1.中国电信集团有限公司网络和信息安全管理部,北京 100140
2.中国电信股份有限公司研究院,上海 200120
张侃(1970- ),男,博士,中国电信集团有限公司网络和信息安全管理部正高级工程师、高级资深专家,主要研究方向为信息通信、网信技术。
王诗雨(1995- ),女,中国电信股份有限公司研究院工程师、软件安全能力中心研究员,主要研究方向为软件供应链安全、安全有效性验证、人工智能技术。
朱沛潼(2000- ),男,中国电信股份有限公司研究院科研助理,主要研究方向为信息安全技术。
徐帅健妮(1994- ),女,博士,中国电信股份有限公司研究院高级工程师,软件安全能力中心副总监,主要研究方向为软件供应链安全、内生安全、容器镜像安全和密码学。
殷铭(1994- ),男,中国电信股份有限公司研究院工程师、软件安全能力中心副总监,主要研究方向为软件供应链安全、移动应用安全。
何国锋(1973- ),男,博士,中国电信股份有限公司研究院正高级工程师,安全应用技术研发部主任,主要研究方向为信息通信、网信安全。
收稿:2025-09-08,
修回:2025-12-26,
录用:2026-01-08,
网络首发:2026-07-21,
纸质出版:2026-06-20
移动端阅览
张侃,王诗雨,朱沛潼等.AIBOM在运营商大模型软件安全治理中的应用与发展研究[J].电信科学,2026,42(06):231-242.
Zhang Kan,Wang Shiyu,Zhu Peitong,et al.Research on application and development of AIBOM in large-scale model software security governance for telecom operators[J].Telecommunications Science,2026,42(06):231-242.
张侃,王诗雨,朱沛潼等.AIBOM在运营商大模型软件安全治理中的应用与发展研究[J].电信科学,2026,42(06):231-242. DOI: 10.11959/j.issn.1000-0801.DXKX250538.
Zhang Kan,Wang Shiyu,Zhu Peitong,et al.Research on application and development of AIBOM in large-scale model software security governance for telecom operators[J].Telecommunications Science,2026,42(06):231-242. DOI: 10.11959/j.issn.1000-0801.DXKX250538.
随着人工智能(artificial intelligence,AI)技术在电信行业的快速应用,大模型软件安全作为“底座安全”,治理需求日益凸显。人工智能物料清单(artificial intelligence bill of material,AIBOM)作为软件物料清单(software bill of material,SBOM)的延伸,能够系统化呈现组件、模型与数据等信息,成为保障大模型软件可信与合规的关键抓手。首先,梳理了AIBOM的定义、核心要素以及其与传统SBOM的区别,强调其在大模型软件安全治理中的战略价值。其次,通过行业案例分析,总结了AIBOM落地过程中的技术与治理难点。在此基础上,从电信运营商视角出发,探讨了大模型软件安全治理的独特挑战,并阐述了AIBOM在应对AI资产透明度、跨部门协同和合规监管等问题上的核心作用。最后,以中国电信实践为例,展示了其在标准政策、工具链与风险管控方面的探索经验,并提出了未来演进方向。
With the rapid adoption of artificial intelligence (AI) technologies in the telecommunications industry
the security of large-scale model software—serving as the “foundation of safety”—has become an increasingly pressing governance demand. As an extension of the software bill of material (SBOM)
the artificial intelligence bill of material (AIBOM) systematically records information related to components
models
and datasets
and has emerged as a key instrument to ensure the trustworthiness and compliance of large-scale AI systems. Firstly
the definition and core elements of AIBOM were reviewed
as well as its distinctions from traditional SBOM
its strategic significance in large-model software security governance was highlighted. Then industry cases were analyzed to summarize technical and governance challenges in AIBOM adoption. Building on this
the unique challenges faced by telecom operators in large-model software security governance were explored
and the central role of AIBOM in addressing AI asset transparency
cross-departmental coordination
and regulatory compliance was elaborated. Finally
the practices of China Telecom were drawn on to demonstrate exploratory efforts in standards
toolchains
and risk management
and future research directions for AIBOM development were outlined.
韩炳涛 , 刘涛 . 大模型关键技术与应用 [J ] . 中兴通讯技术 , 2024 , 30 ( 2 ): 76 - 88 .
Han B T , Liu T . Key technologies and applications of large models [J ] . ZTE Technology Journal , 2024 , 30 ( 2 ): 76 - 88 .
欧阳晔 , 王立磊 , 杨爱东 , 等 . 通信人工智能的下一个十年 [J ] . 电信科学 , 2021 , 37 ( 3 ): 1 - 36 .
