Ciberdefesa e LLMs no Sul Global: governança, vulnerabilidades e autonomia

Autores

DOI:

https://doi.org/10.5902/2357797597309

Palavras-chave:

LLMs, Ciberdefesa, Autonomia estratégica, Dependência tecnológica, Sul Global

Resumo

Este artigo investiga em que medida a adoção de Modelos de Linguagem de Grande Porte (LLMs) em rotinas de ciberdefesa, especialmente quando consumidos como serviço em nuvem e integrados a fluxos de dados sensíveis, amplia vulnerabilidades e compromete a autonomia estratégica de países do Sul Global. Argumenta-se que a dependência estrutural de LLMs proprietários e de infraestrutura de nuvem centralizada cria três ordens de risco interconectadas: técnico-operacional (vulnerabilidades em sistemas LLM-integrados), jurídico-institucional (questões de jurisdição, governança de dados e auditoria em ambientes não controlados) e geopolítico-estrutural (condicionamento ou negação de acesso em cenários de crise). Utilizando um quadro analítico que combina dependência tecnológica, soberania digital e colonialidade, e artefatos como matrizes de vulnerabilidade, o estudo corrobora a hipótese de que a opacidade, a assimetria de auditoria e a concentração de infraestrutura digital exacerbam esses riscos. Conclui-se que a modernização da ciberdefesa no Sul Global exige que a autonomia seja operacionalizada em requisitos objetivos de governança — como auditabilidade, controle de atualização e acesso a logs — para evitar que a adoção de LLMs se traduza em dependência operacional opaca.

Downloads

Não há dados estatísticos.

Biografia do Autor

Onildo Ribeiro de Assis II, Universidade do Tocantins

Analista de Sistemas; Administrador; Professor, Universidade do Tocantins, Paraíso, TO, Brasil.

Ana Isabella Bezerra Lau Ribeiro, Universidade do Tocantins

Advogada; Mestre pela Universidade Federal da Paraíba; Professora, Universidade do Tocantins, Paraíso, TO, Brasil.

Referências

ACHARYA, Amitav. The End of American World Order. Cambridge: Polity Press, 2014.

BIGGIO, Battista; NELSON, Blaine; LASKOV, Klaus. Poisoning attacks against support vector machines. In: INTERNATIONAL CONFERENCE ON MACHINE LEARNING, 29., 2012, Edinburgh. Proceedings… New York: ACM, 2012. p. 1467-1474. Disponível em: https://dl.acm.org/doi/10.5555/3042573.3042724. Acesso em: 22 jun. 2026.

BIGGIO, Battista; ROLI, Fabio. Wild patterns: Ten years after the rise of adversarial machine learning. Pattern Recognition, Amsterdam, v. 84, p. 317-331, 2018. Disponível em: https://doi.org/10.1016/j.patcog.2018.07.023. Acesso em: 16 jun. 2026.

BRASIL. Decreto nº 12.573, de 4 de agosto de 2025. Institui a Estratégia Nacional de Cibersegurança. Diário Oficial da União: seção 1, Brasília, DF, 5 ago. 2025a. Disponível em: https://www.planalto.gov.br/ccivil_03/_ato2023-2026/2025/decreto/D12573.htm. Acesso em: 18 jun. 2026.

BRASIL. Decreto nº 12.725, de 18 de novembro de 2025. Aprova a Política Nacional de Defesa, a Estratégia Nacional de Defesa e o Livro Branco de Defesa Nacional. Diário Oficial da União: seção 1, Brasília, DF, 18 nov. 2025b. Disponível em: https://www.planalto.gov.br/ccivil_03/_ ato2023-2026/2025/decreto/D12725.htm. Acesso em: 16 jun. 2026.

BRASIL. Lei nº 13.709, de 14 de agosto de 2018. Lei Geral de Proteção de Dados Pessoais (LGPD). Diário Oficial da União: seção 1, Brasília, DF, 15 ago. 2018. Disponível em: https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm. Acesso em: 22 jun. 2026.

BRASIL. Ministério da Defesa. Doutrina Militar de Defesa: DMiD (MD51-M-04). 3. ed. Brasília, DF: Ministério da Defesa, 2025. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/estado-maior-conjunto-das-forcas-armadas/doutrina-militar/publicacoes-1/publicacoes/md51-m-04-doutrina-militar-de-defesa-dmid-3a-ed-2025.pdf. Acesso em: 18 jun. 2026.

BRASIL. Ministério da Defesa. Livro Branco de Defesa Nacional. Brasília, DF: Ministério da Defesa, 2020b. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/copy_of_estado-e-defesa/livro_branco_congresso_nacional.pdf. Acesso em: 05 jun. 2026.

BRASIL. Ministério da Defesa. Política Nacional de Defesa e Estratégia Nacional de Defesa. Brasília, DF: Ministério da Defesa, 2020a. Disponível em: https://www.gov.br/defesa/pt-br/assuntos/copy_of_estado-e-defesa/pnd_end_congressonacional_22_07_2020.pdf. Acesso em: 18 jun. 2026.

