arXiv:2606.08661cs.CRcs.AI2026-06被引 1

研究大模型驱动的数据代理系统安全漏洞,发现多个关键风险。

Data Agents Under Attack: Vulnerabilities in LLM-Driven Analytical Systems

论文配图:Data Agents Under Attack: Vulnerabilities in LLM-Driven Analytical Systems
图 1 · 摘自论文原文
  • 构建分层漏洞框架,识别数据代理中的八大风险
  • 实测六套系统,发现普遍存在严重安全隐患
  • 适合关注AI系统安全的开发者与企业安全团队

数据代理将大模型推理、关系型数据访问、可执行分析工具与多步工作流编排相结合,正日益成为企业数据分析的核心。这种融合引入了跨数据资源、数据库执行和代理推理的新安全漏洞,重新组合了数据库安全与通用大模型代理安全中的问题,形成了单一领域无法覆盖的失效模式。为填补这一空白,我们开展数据代理系统的系统性安全研究。贡献包括:首先,提出一个分层漏洞框架,识别出解释、执行和策略三层共八类数据代理特有风险;其次,构建基于攻击者目标、战术与技术的攻击分类体系,涵盖三大目标、七种战术与十四种技术,并配套基于真实数据库模式的LLM驱动载荷生成流水线;最后,在六套系统上评估攻击效果,包含四款开源数据代理与两款生产级云分析服务。实验揭示当前系统存在广泛的安全缺陷,并得出四项关键结论。

原文摘要 · Abstract (English)

Data agents integrate LLM-driven reasoning with relational data access, executable analytical tools, and multi-step workflow orchestration, making them increasingly central to enterprise analytics. This integration introduces new security vulnerabilities across data resources, database execution, and agent reasoning, recombining concerns from database security and general-purpose LLM-agent security into failure modes that neither line of work captures on its own. To address this gap, we present a systematic security study of data agents. Our contributions are threefold. First, we develop a layered vulnerability framework that identifies eight data agent-specific risks across interpretation, execution, and policy layers. Second, we introduce an attack taxonomy organized by adversary goal, tactic, and technique, covering three goals, seven tactics, and fourteen techniques, and pair it with an LLM-driven payload generation pipeline grounded in real database schemas. Third, we evaluate these attacks on six systems, including four open-source data agents and two production cloud analytics services. Our experiments reveal substantial security vulnerabilities across current systems and yield four key takeaways.

数据安全大模型安全智能代理

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。