arXiv:2603.09002cs.CRcs.AI2026-03被引 5

首次系统评估16个AI安全框架在多智能体系统中的覆盖效果,揭示关键漏洞短板。

Security Considerations for Multi-agent Systems

  • 构建多智能体架构知识库,用生成式AI辅助识别9类193项安全威胁
  • 16个框架平均分仅2分(满分3),非确定性与数据泄露问题最被忽视
  • OWASP和CDAO工具包表现领先,分别擅长设计与开发运维阶段

多智能体系统(MAS)由具备工具授权、共享持久记忆并相互通信的自主代理组成,其安全风险与单一AI模型有本质区别。现有安全与治理框架未针对此类新兴攻击面设计。本研究系统刻画了MAS的威胁图景,并对16个AI安全框架进行了量化评估。采用四阶段方法:构建生产级多智能体架构深度知识库;利用生成式AI辅助进行聚焦于MAS网络安全风险的威胁建模,并经领域专家验证;在单个威胁粒度上制定调查计划;以三档评分制评估各框架对网络安全风险的应对情况。共识别出9类193项独立威胁。预期最低平均分为2分,无一框架在任一类别中实现多数覆盖。非确定性(均分1.231)和数据泄露(均分1.340)是关注度最低的领域。OWASP Agentic Security Initiative总体表现最佳,覆盖率达65.3%,在设计阶段领先;CDAO生成式AI负责任AI工具包在开发与运营阶段表现最优。研究首次提供跨框架的实证比较,为框架选型提供基于证据的指导。

原文摘要 · Abstract (English)

Multi-agent artificial intelligence systems or MAS are systems of autonomous agents that exercise delegated tool authority, share persistent memory, and coordinate via inter-agent communication. MAS introduces qualitatively distinct security vulnerabilities from those documented for singular AI models. Existing security and governance frameworks were not designed for these emerging attack surfaces. This study systematically characterizes the threat landscape of MAS and quantitatively evaluates 16 security frameworks for AI against it. A four-phase methodology is proposed: constructing a deep technical knowledge base of production multi-agent architectures; conducting generative AI-assisted threat modeling scoped to MAS cybersecurity risks and validated by domain experts; structuring survey plans at individual-threat granularity; and scoring each framework on a three-point scale against the cybersecurity risks. The risks were organized into 193 distinct main threat items across nine risk categories. The expected minimal average score is 2. No reviewed framework achieves majority coverage of any single category. Non-Determinism (mean score 1.231 across all 16 frameworks) and Data Leakage (1.340) are the most under-addressed domains. The OWASP Agentic Security Initiative leads overall at 65.3\% coverage and in the design phase; the CDAO Generative AI Responsible AI Toolkit leads in development and operational coverage. These results provide the first empirical cross-framework comparison for MAS security and offer evidence-based guidance for framework selection. Please check back for information on the published journal version.

多智能体安全评估威胁建模框架对比

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。