前沿AI正加剧攻防失衡,亟需构建防御型AI体系。
Frontier AI's Impact on the Cybersecurity Landscape
- 从攻防多维度分析发现AI在攻击能力上已超越防御
- 现有AI代理难以灵活规划复杂安全任务流程
- 适合安全研究者与政策制定者关注风险应对
前沿AI(如AI代理与基础模型)对网络安全的影响日益显著。本文通过定量基准测试、定性文献综述、实证评估和专家调查,全面分析该趋势。结果一致表明,AI在攻击端的能力已超过防御端。对主流代理系统在网络安全基准上的实证评估显示,当前AI代理在灵活工作流规划及使用领域专用工具进行复杂安全分析方面存在明显短板——这些能力对防御应用尤为关键。对AI与安全研究人员及从业者进行的专家调查显示,普遍认为未来一段时间内AI仍将更有利于攻击方,尽管差距预期将逐步缩小。因此,迫切需要评估并缓解前沿AI的风险,引导其向提升网络安全防御方向发展。为此,本文提出具体行动建议:构建新的网络安全基准、开发防御型AI代理、设计可证明安全的AI代理、改进部署前安全测试与透明度,以及加强用户导向的教育与防护。论文摘要与博客详见 https://rdi.berkeley.edu/frontier-ai-impact-on-cybersecurity/。
原文摘要 · Abstract (English)
The impact of frontier AI (i.e., AI agents and foundation models) in cybersecurity is rapidly increasing. In this paper, we comprehensively analyze this trend through multiple aspects: quantitative benchmarks, qualitative literature review, empirical evaluation, and expert survey. Our analyses consistently show that AI's capabilities and applications in attacks have exceeded those on the defensive side. Our empirical evaluation of widely used agent systems on cybersecurity benchmarks highlights that current AI agents struggle with flexible workflow planning and using domain-specific tools for complex security analysis -- capabilities particularly critical for defensive applications. Our expert survey of AI and security researchers and practitioners indicates a prevailing view that AI will continue to benefit attackers over defenders, though the gap is expected to narrow over time. These results show the urgent need to evaluate and mitigate frontier AI's risks, steering it towards benefiting cyber defenses. Responding to this need, we provide concrete calls to action regarding: the construction of new cybersecurity benchmarks, the development of AI agents for defense, the design of provably secure AI agents, the improvement of pre-deployment security testing and transparency, and the strengthening of user-oriented education and defenses. Our paper summary and blog are available at https://rdi.berkeley.edu/frontier-ai-impact-on-cybersecurity/.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。