Agent interconnection has become a key development direction for artificial intelligence applications, with significant differences existing in user authorization processes under various deployment models. Current agent authorization models face multiple security risks in interconnection scenarios. Firstly, starting from the differences in agent deployment models, compares the authorization processes of rapid deployment on cloud platforms and enterprise private deployment; analyzes the security risks of intelligent agents in calling and being called scenarios, and analyzes the risks associated with entity identities such as agent identity codes, workflows, model context protocol services, etc; summarizes the risk points of identity forgery from two dimensions: personnel identity verification and identity authentication, with a focus on multimodal forgery and the security challenges posed by intelligent assistants with the ability to autonomously execute long-chain tasks. Finally, technical improvement suggestions are proposed from the aspects of dynamic management of identity codes, workflow authorization granularity, inter service authentication, multimodal liveness detection, and operational traceability, providing reference for security design in agent interconnection environments.
To address the social security risks arising from biases in the underlying algorithms of intelligent applications, this study employs literature review and case analysis methods to systematically retrieve key publications in algorithm ethics and digital governance from recent years both domestically and internationally. By examining major social incidents with significant impact, it first analyzes the risk transmission chain of algorithmic bias. Second, it identifies five fundamental technical biases: historical bias, representation/representativeness bias, measurement/labeling bias, aggregation/algorithmic design bias, and evaluation/deployment bias. Third, it examines the causes of algorithmic bias across four dimensions—technical, commercial, human, and institutional—to further pinpoint five potential types of social security risks. Finally, it proposes the establishment of a multi-faceted governance system for algorithmic bias, comprising“technical correction—institutional constraints—social co-governance”.
The rise of terminal agents has pushed terminal intelligence into a new era centered on autonomous agents. While human-machine integration and edge-cloud collaboration bring brand-new user experiences, they have also reshaped the paradigm of security risks. An analysis of terminal agents reveals prominent challenges including compliance risks of data transmission, permission abuse, and ambiguous accountability. The industry has carried out practical explorations such as constructing end-to-end trusted architectures, implementing refined permission control, and establishing identity mutual trust among agents. Nevertheless, governance is still plagued by fragmented standards, absent hierarchical specifications and fierce ecological gaming. It is proposed to build a risk classification system, unify interconnection standards, clarify end-to-end rights and obligations, and enforce ex ante compliance review and emergency response. A collaborative governance framework guided by the principles of human-centered AI and AI for good shall be established to sustain the sound development of the terminal agent ecosystem.
Data security management capability assessment is an important means of promoting regularized and systematic enterprise data security compliance. This paper reviews the development of China’s data security legislation, evaluation systems, and relevant standards. Drawing on frontline assessment practice, it examines the current state of enterprise data security management capabilities across four dimensions: organizational structure, institutional framework, technical capabilities, and operational mechanisms. Five common problems are identified: formalistic assignment of responsibilities, gaps between policies and actual operations, ineffective data classification and grading, weak internal audit and management review, and inadequate partner management. Accordingly, five improvement approaches are proposed: strengthening organizational safeguards, aligning policies with operations, improving the practical application of data classification and grading, establishing a closed loop for internal audit and continual improvement, and strengthening full-lifecycle security management of partners.
With the deepening implementation of laws and regulations such as the Data Security Law of the People’s Republic of China and the Personal Information Protection Law of the People’s Republic of China, SMEs generally face the dilemma of being“unaffordable, unusable, and unmaintainable”when fulfilling their data compliance obligations, leaving a gap between their governance capabilities and regulatory requirements. Based on the practical pain points of resource scarcity, talent shortages, and high business agility requirements for SMEs, a lightweight data security governance system construction plan is proposed. This solution achieves a balance between the depth and breadth of governance through a virtualized organizational structure, centralized planning, block responsibility governance logic, and risk driven control strategy. In terms of implementation paths, it elaborates on a low-cost evolutionary path supported by cloud-native and SaaS security tools and centered on“small steps, fast running, and continuous iterations”, covering the entire process from basic compliance and fine-grained control to normalized operations. By implementing a lightweight system, SMEs can effectively reduce data breach risks without significantly increasing their administrative and financial burdens, thereby building a data security foundation that meets national standards and providing a secure guarantee for the cultivation of new quality productive forces.
Given that intelligent models are vulnerable to adversarial sample attacks, which pose security risks such as misidentification and functional failure, their safe practical application is somewhat constrained. This paper focuses on patented technologies in the fields of adversarial attacks and defenses, reviews domestic and overseas related patent achievements, categorizes and summarizes key adversarial sample generation techniques and core defense methods against adversarial samples, and analyzes relevant patent layout characteristics and technological evolution trends, aiming to provide references for technological research, patent strategy, and security system development in related fields.
