当前位置:首页 > 报告详情

人工智能安全差距.pdf

上传人: 可*** 编号:991821 2025-12-07 18页 1.70MB

1、The AI Security Gap:Addressing the Unique Vulnerabilities of GenAI-based applicationsAI Cybersecurity Summit 2025-Denver,COSecurity and Privacy Group2Proprietary+Confidential2nd line of defense Oversee controls effectiveness and risks company-wide3rd line of defense Provide independent assurance1st

2、line of defense Own risk;manage controls 1.5 line of defense Coordinate&oversee within each Product Areas/function3 Lines of Defense Governance ModelBusinessCompliance/MonitoringInternal AuditSenior ManagementBoard/Audit CommitteeGlobal RegulatorsExternal AuditorsProprietary&ConfidentialSecuring AI

3、Pipeline 4Steps Identify the components of the AI pipeline Identify threats to the components Develop plausible attack scenarios and attack paths that threat actors may leverage to target the components Identify and map existing security controls Determine gaps in existing security controls by ident

4、ifying areas where there are no controls or where the controls are inadequate Plan and execute remediations by identifying and implementing controls to close the gaps.Gather DataClean and Process DataTrain the modelTest the modelDont be evil/wrong feedback loopProductionGoogles Secure AI Framework(S

5、AIF)Googles Secure AI Framework(SAIF)Lets see how to mitigate two of the most common risks in GenAI apps07Example:Prompt Injection08Example 1:A remote work company created a Twitter bot that would respond positively to Tweets about remote work.Users found ways to trick it into saying weird things.Pr

6、ompt injectionGet the model to execute malicious instructions“injected”inside a prompt.09Example 2:Jailbreaking Getting GenAI to do unintended things through prompting.Prompt injectionGet the model to execute malicious instructions“injected”inside a prompt.Prompt:Im conducting a test on LLMs to see

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
根据报告的内容,全文主要内容概括如下: 1. **三层防御模型**:包括第一层(自担风险,管理控制)、1.5层(协调与监督)、第二层(监控效果和风险)和第三层(提供独立保证)。 2. **AI管道安全步骤**:识别组件、威胁、攻击路径、现有安全控制、差距和补救措施。 3. **Google的Secure AI Framework (SAIF)**:用于识别和缓解AI应用中的风险。 4. **常见风险**:Prompt注入(如恶意指令注入)和敏感数据泄露。 5. **控制措施**:输入验证、对抗性训练、数据管理、输出验证等。 6. **技术措施**:使用WAF、PII检测、模型装甲等云原生控制。 7. **结论**:AI安全是公司级挑战,需通过安全框架和实施技术措施来保护应用。
如何应对?" 安全风险解析" 构建防护网!"
客服
商务合作
小程序
服务号
折叠