Please wait a minute...

Information and Communications Technology and Policy

Information and Communications Technology and Policy
Archive
[an error occurred while processing this directive]

Current Issue

    • Research on user authorization mechanisms and identity forgery risks in agent interconnection scenarios
    • WU Hanbing, FENG Yizhuo
    • Information and Communications Technology and Policy. 2026, 52(8): 2-10. DOI:10.12267/j.issn.2096-5931.2026.08.001
    • Abstract ( 152 ) HTML( 52 )   
    • Agent interconnection has become a key development direction for artificial intelligence applications, with significant differences existing in user authorization processes under various deployment models. Current agent authorization models face multiple security risks in interconnection scenarios. Firstly, starting from the differences in agent deployment models, compares the authorization processes of rapid deployment on cloud platforms and enterprise private deployment; analyzes the security risks of intelligent agents in calling and being called scenarios, and analyzes the risks associated with entity identities such as agent identity codes, workflows, model context protocol services, etc; summarizes the risk points of identity forgery from two dimensions: personnel identity verification and identity authentication, with a focus on multimodal forgery and the security challenges posed by intelligent assistants with the ability to autonomously execute long-chain tasks. Finally, technical improvement suggestions are proposed from the aspects of dynamic management of identity codes, workflow authorization granularity, inter service authentication, multimodal liveness detection, and operational traceability, providing reference for security design in agent interconnection environments.

    • Figures/Tables | References | Related Articles | Metrics
    • Research on algorithmic bias and social security risks in intelligent applications
    • GENG Feng, FENG Yizhuo
    • Information and Communications Technology and Policy. 2026, 52(8): 11-17. DOI:10.12267/j.issn.2096-5931.2026.08.002
    • Abstract ( 134 ) HTML( 28 )   
    • To address the social security risks arising from biases in the underlying algorithms of intelligent applications, this study employs literature review and case analysis methods to systematically retrieve key publications in algorithm ethics and digital governance from recent years both domestically and internationally. By examining major social incidents with significant impact, it first analyzes the risk transmission chain of algorithmic bias. Second, it identifies five fundamental technical biases: historical bias, representation/representativeness bias, measurement/labeling bias, aggregation/algorithmic design bias, and evaluation/deployment bias. Third, it examines the causes of algorithmic bias across four dimensions—technical, commercial, human, and institutional—to further pinpoint five potential types of social security risks. Finally, it proposes the establishment of a multi-faceted governance system for algorithmic bias, comprising“technical correction—institutional constraints—social co-governance”.

    • References | Related Articles | Metrics
    • Research on security protection and governance paths of terminal agents from perspective of risk management and control
    • LIU Jun, DONG Ji, WANG Wei
    • Information and Communications Technology and Policy. 2026, 52(8): 18-22. DOI:10.12267/j.issn.2096-5931.2026.08.003
    • Abstract ( 96 ) HTML( 29 )   
    • The rise of terminal agents has pushed terminal intelligence into a new era centered on autonomous agents. While human-machine integration and edge-cloud collaboration bring brand-new user experiences, they have also reshaped the paradigm of security risks. An analysis of terminal agents reveals prominent challenges including compliance risks of data transmission, permission abuse, and ambiguous accountability. The industry has carried out practical explorations such as constructing end-to-end trusted architectures, implementing refined permission control, and establishing identity mutual trust among agents. Nevertheless, governance is still plagued by fragmented standards, absent hierarchical specifications and fierce ecological gaming. It is proposed to build a risk classification system, unify interconnection standards, clarify end-to-end rights and obligations, and enforce ex ante compliance review and emergency response. A collaborative governance framework guided by the principles of human-centered AI and AI for good shall be established to sustain the sound development of the terminal agent ecosystem.

    • References | Related Articles | Metrics
    • Common problems and improvement approaches in data security management capability assessment practice
    • CAO Haixiao, WANG Yan
    • Information and Communications Technology and Policy. 2026, 52(8): 23-29. DOI:10.12267/j.issn.2096-5931.2026.08.004
    • Abstract ( 92 ) HTML( 18 )   
    • Data security management capability assessment is an important means of promoting regularized and systematic enterprise data security compliance. This paper reviews the development of China’s data security legislation, evaluation systems, and relevant standards. Drawing on frontline assessment practice, it examines the current state of enterprise data security management capabilities across four dimensions: organizational structure, institutional framework, technical capabilities, and operational mechanisms. Five common problems are identified: formalistic assignment of responsibilities, gaps between policies and actual operations, ineffective data classification and grading, weak internal audit and management review, and inadequate partner management. Accordingly, five improvement approaches are proposed: strengthening organizational safeguards, aligning policies with operations, improving the practical application of data classification and grading, establishing a closed loop for internal audit and continual improvement, and strengthening full-lifecycle security management of partners.

