测试主流AI助手对用户自定义权限规则的理解能力,发现普遍存在理解偏差。
"I Apologize For Not Understanding Your Policy": Exploring the Specification and Evaluation of User-Managed Access Control Policies by AI Virtual Assistants
- 通过语音和文本指令测试AI助手对权限规则的解析能力
- 多数助手无法正确理解复杂或非标准权限表达
- 适合关注AI安全与隐私控制的研究者和开发者
以Google Gemini、ChatGPT、Microsoft Copilot、High-Flyer Deepseek为代表的AI虚拟助手,已成为管理智能家居、智能汽车、电子健康记录等技术的重要接口。然而,用户自主管理访问控制策略(U-MAPs)的规范制定与评估面临挑战,这直接影响安全漏洞与隐私泄露风险。本研究通过非结构化到结构化的测试,评估了当前公开可用的虚拟助手在不同场景下对U-MAPs的理解能力,发现其对多种权限表达方式普遍存在理解不足。研究揭示了关键局限性,并为虚拟助手改进复杂授权规则处理与动态适应能力提供了重要参考。
原文摘要 · Abstract (English)
The rapid evolution of Artificial Intelligence (AI)-based Virtual Assistants (VAs) e.g., Google Gemini, ChatGPT, Microsoft Copilot, and High-Flyer Deepseek has turned them into convenient interfaces for managing emerging technologies such as Smart Homes, Smart Cars, Electronic Health Records, by means of explicit commands,e.g., prompts, which can be even launched via voice, thus providing a very convenient interface for end-users. However, the proper specification and evaluation of User-Managed Access Control Policies (U-MAPs), the rules issued and managed by end-users to govern access to sensitive data and device functionality - within these VAs presents significant challenges, since such a process is crucial for preventing security vulnerabilities and privacy leaks without impacting user experience. This study provides an initial exploratory investigation on whether current publicly-available VAs can manage U-MAPs effectively across differing scenarios. By conducting unstructured to structured tests, we evaluated the comprehension of such VAs, revealing a lack of understanding in varying U-MAP approaches. Our research not only identifies key limitations, but offers valuable insights into how VAs can be further improved to manage complex authorization rules and adapt to dynamic changes.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。