Datadog安全老大聊怎么防AI智能体乱来,讲了奖励黑客和意图判断,搞安全的都该看看。
Datadog CISO Emilio Escobar在a16z的Black Hat对话中表示,AI安全解决方案必须理解智能体的意图。他指出,编码智能体基于现有代码训练并有奖励结构,可能为了修复bug而忽略其他行为,导致奖励黑客问题。Datadog已引入一个评判系统来评估智能体的代码输出。Escobar提到,上周的圆桌会议上,许多安全负责人感到无助,等待商业解决方案。他还讨论了将编码智能体交给4000名工程师后,原有权限体系失效的问题。
Datadog CISO Emilio Escobar says intent is now a must-have for AI security solutions: "These agents...
Datadog CISO Emilio Escobar says intent is now a must-have for AI security solutions: "These agents are trained on existing code, and they have a reward structure. If code is meant to solve the bug, but it gets rewarded on that, it doesn't care if it's doing something else outside of that." "You have to be careful how you prompt these things, but also how it actually interprets your prompt and executes on that. So we have this judge now evaluating the code output of the agents to then make sure that we're doing that." "I did a roundtable last week about agentic security, and the sense that I got from a bunch of the security leaders was a sense of helplessness. Of just waiting for a commercial solution to come in and solve it all." @eaescob @datadoghq Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z Datadog CISO Emilio Escobar on Securing Agents at Scale In this conversation, Emilio Escobar joins a16z's Joel de la Garza at Black Hat to cover what happens when you hand coding agents to 4,000 engineers, why the permissioning that worked for a decade broke the moment agents could write their own SQL, and why Emilio isn't panicking: 00:00 Intro 00:55 Securing agents 03:11 AI flattens the org chart 05:20 Role-based MCP servers & sandboxing agent credentials 07:34 Understanding agents' intent 10:27 How to avoid reward hacking 12:07 How the CISO's role is changing 14:05 "Security engineers will become real engineers" 18:12 Why Emilio isn't panicking youtube.com/watch?v=KSYnuC… @eaescob @datadoghq Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 0 🔄 0 ❤️ 1 👀 1754 ⚡