arXiv:2508.20307cs.CRcs.AI2025-08被引 1

AI系统开发部署中面临新型网络威胁,需针对性安全防护。

Surveying the Operational Cybersecurity and Supply Chain Threat Landscape when Developing and Deploying AI Systems

  • 分析AI全生命周期中的供应链与运营安全风险
  • 指出攻击者目标已从权限提升转向操纵AI输出结果
  • 适合关注AI安全的开发者与企业安全团队阅读

人工智能的发展重塑了软硬件生态,通过专用基础设施、大规模数据存储和先进硬件实现强大功能。然而,这些创新引入了传统安全评估常忽视的独特攻击面和目标。网络攻击者的意图正从传统的权限提升和网络横向移动,转向操纵AI输出以达成特定系统影响,如降低系统性能、产生大量误报或降低模型准确性。本文旨在提高对集成AI时引入的新威胁的认识,探讨AI全生命周期中的操作安全与供应链风险,强调需制定定制化安全框架应对不断演变的AI驱动环境下的威胁。文中结合实际案例提供洞见,帮助组织更好地保护AI系统,确保其可靠性和韧性。

原文摘要 · Abstract (English)

The rise of AI has transformed the software and hardware landscape, enabling powerful capabilities through specialized infrastructures, large-scale data storage, and advanced hardware. However, these innovations introduce unique attack surfaces and objectives which traditional cybersecurity assessments often overlook. Cyber attackers are shifting their objectives from conventional goals like privilege escalation and network pivoting to manipulating AI outputs to achieve desired system effects, such as slowing system performance, flooding outputs with false positives, or degrading model accuracy. This paper serves to raise awareness of the novel cyber threats that are introduced when incorporating AI into a software system. We explore the operational cybersecurity and supply chain risks across the AI lifecycle, emphasizing the need for tailored security frameworks to address evolving threats in the AI-driven landscape. We highlight previous exploitations and provide insights from working in this area. By understanding these risks, organizations can better protect AI systems and ensure their reliability and resilience.

AI安全供应链风险威胁分析

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。