觉
AI觉醒星球
Awakening is here
Knowledge File / 全球热点解读
2026-10-06 2 浏览 公开

代理式隐私与安全中的开放与新兴问题:上下文视角

Google Research 与 50 多位学术和产业领袖在 CAPS Workshop 后发布报告,提出以 Contextual Integrity 为框架,解决自主 AI 代理在隐私与安全上的开放问题。报告强调代理需理解并受上下文规范约束,并指出非结构化接口、概率控制流、自主委托三大挑战,需要在系统、模型、用户和生态层面协同防御。

SOURCE / 全球热点解读 MIN / 9 ACCESS / 公开 POST / 2026-10-06 05:08:31

原贴

查看原文
作者:Google Research Blog 来源站点:research.google 原贴时间:

原文

Eugene Bagdasarian, Research Scientist, and Marco Gruteser, Principal Scientist, Google Research To be useful, AI agents must understand and be constrained by contextual behavioral norms to ensure they act appropriately. Inspired by the theory of Contextual Integrity, our new workshop report outlines key open research directions across system, model, and user levels to build AI agents users can trust. We're rapidly transitioning to a computing landscape defined by highly general, increasingly autonomous agents . Driven by large language models (LLMs) that can dynamically generate plans and invoke external tools, these systems offer the potential for AI to seamlessly handle complex, multi-step tasks on our behalf. However, realizing this potential requires solving a key challenge: enabling agent capability while ensuring that agents act appropriately. Today, we share a comprehensive new workshop report, " Open and Emergent Problems in Agentic Privacy and Security: A Contextual Angle ," the result of a collaborative effort bringing together more than 50 academic and industry leaders from numerous institutions. We met at the Google Contextual Agent Privacy and Security (CAPS) Workshop, held in late 2025 in New York City. In this report, you’ll find a breakdown of foundational privacy and security challenges that autonomous agents face today, needing coordinated defenses at the system, model, user, and ecosystem levels. The core challenge of agentic AI is that, for an agent to be useful, it may need to have access to personal data and the ability to take consequential actions across a broad range of contexts. However, this access together with agents’ behavioral flexibility requires meaningfully different approaches from those used in traditional software. Unlike traditional deterministic software, agents differ in three critical dimensions that lead to challenges the research community must address together: Unstructured interfaces and input ambiguity : Agents process instructions in formats like natural language and images, which makes it difficult to define "expected behavior" or protect against adversarial manipulations like prompt injection . Probabilistic control flows : Generative planning leads to probabilistic execution paths that traditional testing methodologies can’t easily secure. Autonomy and delegation : As agents handle longer tasks and delegate sub-tasks to other agents, traditional user oversight becomes less effective and likely insufficient, risking "confirmation fatigue". Agentic AI privacy and security challenges. Given that useful agents may need to share data and complete tasks, we believe that the future of trustworthy agents depends on their ability to reason about, understand, and be constrained by the social norms and appropriateness of their actions— for the specific context in which they operate. But how do we teach an agent to understand "context" and appropriateness? Our report is grounded in the theory of Contextual Integrity (CI), which defines privacy not just as secrecy or control, but as "appropriate information flow" according to established and justifiable social norms. A context-specific informational norm is defined by its actors (who is sending and receiving information about whom), the types of information (specific categories of information, like medical or financial records), and transmission principles (the rules governing the flow, like confidentiality or reciprocity). For example, you might be willing to share your gift shopping list with a virtual shopping assistant, but not your family and friends. Our report extends and generalizes contextual integrity for information sharing to contextual security, that is the appropriateness of agent actions. By anchoring agent privacy and security in CI, we explore how we can design systems that evaluate whether an action is socially and contextually appropriate before executing it. Model of a general AI agent interacting with other

中文翻译

代理式隐私与安全中的开放与新兴问题:一个上下文视角

Eugene Bagdasarian,研究科学家,和 Marco Gruteser,首席科学家,Google Research。

为了有用,AI 代理必须理解并受上下文行为规范约束,以确保它们行为得当。受上下文完整性理论启发,我们的新研讨会报告概述了系统、模型和用户层面的关键开放研究方向,以构建用户可信任的 AI 代理。

