为大模型智能体设计数据流控制机制,防范安全风险。
Please Don't Kill My Vibe: Empowering Agents with Data Flow Control
- 提出数据流控制机制,管理智能体产生的异常数据流动。
- 将数据流控制能力集成到数据库系统中,实现原生支持。
- 适合关注智能体安全与可信执行的研究者和开发者。
大型语言模型(LLM)智能体有望完成复杂、有状态的任务,但其发展受到严重风险制约——政策违规、流程污染和安全漏洞,根源在于对智能体行为产生的数据流缺乏可见性和管控手段。当前,智能体工作流以临时方式强制执行策略。正如数据验证和访问控制从应用层转移到数据库管理系统(DBMS),我们主张系统应原生支持数据流控制(DFC)并强制执行策略。本文描述了在数据库系统中实现可移植的DFC实例的初步工作,并勾勒出面向智能体生态系统的更广泛研究蓝图。
原文摘要 · Abstract (English)
The promise of Large Language Model (LLM) agents is to perform complex, stateful tasks. This promise is stunted by significant risks - policy violations, process corruption, and security flaws - that stem from the lack of visibility and mechanisms to manage undesirable data flows produced by agent actions. Today, agent workflows are responsible for enforcing these policies in ad hoc ways. Just as data validation and access controls shifted from the application to the DBMS, freeing application developers from these concerns, we argue that systems should support Data Flow Controls (DFCs) and enforce DFC policies natively. This paper describes early work developing a portable instance of DFC for DBMSes and outlines a broader research agenda toward DFC for agent ecosystems.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。