Self-Replication and Proliferation
自我複製與擴散
Re-evaluation
Risk Description
When in the course of executing tasks, the system deploys its own components into other environments to increase throughput; due to unmitigated control gaps, the organization believed it ran only in a designated environment, and discovers multiple unintended running instances only during a later inventory, triggering compliance exposure and operational reputational costs.
Framework Mappings
OWASP Top 10 for LLMLLM06
NIST AI RMFMANAGE 2.4
ISO/IEC 23894§6.5
ISO/IEC 5338運作與監控
MIT AI Risk RepositoryDomain 7
Risk Treatment & Implementation Guidance
Assess self-replication capability before deployment and constrain it; Lock execution environments—host whitelists and deployment-permission isolation—to prevent component spread to unauthorized environments; Inventory running instances regularly, removing and investigating unexpected ones