arXiv:2506.23296cs.CRcs.AI2025-06被引 2

梳理11类AI攻击及其对安全三要素的影响,助力非专业人员识别风险。

Securing AI Systems: A Guide to Known Attacks and Impacts

  • 归纳11种针对预测与生成式AI的特有攻击方法。
  • 明确每类攻击对机密性、完整性、可用性的具体破坏后果。
  • 面向开发者、安全人员和政策制定者,提供可操作的防御基础。

人工智能嵌入信息系统后面临特定安全威胁,这些威胁利用AI系统本身的漏洞。本文提供了对预测型与生成型AI系统中独特对抗攻击的易懂概述。我们识别出十一类主要攻击类型,并明确将攻击技术与其影响(包括信息泄露、系统被攻破、资源耗尽)对应起来,映射至保密性、完整性、可用性(CIA)安全三要素。旨在为研究人员、开发人员、安全从业者及政策制定者——即使缺乏专门的AI安全知识——提供基础认知,以识别AI特有风险并实施有效防护,从而提升整体AI系统的安全水平。

原文摘要 · Abstract (English)

Embedded into information systems, artificial intelligence (AI) faces security threats that exploit AI-specific vulnerabilities. This paper provides an accessible overview of adversarial attacks unique to predictive and generative AI systems. We identify eleven major attack types and explicitly link attack techniques to their impacts -- including information leakage, system compromise, and resource exhaustion -- mapped to the confidentiality, integrity, and availability (CIA) security triad. We aim to equip researchers, developers, security practitioners, and policymakers, even those without specialized AI security expertise, with foundational knowledge to recognize AI-specific risks and implement effective defenses, thereby enhancing the overall security posture of AI systems.

AI安全对抗攻击信息安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。