为智能体供应链运行时安全构建攻击与防御分类体系
SOK: A Taxonomy of Attack Vectors and Defense Strategies for Agentic Supply Chain Runtime
- 提出运行时攻击分类框架,区分数据与工具供应链风险
- 发现病毒式智能体循环机制,可无代码漏洞自我传播
- 主张零信任架构,以密码学溯源替代语义信任
基于大语言模型的智能体系统不仅是文本生成器,更是能动态检索信息并调用工具的自主实体。这种执行模式将攻击面从传统的构建期资产转移至推理期依赖,使智能体易受不可信数据和概率性能力解析的操控。尽管已有研究关注模型层面漏洞,但智能体复杂、循环的运行时行为所引发的安全风险仍分散孤立。本文系统化现有研究,构建统一的运行时框架。将威胁分为数据供应链攻击(区分瞬时上下文注入与持久记忆污染)和工具供应链攻击(涵盖发现、实现与调用阶段)。关键发现:出现病毒式智能体环,智能体成为无需代码漏洞即可自我传播的生成型蠕虫载体。主张转向零信任运行时架构,将上下文视为不可信控制流,工具执行通过密码学溯源而非语义可能性进行约束。
原文摘要 · Abstract (English)
Agentic systems based on large language models (LLMs) operate not merely as text generators but as autonomous entities that dynamically retrieve information and invoke tools. This execution model shifts the attack surface from traditional build-time artifacts to inference-time dependencies, exposing agents to manipulation through untrusted data and probabilistic capability resolution. While prior work has examined model-level vulnerabilities, security risks arising from the complex, cyclic runtime behavior of agents remain fragmented. This paper systematizes existing research into a unified runtime framework. We categorize threats into data supply chain attacks (distinguishing between transient context injection and persistent memory poisoning) and tool supply chain attacks (spanning discovery, implementation, and invocation phases). Crucially, we identify the emergence of the Viral Agent Loop, where agents effectively become vectors for self-propagating generative worms that require no code vulnerabilities to spread. We argue for a transition to a Zero-Trust Runtime Architecture, where context is treated as untrusted control flow, and tool execution is bounded by cryptographic provenance rather than semantic likelihood.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。