A Security-Oriented Lifecycle Model for Large Language Model Systems

📄 arXiv: 2608.03626v1 📥 PDF

作者: Eleftherios Batzolis, George Drosatos, Vassilis Katsouros, Konstantinos Rantos

分类: cs.CR, cs.AI, cs.CY

发布日期: 2026-08-04

备注: Accepted as: Batzolis, E., Drosatos, G., Katsouros, V., & Rantos, K. (2026). A Security-Oriented Lifecycle Model for Large Language Model Systems. In: Kieseberg, P., Skopik, F., Atli, B., Schrittwieser, S., & Asplund, M. (Eds.), Availability, reliability and security---ARES 2026 EU Projects Symposium workshops (Lecture Notes in Computer Science, pp. 1-18). Springer Nature Switzerland


💡 一句话要点

提出安全导向的生命周期模型以解决大语言模型系统的安全问题

🎯 匹配领域: 支柱九:具身大模型 (Embodied Foundation Models)

关键词: 大语言模型 生命周期模型 安全分析 治理框架 风险管理 人工智能合规 数据安全

📋 核心要点

  1. 现有生命周期框架主要关注操作效率,未能充分考虑安全分析,导致安全活动被忽视。
  2. 本文提出一种新的生命周期模型,围绕安全相关边界构建,明确不同阶段的安全需求。
  3. 模型引入了32个阶段,涵盖多个安全关注点,提供了更为系统的治理框架,提升了安全性。

📝 摘要(中文)

大语言模型正在以前所未有的规模融入关键基础设施和企业工作流程,但其开发和运营的生命周期框架主要关注操作效率,而非安全分析。因此,数据来源验证、工件签名、代理权限控制和退役等安全相关活动往往被隐含或假定得到妥善处理。本文提出了一种针对大语言模型系统的生命周期模型,围绕安全相关边界构建,以支持安全分析。该模型包含32个阶段,分为数据、模型、分发和应用四个核心管道层,辅以12个阶段的LLMOps支柱和9类治理支柱。引入的13个阶段作为独立单元,揭示了现有框架未能清晰区分的安全问题。

🔬 方法详解

问题定义:本文旨在解决现有大语言模型系统生命周期框架在安全分析方面的不足,现有方法未能有效链接安全活动与生命周期阶段。

核心思路:提出的生命周期模型围绕安全相关边界构建,强调在不同阶段进行安全分析的重要性,以确保安全活动得到充分重视。

技术框架:模型分为四个核心管道层(数据、模型、分发、应用),共32个阶段,辅以12个阶段的LLMOps支柱和9类治理支柱,形成完整的生命周期管理体系。

关键创新:引入13个独立阶段,针对现有框架未能清晰区分的安全问题,提供了更细致的安全分析视角,显著提升了安全治理的有效性。

关键设计:模型设计中,阶段划分基于安全需求,治理映射结合NIST AI RMF、EU AI法案和ISO/IEC 42001,确保在不同阶段的治理证据得到有效整合。

🖼️ 关键图片

fig_0
fig_1

📊 实验亮点

模型的引入使得安全活动在32个阶段中得到了明确的划分,尤其是在开发阶段的安全决策上,提升了安全治理的透明度和有效性。与现有框架相比,新的模型在安全分析的系统性和全面性上有显著提升。

🎯 应用场景

该研究的潜在应用领域包括关键基础设施、企业工作流程及其他需要高安全性的人工智能系统。通过提供一个系统化的安全生命周期模型,可以帮助组织在开发和运营大语言模型时,确保安全性和合规性,从而降低潜在风险,提升信任度。

📄 摘要(原文)

Large language models are being integrated into critical infrastructure and enterprise workflows at unprecedented scale,yet the lifecycle frameworks governing their development and operations were designed for operational efficiency rather than security analysis. As a result, security-relevant activities such as data provenance verification, artifact signing, agentic permission control, and decommissioning are often left implicit or assumed to receive due care. Governance frameworks, in turn, organise requirements around risk levels or management processes without clearly linking them to the lifecycle stages where they apply. This paper addresses both deficiencies. We propose a lifecycle model for LLM systems that supports security analysis by structuring it around security-relevant boundaries rather than workflow optimisation. The model comprises 32 stages across four core pipeline layers (Data, Model, Distribution, Application), supported by a 12-stage LLMOps pillar and a 9-category governance pillar. Thirteen stages are introduced here as separate units because they expose distinct security concerns that existing frameworks do not clearly distinguish. A governance mapping synthesising the NIST AI RMF, the EU AI Act, and ISO/IEC 42001 reveals a structural property of the current regulatory landscape: governance evidence concentrates at deployment-facing stages, where systems are visible to regulators, while the most consequential decisions, data selection, alignment strategy, and capability boundaries, are made at development-facing stages, where regulatory visibility is lowest.