构建统一框架,系统识别和防御AI全生命周期安全风险
Cisco Integrated AI Security and Safety Framework Report
- 提出覆盖多模态与生态的整合式安全框架
- 涵盖内容安全、模型完整性、运行时攻击等四类风险
- 适合安全团队用于威胁识别与防御策略设计
人工智能系统正快速渗透至消费平台、企业软件及嵌入式代理网络。尽管提升了生产力,攻击面也同步扩大:包括有害输出、模型与数据篡改、运行时操控(如提示注入)以及生态风险(如多代理合谋)。现有框架如MITRE ATLAS、NIST AI 100-2、OWASP LLMs与代理应用十大风险虽各有价值,但仅覆盖部分维度。本文提出思科集成AI安全与安全框架(AI Security Framework),一个全生命周期感知的统一分类与实操框架,可覆盖多模态、代理、管道与整体生态中的各类风险。该框架支持威胁识别、红队测试与风险优先级排序,具备可扩展性,适用于多模态、人形机器人、可穿戴设备与传感基础设施等新兴场景。通过分析现有框架缺口,阐述设计原则,并展示该分类体系如何帮助理解现代AI系统失效机制、对手利用方式,以及组织如何在能力演进中构建动态防御。
原文摘要 · Abstract (English)
Artificial intelligence (AI) systems are being readily and rapidly adopted, increasingly permeating critical domains: from consumer platforms and enterprise software to networked systems with embedded agents. While this has unlocked potential for human productivity gains, the attack surface has expanded accordingly: threats now span content safety failures (e.g., harmful or deceptive outputs), model and data integrity compromise (e.g., poisoning, supply-chain tampering), runtime manipulations (e.g., prompt injection, tool and agent misuse), and ecosystem risks (e.g., orchestration abuse, multi-agent collusion). Existing frameworks such as MITRE ATLAS, National Institute of Standards and Technology (NIST) AI 100-2 Adversarial Machine Learning (AML) taxonomy, and OWASP Top 10s for Large Language Models (LLMs) and Agentic AI Applications provide valuable viewpoints, but each covers only slices of this multi-dimensional space. This paper presents Cisco's Integrated AI Security and Safety Framework ("AI Security Framework"), a unified, lifecycle-aware taxonomy and operationalization framework that can be used to classify, integrate, and operationalize the full range of AI risks. It integrates AI security and AI safety across modalities, agents, pipelines, and the broader ecosystem. The AI Security Framework is designed to be practical for threat identification, red-teaming, risk prioritization, and it is comprehensive in scope and can be extensible to emerging deployments in multimodal contexts, humanoids, wearables, and sensory infrastructures. We analyze gaps in prevailing frameworks, discuss design principles for our framework, and demonstrate how the taxonomy provides structure for understanding how modern AI systems fail, how adversaries exploit these failures, and how organizations can build defenses across the AI lifecycle that evolve alongside capability advancements.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。