基于业务场景的大模型安全风险评估体系研究
网络安全与数据治理
魏光辉1,2,陈宇杰1,2,孔德智1,2,刘茂珍3,庞晓健4,甘清鎔1,2
1.中国电子产品可靠性与环境试验研究所; 2.智能制造装备通用质量技术及应用工业和信息化部重点实验室; 3.广东电力人工智能试验研究院有限公司; 4.南方电网财务有限公司
摘要: 提出一种基于业务场景的大模型安全风险评估模型,构建了涵盖安全能力、大模型模态、大模型在业务场景中的角色及交互的三维安全体系,围绕大模型业务及其资产进行风险评估建模,给出了完整的风险识别、风险分析与量化评价方法,并通过电力场景大模型实践验证了风险评估模型的全面性、准确性及可行性。该模型支持基于业务、技术及行业地区要求等要素的安全体系动态设计与差异化风险评估,为风险精准识别与有效防范提供科学的方法指引和实践指南。
中图分类号:TP309文献标志码:ADOI:10.19358/j.issn.2097-1788.2026.06.007中文引用格式:魏光辉,陈宇杰,孔德智,等.基于业务场景的大模型安全风险评估体系研究[J].网络安全与数据治理,2026,45(6):47-56.
英文引用格式:Wei Guanghui,Chen Yujie,Kong Dezhi,et al.Research on large model security risk assessment system based on business scenarios[J].Cyber Security and Data Governance,2026,45(6):47-56.
Research on large model security risk assessment system based on business scenarios
Wei Guanghui1,2,Chen Yujie1,2,Kong Dezhi1,2,Liu Maozhen3,Pang Xiaojian4,Gan Qingrong1,2
1. China Electronic Product Reliability and Environment Test Research Institute; 2.The Ministry of Industry and Information Technology Key Laboratory of General Quality Technology and Application for Intelligent Manufacturing Equipment; 3.Guangdong Power Artificial Intelligence Experimental Research In.; 4. China Southern Power Grid Finance Co.,Ltd.,Guangzhou 510623
Abstract: This paper proposes a business scenariobased security risk assessment model for large models.It constructs a threedimensional security system encompassing security capabilities,large model modalities,and the roles and interactions of large models in business scenarios.Risk assessment modeling is conducted around large model businesses and their assets,and a complete set of methods for risk identification,risk analysis and quantitative evaluation is presented.The comprehensiveness,accuracy and feasibility of the proposed risk assessment model are verified through the practice of large models in the power industry scenario.This model supports the dynamic design of security systems and differentiated risk assessment based on factors such as business requirements,technical specifications,and industry and regional regulations,providing scientific methodological guidance and practical references for accurate risk identification and effective prevention.
Key words : business scenario; large model security; risk assessment; risk identification; risk analysis; risk evaluation
引言
近年来,大语言模型在电力、金融等行业深度应用的同时,衍生出提示词注入、模型幻觉、数据投毒等新型安全风险,并可能通过业务交互链条引发连锁式安全事件。现有研究多聚焦于算力、算法、数据、应用、内容等层面安全,缺乏一套能够系统融合业务场景特性与风险全要素的可量化风险评估体系。本文构建了基于业务场景的涵盖安全能力、大模型模态、大模型在业务场景中的角色及交互的大模型安全体系及其风险评估模型,并通过电力调度知识问答大模型验证其有效性,实现大模型全要素安全风险的精准识别、分析与评价,为大模型赋能千行百业的安全风险管理提供科学指引和实践指南。
本文详细内容请下载:
http://www.chinaaet.com/resource/share/2000007126
作者信息:
魏光辉1,2,陈宇杰1,2,孔德智1,2,刘茂珍3,庞晓健4,甘清鎔1,2
(1.中国电子产品可靠性与环境试验研究所,广东广州511370;
2.智能制造装备通用质量技术及应用工业和信息化部重点实验室,广东广州511370;
3.广东电力人工智能试验研究院有限公司,广东广州510700;
4.南方电网财务有限公司,广东广州510623)