自主AI安全代理让攻击门槛降低,引发伦理难题。
The Ethics of Autonomous AI Agents for Offensive Security
- 用非确定性策略实现自动化渗透,难以追溯行为原因。
- 攻击影响不可控,且使用者技能要求大幅下降。
- 现有伦理框架难应对,需分层制定责任规范。
LLM驱动的自主安全代理正在重塑进攻性安全领域。与传统渗透测试工具(确定性、范围狭窄、依赖专业人员)不同,这类代理在三个独立维度上表现出不确定性:第一,其行为由非确定性策略生成,既无法提前也无法事后解释,导致事件溯源困难,预部署安全审查受阻;第二,由于行为不可预测、模型具备自主性以及大模型供应链不透明,其影响范围开放且不可控;第三,用户群体规模与技能要求均不确定,使用或开发攻击能力的技能门槛急剧下降。这三个特性虽主题相关但彼此独立,结合攻防成本结构失衡,推动了进攻能力的工业化。短期效应有利于攻击方,尽管长期可能促进防御技术普及。现有双重用途网络安全与人工智能伦理框架难以应对此组合。本文分析了在使用自主AI代理进行进攻安全时,道德责任在用户、开发者和第三方间的分散问题,并评估各方利益影响,提出分层建议。
原文摘要 · Abstract (English)
LLM-driven autonomous agents are reshaping offensive security. Unlike traditional penetration-testing tooling - deterministic, narrowly scoped, and operated by trained practitioners - agentic security tools exhibit indeterminacy along three independent dimensions. First, their actions are drawn from a non-deterministic policy whose outputs resist both ex-ante and ex-post explanation. This complicates incident attribution and pre-deployment safety reviews. Second, their impact is open-ended due to their non-deterministic actions, agency of utilized models, and opaque LLM supply-chains. Third, their user population is indeterminate in both size and required skill: the operating skill floor for using or developing offensive capabilities has dropped sharply. These three properties are linked thematically, but are not derivable from one another. Combined with the structural cost asymmetry between offense and defense, they enable the industrialization of offensive capability. The net short-term effect favors attackers, even if the same technology may, in the long run, democratize access to defensive practice. Existing dual-use cybersecurity and AI-ethics frameworks struggle to address this combination. Our work analyzes how moral attribution becomes diffuse between users, tool-makers, and third parties when employing autonomous AI agents for offensive security. We also examine the stakeholder impact of this technology and provide stratified recommendations.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。