为智能代理系统构建风险建模框架,评估攻击面与实际威胁的关联。
MATRA: Modeling the Attack Surface of Agentic AI Systems -- OpenClaw Case Study

- 基于资产影响评估与攻击树,系统化分析代理系统的潜在风险。
- 实证显示网络沙箱和最小权限可降低攻击扩散范围,风险下降显著。
- 适合安全研究人员、部署者用于评估智能代理的安全控制效果。
大型语言模型正越来越多地作为具备工具、数据库和外部服务访问权限的自主代理部署,但各领域从业者仍缺乏系统方法来评估已知威胁类别如何转化为特定部署中的具体风险。我们提出MATRA,一种针对智能代理系统的实用威胁建模框架,将成熟的风控方法适配至智能代理场景,系统性地评估已知LLM威胁在特定架构中的风险转化。MATRA从资产影响评估出发,利用攻击树分析这些影响在系统架构中发生的可能性。我们在使用OpenClaw的个人智能代理部署中验证了MATRA,量化表明网络沙箱与最小权限机制能有效限制注入攻击的扩散范围,显著降低整体风险。
原文摘要 · Abstract (English)
LLMs are increasingly deployed as autonomous agents with access to tools, databases, and external services, yet practitioners (across different sectors) lack systematic methods to assess how known threat classes translate into concrete risks within a specific agentic deployment. We present MATRA, a pragmatic threat modeling framework for agentic AI systems that adapts established risk assessment methodology to systematically assess how known LLM threats translate into deployment-specific risks. MATRA begins with an asset-based impact assessment and utilizes attack trees to determine the likelihood of these impacts occurring within the system architecture. We demonstrate MATRA on a personal AI agent deployment using OpenClaw, quantifying how architectural controls such as network sandboxing and least-privilege access reduce risk by limiting the blast radius of successful injections.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。