AI安全与数据隐私
隐私、数据卫生、安全失效模式、治理和安全的AI连接。
40 项内容 (29 篇文章 · 11 个视频)
从这里开始
浏览完整内容之前,先阅读几篇推荐文章。
6 分钟阅读隐私入门:ChatGPT会记住、看到和分享什么
客观看看AI助手究竟会如何处理你的数据——哪些内容会被存储、哪些会用于训练、隐私设置到底意味着什么,以及今天就值得做出的三项调整。
AI新手
8 分钟阅读在工作中使用AI时的隐私与数据卫生
一份实用指南,帮助你在工作中使用AI时避免意外泄露客户数据、违反公司政策或违反GDPR。了解界限、工具以及需要养成的习惯。
初级
14 分钟阅读提示词注入与大语言模型安全:威胁模型与纵深防御
提示词注入是长期存在的一类大语言模型安全风险,并非提示词编写失误。本文是一份面向生产环境的指南,涵盖威胁模型、数据边界、工具权限、回归测试、监控和事件响应。
高级此主题下的更多内容
6 分钟阅读Do Not Paste Bank Statements Into AI
Account numbers, balances, counterparties, and payroll lines are paste bans for consumer AI. How to get literacy help from a model using typed, redacted fields - without uploading full statements, screenshots, or PDF exports.
AI新手
6 分钟阅读Home Photos and Floorplans: Privacy Before You Upload
Uploading interiors and floorplans to consumer AI can leak layout, valuables, kids' rooms, and security cues. A privacy-first checklist for what to redact, what to keep offline, and how to still get planning help without broadcasting your house.
AI新手
5 分钟阅读Solo AI Rules for Client Work
Before you put a client's brief, draft, or data near a consumer AI tool, write a one-page personal policy card: what you will never paste, what needs client consent, what you still price and scope yourself, and when you escalate to a human specialist. Freelancers do not inherit an employer AI policy - you need your own.
AI新手
7 分钟阅读Coordinating an Ageing Parent's Care Without Losing Their Voice
When siblings start coordinating a parent's care, information sprawls across group chats, and the person it's about gets talked over. A consent-aware record — what to share, with whom, and a strict line between emergency and administrative information — keeps the coordination practical and keeps your parent's voice in the decisions.
初级
7 分钟阅读A Caregiving Handoff That Preserves Dignity and Context
When care shifts between family members, shifts, or a new paid caregiver, what usually transfers is a list of tasks and a rushed verbal summary. A handoff template carries the cared-for person's own preferences forward too - without AI turning them into behavioural labels.
初级
7 分钟阅读Is This AI Product Safe for My Child's Data? A Privacy Checklist
A seven-point checklist — age rules, collection, retention, training use, sharing, controls, and deletion — for deciding whether an AI product gets allow, allow-with-controls, or do-not-use for your child.
初级
8 分钟阅读Chronic-Condition Administration: Build a Care Calendar, Not a Treatment Plan
Managing a chronic condition, your own or a family member's, is mostly logistics: appointments, refills, forms, transport, and follow-ups, each with an owner and a deadline. A care-operations board handles that coordination - and stops firmly at the edge of anything clinical.
中级
7 分钟阅读Archiving Family Photos and Stories Without Inventing History
AI makes it fast to caption, transcribe, and organize decades of family photos and recordings — and just as fast to quietly invent a date, a name, or a detail nobody actually confirmed. A metadata schema for consent, provenance, and uncertainty keeps the archive honest, restricts children's images by default, and keeps them out of unreviewed AI tools.
中级
9 分钟阅读A personal knowledge system that helps you retrieve, not hoard
Highlights, clippings, and AI summaries pile up without making you smarter. A small capture-to-retrieval system built around three real decisions — plus what to do about sensitive notes, other people's data, and the false privacy of a personal account.
中级
7 分钟阅读Get Consent Before You AI-Edit or Share Someone's Photo
Uploading a friend's photo to an AI tool to remove a background, swap a smile, or turn it into an illustration feels like a small, personal edit. For the person in the photo, it can be a much bigger decision they never got to make.
初级
6 分钟阅读Finding Subscription Drift Without Exposing Your Bank History
Review a locally redacted transaction export for recurring charges and drift, without ever connecting an AI tool to your bank account. A confidence-flagged merchant list, and a cancellation checklist a human actually executes.
