免费领取大会全套演讲PPT    

点击领取

我要参会

Dong Zhang

Tencent Distinguished Engineer and Head of Agent Security

Dong Zhang is a Tencent Distinguished Engineer and Head of AI Agent Security. He has 12 years of experience in the R&D and architecture of high-concurrency infrastructure. At Tencent, he has led the development and production deployment of infrastructure at massive scale, supporting tens of millions of hosts, millions of code repositories, petabyte-scale daily traffic, and trillions of computing operations. Across five heterogeneous domains—big data, networking, host infrastructure, code, and software supply chains—he has developed reusable architectural paradigms. He is currently extending this infrastructure expertise to AI and Agent scenarios, focusing on AI Agent security and large language model supply chain security. He has led the incubation and large-scale production deployment of multiple AI-native initiatives at Tencent, with the goal of building security infrastructure for the agentic era. He has been deeply involved in the development of multiple national standards related to AI/Agents, infrastructure, cloud computing, and cybersecurity. He is also committed to translating technical achievements into academic research, with multiple papers accepted by top international academic conferences. He holds more than 30 granted invention patents in China and abroad.

Topic

Agent Security: An Infrastructure Problem, Not a Model Problem

AI security over the past two years has essentially been about content security—a category of risks that can largely be addressed through improvements to the model itself, because the content is generated by the model. But Agents represent a shift from “generating content” to “taking actions”: calling tools, modifying data, and using credentials. These actions take place outside the model. The model can only make requests; it cannot guarantee that a particular operation will or will not occur. Our view is that tool calling is the system call of the Agent. Today’s Agents are at their “DOS moment”: they can directly invoke arbitrary tools, credentials are persistently overprivileged, instructions and data share the same channel, and isolation and auditing are often lacking. The computer industry has faced this class of problems before. The answer was not to make programs more self-disciplined—it was to build an operating system. This session will explore the core processes and risks of Agent security, share industry practices and enterprise deployment experiences, and help organizations understand the risks while identifying practical approaches to mitigating and containing them. Outline I. In the Agent Era: What Models Cannot Control Risk patterns: credential overreach, tool parameter tampering, and indirect prompt injection taking control Root cause: content is generated by the model, but actions are not Three blind spots: reviewing content but not behavior; asking models to guard other models; and execution chains without clear boundaries II. Tool Calling Is System Calling: Agents Need an Operating System The Agent’s DOS moment: direct access to arbitrary tools, with credentials approaching root-level privileges Five gates: a single point of egress, privilege separation, process isolation, least privilege, and audit trails Infrastructure redesign: reusing legacy architecture vs. rebuilding for the new era Edge-cloud division of labor: strong constraints at the edge, strong intelligence in the cloud III. Practical Cases: Balancing Value and Cost Tool gateways: enforcement at the SDK, proxy, or gateway layer—and how to prevent bypasses Permission scoping: from “who are you?” to “what are you trying to do this time?” Audit granularity: how much detail is needed for accountability without making storage costs unsustainable Lessons from rework: decisions that initially seemed right but were later overturned and rebuilt IV. Looking Ahead: Model vs. Agent vs. Infrastructure A three-layer division of responsibility: judgment can be probabilistic; execution must be deterministic Mature precedents: SELinux labeling and mandatory separation—enforcement must happen at the kernel level Directions for standardization: capability tiers, identity interoperability, and behavioral auditing interfaces Key Takeaways Develop a systematic understanding of the core risks and root causes of enterprise-grade Agents. Learn how to build an Agent security framework spanning identity, behavior, data, tools, and compliance governance. Gain practical reference for helping enterprises move from “wanting to use Agents” to “being confident in using Agents—and using them effectively.”

© boolan.com 博览 版权所有

沪ICP备15014563号-6

沪公网安备31011502003949号