网络安全 AI:自动化与自主性之间的危险鸿沟
摘要
网络安全行业将“自动化”和“自主”AI 结合在一起,制造了关于系统能力的危险误解。近期像 XBOW 登上 HackerOne 排行榜的里程碑展示了令人印象深刻的进展,但这些系统仍然是根本半自主的——需要人工监督。drawing from robotics principles, where the distinction between automation and autonomy is well-established, I take inspiration from prior work and establish a 6-level taxonomy (Level 0-5) distinguishing automation from autonomy in Cybersecurity AI. Current "autonomous" pentesters operate at Level 3-4: they execute complex attack sequences but need human review for edge cases and strategic decisions. True Level 5 autonomy remains aspirational. Organizations deploying mischaracterized "autonomous" tools risk reducing oversight precisely when it's most needed, potentially creating new vulnerabilities. The path forward requires precise terminology, transparent capabilities disclosure, and human-AI partnership-not replacement.
引用
@article{arxiv.2506.23592,
title = {Cybersecurity AI: The Dangerous Gap Between Automation and Autonomy},
author = {Víctor Mayoral-Vilches},
journal= {arXiv preprint arXiv:2506.23592},
year = {2025}
}