看影片(在新分頁開啟原站)連到 AI Native Dev
摘要
收錄 AI DevCon London 四場演講,探討 AI 代理的安全漏洞與防護工程。內容涵蓋產業安全專員缺口、4000 個技能中的惡意軟體比例、語境清除導致代理繞過拒絕機制,以及記憶版本化與一致性檢查等生產環境實踐。
A compilation of talks from AI DevCon London discussing security gaps in AI agents, malicious skills, context manipulation, and production memory safety engineering.
摘要、重點與章節標題由語言模型整理,細節(誰說的、數字、先後)可能有誤;要引用請以原始內容為準。
重點
- 產業安全專員與開發者比例嚴重不足,需從源頭開始強化安全。
- 約七成的公開 AI 技能存在惡意軟體或許可權濫用風險。
- 透過記憶版本化與雜湊檢查,確保多代理環境下的資料安全。
章節
依話題轉折切分,標題由 AI 產生
- 00:00Introduction
- 00:35Joseph Katsioloudes, GitHub Security Lab: AI and code security
- 01:47One security specialist for every 100 developers
- 02:38Why "shift left" should be "start left"
- 02:59Liran Tal, Snyk: what's inside 4,000 published skills
- 04:121 in 7 skills had something wrong with it
- 05:16Oleg Šelajev, Docker: getting an agent to run what it refused
- 06:56Clearing the context, and the agent complies
- 07:31Lamis Mukta, Anthropic: keeping agent memory safe
- 09:09Concurrency, and stopping two agents overwriting each other
提到的工具與公司
- Snyk
- Docker
- Claude
- Anthropic
- ClawHub
- 1Password
適合誰看
負責開發、維護或部署 AI 代理與自動化系統的工程師與安全專家。
摘要依據
- 依據
- 人工字幕
為什麼排在這裡
- 人氣
- 0.27
- 新鮮
- 0.87
在主題頁與搜尋結果裡,名次由相關、人氣、新鮮三個分數決定;這一頁沒有搜尋的關鍵字,所以沒有相關分數。排序怎麼算
相關內容
- We Scanned 3,984 Skills — 1 in 7 Can Hack Your MachinePodcast ・ The AI Native Dev ・ 35 分鐘
- Don't Secure the Code. Secure the Coder.Podcast ・ The AI Native Dev ・ 40 分鐘
- Securing tomorrow’s git forge, so we can reimagine everything else | Entire's Thomas Dohmke & Apiiro's Idan PlotnikPodcast ・ Dev Interrupted ・ 55 分鐘
- BONUS EPISODE: 76 Malicious AI Skills Were Hiding in Plain Sight影片 ・ AI Native Dev ・ 32 分鐘
- Breaking Autonomy: Hacking Cloud-Native AI Agents影片 ・ HITCON ・ 42 分鐘(在新分頁開啟原站)
- The vulnpocalypse might not be so bad after all影片 ・ IBM Technology ・ 34 分鐘(在新分頁開啟原站)
摘要由 AI 根據原文產生,可能有誤;完整內容請看原站。看影片(在新分頁開啟原站)
