从对齐到访问控制:GenAI 政策执行框架
From Alignment to Access Control: A Framework for GenAI Policy Enforcement
安全圈值得看:这篇论文把 GenAI 里各家混乱的 policy 执行方案拆开对比,还给了统一分析框架。
arXiv 论文系统梳理了生成式 AI 应用中政策定义与执行的现状,指出安全机制发展滞后已导致真实事故。作者提出一套方法来拆解分析业界现有的政策执行方案,并区分了不同从业者对 policy 的理解差异。论文是 Nathalie Baracaldo 在 USENIX Security 2026 Enigma 演讲的扩展,最终给出了面向社区的建议与行动号召。
From Alignment to Access Control: A Framework for GenAI Policy Enforcement
Generative AI (GenAI) applications have flourished enabling users to chat with large language models, and to create agents to act on their behalf for a variety of tasks. The pace of development of capabilities in this field is incredibly fast with security and safety taking a back seat. Unfortunately, the slower pace at which security and safety mechanisms have evolved has led to real incidents. Policy enables the definition of desirable behavior of applications, and for that reason, it is a cornerstone of making systems secure and compliant. Policy however means different things to different practitioners creating confusion and siloed solutions that are not adequate for compliance. This paper takes a tour of the good, the bad and the ugly when it comes to policy enforcement in GenAI applications. We propose a methodology to systematically analyze and dissect existing approaches to define and enforce policy found in the wild. Based on this principled analysis, we provide recommendations and call for action for the community to address. This paper is a companion extension of USENIX Security 2026 Enigma talk titled "From Alignment to Access Control: A Unified View of GenAI Policy Enforcement" by the author Nathalie Baracaldo.