arXiv:2605.09721cs.CRcs.AI2026-05中稿 · as a short paper a…

分析云上智能体的权限风险,揭示安全漏洞根源

Security Risks in Tool-Enabled AI Agents: A Systematic Analysis of Privileged Execution Environments

论文配图:Security Risks in Tool-Enabled AI Agents: A Systematic Analysis of Privileged Execution Environments
图 1 · 摘自论文原文
  • 构建风险分类体系,识别权限滥用等三类核心问题
  • 实验证明轻量防护可降低风险,但无法根治权限过度分配
  • 适合关注AI系统安全的开发者与云平台设计者

工具增强型AI智能体正越来越多地部署在云端执行环境,通过具有特权的工具执行有副作用的操作。尽管这类智能体实现了强大自动化,但其在特权环境中运行的安全隐患尚未充分研究。本文提出对云托管智能体安全风险的系统性分析,构建风险类别分类体系,通过三个典型智能体场景展示风险表现,并讨论缓解策略及其权衡。小规模可控实验验证了风险的显现及轻量缓解措施的效果。分析表明,多数自主云智能体的风险并非源于新型漏洞,而是由于工具权限过度、能力与意图不匹配,以及执行环境中的隐性权限泄露。基于此,我们提出了实际可行的设计指南,以更安全地部署云端智能体。

原文摘要 · Abstract (English)

Tool-enabled AI agents are increasingly deployed in cloud-hosted environments and offered as services, where they perform side-effecting operations through privileged tools within execution environments. While such agents enable powerful automation, the security implications of hosting autonomous agents in privileged execution environments are not yet fully explored. This paper presents a structured analysis of security risks associated with cloud-hosted AI agents. We introduce a taxonomy of risk categories, illustrate these risks through three representative agent scenarios, and discuss mitigation strategies along with their tradeoffs. A small controlled experiment empirically illustrates risk manifestation and the effect of lightweight mitigations in this setup. Our analysis suggests that many risks in autonomous cloud agents arise not from novel vulnerabilities, but from over-privileged tools, capability-intent mismatches, and ambient authority leakage in execution environments. Based on these findings, we derive practical design guidelines for deploying AI agents in the cloud more securely.

AI安全云智能体权限控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。