LLM代理在高性能计算中易被劫持,导致合法账号执行恶意操作。
Trusted Credentials, Untrusted Behavior: Benchmarking LLM-Agent Security in High-Performance Computing
- 提出HPC环境下代理被劫持的威胁模型
- 发现调度系统、共享存储等是主要攻击面
- 适合关注AI安全与科研系统防护的研究者
大型语言模型(LLM)代理正开始承担高性能计算(HPC)中的常规任务,如监控Slurm作业、诊断失败构建、检查模拟输出和协调科学工作流。为完成这些任务,代理通常以用户凭证运行,并继承用户的文件和调度器访问权限。这种安排引入了一种传统账户级控制无法捕捉的故障模式:日志、工具描述、共享文件或同行代理消息中的恶意指令,可将代理引导至超出用户原定任务的行动,尽管所有执行命令均经认证且对账户合法。我们称此为“被劫持的授权代理问题”。现有研究虽解释了间接提示注入和工具滥用等机制,但多在网页、企业或个人助理场景下评估。而HPC虽有成熟的身份与隔离控制,却通常不体现特定任务意图。本文定义了HPC场景下的威胁模型,识别出调度器、共享存储、多项目账户和科学工作流带来的攻击面,并分析现有控制的不足。最后提出研究议程与实证基准计划TaskBound。
原文摘要 · Abstract (English)
Large language model (LLM) agents are starting to take on routine work in high-performance computing (HPC), including monitoring Slurm jobs, diagnosing failed builds, inspecting simulation output, and coordinating scientific workflows. To do this work, an agent commonly acts under its user's credentials and inherits the user's access to files and the scheduler. This arrangement creates a failure mode that ordinary account-level controls do not capture. Adversarial instructions in a log, tool description, shared file, or peer-agent message may redirect the agent beyond the task the user assigned, even though every resulting command is authenticated and permitted for that account. We refer to this as the hijacked authorized agent problem. Existing agent-security studies explain relevant mechanisms, such as indirect prompt injection and tool misuse, but generally evaluate them in web, enterprise, or personal-assistant settings. HPC security, by contrast, has mature controls for identity and isolation but does not ordinarily represent the intent of a particular task. This paper defines the threat model in the HPC setting, identifies attack surfaces created by schedulers, shared storage, multi-project accounts, and scientific workflows, and examines where current controls fall short. It concludes with a research agenda and a plan for an empirical benchmark, TaskBound.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。