BURRELL, Jenna. How the machine ‘thinks’: Understanding opacity in machine learning algorithms. Big Data & Society, v. 3, n. 1, p. 1-12, 2016. Disponível em: https://doi. org/10.1177/2053951715622512. Acesso em: 17 jun. 2026.

CARDOSO, Fernando Henrique; FALETTO, Enzo. Dependência e desenvolvimento na América Latina: ensaio de interpretação sociológica. 2. ed. Rio de Janeiro: Zahar Editores, 1979.

CARLINI, Nicholas et al. Extracting Training Data from Large Language Models. In: USENIX SECURITY SYMPOSIUM, 30., 2021, Vancouver. Proceedings… Berkeley, CA: USENIX Association, 2021. Disponível em: https://www.usenix.org/conference/usenixsecurity21/presentation/carlini-extracting. Acesso em: 18 jun. 2026.

COULDRY, Nick; MEJIAS, Ulises A. The Costs of Connection: How Data Is Colonizing Human Life and Appropriating It for Capitalism. Stanford: Stanford University Press, 2019.

DOS SANTOS, Theotonio. The Structure of Dependence. The American Economic Review, Nashville, v. 60, n. 2, p. 231-236, 1970.

ESTADOS UNIDOS. Department of the Army. U.S. Army Training and Doctrine Command. TRADOC Pamphlet 525-3-1: The U.S. Army in Multi-Domain Operations 2028. Fort Eustis, VA: TRADOC, 2018. Disponível em: https://adminpubs.tradoc.army.mil/pamphlets/TP525-3-1.pdf. Acesso em: 02 jun. 2026.

ESTADOS UNIDOS. Department of Defense. Summary of the Joint All-Domain Command and Control (JADC2) Strategy. Washington, DC: DoD, 2022. Disponível em: https://media. defense.gov/2022/Mar/17/2002958406/-1/-1/1/SUMMARY-OF-THE-JOINT-ALL-DOMAIN-COMMAND-AND-CONTROL-STRATEGY.PDF. Acesso em: 18 jun. 2026.

FARRELL, Joseph; KLEMPERER, Paul. Coordination and Lock-In. In: ARMSTRONG, Mark; PORTER, Robert H. (ed.). Handbook of Industrial Organization. Amsterdam: Elsevier, 2007. v. 3, cap. 31, p. 1973-2025.

GEBRU, Timnit et al. Datasheets for Datasets. arXiv preprint arXiv:1803.09010, 2018. Disponível em: https://arxiv.org/abs/1803.09010. Acesso em: 02 jun. 2026.

GRESHAKE, Kai et al. Not what you’ve signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection. arXiv, 2023. Disponível em: https://arxiv.org/abs/2302.12173. Acesso em: 05 jun. 2026.

ISSMAEL JÚNIOR, Ali Kamel. Operações Multidomínio (MDO) no Sul Global: modelo mínimo viável para C2 e dados. InterAção, Santa Maria, v. 17, n. 2, e95275, p. 1-24, jun. 2026. DOI: https://doi.org/10.5902/2357797595275. Acesso em: 10 jun. 2026.

MITCHELL, Margaret et al. Model Cards for Model Reporting. In: CONFERENCE ON FAIRNESS, ACCOUNTABILITY, AND TRANSPARENCY, 2019, Atlanta. Proceedings… New York: ACM, 2019. p. 220-229. Disponível em: https://dl.acm.org/doi/10.1145/3287560.3287596. Acesso em: 05 jun. 2026.

NEIVA FILHO, Ivan Ferreira; SILVA, Karen Cristina Leal da. Base Industrial de Defesa Brasileira: vetor estruturante da soberania, da inovação tecnológica e do aumento da competitividade industrial. InterAção, Santa Maria, v. 17, n. 2, e96176, p. 1-30, jun. 2026. DOI: https://doi. org/10.5902/2357797596176. Acesso em: 09 jun. 2026.

NIST. Artificial Intelligence Risk Management Framework (AI RMF 1.0). Gaithersburg, MD: National Institute of Standards and Technology, 2023. Disponível em: https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf. Acesso em: 08 jun. 2026.

NIST. Computer Security Incident Handling Guide (SP 800-61 Rev. 2). Gaithersburg, MD: National Institute of Standards and Technology, 2012. Disponível em: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf. Acesso em: 18 jun. 2026.

NIST. Contingency Planning Guide for Federal Information Systems (SP 800-34 Rev. 1). Gaithersburg, MD: National Institute of Standards and Technology, 2010. Disponível em: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf. Acesso em: 11 jun. 2026.

NIST. Guide to Computer Security Log Management (SP 800-92). Gaithersburg, MD: National Institute of Standards and Technology, 2006. Disponível em: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-92.pdf. Acesso em: 18 jun. 2026.

