arXiv論文メモ
新着一覧
cs.CR / cs.SE · 査読状況未確認

人とAIエージェントが同じアプリを操作する際の安全性

Security of Agent-Integrated Software: When Human Operations and Agent Actions Coexist

Ding Yang, Yuchen Ling, Shengcheng Yu, Zhenyu Chen, Chunrong Fang

この論文をやさしく読む

ひとことで言うと

人とAIエージェントが同じアプリを操作するとき、全体の安全性をどう評価するか整理する。

何に役立つ?

エージェントを組み込むアプリの権限管理や監査の設計課題を見つける助けになる。

この研究の面白いところ

人とエージェントが互いの操作結果を使うため、個別の安全対策だけでは全体の安全性を示せないと論じる。

どこまで分かった?

概念整理と研究課題の提示であり、具体的な防御策の有効性を実験で証明したものではない。

v1のアブストラクトに基づくAI解説。日本語訳とは別に、用途の解釈を含みます。

アブストラクトの日本語訳

エージェント統合ソフトウェア(AIS)は、従来型のアプリケーションに知的なエージェントを組み込み、人の操作とエージェントの動作の両方を支える。人は正確な変更を行い結果を確認でき、エージェントは定型的または多段階の作業を進める。このような補完的な役割から、多くのソフトウェアで両者の共存は長く続くと考えられる。人とエージェントの操作は同じソフトウェアの状態を変え、互いの結果を利用できる。そのため、セキュリティ方針は両方の経路を通じて有効でなければならない。 本論文は、AISの安全性をソフトウェアシステム全体の水準で評価すべきだと論じる。エージェントと従来のソフトウェア本体をそれぞれ守っても、組み合わせた状態の安全性は保証されない。全体としての分析を導くため、共存によって生じる問題を、文脈の誤用、権限違反、実行の制御、効果の完全性の四つに整理する。この分類に沿って、現在の実践がAISの安全上の問題へどう対応し、どこに保護の限界があるかを検討する。そのうえで、情報の出所の保持、操作経路をまたぐ方針の適用、時間が経過しても正しい認可の維持、持続する効果と復旧の管理に関する研究課題を示す。得られた見方は、AISの安全性を理解し改善するための概念的な枠組みを提供する。

v1の要旨から自動生成。本文の精読・人による確認は未実施。

初稿
2026-09-19(UTC)
最新改訂
2026-09-19 · v1
査読・掲載
査読状況未確認
arXivで読むPDF

更新履歴

取得できた版を表示。版の更新は査読済みを意味しません。過去版の本文差分は未解析です。

原文の要旨

Agent-Integrated Software (AIS) embeds an intelligent agent in a conventional application, supporting both human operations and agent actions. Human operations let users make precise changes and inspect results, while agent actions carry out routine or multi-step tasks. These complementary roles make coexistence a likely long-term feature of many software systems. Human operations and agent actions affect the same software state and can use one another's results. Therefore, security policies must remain effective across both paths. We argue that AIS security must be assessed at the level of the whole software system. Protecting the agent and the conventional software core separately does not establish that they are secure together. To guide security analysis of AIS as a whole, we organize the problems arising from this coexistence into four categories: context misuse, authorization violation, execution control, and effect integrity. Using these categories, we examine how current practices address the security problems in AIS and where their protection remains limited. Building on this analysis, we identify research opportunities in preserving information provenance, enforcing policy across operation paths, maintaining valid authorization over time, and managing persistent effects and recovery. This resulting perspective provides a conceptual framework for understanding and improving the security of AIS.

arXiv ID: 2609.23226 / 要約の誤りについて