为大模型系统设计安全导向的全生命周期管理框架
A Security-Oriented Lifecycle Model for Large Language Model Systems

- 按安全边界划分32个阶段,覆盖数据到应用全流程
- 发现监管证据集中于部署阶段,关键决策却在开发阶段
- 适合大模型安全治理、合规团队参考
大语言模型正以空前规模融入关键基础设施和企业流程,但其生命周期框架原为提升效率而设,缺乏对安全活动的明确支持。数据溯源验证、产物签名、智能体权限控制、系统退役等关键安全行为常被隐含处理。现有治理框架按风险等级或管理流程组织要求,未清晰关联具体生命周期阶段。本文提出一种以安全为中心的生命周期模型,涵盖数据、模型、分发、应用四层共32个阶段,辅以12阶段的LLMOps支柱和9类治理支柱。其中13个阶段被单独定义,因其暴露独特安全风险,现有框架未清晰区分。通过映射NIST AI RMF、欧盟《人工智能法案》和ISO/IEC 42001,发现当前监管格局存在结构性问题:治理证据集中在部署阶段(监管可见),而最关键的决策——数据选择、对齐策略与能力边界——均在开发阶段做出,监管可见度最低。
原文摘要 · Abstract (English)
Large language models are being integrated into critical infrastructure and enterprise workflows at unprecedented scale,yet the lifecycle frameworks governing their development and operations were designed for operational efficiency rather than security analysis. As a result, security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit or assumed to receive due care. Governance frameworks, in turn, organise requirements around risk levels or management processes without clearly linking them to the lifecycle stages where they apply. This paper addresses both deficiencies. We propose a lifecycle model for LLM systems that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation. The model comprises 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar. Thirteen stages are introduced here as separate units because they expose distinct security concerns that existing frameworks do not clearly distinguish. A governance mapping synthesising the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages, where systems are visible to regulators, while the most consequential decisions, data selection, alignment strategy, and capability boundaries, are made at development-facing stages, where regulatory visibility is lowest.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。