虎嗅

**Competitive Integrity: From ‘Passive Defense’ to ‘Game Theory Ontology’**

原文:对抗性完整:从「被动防御」到「博弈论本体论」

Summary of Key Points

This article introduces a new security concept called "Adaptive Resilience," which breaks away from the limitations of traditional "passive defense" approaches. Traditional security views threats as occasional "abnormalities" that can be prevented by building barriers, adding locks, and setting up defenses. In contrast, Adaptive Resilience recognizes that deception, conflict, errors, and divergent interests are inherent in the real world. System security should not rely on "perfect entities" (people or AI that are always correct) but rather on designing "trustworthy structures" that allow systems to remain intact and functional even in the face of continuous challenges. In simple terms, it shifts from trying to keep threats out to ensuring that the system can withstand them even if they are already inside.

Detailed Analysis

1. The "Naivety" of Traditional Security: Assuming Threats Are Always "Outside"

The fundamental assumption of traditional security is that the world is normal, with good people acting according to rules and bad people being external anomalies. Examples include building walls to defend against enemies, installing firewalls to prevent hackers, and conducting audits to stop external theft. However, reality shows otherwise:

  • Companies often fail not due to external attacks but because of internal misconduct by executives (such as embezzlement).
  • Financial crises are not caused by a few bad actors but by everyone making choices that are beneficial to themselves but detrimental to the overall system (e.g., everyone borrowing money to buy houses, leading to a bubble burst).
  • Even our own impulsive spending (internal risks) can be more destructive than theft.

Key Issue: Threats are never solely external; they are often inherent in systems, stemming from human greed, misjudgments, and organizational flaws. Passive defense is like installing security doors on a house without addressing the potential for internal damage.

2. The Secret of Civilizational Progress: Moving From "Finding Good People" to "Building Structures"

In ancient times, governance relied on "wise rulers and virtuous officials," expecting them to be perfect. However, history has shown that no one is always good (emperors can be incompetent, and officials can be corrupt). Modern systems are smarter in that they focus on designing structures that can function even with imperfect individuals:

  • Separation of powers (legislation, executive, and judicial branches) ensures that even if the president acts improperly, Congress can veto or the court can hold him accountable.
  • Corporate financial approval processes require multiple signatures from finance and board members to prevent misuse of funds.
  • Banks conduct regular credit checks on customers, even those with a good track record, because they may face sudden financial difficulties.

Core Logic: Mature systems do not place their hopes on human integrity but use structures to mitigate the impact of errors, ensuring that even good people's mistakes do not cause the system to collapse.

3. A Change in Worldview: From "Coping with Risks" to "Playing a Game of Strategy"

Previously, we viewed risks as static events (e.g., earthquakes, server failures) that could be predicted. Now, we face strategic interactions where opponents will adapt to our actions:

  • If you implement expense approval processes, employees may find more concealed ways to obtain reimbursements.
  • If you introduce purchase restrictions, people may fake divorces to buy houses.
  • If you restrict AI permissions, hackers will develop new attack methods.

Key Difference: Risks are static, but strategic interactions are dynamic. Blocking one vulnerability will only lead to the emergence of others. Therefore, the goal of security is no longer to eliminate risks but to ensure that the system does not collapse despite external threats.

4. Adaptive Resilience: Accepting Imperfection Without Letting It Destroy Everything

"Resilience" does not mean that systems will never experience problems; it means they can withstand them. For example:

  • Bridges are designed to withstand strong winds, not to be completely windproof.
  • Aircraft have redundant parts (e.g., dual engines) in case one fails.
  • Democracies allow for disagreements and resolve them through rules.

Core Principle of Adaptive Resilience: The ability to recover from errors without being completely destroyed. This means allowing for mistakes without letting them cause catastrophic failures. For instance, a payment system will have transaction logs, refund mechanisms, and multiple verification steps to limit the impact of individual errors.

5. In the Age of AI, Avoid Old Mistakes: Focus on Managing "Boundaries of Actions"

With the increasing use of AI agents (e.g., automated report writing, software operations), people often try to create "perfect" AI models. However, this is as naive as expecting a perfect ruler in ancient times. AI can have misunderstandings and be vulnerable to attacks. The right approach is to:

  • Limit what AI can do (e.g., it can provide investment advice but not transfer funds directly).
  • Separate judgment from execution (AI analyzes, humans make final decisions).
  • Retain the ability to override AI decisions (e.g., humans can still cancel actions).

Analogie: You wouldn't let a child use a bank card freely; instead, you give them pocket money to control their spending. Similarly, we need to restrict AI's capabilities within a structured framework.

Conclusion

Adaptive Resilience is not about being more pessimistic but about being more realistic. It acknowledges that the world is imperfect, but we can design systems that can accommodate these imperfections and still function effectively. This is true maturity.