arXiv:2607.01510cs.AIcs.CR2026-07被引 2

提出用户参与式智能体权限管理框架,提升安全与隐私。

Janus: a Playground for User-Involved Agentic Permission Management

  • 构建模块化系统支持多种用户参与权限设计
  • 实验证明用户输入显著增强安全与隐私保护
  • 强调需考虑用户疲劳,适合安全敏感场景

自主执行工具调用的AI智能体引发权限管理挑战:用户应扮演何种角色?尽管已有多种方案,用户在智能体权限管理中的作用仍研究不足。本文提出Janus,一个用于实现与评估用户参与式权限管理设计的实验平台,包含支持多样化设计的Janus-Core和自动化评估框架Janus-Harness。基于用户参与的设计轴心模型,我们实现了六种权限助手,并在三个场景与三种合成响应者下进行评估。结果表明:用户输入对隐私与安全至关重要;AI辅助可减轻认知负担;真实用户行为(如权限疲劳)必须纳入系统设计。单一设计无法在所有情境下最优,推动更严谨、情境敏感的权限助手部署策略。Janus已开源,支持未来相关研究。

原文摘要 · Abstract (English)

AI agents that autonomously execute tool calls on a user's behalf raise pressing questions about permission management: what role could users play, and what role should they play? Despite many proposed approaches, the user's role in agentic permission management remains under explored. We introduce Janus, a playground system for implementing and evaluating user-involved agentic permission management designs. Janus consists of two components: Janus-Core, a modular agentic system supporting a diverse spectrum of permission management designs, and Janus-Harness, an automated evaluation framework. Grounded in a conceptual model that identifies key design axes for user involvement, we implement six permission assistants spanning the design space and evaluate them across three scenarios and three synthetic responders. We demonstrate that user input is critical and can significantly strengthen privacy and security, that AI augmentation of user decisions can help reduce cognitive load, and that realistic user behavior including permission fatigue must be accounted for in system design. No single design performs optimally across all contexts, motivating a more principled and context-sensitive approach to deploying permission assistants in agentic systems. Janus is publicly available to support future investigation into this dimension of agentic system design.

智能体权限管理用户参与安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。