LLM在运维中越权,安全如何保障?
Large Language Models for Agentic NetOps and AIOps: Architectures, Evaluation, and Safety

- 构建运维操作保证契约,分级管控模型权限与证据要求
- 配置变更等高风险操作缺乏完整证据链,存在安全缺口
- 适合关注AI运维安全、系统可信控制的研究者与工程师
大型语言模型(LLMs)正被广泛用于网络运维(NetOps)和智能IT运维(AIOps),涵盖遥测数据获取、故障诊断、配置规划及受控修复等任务。随着模型获得更高操作权限,核心问题已从‘能做什么’转向‘是否可信赖’。本综述通过结构化、证据分层的分析,围绕自主性、工具范围、证据追溯、保障控制、评估、安全与治理展开。提出一种操作保证契约,将每个自主等级对应允许的工具、必要证据、独立验证门禁、执行预算、部署回滚责任及审计要求。研究发现:读取辅助与工具驱动诊断有较强证据支持,但接近配置变更、受限执行和闭环运行时,证据完整性显著下降。因此主张评估应从静态问答转向工作流级评估,涵盖证据质量、工具使用、策略与不变量合规、分阶段执行、恢复能力、校准、成本及人工干预。同时分析了提示攻击、污染或过期证据、过度自主、权限边界模糊及审计薄弱等问题。综上,智能运维本质是受控的操作控制,真正的可靠性依赖独立保障机制而非模型能力本身。
原文摘要 · Abstract (English)
Large language models (LLMs) are increasingly being used in network operations (NetOps) and artificial intelligence for IT operations (AIOps) for tasks ranging from telemetry retrieval and incident diagnosis to configuration planning and bounded remediation. As these systems acquire greater access to operational tools, the central question is no longer only what an LLM can do, but whether operational assurance increases commensurately with the authority granted to it. This survey examines that question through a structured, evidence-stratified review of agentic NetOps and AIOps. We organise the field around autonomy, tool scope, evidence traces, assurance controls, evaluation, security, and governance, and introduce an operational assurance contract that links each autonomy level to permitted tools, required evidence, independent gates, execution budgets, rollout and rollback duties, and audit requirements. The synthesis reveals a capability--assurance gap: evidence is comparatively strong for read-oriented assistance and tool-grounded diagnosis, but becomes substantially less complete as systems approach configuration change, bounded execution, and closed-loop operation. We therefore argue that evaluation should move beyond static question answering and model accuracy towards workflow-level assessment of evidence quality, tool use, policy and invariant compliance, staged execution, recovery, calibration, cost, and human intervention. We also examine prompt-borne attacks, poisoned or stale operational evidence, excessive agency, privilege boundaries, and weak auditability. Taken together, the survey frames agentic NetOps and AIOps as constrained operational control, in which useful autonomy depends on independently enforced assurance rather than model capability alone.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。