初级
7 分钟阅读Understand a Medical Document Without Turning It Into Medical Advice
A discharge note or test report arrives full of clinical shorthand you were never taught to read. A four-column method - exact text, plain paraphrase, uncertainty, clinician question - lets AI translate the language without ever telling you what your results mean.
初级
7 分钟阅读Voice-cloning fraud: the SME controls that actually work
Three procedural controls that protect SME payments and sensitive changes when a caller or video participant can convincingly imitate a director, colleague, or supplier.
中级
7 分钟阅读Proving what is real: provenance, watermarking, and Content Credentials
What C2PA Content Credentials and watermarks can actually prove, what disappears after screenshots and re-uploads, and how an SME can publish media with an honest provenance policy.
中级
6 分钟阅读The voice on the phone sounds familiar: recognising AI-enabled scams
A calm, practical guide to voice-clone emergencies, impersonation messages, fake media, and AI-polished scams — with a family verification plan that works even when the fake looks or sounds convincing.
AI新手
7 分钟阅读What not to delegate to AI: draw your personal line
Use a practical boundary test to keep accountability, relationships, and important skills in human hands while still getting useful AI assistance.
初级
20 分钟RAG权限与访问控制:深入教程
Paragon. 视频逐步讲解生产环境中的RAG权限问题,并比较工具调用、命名空间、ACL表和基于关系的权限。这直接支持文章的核心规则:检索只能返回当前用户获准查看的来源,而且不能把源系统权限视为事后补充。
高级
30 分钟解读《欧盟人工智能法案》:将合规转化为竞争优势|Carme Artigas
MSP GLOBAL. Carme Artigas主持了促成《人工智能法案》的欧盟理事会谈判,并在视频中面向托管服务提供商讲解该法案——中小企业实际正是通过这类公司采购AI。她梳理了分阶段时间表,从2025年8月的通用人工智能行为准则,到2026年8月的合格评定期限,并说明了随之而来的具体义务,例如要求供应商提供合规文件。这些正是文章转化为运营方案的系统清点、供应商证据和责任归属工作。
高级
69 分钟智能体生态:将智能体投入生产后得到的经验
MLOps.community. Prosus的AI副总裁和一位AI工程师讲述了他们在集团旗下公司部署智能体时真正出现的问题:上线前进行提示词注入渗透测试;Jira智能体无法理解人类简写而执行了不安全的写入;通过让智能体明确展示自身假设来处理陈旧上下文;以及在降级设计中,一旦智能体增加认知负担,就将其合并或停用。这就像把文章中的失败模式登记表搬进了一场现场复盘。
高级
7 分钟用Docling提升RAG与AI智能体
IBM Technology. 视频讲解RAG和智能体的摄取环节:如何准备PDF和其他文件,使文档结构、表格和版面布局能够保留到后续检索阶段。这印证了文章的提醒:RAG的质量与安全始于嵌入之前,解析复杂业务文档时尤其如此。
高级
9 分钟阅读AI投资回报率与成熟度:如何衡量真正有效的应用
衡量AI应用成效,不能只看有多少人尝试过ChatGPT。本文提供一个衡量工作流投资回报率、质量、风险、成熟度和规模化准备程度的实用框架。
