论文

论文基于23位专家意见定义AI Agent安全事件报告要素

Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents

精选理由

Agent出了安全事故该报什么?23位专家把清单列好了,做Agent治理可以直接对照。

一篇arXiv论文研究AI Agent安全事件应报告哪些信息,作者先对比了AI系统与AI Agent的特性差异。研究汇总23位学术界与产业界专家的意见,提出报告要素应包含Agent的记忆及访问记录、实际与潜在自主程度、工具使用情况。论文列出的开放问题包括如何高效记录事件、如何判断漏洞是否会跨系统泛化。专家还提醒报告机制自身存在数据泄漏和被攻击的风险,论文相应归纳了隐私要求与应对方向。

原文 · arXiv cs.AI

Beyond Predictable Paths: Redefining AI Security Incident Reporting for Agents

AI agents are being deployed rapidly, accompanied by a growing number of AI-specific attacks and corresponding incidents. As incident reporting becomes increasingly important for legal compliance, governance, accountability, and security; current frameworks must be adapted to the unique characteristics of AI agents. In this paper, two editorial authors compare AI systems and AI agents and, drawing on input from 23 experts in academia and industry, identify the information required for reporting incidents where the security of AI agents is harmed. %involving AI agents. Potential reporting elements include, for example, agent memory and memory accesses, actual and potential levels of autonomy, and tool usage. Based on these findings, we identify several open research questions, including how to efficiently record incidents and how to determine whether vulnerabilities and incidents generalize. Expert feedback also highlighted potential reporting weaknesses, such as risks of data leakage and attacks targeting the reporting infrastructure itself, creating additional research needs. Lastly, we summarize privacy requirements and outline research directions for the secure and trustworthy deployment of AI agents.