arXiv:2603.18197cs.AIcs.CR2026-03被引 1

为代理型AI设计细粒度网站访问控制机制,保障关键任务安全委托。

Access Controlled Website Interaction for Agentic AI with Delegated Critical Tasks

  • 基于网站设计与授权协议改造,实现对AI代理的细粒度访问控制。
  • 评估验证了该机制在支持代理型AI执行关键任务时的有效性。
  • 适合关注AI代理安全交互与权限管理的研究者与开发者。

近期研究表明,当代理型AI代表用户访问网站时,存在关键任务委托的漏洞,主要源于网站缺乏针对代理型AI的访问控制机制。为此,我们提出一种面向代理型AI的网站交互设计,支持对委托关键任务的细粒度访问控制。该方法包括网站设计与实现,以及对开源授权服务中访问授权协议的修改,以适配代理型AI的使用场景。评估结果表明,所提出的受控网站能够有效支持AI代理完成关键任务,具备良好的可用性与安全性。

原文摘要 · Abstract (English)

Recent studies reveal gaps in delegating critical tasks to agentic AI that accesses websites on the user's behalf, primarily due to limited access control mechanisms on websites designed for agentic AI. In response, we propose a design of website-based interaction for AI agents with fine-grained access control for delegated critical tasks. Our approach encompasses a website design and implementation, as well as modifications to the access grant protocols in an open-source authorization service to tailor it to agentic AI, with delegated critical tasks on the website. The evaluation of our approach demonstrates the capabilities of our access-controlled website used by AI agents.

AI代理访问控制网站交互

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。