arXiv:2606.28450cs.CRcs.AI2026-06综述被引 1

梳理大模型智能体在自保与赋能安全中的双重角色,揭示其协同增效潜力。

LLM agents security duality: a comprehensive survey of self-security and empowered cybersecurity

论文配图:LLM agents security duality: a comprehensive survey of self-security and empowered cybersecurity
图 1 · 摘自论文原文
  • 从内外攻击面出发,构建智能体安全威胁分类体系。
  • 提出首个覆盖攻防全周期的智能体赋能安全框架。
  • 发现自保能力与安全赋能间存在正向协同效应,适合安全研究者参考。

大型语言模型(LLM)智能体正快速融入现实系统,其自主性与工具使用能力带来巨大价值,同时扩展了安全攻击面。本综述全面探讨了智能体在安全领域的机遇与挑战,聚焦两大核心方向:(1) 智能体自身面临的安全威胁及应对策略(自保安全),(2) 智能体在攻防全生命周期中赋能网络安全的能力(赋能安全)。首先分析智能体的内外攻击面,按威胁来源构建分类体系,评估缓解措施与评估框架;随后考察智能体能力在实际安全实践中的应用,首次提出与完整攻防生命周期对齐的智能体赋能框架。通过系统性调研这两方面,我们首次揭示智能体自保安全与赋能安全之间的正向反馈协同效应,为两者协同发展提供新洞见。进一步指出当前局限,并展望未来研究方向。研究成果旨在推动智能体自保与赋能安全的协同演进,促进更强大、更稳健的智能体应用落地。

原文摘要 · Abstract (English)

Large language model (LLM) agents are rapidly being integrated into real-world systems. Their autonomy and tool-use capabilities generate substantial value while simultaneously expanding the security attack surface. This survey provides a comprehensive overview of the opportunities and challenges of LLM agents in security, focusing on two core areas: (1) threats to LLM agents themselves and corresponding mitigation strategies (LLM agents self-security), and (2) the role of LLM agents in empowering the cybersecurity lifecycle across offense and defense (LLM agents empowered cybersecurity). We first examine the internal and external attack surfaces of agents, propose a taxonomy organized by threat sources, and analyze associated mitigations and evaluation frameworks. We then investigate how agent capabilities are applied in cybersecurity practice and present, to our knowledge, the first agent-empowerment framework aligned with the full cyber offense-defense lifecycle. By systematically surveying these two areas, we are the first to highlight a positive feedback synergy between LLM agents self-security and empowered cybersecurity, offering new insights for the advancement of both. We further identify current limitations and outline promising directions for future research. The insights provided aim to catalyze the coordinated development of LLM agents self-security and agent empowered cybersecurity, paving the way for more capable and robust agent applications.

大模型安全智能体攻防协同自保

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。