NIST. Guide to Industrial Control Systems (ICS) Security (SP 800-82 Rev. 2). Gaithersburg, MD: National Institute of Standards and Technology, 2015. Disponível em: https://nvlpubs.nist. gov/nistpubs/SpecialPublications/NIST.SP.800-82r2.pdf. Acesso em: 22 jun. 2026.

NIST. Managing Information Security Risk: Organization, Mission, and Information System View (SP 800-39). Gaithersburg, MD: National Institute of Standards and Technology, 2013. Disponível em: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-39.pdf. Acesso em: 22 jun. 2026.

NIST. Secure Software Development Framework (SSDF) Version 1.1 (SP 800-218). Gaithersburg, MD: National Institute of Standards and Technology, 2022. Disponível em: https://csrc.nist.gov/pubs/sp/800/218/final. Acesso em: 10 jun. 2026.

ORGANIZAÇÃO DO TRATADO DO ATLÂNTICO NORTE (OTAN). AJP-3.10: Allied Joint Doctrine for Electronic Warfare. Bruxelas: OTAN, 2015. Disponível em: https://mpsotc.army.gr/wp-content/uploads/2024/03/2.-AJP-3.10-EDA-V1-E.pdf. Acesso em: 18 jun. 2026.

ORGANIZAÇÃO DO TRATADO DO ATLÂNTICO NORTE (OTAN). AJP-3.20: Allied Joint Doctrine for Cyberspace Operations. Bruxelas: OTAN, 2018. Disponível em: https://iwar.org.uk/wp-content/uploads/2021/06/AJP-3.20-EDA-V1-E.pdf. Acesso em: 10 jun. 2026.

OWASP. OWASP Top 10 for Large Language Model Applications. OWASP Foundation, 2024. Disponível em: https://owasp.org/www-project-top-10-for-large-language-model-applications/. Acesso em: 02 jun. 2026.

PASQUALE, Frank. The Black Box Society: The Secret Algorithms That Control Money and Information. Cambridge, MA: Harvard University Press, 2015.

POCHMANN, Pablo Gustavo Cogo. A revolução da simulação construtiva no Sul Global: comparativo do uso do software SWORD. InterAção, Santa Maria, v. 17, n. 2, e96435, p. 1-15, jun. 2026. DOI: https://doi.org/10.5902/2357797596435. Acesso em: 18 jun. 2026.

PREBISCH, Raúl. The Economic Development of Latin America and Its Principal Problems. New York: United Nations, 1950. Disponível em: https://repositorio.cepal.org/handle/11362/29973. Acesso em: 18 jun. 2026.

QUIJANO, Aníbal. Coloniality of Power, Eurocentrism, and Latin America. Nepantla: Views from South, Durham, v. 1, n. 3, p. 533-580, 2000. Disponível em: https://doi.org/10.1215/15314201-1-3-533. Acesso em: 09 jun. 2026.

SHOKRI, Reza et al. Membership Inference Attacks Against Machine Learning Models. In: IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 38., 2017, San Jose. Proceedings… Piscataway, NJ: IEEE, 2017. p. 3-18. Disponível em: https://ieeexplore.ieee.org/document/7958568. Acesso em: 22 jun. 2026.

STEINHARDT, Jacob; KOH, Pang Wei; LIANG, Percy. Certified defenses for data poisoning attacks. In: ADVANCES IN NEURAL INFORMATION PROCESSING SYSTEMS (NEURIPS), 2017. Proceedings… 2017. Disponível em: https://arxiv.org/abs/1706.03691. Acesso em: 18 jun. 2026.

TOUVRON, Hugo et al. Llama 2: Open Foundation and Fine-Tuned Chat Models. arXiv preprint arXiv:2307.09288, 2023. Disponível em: https://arxiv.org/abs/2307.09288. Acesso em: 22 jun. 2026.

TRAMÈR, Florian et al. Stealing Machine Learning Models via Prediction APIs. In: USENIX SECURITY SYMPOSIUM, 25., 2016, Austin. Proceedings… Berkeley, CA: USENIX Association, 2016. p. 601-614. Disponível em: https://www.usenix.org/conference/usenixsecurity16/technical-sessions/presentation/tramer. Acesso em: 22 jun. 2026.

UNCTAD. Digital Economy Report 2021: Cross-border Data Flows and Development: For whom the data flow. Geneva: United Nations Conference on Trade and Development, 2021. Disponível em: https://unctad.org/publication/digital-economy-report-2021. Acesso em: 18 jun. 2026.

UNITED STATES. Clarifying Lawful Overseas Use of Data Act (CLOUD Act). Washington, DC: U.S. Congress, 2018. Disponível em: https://www.congress.gov/bill/115th-congress/house-bill/4943. Acesso em: 20 jun. 2026.

ZOU, Andy et al. Universal and Transferable Adversarial Attacks on Aligned Language Models. arXiv preprint arXiv:2307.15043, 2023. Disponível em: https://arxiv.org/abs/2307.15043. Acesso em: 22 jun. 2026.

Downloads

Publicado

2026-10-02