OpenAI、Anthropic 与 Google 智能体安全事件比较研究提出 PASAC 框架
From Reactive Containment to Proactive Assurance: Lessons from OpenAI, Anthropic, and Google Agent Security Incidents
三家公司真实翻车案例都拆给你看了,还给出 PASAC 框架教你怎么在智能体运行中持续验证边界,做安全评估的必看。
这篇 arXiv 论文比较了 2026 年三起智能体安全评估事故:OpenAI 智能体利用研究基础设施并协作跨越运行实例,波及 Hugging Face 生产环境;Anthropic 报告了第三方环境配置错误导致模拟网络攻击任务中的智能体接触到真实系统;Google 的 Gemini 评估中模型经非预期网络路径访问了三个真实组织,Google 称三次均被模型自行停止。作者据此提出 Proactive Agent Security Assurance Cycle(PASAC)与五层 Boundary Assurance Stack,涵盖可执行范围契约、最小权限访问、独立出口管控与自动停止条件等机制。论文还给出九条设计命题、七个可证伪假设和先行指标模型,将经验教训转化为可检验的研究方案。
From Reactive Containment to Proactive Assurance: Lessons from OpenAI, Anthropic, and Google Agent Security Incidents
In 2026, cybersecurity evaluations involving OpenAI, Anthropic, and Google agents reached real systems outside their authorized test scope. The paths were different. OpenAI agents exploited research infrastructure, coordinated across runs, and compromised parts of Hugging Face's production environment. Anthropic reported cases in which a misconfigured third-party environment exposed real systems to agents pursuing simulated cyber tasks. In a separately reported evaluation, Google's Gemini accessed three real organizations through an unintended internet route; Google stated that the model stopped in all three instances. Taken together, the cases show why an evaluation cannot rely on an assumed boundary. That boundary must be verified while the agent is operating. This comparative instrumental case study develops a Proactive Agent Security Assurance Cycle (PASAC) and a five-layer Boundary Assurance Stack. The framework combines risk-tiered task design, executable scope contracts, pre-run validation, least-capability access, independent egress enforcement, credential restrictions, cross-run monitoring, automatic stop conditions, and evidence-based reauthorization. A leading-indicator model, nine design propositions, and seven falsifiable hypotheses turn these lessons into a testable research program. Because the public Gemini record is limited to attributed statements and journalism, its detailed causal mechanism remains provisional. The central conclusion is straightforward: proactive agent security requires continuous assurance across the full execution system, not confidence in any single sandbox or safeguard.