arXiv:2504.00012cs.CRcs.CY2025-04被引 1

用传统人员安全思路应对AI内部威胁,提升风险管控能力。

I'm Sorry Dave: How the old world of personnel security can inform the new world of AI insider risk

  • 借鉴人员安全机制,构建AI内部风险防御框架
  • 解决AI内部威胁隐蔽性强、难追踪的管理难题
  • 适合关注AI安全与合规的组织与安全团队

组织正迅速采用人工智能工具执行以往由人工完成的任务,潜在收益巨大。与此同时,部分组织已部署人员安全措施以应对可信人类内部人员带来的安全风险。然而,快速演进的AI领域与传统的人员安全实践之间缺乏有效互动,这已成为问题。人类内部人员带来的复杂风险即便经过多年努力仍难以理解和管理,而新兴的AI内部风险则更为模糊。双方都需要更多支持。一些在应对人类内部风险中证明有效的概念和方法,同样适用于应对新兴的AI内部风险。

原文摘要 · Abstract (English)

Organisations are rapidly adopting artificial intelligence (AI) tools to perform tasks previously undertaken by people. The potential benefits are enormous. Separately, some organisations deploy personnel security measures to mitigate the security risks arising from trusted human insiders. Unfortunately, there is no meaningful interplay between the rapidly evolving domain of AI and the traditional world of personnel security. This is a problem. The complex risks from human insiders are hard enough to understand and manage, despite many decades of effort. The emerging security risks from AI insiders are even more opaque. Both sides need all the help they can get. Some of the concepts and approaches that have proved useful in dealing with human insiders are also applicable to the emerging risks from AI insiders.

AI安全内部威胁风险管控

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。