Databricks Omnigent 上下文策略阻断提示注入数据外泄
本文展示 Omnigent 上下文策略如何在 AI 代理组合出数据泄露条件时切断最后一步,保护私有数据。
Omnigent 的上下文策略(根据会话历史而非单次操作判断的安全机制)能识别并拦截提示注入攻击:当一次会话同时具备读取私有数据、接触不可信内容和对外发送消息这三个条件时,即时阻断外发动作,防止数据泄露。示例中,攻击者通过操控工单内容诱导代理读取内部财务文档并外发,策略在最后一步成功拦截。
正文摘录
How Omnigent's contextual policies stop a prompt-injected agent before it leaks your data by Nishith Sinha , Arun Pamulapati and Omar Khawaja In earlier posts, we introduced contextual policies in Omnigent , showed them blocking slow-burn attacks , and used them to enforce a declared intent . This time, we tackle the lethal trifecta. Simon Willison's observation is that an AI agent is exposed to data theft whenever a single session combines three things: access to private data, exposure to untrusted content, and a way to communicate externally. Each capability is useful and ordinary on its own. The problem is the combination, because untrusted content can carry an instruction that turns the agent's private data access and its outbound channel into a data exfiltration tool. We'll show you h…