Ouyang Y , Wang L L , Yang A D , et al . Next decade of telecommunications artificial intelligence [J ] . Telecommunications Science , 2021 , 37 ( 3 ): 1 - 36 .
中国移动 . 2023电信AI产业发展白皮书 [R ] . 2023 .
China Mobile . White paper on AI industry development in telecommunications 2023 [R ] . 2023 .
乔喆 . 人工智能生成内容技术在内容安全治理领域的风险和对策 [J ] . 电信科学 , 2023 , 39 ( 10 ): 136 - 146 .
Qiao Z . Risks and countermeasures of artificial intelligence generated content technology in content security governance [J ] . Telecommunications Science , 2023 , 39 ( 10 ): 136 - 146 .
工业和信息化部 , 国家标准化管理委员会 . 国家人工智能产业综合标准化体系建设指南 (2024版) [R ] . 2024 .
Ministry of Industry and Information Technology , Standardization Administration of China . Guidelines for the construction of a comprehensive standardization system for the artificial intelligence industry (2024 Edition) [R ] . 2024 .
新华网 . 建立人工智能安全监管制度 [N ] . 新华网 , 2024-11-06 .
Xinhuanet . Establishing an artificial intelligence security supervision system [N ] . Xinhuanet , 2024-11-06 .
中共中央政治局 . 把握人工智能发展规律 构建风险预警体系 [N ] . 人民网 , 2025-04-26 .
The Political Bureau of the CPC Central Committee . Grasping the law of artificial intelligence development and building a risk early warning system [N ] . People's Daily Online , 2025-04-26 .
王戈 , 郭新海 , 刘安 , 等 . 基于SBOM的软件安全治理实践 [J ] . 邮电设计技术 , 2023 ( 8 ): 9 - 13 .
Wang G , Guo X H , Liu A , et al . Practice of software security governance based on SBOM [J ] . Designing Techniques of Posts and Telecommunications , 2023 ( 8 ): 9 - 13 .
SPDX Workgroup . SPDX AI BOM draft specification 3.0 [EB ] . 2023 .
Santos O , Radanliev P . Toward trustworthy AI: an analysis of artificial intelligence (AI bill of materials) (AI BOMs) [EB ] . 2023 .
国家发展和改革委员会 . 新一代人工智能发展规划 [R ] . 2017 .
National Development and Reform Commission . Development plan for a new generation of artificial intelligence [R ] . 2017 .
Xia B , Zhang D , Liu Y , Lu Q , Xing Z , Zhu L . Trust in software supply chains: blockchain-enabled SBOM and the AIBOM future [EB ] . 2023 .
Bennet K , Rajbahadur G K , Suriyawongkul A , et al . Implementing AI bill of materials (AI BOM) with SPDX 3.0: a comprehensive guide to creating AI and dataset bill of materials [PP ] . V1. arXiv ( 2025-04-23 )[ 2025-09-08 ] . arXiv: 2504.16743 .
陈禹存 , 黄科满 , 杜小勇 . 基于生命周期与风险防范双视角的数据流通安全技术体系 [J ] . 大数据 , 2024 , 10 ( 6 ): 16 - 32 .
Chen Y C , Huang K M , Du X Y . A data circulation security technology system based on the dual perspectives of lifecycle and risk prevention [J ] . Big Data Research , 2024 , 10 ( 6 ): 16 - 32 .
中国联通 . 中国通信运营商AI+DevOps实践报告 (2024) [R ] . 2024 .
China Unicom . Report on AI+DevOps practices of Chinese telecom operators (2024) [R ] . 2024 .
牛红韦华 , 黄永宝 , 丁国强 , 等 . 基于数据和知识驱动的超万卡智算集群稳定性保障实践 [J ] . 电信科学 , 2025 , 41 ( 7 ): 145 - 163 .
Niu H W H , Huang Y B , Ding G Q , et al . A data and knowledge-driven practice for ensuring stability in ultra-large intelligent computing clusters [J ] . Telecommunications Science , 2025 , 41 ( 7 ): 145 - 163 .
曹建峰 , 方龄曼 . 欧盟人工智能伦理与治理的路径及启示 [J ] . 人工智能 , 2019 ( 4 ): 39 - 47 .
Cao J F , Fang L M . The path and enlightenment of EU artificial intelligence ethics and governance [J ] . AI-View , 2019 ( 4 ): 39 - 47 .
0
浏览量
0
下载量
0
CSCD
关联资源
相关文章
相关作者
相关机构
京公网安备11010802024621