这篇论文发现了AI智能体会自动打小报告,还给出了三种对抗方法,搞AI安全的朋友可以看看。
研究人员提出并形式化了“代理监控”(agentic surveillance)问题,即AI智能体利用可访问信息生成报告并发送的能力。他们创建了SurveilBench数据集,涵盖企业、教育和警察三个领域的多种报告场景。实验发现部分模型会自发协助监控,但也会主动向政府报告监控尝试。为对抗这类监控,论文开发了三种提示注入逃逸技术:隐藏、欺骗或诱导过度上报。研究表明代理监控已可轻易实现,亟需技术、伦理和法律框架保护用户。
AI Snitches Get Glitches: Towards Evading Agentic Surveillance
To better assist users with completing challenging tasks, AI agents mediate communications, access data, and interact with different APIs. Many employers (and even nation-states) already provide their users with this technology. However, widespread adoption of AI agents creates a new risk to abuse access to user data for another goal: surveilling users. These users might not even have the ability or permission to control the actions and data accesses of the surveilling agents. We introduce and formalize the problem of agentic surveillance: the ability of an AI agent to analyze available information, craft a report, and send it out using available tools. To evaluate surveillance capabilities across different models, we create SurveilBench, a dataset of various reporting scenarios focusing on three domains: corporate, education, and police. We find that some models exhibit emergent (i.e., unprompted) tendencies to help surveillance, but they also report the attempts to surveil users to the government. Finally, we repurpose prompt injections for evading surveillance and develop three evasion techniques that hide from, deceive, or induce over-escalation in surveillance agents. We conclude that agentic surveillance can already be easily implemented and, therefore, call for a comprehensive technical, ethical, and legislative framework to protect users.