Testing AI Agent: Quy Trình QA Và Quản Trị Rủi Ro

Admin T5Edu
— Lượt đọc
#testing#ai agents#qa/qc
Testing AI Agent: Quy Trình QA Và Quản Trị Rủi Ro
Chi tiết ảnh bìa
Testing AI Agent: Quy Trình QA Và Quản Trị Rủi Ro

Kiểm thử AI Agent không chỉ kiểm tra câu trả lời, mà còn đánh giá kế hoạch, tool call, memory, guardrail và trạng thái cuối. Bài viết giúp Tester, QA, QC xây test case, tìm root cause và kiểm soát rủi ro trước production.

Kiểm thử AI Agent là gì?

Kiểm thử AI Agent là quá trình đánh giá một hệ thống có thể nhận mục tiêu, lập kế hoạch, gọi công cụ, thay đổi trạng thái và tự điều chỉnh qua nhiều bước. Tester không chỉ kiểm tra câu trả lời cuối mà phải xác minh toàn bộ chuỗi hành vi:

Mục tiêu → Kế hoạch → Tool call → Observation → Cập nhật trạng thái → Dừng hoặc tiếp tục

Agent được mô tả qua các thành phần như LLM Core, planning, memory, tool interface và execution engine. Đây cũng là các bề mặt cần tách riêng khi thiết kế test.

Ví dụ, một agent xử lý hoàn tiền có thể đọc yêu cầu, truy vấn đơn hàng, kiểm tra chính sách, gọi API hoàn tiền rồi cập nhật CRM. Dù response nghe hợp lý, hệ thống vẫn có thể lỗi nếu agent dùng sai order_id, gọi tool hai lần, dùng memory sai người hoặc báo thành công khi backend chưa thay đổi.

Anthropic lưu ý agent khó đánh giá hơn ứng dụng một lượt vì chúng gọi tool qua nhiều vòng, sửa trạng thái môi trường và thích ứng theo kết quả trung gian. Sai sót ở bước sớm có thể lan sang toàn bộ workflow.

Ba nhóm hành vi Tester cần kiểm tra

Mỗi nhóm cần test oracle và bằng chứng riêng.

Quyết định

Agent có hiểu đúng intent, lập kế hoạch hợp lý và chọn đúng bước tiếp theo không?

Hành động

Agent có gọi đúng tool, đúng tham số, đúng số lần và trong phạm vi quyền không?

Trạng thái

Agent có đọc đúng observation, cập nhật memory và dừng đúng điều kiện không?

AI Agent khác chatbot ở đâu?

Đối tượngPhạm vi kiểm thửRủi ro chính
ChatbotInput, response, groundednessNội dung sai hoặc không phù hợp
Workflow cố địnhRule, API, databaseLogic xử lý sai
AI AgentGoal, plan, tool, memory, trajectory, guardrailHành động sai, vượt quyền, lặp hoặc tạo side effect

Một chatbot trả lời sai chủ yếu tạo nội dung sai. Một AI Agent quyết định sai có thể gửi email, sửa dữ liệu hoặc tạo giao dịch. Vì vậy, AI Agent testing phải tập trung vào hành vi và tác động, không chỉ chất lượng câu chữ.

Agent báo “đã hoàn tiền” nhưng backend không có giao dịch mới. QA nên kiểm tra gì trước?

Chọn một đáp án

Wide 3:1 educational diagram explaining AI agent testing as system testing. Layout: left section contains a goal card labeled 'Mục tiêu'; center section contains connected blocks labeled 'Kế hoạch', 'Tool', 'Quan sát', 'Bộ nhớ'; right section contains outcome and stop gates labeled 'Kết quả' and 'Dừng'. A solid T5Edu Blue arrow connects the normal execution path, while dashed Amber arrows connect tool failure and stale memory back to the planning block. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Test oracle và bản đồ rủi ro AI Agent

Hai lần chạy có thể dùng cách diễn đạt hoặc lộ trình khác nhau nhưng vẫn cùng đúng. Tester cần phân biệt phần được phép biến đổi và phần bắt buộc ổn định.

Google Cloud tách việc đánh giá AI Agent thành final response evaluationtrajectory evaluation. Cách tiếp cận này giúp phát hiện trường hợp output đúng nhưng agent dùng sai tool, bỏ qua bước xác minh hoặc đi qua một đường rủi ro.

