arXiv:2607.13718cs.CRcs.AI2026-07被引 3

研究用户如何控制AI代理的权限,提出权限管理新框架。

How Agents Ask for Permission: User Permissions for AI Agents, from Interfaces to Enforcement

论文配图:How Agents Ask for Permission: User Permissions for AI Agents, from Interfaces to Enforcement
图 1 · 摘自论文原文
  • 构建用户级权限管理的分类体系,涵盖界面与内部策略
  • 分析5个主流代理的权限机制,发现与学术方案存在差距
  • 为个性化安全防护提供可落地的参考,适合开发者与设计者

随着AI代理日益普及,用户面临越来越多风险,如提示注入攻击和幻觉导致隐私泄露,以及未经许可执行敏感操作(如银行交易)。尽管学术界已提出多种安全代理系统方案,但多数集中于产品级统一策略。本文调研21项权限系统提案,构建用户级权限管理的分类体系,涵盖界面设计、用户输入推导策略及运行时执行机制。进一步对比分析5个主流商业代理的权限处理方式,揭示其与学术研究之间的共性与差异,并识别出多个未来研究方向,为实现更灵活、个性化的代理安全机制提供基础。

原文摘要 · Abstract (English)

As AI agents gain prevalence, users are increasingly exposed to the risks such systems entail. Prompt injection attacks, as well as hallucination, can cause agents to leak private information to third parties. As autonomous systems, agents also present the more active danger of performing sensitive tasks, such as bank transactions, without the user's intent or authorization. Recognizing this challenge, the agentic security community has developed numerous proposals for secure agentic systems. Much of this work has focused on product-level approaches, where agentic system developers determine and apply the same security policies and permissions to all users. Yet different users have different needs and preferences, necessitating support for user-level permissions policies in agentic AI systems. To understand how user-level permissions are handled in AI agent systems, we survey 21 proposals for agent permissions systems. From this review, we construct a taxonomy of how different systems specify user-level permissions policies, both at the user interface and internally; derive internal policies from user input; and enforce those policies at run-time. We then analyze five prominent commercial agents and compare their permissions handling to agentic permissions systems in the literature. We identify several high-level themes across the literature and commercial agents, as well as multiple gaps where future work is needed.

AI安全权限管理用户控制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。