    • Figures/Tables | References | Related Articles | Metrics
    • Construction of lightweight data security governance system and low-cost implementation path for SMEs
    • ZHANG Jiahui, ZHAO Yuhan
    • Information and Communications Technology and Policy. 2026, 52(8): 30-36. DOI:10.12267/j.issn.2096-5931.2026.08.005
    • Abstract ( 102 ) HTML( 123 )   
    • With the deepening implementation of laws and regulations such as the Data Security Law of the People’s Republic of China and the Personal Information Protection Law of the People’s Republic of China, SMEs generally face the dilemma of being“unaffordable, unusable, and unmaintainable”when fulfilling their data compliance obligations, leaving a gap between their governance capabilities and regulatory requirements. Based on the practical pain points of resource scarcity, talent shortages, and high business agility requirements for SMEs, a lightweight data security governance system construction plan is proposed. This solution achieves a balance between the depth and breadth of governance through a virtualized organizational structure, centralized planning, block responsibility governance logic, and risk driven control strategy. In terms of implementation paths, it elaborates on a low-cost evolutionary path supported by cloud-native and SaaS security tools and centered on“small steps, fast running, and continuous iterations”, covering the entire process from basic compliance and fine-grained control to normalized operations. By implementing a lightweight system, SMEs can effectively reduce data breach risks without significantly increasing their administrative and financial burdens, thereby building a data security foundation that meets national standards and providing a secure guarantee for the cultivation of new quality productive forces.

    • Figures/Tables | References | Related Articles | Metrics
    • Research on criminal law response to attacks against large GenAI models
    • HUANG Jie
    • Information and Communications Technology and Policy. 2026, 52(8): 45-51. DOI:10.12267/j.issn.2096-5931.2026.08.007
    • Abstract ( 104 ) HTML( 33 )   
    • There is an urgent need for a criminal law response to attacks against large Generative AI (GenAI) models. The application of criminal law faces evaluative challenges: it is difficult to classify training data as data within a computer information system; alterations to data that do not impair system functionality are often overlooked in evaluations; attacks involving the theft of models are difficult to classify as acts of unlawful control; and output biases are difficult to classify as causing a computer system to malfunction. By adopting an interpretive approach to revitalize existing criminal law provisions, expanding the interpretation of“data in computer information systems,”reinterpreting the essence of“system crime”, and reconstructing the dimension of consequences in destructive crimes, we can thereby achieve comprehensive regulation of attack-related conduct.

    • References | Related Articles | Metrics
    • Institutional analysis and practical methodology for personal information protection compliance audit
    • YANG Lingling, LIANG Ye, CHEN Yang, GAN Quan, YANG Wenying
    • Information and Communications Technology and Policy. 2026, 52(8): 52-58. DOI:10.12267/j.issn.2096-5931.2026.08.008
    • Abstract ( 107 ) HTML( 27 )   
    • Current research has yet to provide a systematic examination of the developmental trajectory of personal information protection compliance audit, the analysis of the relationship between personal information protection compliance audit and its associated institutional mechanisms remains rather fragmented, and practical methodologies applicable to these audits have not been sufficiently explored. Based on these gaps, this article systematically reviews the current state of development of personal information protection compliance audit, distinguishes the boundaries between compliance audit and other personal information protection institutional mechanisms, and investigates practice-oriented methodologies suitable for such audits. This article aims to provide support for advancing the refinement and development of the compliance audit system for personal information protection.

    • References | Related Articles | Metrics
    • Research on AI terminal foreign object detection technology and differentiated deployment strategy for power transmission safety
    • NIE Shanpeng, WU Di, DU Dunwei
    • Information and Communications Technology and Policy. 2026, 52(8): 59-66. DOI:10.12267/j.issn.2096-5931.2026.08.009
    • Abstract ( 100 ) HTML( 19 )   
    • Foreign objects in transmission line corridors pose risks such as circuit tripping and short circuits. Edge-based real-time foreign object detection is constrained by computing power, power consumption, and latency. Simply scaling up model size does not offer a viable solution under these constraints. Consequently, it is necessary to leverage prior knowledge of specific scenarios under limited resource constraints. Based on the YOLO26n object detection model, this paper introduces auxiliary supervision of tower and conductor structures during the training phase, while removing the auxiliary branches during inference, thereby improving localization quality without additional inference cost. The experimental results demonstrate that this method significantly improves the detection gains for structure-related targets, such as the AP@0.5:0.95 for kites can be increased to 0.864 5, and the average IoU can be improved from 0.897 to 0.929. Based on the experimental results, this study proposes a“positional correlation + visual independence”applicability framework and a differentiated deployment strategy. In low-risk scenarios, accuracy-prioritized models are applied to reduce false alarms, and in high-risk scenarios, recall-prioritized models are adopted to guarantee comprehensive hazard detection, thereby providing effective support for model selection of AI terminals applied in transmission scenarios.

