arXiv:2603.05068cs.CRcs.AI2026-03被引 1

为AI系统构建专用威胁情报体系,应对传统防御无法覆盖的新型攻击

Cyber Threat Intelligence for Artificial Intelligence Systems

  • 基于AI供应链各阶段设计具体威胁指标(IoC)
  • 揭示现有资源存在知识空白与质量缺陷
  • 适合安全研究人员和AI系统开发者参考

随着人工智能深度嵌入关键服务与日常产品,其面临传统网络安全防御难以应对的新威胁。本文研究如何演进威胁情报以防御针对AI系统的攻击。首先分析传统威胁情报在假设与流程上与AI防护需求的不匹配,识别出AI特有的资产与脆弱性;随后梳理并组织当前AI安全知识现状。在此基础上,提出面向AI的威胁情报知识库应包含的内容,具体描述不同供应链阶段与产物的指示器(IoC),并说明其如何支持安全工具。最后探讨衡量新发现的AI产物与已知指标间相似性的技术。综述揭示现有资源存在明显空白与质量问题,指明未来可构建实用化AI专用威胁情报框架的研究方向。

原文摘要 · Abstract (English)

As artificial intelligence (AI) becomes deeply embedded in critical services and everyday products, it is increasingly exposed to security threats which traditional cyber defenses were not designed to handle. In this paper, we investigate how cyber threat intelligence (CTI) may evolve to address attacks that target AI systems. We first analyze the assumptions and workflows of conventional threat intelligence with the needs of AI-focused defense, highlighting AI-specific assets and vulnerabilities. We then review and organize the current landscape of AI security knowledge. Based on this, we outline what an AI-oriented threat intelligence knowledge base should contain, describing concrete indicators of compromise (IoC) for different AI supply-chain phases and artifacts, and showing how such a knowledge base could support security tools. Finally, we discuss techniques for measuring similarity between collected indicators and newly observed AI artifacts. The review reveals gaps and quality issues in existing resources and identifies potential future research directions toward a practical threat intelligence framework tailored to AI.

威胁情报AI安全供应链

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。