Tester nên kết hợp năm loại oracle:

  • Outcome oracle: Trạng thái nghiệp vụ cuối có đúng không?
  • Trajectory oracle: Các checkpoint bắt buộc có xuất hiện không?
  • Tool oracle: Tool, tham số và số lần gọi có đúng không?
  • Safety oracle: Agent có vi phạm quyền, policy hoặc giới hạn không?
  • Evidence oracle: Kết luận có được observation thực tế hỗ trợ không?

Bốn nhóm rủi ro cốt lõi

NIST AI Risk Management Framework tổ chức quản trị rủi ro theo bốn chức năng Govern, Map, Measure và Manage. Khi áp dụng cho QA, team cần xác định ai sở hữu rủi ro, agent có quyền truy cập gì, rủi ro được đo bằng test nào và control nào được kích hoạt khi xảy ra lỗi.

Bản đồ rủi ro cho AI Agent

Dùng để tạo risk register và ưu tiên test.

Sai quyết định

Hiểu sai intent, thiếu bước xác minh hoặc kết luận không có bằng chứng.

Sai hành động

Chọn nhầm tool, truyền sai tham số, gọi trùng hoặc vượt quyền.

Sai context

Memory cũ, dữ liệu nhiễm độc, trộn tenant hoặc parser hiểu sai observation.

Mất kiểm soát

Lặp vô hạn, vượt ngân sách, không dừng hoặc không chuyển human review.

Về bảo mật, OWASP Top 10 for Agentic Applications 2026 cung cấp khung rủi ro cho hệ thống có khả năng lập kế hoạch và hành động. MITRE ATLAS bổ sung các kỹ thuật tấn công như prompt injection, context poisoning, tool poisoning, tool invocation và exfiltration qua tool. Tester có thể dùng hai nguồn này để xây adversarial test thay vì chỉ thử một vài prompt “xấu”.

Wide 3:1 risk and oracle map for AI agent testing. Layout: five oracle cards labeled 'Outcome', 'Trajectory', 'Tool', 'Safety', 'Evidence' connected to four risk cards labeled 'Quyết định', 'Hành động', 'Context', 'Kiểm soát'. Solid T5Edu Blue connectors show validation coverage, while dashed Amber connectors show how an early failure propagates to the business outcome. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Cách test AI Agent theo sáu lớp

Một chiến lược hiệu quả không bắt đầu bằng end-to-end test. Tester nên tách hệ thống thành sáu lớp để cô lập lỗi nhanh hơn.

  1. Input, prompt và policy

Kiểm tra input thiếu dữ liệu, instruction mâu thuẫn, yêu cầu ngoài phạm vi, PII, direct prompt injection và indirect prompt injection nằm trong website, email, file hoặc tool output.

Expected phải nêu rõ agent cần tiếp tục, hỏi lại, từ chối hay chuyển human review.

  1. Planning và decision

Xác minh agent hiểu đúng intent, có đủ bước bắt buộc, xác minh trước khi ghi dữ liệu và không tự tạo giả định để lấp thông tin thiếu.

  1. Tool calling và integration

Test từng tool với input sai, timeout, rate limit, permission denied, output rỗng, sai schema, partial success và response bị mất sau khi side effect đã xảy ra.

Microsoft Foundry tách process evaluation thành tool selection, tool input accuracy, tool output utilization và tool call success. Đây là các tiêu chí trực tiếp để thiết kế test cho tool calling.

  1. Memory, retrieval và state

Kiểm tra dữ liệu đúng người dùng, đúng tenant, đúng phiên bản; retrieval không lấy tài liệu gần nghĩa nhưng sai nghiệp vụ; suy luận của model không bị lưu thành sự thật chưa xác minh.

  1. Orchestration và recovery

Mô phỏng tool lỗi, callback trễ, response bị mất, cùng action bị gọi lại, agent đạt mục tiêu nhưng vẫn tiếp tục hoặc vượt step, time và cost budget.

  1. End-to-end, safety và business outcome

Xác minh đồng thời trạng thái backend, audit log, quyền, approval gate, privacy, rollback, alert và kill switch.

Bốn hướng fault injection nên có

Cố tình làm hỏng từng lớp để kiểm tra recovery.