我们正迅速转向一个由高度通用、日益自主的代理所定义的计算机景观。在大语言模型驱动下,这些模型可以动态生成计划并调用外部工具,这些系统有潜力让 AI 无缝地代表我们处理复杂的多步骤任务。然而,实现这一潜力需要解决一个关键挑战:在使能代理能力的同时,确保代理行为得当。

今天,我们分享一份全面的新研讨会报告,“代理式隐私与安全中的开放与新兴问题:一个上下文视角”,这是由来自众多机构的 50 多位学术和行业领袖共同努力的成果。我们在 Google 上下文代理隐私与安全(CAPS)研讨会上会面,该研讨会于 2025 年末在纽约市举行。

在这份报告中,你将看到自主代理今天面临的基础隐私和安全挑战的分解,这些挑战需要在系统、模型、用户和生态系统层面进行协调防御。

代理式 AI 的核心挑战是,一个代理要有用,它可能需要访问个人数据,并具备在广泛上下文中采取有后果行动的能力。然而,这种访问以及代理的行为灵活性,需要与传统软件所用方法有实质不同的方法。

与传统确定性软件不同,代理在三个关键维度上不同,这导致研究社区必须共同应对的挑战:

非结构化接口和输入歧义:代理处理自然语言和图像等格式的指令,这使得定义“预期行为”或防护提示注入等对抗性操纵变得困难。

概率性控制流:生成式规划导致概率性执行路径,传统测试方法难以轻松保障其安全。

自主性和委托:随着代理处理更长任务并将子任务委托给其他代理,传统用户监督变得不太有效,并且可能不足,带来“确认疲劳”风险。

代理式 AI 隐私和安全挑战。

鉴于有用的代理可能需要共享数据并完成任务,我们认为可信代理的未来取决于它们推理、理解并受其行动的社会规范和适当性约束的能力——针对它们所运作的特定上下文。

但我们如何教代理理解“上下文”和适当性?

我们的报告以上下文完整性(CI)理论为基础,该理论将隐私不仅定义为保密或控制,还定义为根据既定且可辩护的社会规范的“适当信息流”。

上下文特定的信息规范由其行动者(谁在发送和接收关于谁的信息)、信息类型(特定类别信息,如医疗或财务记录)和传输原则(约束流动的规则,如保密或互惠)定义。

例如,你可能愿意与虚拟购物助手分享你的礼物购物清单,但不愿与家人和朋友分享。

我们的报告将信息共享的上下文完整性扩展并泛化到上下文安全,即代理行动的适当性。

通过将代理隐私和安全锚定在 CI 中,我们探索如何设计系统,在行动执行前评估其是否在社会和上下文上适当。

一个通用 AI 代理与其他代理交互的模型。

核心信息

Google Research 与 50 多位学术和产业领袖在 CAPS Workshop 后发布报告,提出以 Contextual Integrity 为框架,解决自主 AI 代理在隐私与安全上的开放问题。报告强调代理需理解并受上下文规范约束,并指出非结构化接口、概率控制流、自主委托三大挑战,需要在系统、模型、用户和生态层面协同防御。

  • Google Research 与 50 多位学术和产业领袖在 CAPS Workshop 后发布报告,提出以 Contextual Integrity 为框架,解决自主 AI 代理在隐私与安全上的开放问题。报告强调代理需理解并受上下文规范约束,并指出非结构化接口、概率控制流、自主委托三大挑战,需要在系统、模型、用户和生态层面协同防御。
  • 原贴提到:Eugene Bagdasarian, Research Scientist, and Marco Gruteser, Principal Sc
  • 来源:research.google

