为集成AI代理设计资产为中心的威胁建模方法
Threat Modeling for AI: The Case for an Asset-Centric Approach
- 从资产出发,系统识别漏洞对关键AI资产的影响
- 可量化第三方AI组件的安全假设,无需了解内部实现
- 适合复杂自主能力的AI系统安全防护
当前AI发展正推动其从独立应用向深度集成的AI代理演进。这些代理具备自主决策与行动能力,可调用现有应用(无论是否基于AI)并执行脚本。随着AI系统能自主运行代码、交互外部系统且无须人工监督,传统安全方法已不适用。本文提出一种以资产为中心的威胁建模方法,突破现有自上而下分析特定产品攻击的局限,采用自下而上的方式,帮助防御者系统性识别分布式开发与部署环境中,常规及AI特有漏洞对关键资产的影响。该方法使安全团队能够:(1) 跨技术领域进行全面分析并有效沟通;(2) 在不依赖第三方实现细节的前提下量化其安全假设;(3) 全面识别与其产品上下文相关的AI漏洞。该方法特别适用于具备复杂自主能力的代理系统,通过聚焦资产而非攻击,可随快速演进的威胁环境扩展,并适配日益复杂的分布式的AI开发流程。
原文摘要 · Abstract (English)
Recent advances in AI are transforming AI's ubiquitous presence in our world from that of standalone AI-applications into deeply integrated AI-agents. These changes have been driven by agents' increasing capability to autonomously make decisions and initiate actions, using existing applications; whether those applications are AI-based or not. This evolution enables unprecedented levels of AI integration, with agents now able to take actions on behalf of systems and users -- including, in some cases, the powerful ability for the AI to write and execute scripts as it deems necessary. With AI systems now able to autonomously execute code, interact with external systems, and operate without human oversight, traditional security approaches fall short. This paper introduces an asset-centric methodology for threat modeling AI systems that addresses the unique security challenges posed by integrated AI agents. Unlike existing top-down frameworks that analyze individual attacks within specific product contexts, our bottom-up approach enables defenders to systematically identify how vulnerabilities -- both conventional and AI-specific -- impact critical AI assets across distributed infrastructures used to develop and deploy these agents. This methodology allows security teams to: (1) perform comprehensive analysis that communicates effectively across technical domains, (2) quantify security assumptions about third-party AI components without requiring visibility into their implementation, and (3) holistically identify AI-based vulnerabilities relevant to their specific product context. This approach is particularly relevant for securing agentic systems with complex autonomous capabilities. By focusing on assets rather than attacks, our approach scales with the rapidly evolving threat landscape while accommodating increasingly complex and distributed AI development pipelines.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。