为工业场景中的AI代理设计基于角色的访问控制,提升安全性
Securing AI Agents: Implementing Role-Based Access Control for Industrial Applications
- 将角色权限控制机制嵌入AI代理,限制其访问能力
- 解决提示注入等安全威胁,保障工业应用可靠性
- 适合需要本地部署的制造业、自动化系统开发者
大型语言模型(LLMs)在政治科学、软件开发等多个领域推动了技术进步,但受限于静态且截止于特定日期的训练数据。其通用性也常需微调以完成具体任务。借助外部工具与实时数据,基于LLM的AI代理缓解了这些局限,实现如实时天气报告、数据分析等功能。在工业环境中,这类代理正推动运营变革,在制造领域实现近自主系统,提升生产效率并支持实时决策。然而,当前AI代理仍面临提示注入等安全威胁,危及其完整性与可靠性。本文提出一种将基于角色的访问控制(RBAC)集成到AI代理的框架,构建稳健的安全防护机制,支持在本地部署环境下的高效、可扩展应用。
原文摘要 · Abstract (English)
The emergence of Large Language Models (LLMs) has significantly advanced solutions across various domains, from political science to software development. However, these models are constrained by their training data, which is static and limited to information available up to a specific date. Additionally, their generalized nature often necessitates fine-tuning -- whether for classification or instructional purposes -- to effectively perform specific downstream tasks. AI agents, leveraging LLMs as their core, mitigate some of these limitations by accessing external tools and real-time data, enabling applications such as live weather reporting and data analysis. In industrial settings, AI agents are transforming operations by enhancing decision-making, predictive maintenance, and process optimization. For example, in manufacturing, AI agents enable near-autonomous systems that boost productivity and support real-time decision-making. Despite these advancements, AI agents remain vulnerable to security threats, including prompt injection attacks, which pose significant risks to their integrity and reliability. To address these challenges, this paper proposes a framework for integrating Role-Based Access Control (RBAC) into AI agents, providing a robust security guardrail. This framework aims to support the effective and scalable deployment of AI agents, with a focus on on-premises implementations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。