基于业务场景的大模型安全风险评估体系研究
网络安全与数据治理
魏光辉1,2,陈宇杰1,2,孔德智1,2,刘茂珍3,庞晓健4,甘清鎔1,2
1.中国电子产品可靠性与环境试验研究所; 2.智能制造装备通用质量技术及应用工业和信息化部重点实验室; 3.广东电力人工智能试验研究院有限公司; 4.南方电网财务有限公司
摘要: 提出一种基于业务场景的大模型安全风险评估模型,构建了涵盖安全能力、大模型模态、大模型在业务场景中的角色及交互的三维安全体系,围绕大模型业务及其资产进行风险评估建模,给出了完整的风险识别、风险分析与量化评价方法,并通过电力场景大模型实践验证了风险评估模型的全面性、准确性及可行性。该模型支持基于业务、技术及行业地区要求等要素的安全体系动态设计与差异化风险评估,为风险精准识别与有效防范提供科学的方法指引和实践指南。
中圖分類號:TP309文獻標志碼:ADOI:10.19358/j.issn.2097-1788.2026.06.007中文引用格式:魏光輝,陳宇杰,孔德智,等.基于業務場景的大模型安全風險評估體系研究[J].網絡安全與數據治理,2026,45(6):47-56.
英文引用格式:Wei Guanghui,Chen Yujie,Kong Dezhi,et al.Research on large model security risk assessment system based on business scenarios[J].Cyber Security and Data Governance,2026,45(6):47-56.
英文引用格式:Wei Guanghui,Chen Yujie,Kong Dezhi,et al.Research on large model security risk assessment system based on business scenarios[J].Cyber Security and Data Governance,2026,45(6):47-56.
Research on large model security risk assessment system based on business scenarios
Wei Guanghui1,2,Chen Yujie1,2,Kong Dezhi1,2,Liu Maozhen3,Pang Xiaojian4,Gan Qingrong1,2
1. China Electronic Product Reliability and Environment Test Research Institute; 2.The Ministry of Industry and Information Technology Key Laboratory of General Quality Technology and Application for Intelligent Manufacturing Equipment; 3.Guangdong Power Artificial Intelligence Experimental Research In.; 4. China Southern Power Grid Finance Co.,Ltd.,Guangzhou 510623
Abstract: This paper proposes a business scenariobased security risk assessment model for large models.It constructs a threedimensional security system encompassing security capabilities,large model modalities,and the roles and interactions of large models in business scenarios.Risk assessment modeling is conducted around large model businesses and their assets,and a complete set of methods for risk identification,risk analysis and quantitative evaluation is presented.The comprehensiveness,accuracy and feasibility of the proposed risk assessment model are verified through the practice of large models in the power industry scenario.This model supports the dynamic design of security systems and differentiated risk assessment based on factors such as business requirements,technical specifications,and industry and regional regulations,providing scientific methodological guidance and practical references for accurate risk identification and effective prevention.
Key words : business scenario; large model security; risk assessment; risk identification; risk analysis; risk evaluation
引言
近年來,大語言模型在電力、金融等行業深度應用的同時,衍生出提示詞注入、模型幻覺、數據投毒等新型安全風險,并可能通過業務交互鏈條引發連鎖式安全事件。現有研究多聚焦于算力、算法、數據、應用、內容等層面安全,缺乏一套能夠系統融合業務場景特性與風險全要素的可量化風險評估體系。本文構建了基于業務場景的涵蓋安全能力、大模型模態、大模型在業務場景中的角色及交互的大模型安全體系及其風險評估模型,并通過電力調度知識問答大模型驗證其有效性,實現大模型全要素安全風險的精準識別、分析與評價,為大模型賦能千行百業的安全風險管理提供科學指引和實踐指南。
本文詳細內容請下載:
http://www.tom3567.com/resource/share/2000007126
作者信息:
魏光輝1,2,陳宇杰1,2,孔德智1,2,劉茂珍3,龐曉健4,甘清鎔1,2
(1.中國電子產品可靠性與環境試驗研究所,廣東廣州511370;
2.智能制造裝備通用質量技術及應用工業和信息化部重點實驗室,廣東廣州511370;
3.廣東電力人工智能試驗研究院有限公司,廣東廣州510700;
4.南方電網財務有限公司,廣東廣州510623)

此內容為AET網站原創,未經授權禁止轉載。
