arXiv:2604.06148cs.CRcs.AI2026-04被引 2

为失控的机器身份建立治理框架,防范企业与国家级攻击风险

Who Governs the Machine? A Machine Identity Governance Taxonomy (MIGT) for AI Systems Operating Across Enterprise and Geopolitical Boundaries

  • 构建六域协同的MIGT治理框架,覆盖技术、合规与跨境协调
  • 揭示80:1的机器身份占比及2024年CrowdStrike事件超50亿美元损失
  • 针对丝路台风等黑客组织提供针对性防御策略,适合安全架构师参考

人工智能治理存在盲区:AI系统使用的机器身份缺乏管控。当前企业环境中自动化代理、服务账号、API密钥和工作流数量已超过人类身份80倍以上,却无统一治理框架。单个未受控的自动化代理在2024年CrowdStrike事件中造成54亿至100亿美元损失;包括丝路台风(Silk Typhoon)和盐台风(Salt Typhoon)在内的国家行为体已将未受控的机器凭证作为关键基础设施的主要间谍手段。本文提出四项原创贡献:第一,构建AI-身份风险分类法(AIRT),涵盖8个领域共37类风险子项,基于真实事件、监管认可、实践数据与威胁情报;第二,提出集成式机器身份治理框架(MIGT),同步解决技术治理、合规缺口与跨司法管辖区协调难题;第三,建立外国国家行为体威胁模型,证实丝路台风、盐台风、伏特台风(Volt Typhoon)及朝鲜的AI增强身份欺诈已实际利用AI身份漏洞实施攻击;第四,映射欧盟、美国与中国框架下的企业治理义务,识别不可调和冲突并提供管理机制。提供四阶段实施路线图,推动MIGT落地。

原文摘要 · Abstract (English)

The governance of artificial intelligence has a blind spot: the machine identities that AI systems use to act. AI agents, service accounts, API tokens, and automated workflows now outnumber human identities in enterprise environments by ratios exceeding 80 to 1, yet no integrated framework exists to govern them. A single ungoverned automated agent produced $5.4-10 billion in losses in the 2024 CrowdStrike outage; nation-state actors including Silk Typhoon and Salt Typhoon have operationalized ungoverned machine credentials as primary espionage vectors against critical infrastructure. This paper makes four original contributions. First, the AI-Identity Risk Taxonomy (AIRT): a comprehensive enumeration of 37 risk sub-categories across eight domains, each grounded in documented incidents, regulatory recognition, practitioner prevalence data, and threat intelligence. Second, the Machine Identity Governance Taxonomy (MIGT): an integrated six-domain governance framework simultaneously addressing the technical governance gap, the regulatory compliance gap, and the cross-jurisdictional coordination gap that existing frameworks address only in isolation. Third, a foreign state actor threat model for enterprise identity governance, establishing that Silk Typhoon, Salt Typhoon, Volt Typhoon, and North Korean AI-enhanced identity fraud operations have already operationalized AI identity vulnerabilities as active attack vectors. Fourth, a cross-jurisdictional regulatory alignment structure mapping enterprise AI identity governance obligations under EU, US, and Chinese frameworks simultaneously, identifying irreconcilable conflicts and providing a governance mechanism for managing them. A four-phase implementation roadmap translates the MIGT into actionable enterprise programs.

AI治理身份安全跨境合规威胁建模

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。