There is an urgent need for a criminal law response to attacks against large Generative AI (GenAI) models. The application of criminal law faces evaluative challenges: it is difficult to classify training data as data within a computer information system; alterations to data that do not impair system functionality are often overlooked in evaluations; attacks involving the theft of models are difficult to classify as acts of unlawful control; and output biases are difficult to classify as causing a computer system to malfunction. By adopting an interpretive approach to revitalize existing criminal law provisions, expanding the interpretation of“data in computer information systems,”reinterpreting the essence of“system crime”, and reconstructing the dimension of consequences in destructive crimes, we can thereby achieve comprehensive regulation of attack-related conduct.
Current research has yet to provide a systematic examination of the developmental trajectory of personal information protection compliance audit, the analysis of the relationship between personal information protection compliance audit and its associated institutional mechanisms remains rather fragmented, and practical methodologies applicable to these audits have not been sufficiently explored. Based on these gaps, this article systematically reviews the current state of development of personal information protection compliance audit, distinguishes the boundaries between compliance audit and other personal information protection institutional mechanisms, and investigates practice-oriented methodologies suitable for such audits. This article aims to provide support for advancing the refinement and development of the compliance audit system for personal information protection.
Foreign objects in transmission line corridors pose risks such as circuit tripping and short circuits. Edge-based real-time foreign object detection is constrained by computing power, power consumption, and latency. Simply scaling up model size does not offer a viable solution under these constraints. Consequently, it is necessary to leverage prior knowledge of specific scenarios under limited resource constraints. Based on the YOLO26n object detection model, this paper introduces auxiliary supervision of tower and conductor structures during the training phase, while removing the auxiliary branches during inference, thereby improving localization quality without additional inference cost. The experimental results demonstrate that this method significantly improves the detection gains for structure-related targets, such as the AP@0.5:0.95 for kites can be increased to 0.864 5, and the average IoU can be improved from 0.897 to 0.929. Based on the experimental results, this study proposes a“positional correlation + visual independence”applicability framework and a differentiated deployment strategy. In low-risk scenarios, accuracy-prioritized models are applied to reduce false alarms, and in high-risk scenarios, recall-prioritized models are adopted to guarantee comprehensive hazard detection, thereby providing effective support for model selection of AI terminals applied in transmission scenarios.
Artificial Intelligence (AI) has powerfully driven the transformation and modernization of smart education in higher education. Nevertheless, the rapid proliferation of intelligent technologies has brought prominent data security challenges, which extend far beyond technical defense issues and profoundly affect the stability of teaching operations, the protection of teachers and students’ legitimate rights and interests, and the sustainable innovation of smart education. Focusing on data security practices in university smart education, this paper examines the current construction status and practical dilemmas of smart education, and systematically analyzes the potential security and ethical risks embedded in AI-empowered educational scenarios. Oriented by the principles of security, stability and reliability, this study proposes a systematic safety barrier framework for smart education in institutions of higher education. The research results facilitate the standardized, normative and sustainable development of smart education, and offer feasible implications for improving data security governance in the construction of high-quality university smart education systems.
With the large-scale deployment of autonomous AI Agents in low-altitude intelligent network, industrial control, financial services and urban governance, new security vulnerabilities such as prompt injection, unauthorized tool calling, context poisoning and multi-agent trust hijacking continue to break out. Traditional testing methods including static code scanning, dynamic payload blasting and manual red team penetration suffer from low vulnerability detection accuracy, high false positive rate, inability to cover emergent risks in long link tasks and insufficient efficiency of test case generation. A hierarchical agent security testing scheme driven by retrieval-augmented large language model is proposed to meet the full-lifecycle security verification requirements of AI Agents. The scheme can effectively identify emergent security defects in multi-step chains that cannot be captured by traditional testing solutions, providing a complete technical path for standardized security testing of agent software.
The integration of smart devices, mobile health applications, and commercial health insurance is transforming proactive health data into a crucial basis for underwriting, pricing, claims processing, and health interventions. Drawing on the analytical evaluation approach of Design Science Research (DSR), this paper proposes a secure data circulation mechanism centered on purpose limitation and accountable computing. The mechanism categorizes data sensitivity into high, medium, and low levels, and classifies usage purposes into service, transaction, and modeling categories, thereby establishing a“data sensitivity×purpose type”matrix for authorization and computation. Based on this framework, it configures verification channels using individual-level Trusted Execution Environments (TEEs) and modeling channels utilizing population-level privacy-preserving computing. The study concludes that the mechanism’s effectiveness hinges on the alignment among scenarios, data granularity, computing environments, output formats, and audit evidence, offering an actionable framework for the secure circulation of proactive health data within health insurance ecosystems.
Aiming at the characteristics of discrete manufacturing products, such as diverse process, frequent design changes and complex production process control, this paper defines the concept of industrial large-scale model, the core competence of industrial large-scale models for discrete industries is defined, and the mainstream technology paths of industrial large-scale models at home and abroad are reviewed. The architecture of future industrial large-scale model is proposed innovatively, which provides reference for the construction of industrial large-scale model of intelligent factory in discrete industry.