arXiv:2503.16392cs.CRcs.AI2025-03被引 1

提出图谱方法量化攻击者使用AI漏洞的难度,助力企业优先防御风险。

Graph of Effort: Quantifying Risk of AI Usage for Vulnerability Assessment

  • 构建'努力图谱'模型,评估攻击者利用AI攻击漏洞所需投入
  • 可对组织内所有资产进行风险排序,尤其适用于复杂云环境
  • 为安全团队提供可量化的威胁分析工具,适合安全建模与漏洞管理

随着基于AI的软件日益普及,其高自动化和复杂模式识别能力可能被恶意利用,带来显著风险。将用于攻击非AI资产的AI称为进攻型AI。当前研究已探索其使用方式及分类,并开发了针对组织内AI资产的威胁建模方法。但仍有两大空白:一是缺乏对威胁因素的量化;二是缺少针对全组织资产、评估被AI攻击风险的威胁模型,这在具有复杂基础设施和访问控制的云环境中尤为关键。本文提出‘努力图谱’(Graph of Effort),一种直观、灵活且有效的威胁建模方法,用于分析对手使用进攻型AI实施漏洞攻击所需的努力程度。该模型能帮助分析师对漏洞进行排序,并优先部署主动防御措施。尽管方法有效,其设计选择仍需未来实证验证。

原文摘要 · Abstract (English)

With AI-based software becoming widely available, the risk of exploiting its capabilities, such as high automation and complex pattern recognition, could significantly increase. An AI used offensively to attack non-AI assets is referred to as offensive AI. Current research explores how offensive AI can be utilized and how its usage can be classified. Additionally, methods for threat modeling are being developed for AI-based assets within organizations. However, there are gaps that need to be addressed. Firstly, there is a need to quantify the factors contributing to the AI threat. Secondly, there is a requirement to create threat models that analyze the risk of being attacked by AI for vulnerability assessment across all assets of an organization. This is particularly crucial and challenging in cloud environments, where sophisticated infrastructure and access control landscapes are prevalent. The ability to quantify and further analyze the threat posed by offensive AI enables analysts to rank vulnerabilities and prioritize the implementation of proactive countermeasures. To address these gaps, this paper introduces the Graph of Effort, an intuitive, flexible, and effective threat modeling method for analyzing the effort required to use offensive AI for vulnerability exploitation by an adversary. While the threat model is functional and provides valuable support, its design choices need further empirical validation in future work.

威胁建模AI安全漏洞评估云安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。