高级
10 分钟阅读企业知识RAG:权限、泄露与来源边界
只有检索过程遵守权限,企业知识助手才是安全的。本文介绍如何设计RAG来源边界、ACL筛选、文档责任归属、日志记录、过时来源处理和拒绝行为。
高级
9 分钟阅读面向中小企业的欧盟《人工智能法案》:实用治理方案
欧盟《人工智能法案》并非只给大型供应商带来法律问题。本指南为中小企业提供一套实用方案,涵盖清单盘点、风险分类、人工监督、透明度、供应商记录和分阶段落地规范。
高级
9 分钟阅读AI工作流中的人在回路设计模式
人工审核并不是含糊的安全保障。本文提供一份实用指南,帮助你确定在AI工作流中,哪些事项应由人工审批、抽查、审计、升级处理,或绝不交由AI完成。
中级
10 分钟阅读私有AI部署模式:本地、VPC、自托管与混合架构
私有AI并非单一架构。针对中小企业在隐私和控制需求下的本地模型、企业SaaS、VPC部署、自托管推理和混合模式的实用对比。
高级
10 分钟阅读生产AI失败模式:演示之后会出什么问题
AI系统通常以可预测的方式失败:幻觉、上下文过时、过度迎合、提示词注入、不安全的工具调用、模式漂移和薄弱的降级机制。这是一份面向真实工作流交付团队的生产AI失败模式清单。
高级
11 分钟阅读面向RAG的安全文档摄取:PDF、OCR、元数据与保留
RAG质量始于检索之前。本文是一份安全摄取指南,涵盖PDF、OCR、元数据、权限、来源时效性、删除、恶意软件风险和运营责任归属。
高级
10 分钟阅读如何安全地将AI连接到电子邮件、日历和CRM
将AI连接到实际使用的工具——电子邮件、日历、CRM——既能释放生产力,也会带来风险。本指南介绍2026年行之有效的集成、安全模式,以及不应逾越的界限。
中级
10 分钟阅读在Mac上运行本地AI:Ollama、LM Studio,以及7B模型究竟能做什么
本地运行AI已日趋成熟。借助Ollama或LM Studio和一台现代Mac,你可以离线、免费且私密地运行能力不俗的模型。本文将介绍哪些方法可行、哪些不可行,以及真正能从中受益的使用场景。
中级
6 分钟阅读与AI分享图像:哪些可以上传,哪些不应该上传
现代AI读取照片、图表、屏幕截图和手写内容几乎和读取文本一样轻松。本指南将实用地介绍哪些做法有效、哪些无效,以及上传任何内容前应完成的三十秒隐私检查。
AI新手
25 分钟OWASP攻击LLM的10种方式:AI漏洞揭秘
IBM Technology. 视频从提示词注入扩展到更全面的OWASP LLM十大风险——不安全的输出处理、敏感信息泄露、过度代理等。在向任何工具授予Gmail或HubSpot权限范围之前,你正需要在脑中备好这份故障模式清单。
中级
11 分钟什么是提示词注入攻击?
IBM Technology. Jeff Crume用“以$1购买一辆SUV”的例子,在10分钟内极其清楚地解释了为什么直接提示词注入与间接提示词注入是两类不同的问题,以及为什么过滤无法彻底解决任何一类。这与文章的论点直接呼应:对于任何不可逆操作,你需要最小权限范围、专用智能体账号和人在回路机制,而不是更巧妙的系统提示词。
中级
93 分钟Sam Altman|Theo Von访谈节目This Past Weekend第599期
Theo Von. 大约在第十二分钟,Altman承认与ChatGPT的对话不受法律特权保护,而且在诉讼中OpenAI可能会被要求交出这些对话。这是关于该话题引用最广的一段视频,值得听他亲口说明,而不是通过新闻片段了解。后面的谈话涉及许多其他话题,但仅这段对话就诚实回答了文章提出的问题:“公司究竟会如何处理我输入的内容?”
AI新手
13 分钟如何保障AI商业模型的安全
IBM Technology. Jeff Crume通过白板讲解了生成式AI引入风险的三个环节——数据、模型和使用方式——以及各环节应采用的良好管控措施。这有助于理解文章的观点:“务必小心”并不足够;作为员工,你需要判断自己实际面对的是哪一类风险。
初级
11 分钟什么是影子AI?网络安全威胁中的黑马
IBM Technology. 虽然观看次数低于我们通常采用的100K门槛,但它仍值得入选,因为它用很短的篇幅出色地说明了为什么员工使用个人ChatGPT账户处理工作问题,才是多数公司真正面对的风险。Crume所说的“不要只说不行,要说明怎样才行”,与文章采用的立场完全一致——目的不是禁止AI,而是让安全使用成为最省事的默认选择。
初级
13 分钟攻击LLM:提示词注入
LiveOverflow. 视频将提示词注入描述为一种经典的注入攻击,目标是混合指令与不可信数据的系统,并给出一个具体的内容审核示例:攻击者借此陷害无辜用户。从“模型是攻击目标”转变为“应用才是攻击目标”,正是文章开篇要求建立的思维方式。
高级
17 分钟保护LLM:防御提示词注入
LiveOverflow. 视频逐一讲解实际的纵深防御方案:对LLM输出进行污点分析、限制预期输出形态、用户隔离、少样本脚手架、微调、使用温度0实现确定性,以及为关键路径设置冗余。它与文章的防御体系章节几乎逐项对应。
高级