让大模型根据员工角色控制访问权限,提升企业安全
Role-Aware Language Models for Secure and Contextualized Access Control in Organizations
- 用角色信息微调大模型,实现权限感知的响应生成
- 在不同组织结构下验证模型能有效区分角色权限
- 适合需要精细化权限管理的企业级AI应用
随着大语言模型在企业环境中的广泛应用,基于用户角色控制模型行为成为关键需求。现有安全方法通常假设权限统一,仅关注防止有害或不当输出,未考虑角色相关的访问限制。本文研究大模型是否可通过微调生成反映不同组织角色权限的回应。提出三种建模策略:基于BERT的分类器、基于LLM的分类器,以及角色条件生成。为评估方法,构建两个互补数据集:第一个基于已有指令调优语料通过聚类和角色标注构建,第二个为合成数据,反映真实企业场景下的角色敏感性。在多种组织结构下评估模型表现,并分析其对提示注入、角色错配和越狱攻击的鲁棒性。
原文摘要 · Abstract (English)
As large language models (LLMs) are increasingly deployed in enterprise settings, controlling model behavior based on user roles becomes an essential requirement. Existing safety methods typically assume uniform access and focus on preventing harmful or toxic outputs, without addressing role-specific access constraints. In this work, we investigate whether LLMs can be fine-tuned to generate responses that reflect the access privileges associated with different organizational roles. We explore three modeling strategies: a BERT-based classifier, an LLM-based classifier, and role-conditioned generation. To evaluate these approaches, we construct two complementary datasets. The first is adapted from existing instruction-tuning corpora through clustering and role labeling, while the second is synthetically generated to reflect realistic, role-sensitive enterprise scenarios. We assess model performance across varying organizational structures and analyze robustness to prompt injection, role mismatch, and jailbreak attempts.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。