
A Framework for Evaluating Emerging Cyberattack Capabilities of AI
- 基于真实事件构建七类典型AI攻击链,覆盖端到端流程。
- 发现AI可显著放大攻击在特定阶段的破坏力,如渗透与持久化。
- 适合安全团队用于红队模拟与防御策略优化。
随着前沿AI模型能力增强,评估其潜在支持网络攻击的能力对确保通用人工智能(AGI)的安全发展至关重要。当前的网络安全评估多为零散尝试,缺乏对攻击各阶段的系统分析及针对性防御指引。本文提出一种新评估框架,通过:(1) 分析端到端攻击链,(2) 识别AI威胁评估中的空白点,(3) 帮助防御者确定重点缓解措施,并开展基于AI的对手模拟以支持红队演练。该方法借鉴现有攻击链框架,结合谷歌威胁情报组整理的超过12,000个涉及AI的真实网络事件,归纳出七种代表性攻击链范式。通过对这些范式进行瓶颈分析,定位了最易受AI驱动干扰的阶段。随后,我们采用外部开发的网络安全模型评估,聚焦于这些关键阶段。结果表明,AI可在特定攻击环节显著增强攻击能力,并据此提出防御优先级建议。我们认为这是迄今最全面的AI网络安全风险评估框架。
原文摘要 · Abstract (English)
As frontier AI models become more capable, evaluating their potential to enable cyberattacks is crucial for ensuring the safe development of Artificial General Intelligence (AGI). Current cyber evaluation efforts are often ad-hoc, lacking systematic analysis of attack phases and guidance on targeted defenses. This work introduces a novel evaluation framework that addresses these limitations by: (1) examining the end-to-end attack chain, (2) identifying gaps in AI threat evaluation, and (3) helping defenders prioritize targeted mitigations and conduct AI-enabled adversary emulation for red teaming. Our approach adapts existing cyberattack chain frameworks for AI systems. We analyzed over 12,000 real-world instances of AI involvement in cyber incidents, catalogued by Google's Threat Intelligence Group, to curate seven representative attack chain archetypes. Through a bottleneck analysis on these archetypes, we pinpointed phases most susceptible to AI-driven disruption. We then identified and utilized externally developed cybersecurity model evaluations focused on these critical phases. We report on AI's potential to amplify offensive capabilities across specific attack stages, and offer recommendations for prioritizing defenses. We believe this represents the most comprehensive AI cyber risk evaluation framework published to date.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。