arXiv:2605.23448cs.CRcs.AI2026-05

AI安全研究偏重攻击,应激励更多防御性工作。

AI Security Research Should Better Incentivize Defense Research

论文配图:AI Security Research Should Better Incentivize Defense Research
图 1 · 摘自论文原文
  • 分析发现各子领域攻击论文远多于防御论文。
  • 攻击评估条件宽松,防御标准过高导致难落地。
  • 适合关注安全实践与研究导向的学者阅读。

本研究考察了人工智能安全领域的不平衡现象:该领域产出的攻击类研究远多于防御类研究。基于相关学术论文分析,发现联邦学习、语音识别、成员推断、大语言模型等多个子领域均存在攻击与防御论文比例失衡。这种失衡不仅体现在数量上,更深层在于:攻击研究通常在理想条件下评估,使威胁显得比实际更严重;而防御方法则面临更严格的标准,极少能达标。结果是文献中充斥着可演示的漏洞,却缺乏可用且可部署的防护方案。因此,我们主张应调整机制,更好激励防御性研究。

原文摘要 · Abstract (English)

This work examines an imbalance in artificial intelligence (AI) security research: the field tends to produce more work on attacking AI systems than on defending them. Drawing on related academic papers, we find biased attack-to-defense ratios across subfields, including federated learning, speech recognition, membership inference, large language models, etc. The imbalance possibly means far beyond a simple count: attack papers are routinely evaluated under favorable conditions that make threats look more severe than they are in practice, while defenses are held to a stricter standard that few can meet. The result is a literature rich in demonstrated vulnerabilities and thin on usable and deployed protections. We thus argue that AI security research should better incentivize defense research.

AI安全研究激励防御研究

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。