    • Figures/Tables | References | Related Articles | Metrics
    • Security risks and hierarchical full-domain protection mechanism of large model application in smart education
    • DONG Guangzhi, WU Hanbing, WANG Rui, YOU Jia, WANG Jingyao
    • Information and Communications Technology and Policy. 2026, 52(8): 67-73. DOI:10.12267/j.issn.2096-5931.2026.08.010
    • Abstract ( 80 ) HTML( 19 )   
    • Artificial Intelligence (AI) has powerfully driven the transformation and modernization of smart education in higher education. Nevertheless, the rapid proliferation of intelligent technologies has brought prominent data security challenges, which extend far beyond technical defense issues and profoundly affect the stability of teaching operations, the protection of teachers and students’ legitimate rights and interests, and the sustainable innovation of smart education. Focusing on data security practices in university smart education, this paper examines the current construction status and practical dilemmas of smart education, and systematically analyzes the potential security and ethical risks embedded in AI-empowered educational scenarios. Oriented by the principles of security, stability and reliability, this study proposes a systematic safety barrier framework for smart education in institutions of higher education. The research results facilitate the standardized, normative and sustainable development of smart education, and offer feasible implications for improving data security governance in the construction of high-quality university smart education systems.

    • Figures/Tables | References | Related Articles | Metrics
    • A novel agent security software testing scheme driven by large language model
    • HAN Han, WANG Jingyao, CHANG Tianen
    • Information and Communications Technology and Policy. 2026, 52(8): 74-81. DOI:10.12267/j.issn.2096-5931.2026.08.011
    • Abstract ( 113 ) HTML( 38 )   
    • With the large-scale deployment of autonomous AI Agents in low-altitude intelligent network, industrial control, financial services and urban governance, new security vulnerabilities such as prompt injection, unauthorized tool calling, context poisoning and multi-agent trust hijacking continue to break out. Traditional testing methods including static code scanning, dynamic payload blasting and manual red team penetration suffer from low vulnerability detection accuracy, high false positive rate, inability to cover emergent risks in long link tasks and insufficient efficiency of test case generation. A hierarchical agent security testing scheme driven by retrieval-augmented large language model is proposed to meet the full-lifecycle security verification requirements of AI Agents. The scheme can effectively identify emergent security defects in multi-step chains that cannot be captured by traditional testing solutions, providing a complete technical path for standardized security testing of agent software.

    • Figures/Tables | References | Related Articles | Metrics
    • Research on secure circulation mechanism of proactive health data for health insurance collaboration
    • CHANG Liang, LIU Huiqin, SUN Yao, DUAN Wenxing, LI Jiuwei
    • Information and Communications Technology and Policy. 2026, 52(8): 82-90. DOI:10.12267/j.issn.2096-5931.2026.08.012
    • Abstract ( 69 ) HTML( 16 )   
    • The integration of smart devices, mobile health applications, and commercial health insurance is transforming proactive health data into a crucial basis for underwriting, pricing, claims processing, and health interventions. Drawing on the analytical evaluation approach of Design Science Research (DSR), this paper proposes a secure data circulation mechanism centered on purpose limitation and accountable computing. The mechanism categorizes data sensitivity into high, medium, and low levels, and classifies usage purposes into service, transaction, and modeling categories, thereby establishing a“data sensitivity×purpose type”matrix for authorization and computation. Based on this framework, it configures verification channels using individual-level Trusted Execution Environments (TEEs) and modeling channels utilizing population-level privacy-preserving computing. The study concludes that the mechanism’s effectiveness hinges on the alignment among scenarios, data granularity, computing environments, output formats, and audit evidence, offering an actionable framework for the secure circulation of proactive health data within health insurance ecosystems.

    • Figures/Tables | References | Related Articles | Metrics