arXiv:2601.05293cs.CRcs.AI2026-01综述被引 28

agentic AI在网络安全中既可自动防御,也助长攻击,带来新风险与挑战。

A Survey of Agentic AI and Cybersecurity: Challenges, Opportunities and Use-case Prototypes

  • 构建能持续推理、规划与自适应的智能体系统,实现长期自主任务。
  • 支持自动化威胁狩猎与大规模欺诈检测,提升防御效率。
  • 适合安全研究人员、AI治理者及系统设计者参考其风险与应用实践。

Agentic AI标志着从单步生成模型向具备推理、规划、行动和长期任务适应能力系统的重大转变。通过整合记忆、工具使用和迭代决策循环,这些系统能够在真实环境中实现持续的自主工作流。本文综述了agentic AI对网络安全的影响。在防御方面,其能力支持持续监控、自主事件响应、自适应威胁狩猎和规模化欺诈检测。相反,相同特性也增强了攻击方的能力,加速侦察、漏洞利用、协调攻击和社交工程。这种双重用途暴露出现有治理、保证和问责机制的重大缺陷,这些机制主要针对非自主和短期运行的AI系统而设计。为此,本文调研了针对agentic系统的新兴威胁模型、安全框架和评估流程,并分析了代理合谋、级联故障、监管规避和记忆污染等系统性风险。最后,提出了三个代表性应用场景原型,展示agentic AI在实际网络安全工作流中的表现,以及设计选择如何影响其可靠性、安全性与有效性。

原文摘要 · Abstract (English)

Agentic AI marks an important transition from single-step generative models to systems capable of reasoning, planning, acting, and adapting over long-lasting tasks. By integrating memory, tool use, and iterative decision cycles, these systems enable continuous, autonomous workflows in real-world environments. This survey examines the implications of agentic AI for cybersecurity. On the defensive side, agentic capabilities enable continuous monitoring, autonomous incident response, adaptive threat hunting, and fraud detection at scale. Conversely, the same properties amplify adversarial power by accelerating reconnaissance, exploitation, coordination, and social-engineering attacks. These dual-use dynamics expose fundamental gaps in existing governance, assurance, and accountability mechanisms, which were largely designed for non-autonomous and short-lived AI systems. To address these challenges, we survey emerging threat models, security frameworks, and evaluation pipelines tailored to agentic systems, and analyze systemic risks including agent collusion, cascading failures, oversight evasion, and memory poisoning. Finally, we present three representative use-case implementations that illustrate how agentic AI behaves in practical cybersecurity workflows, and how design choices shape reliability, safety, and operational effectiveness.

安全智能体治理风险

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。