ai.hackcv
论文精选 60arXiv

Dynamic Capability Scoping for Enterprise AI Agents: A Synthetic Dataset and Three-Source Permission Architecture· 企业 AI 代理的动态能力范围

Enterprise AI agents are typically granted static credential sets at configuration time, holding every tool the role might need for every task they perform. This persistent over-privilege expands the attack surface. We argue that capability scoping must follow a dynamic least-privilege principle and be treated as a prevention mechanism before a detection one. A credential that does not exist in an agent's context cannot be misused regardless of the agent's reasoning or evasion sophistication. We outline a three-source architecture instantiating this principle: role-based ceilings, a task-context classifier, and policy-derived combination prohibitions creating a layered proactive defense against LLM agent misalignment and misuse cases. The architecture supports both enforcing and observe-on

AI 解读论文

提出企业 AI 代理动态最小权限原则和三源权限架构

核心方法
设计三源架构:基于角色的上限、任务上下文分类器和政策衍生的组合限制,实现动态能力范围
适合谁读
研究者 / 工程师
要解决的问题
企业 AI 代理在配置时通常被赋予静态的权限集,导致过度授权和攻击面扩大
关键实验
未提供
主要贡献
提出了一种新的动态最小权限架构,有效减少 AI 代理的攻击面
意义与局限
此架构对于提高企业 AI 安全性有重要意义,但需要进一步实验验证其效果和实际可行性
领域:cs.AI作者:Halil Burak Noyan
相关推荐

本站内容由 LLM 精选聚合,原文版权归 arXiv 所有 · 摘录仅供参考