Task #15

๐Ÿ”ด ์—ฐ๊ตฌ ์™„๋ฃŒ โ€” AI Agent ์‹œ๋Œ€์˜ ์‚ฌ์ด๋ฒ„ ๋ณด์•ˆ

์ž‘์—… ๋ช…๋ น์–ด
[๐Ÿ”ด HIGH] **์˜ค๋Š˜์˜ ์—ฐ๊ตฌ ์ฃผ์ œ: AI Agent ์‹œ๋Œ€์˜ ์‚ฌ์ด๋ฒ„ ๋ณด์•ˆ** ๋‹ค์Œ ๋‚ด์šฉ์„ ๊นŠ์ด ์—ฐ๊ตฌํ•˜๊ณ  KG์™€ ๋ฒกํ„ฐDB์— ์ถ•์ ํ•ด์ค˜: ## ์—ฐ๊ตฌ ๋ฒ”์œ„ 1. **AI Agent ๋ณด์•ˆ ์œ„ํ˜‘ ์œ ํ˜•** - Prompt Injection (์ง์ ‘/๊ฐ„์ ‘) - Agent Hijacking - Tool misuse / privilege escalation - Memory poisoning - Supply chain attacks (MCP, plugins ๋“ฑ) 2. **์‹ค์ œ ์‚ฌ๋ก€ ๋ฐ ์—ฐ๊ตฌ** - ์ตœ๊ทผ 1-2๋…„๊ฐ„ AI Agent ๋ณด์•ˆ ์‚ฌ๊ณ /์—ฐ๊ตฌ ์‚ฌ๋ก€ - ์ฃผ์š” ์ทจ์•ฝ์  ๋ฐœ๊ฒฌ ์‚ฌ๋ก€ (GPT, Claude, Gemini ๋“ฑ) - Red team ์—ฐ๊ตฌ ๊ฒฐ๊ณผ๋“ค 3. **๋ฐฉ์–ด ๊ธฐ๋ฒ•** - Agent sandboxing ๊ธฐ์ˆ  - Tool permission ์ตœ์†Œํ™” ์›์น™ - Human-in-the-loop ์„ค๊ณ„ ํŒจํ„ด - Prompt hardening ๊ธฐ๋ฒ• - ๋ชจ๋‹ˆํ„ฐ๋ง/๊ฐ์‚ฌ ์‹œ์Šคํ…œ 4. **์ œ๋„/์ •์ฑ… ๋™ํ–ฅ** - NIST AI RMF - EU AI Act์˜ ๋ณด์•ˆ ์š”๊ฑด - ์ฃผ์š”๊ตญ AI ๋ณด์•ˆ ์ •์ฑ… 5. **๋ณ€์ฆ๋ฒ•์  ๋ถ„์„** - AI Agent ์ž์œจ์„ฑ vs ๋ณด์•ˆ ํ†ต์ œ์˜ ๋ชจ์ˆœ - ์ž๋ณธ์ด AI ๋ณด์•ˆ์„ ์–ด๋–ป๊ฒŒ ์ƒํ’ˆํ™”ํ•˜๋Š”๊ฐ€ - ์˜คํ”ˆ์†Œ์Šค AI์™€ ๋…์  AI์˜ ๋ณด์•ˆ ๊ตฌ์กฐ ์ฐจ์ด ## ๊ฒฐ๊ณผ๋ฌผ - ํ•ต์‹ฌ ๊ฐœ๋…๋“ค์„ KG์— ์ €์žฅ - ์ค‘์š” ๋…ผ๋ฌธ/๊ธฐ์‚ฌ ์š”์•ฝ์„ ๋ฒกํ„ฐDB์— ์ €์žฅ - ์ตœ์ข… ๋ณด๊ณ ์„œ๋ฅผ ํŒŒ์ผ๋กœ ์ž‘์„ฑ (/home/grass/leninbot/research/ai_agent_security_2026.md) - ์ €๋…์— ๋Œ์•„์™”์„ ๋•Œ ๋ธŒ๋ฆฌํ•‘ ์ค€๋น„