详细解读

这是什么信号: Google Research 发布了一份由 50 多位学术和产业领袖参与的研讨会报告,把代理式 AI 的隐私与安全问题从传统软件安全框架,推进到“上下文完整性”和“上下文安全”框架。报告的核心判断是:有用的 AI 代理需要访问个人数据并采取有后果行动,因此不能只靠保密或控制,而必须理解并受特定场景中的社会规范约束,在执行前判断信息流和行动是否适当。

为什么重要: 代理与普通软件有三大结构性差异:非结构化接口和输入歧义让“预期行为”难以定义,并放大提示注入等对抗风险;概率性控制流让传统测试方法难以保障安全;自主性和委托会让传统用户监督失效,并带来确认疲劳。随着代理从单步工具调用走向多步任务和多代理协作,企业若缺少上下文感知的权限、策略和评测机制,代理能力越强,隐私与安全暴露面越大。

对谁有价值: 对构建浏览器代理、操作系统代理、企业工作流代理、个人助理和多代理系统的产品与平台团队最有价值;对安全、隐私、合规、模型对齐、评测和红队团队也有直接启发;对投资与战略团队而言,这是判断代理能否进入受监管和敏感业务的关键前置条件。

可以怎么行动: 把上下文完整性落到产品设计中:明确行动者、信息类型和传输原则,建立上下文策略引擎;在工具调用和外部行动前增加适当性检查;针对提示注入、概率执行路径和委托链设计防御与审计;用分层授权、可撤销授权和风险分级减少确认疲劳。报告适合作为内部研究议程,推动安全、产品、法务和模型团队共同定义可测试的代理行为规范。

风险或限制: 上下文完整性从理论到工程仍有距离:上下文边界可能模糊,社会规范因文化、行业和场景而异,模型未必能稳定推理;过度约束会削弱代理实用性,过少约束又会带来安全与合规风险。该报告是开放研究方向,不是即用标准或认证方案,落地时仍需结合具体业务流程、法律要求和用户预期,不能只依赖模型层解决。

信息差价值

这条内容的真正价值,不只是“有人发布了一个新功能”,而是它揭示了 research.google 背后的产品方向、工作流变化或竞争信号。对 OPC 来说,这种信息可以转化成持续追踪的栏目选题。

如果把《代理式隐私与安全中的开放与新兴问题:上下文视角》放到你的内容系统里,它最大的价值在于帮助读者更快看懂“为什么值得关注”,而不是只看到一条碎片化动态。

参考来源

AI SUMMARY

这篇文章回答了什么

代理式隐私与安全中的开放与新兴问题:上下文视角主要讲什么?

Google Research 与 50 多位学术和产业领袖在 CAPS Workshop 后发布报告,提出以 Contextual Integrity 为框架,解决自主 AI 代理在隐私与安全上的开放问题。报告强调代理需理解并受上下文规范约束,并指出非结构化接口、概率控制流、自主委托三大挑战,需要在系统、模型、用户和生态层面协同防御。

这篇文章最值得关注的要点是什么?

Google Research 与 50 多位学术和产业领袖在 CAPS Workshop 后发布报告,提出以 Contextual Integrity 为框架,解决自主 AI 代理在隐私与安全上的开放问题。报告强调代理需理解并受上下文规…;原贴提到:Eugene Bagdasarian, Research Scientist, and Marco Gruteser, Principal Sc;来源:research.google

这篇文章和哪些AI专题相关?

它适合放在Agent工作流、AI日报、AI工具专题里阅读。 关联原因:这篇内容命中「Agent、智能体」等主题信号。;这篇内容命中「热点解读」等主题信号。;这篇内容命中「模型」等主题信号。

阅读这篇文章建议先理解哪些关键词?

建议先理解AI日报、每日AI日报、AI信号、热点解读、BuilderPulse这些关键词,再结合正文判断工具、机会或风险是否值得进入自己的工作流。

上一篇 【必读】每日AI日报 2026-10-06 下一篇 新民调发现,大多数美国人希望 AI 发展放缓或完全停止
北竹游乐场 免费玩小游戏 免费玩