Prompt

Xóa ràng buộc hoặc chèn instruction độc hại.

Tool

Trả timeout, output rỗng hoặc trạng thái thành công giả.

Memory

Đưa dữ liệu cũ, sai tenant hoặc mâu thuẫn.

Orchestration

Làm mất response, đảo callback hoặc gọi action hai lần.

Wide 3:1 layered AI agent testing strategy. Layout: six horizontal layers labeled 'Input', 'Planning', 'Tool', 'Memory', 'Recovery', 'E2E'. A solid T5Edu Blue path connects all layers, while dashed Amber fault-injection arrows enter the prompt, tool, memory and recovery layers. Add a shield and business outcome gate at the final layer. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Cách viết test case và đánh giá AI Agent

Một test case AI Agent nên có:

  1. Mục tiêu nghiệp vụ.
  2. Precondition và quyền.
  3. Input cùng context.
  4. Tool được phép và hành động bị cấm.
  5. Expected outcome.
  6. Checkpoint bắt buộc trong trajectory.
  7. Evidence cần thu thập.
  8. Stop condition hoặc escalation.
  9. Số lần chạy và ngưỡng pass.

Anthropic phân biệt task, trial, graderoutcome. Vì output có thể thay đổi, một scenario nên được chạy nhiều trial; outcome cần đo trạng thái thực tế trong môi trường, không dựa vào việc agent tự tuyên bố đã hoàn thành.

Bảng Testcase
9 dòng x 6 cột

Metric QA nên theo dõi

  • Task completion và business outcome correctness.
  • Intent resolution và task adherence.
  • Tool selection, tool input accuracy và tool call success.
  • Duplicate side effect và recovery rate.
  • Guardrail violation, privacy incident và authorization incident.
  • Số bước, latency và chi phí trên mỗi task.
  • Tỷ lệ trace có đủ evidence.
  • Regression theo model, prompt, tool và policy version.

OpenAI khuyến nghị bắt đầu debug bằng trace vì trace ghi lại model call, tool call, guardrail và handoff. Khi đã xác định được hành vi tốt, team có thể chuyển trace thành dataset và eval run để kiểm tra regression.

Metric nào phát hiện agent chọn đúng tool nhưng dùng sai kết quả trả về?

Chọn một đáp án

Wide 3:1 test case and evaluation diagram for AI agents. Layout: a left test case card flows into trajectory checkpoints, tool assertions and a right business outcome gate; below it, metric cards are grouped into 'Outcome', 'Process' and 'Safety'. Solid T5Edu Blue arrows connect evidence to metrics and regression tests, while Amber markers highlight duplicate side effects and missing evidence. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Cách xác định root cause khi AI Agent lỗi

Thông báo lỗi cuối thường chỉ là triệu chứng. Root cause có thể nằm ở prompt, planner, tool description, API, parser, memory, state machine hoặc hạ tầng.

Nguyên tắc quan trọng nhất:

Tìm điểm sai lệch đầu tiên giữa trace thực tế và hành vi kỳ vọng.

Quy trình điều tra

  1. Thu thập input, model, prompt version, tool version, memory snapshot và environment.
  2. Đọc trace theo thứ tự thời gian.
  3. So sánh từng action và observation với checkpoint.
  4. Xác định bước sai đầu tiên.
  5. Cô lập tầng lỗi bằng mock, replay hoặc bypass.
  6. Chạy tool độc lập trước khi kết luận lỗi model.
  7. Chuyển defect thành regression test.
Tầng lỗiDấu hiệuCách cô lập
Goal hoặc promptHiểu sai nhiệm vụGiữ tool cố định, rút gọn input
PlanningThiếu bước hoặc sai thứ tựBypass bằng plan chuẩn
Tool selectionChọn nhầm chức năngMock danh sách tool
Tool inputSai ID, kiểu hoặc formatValidate schema
Tool executionTimeout, permission, partial successGọi tool ngoài agent
ObservationRaw output đúng nhưng state saiSo sánh parser với response gốc
MemoryDữ liệu cũ hoặc sai tenantChạy lại với memory rỗng
OrchestrationLặp, retry trùng, dừng sớmReplay từ checkpoint
GuardrailChặn sai hoặc không chặnKiểm tra policy log
Wide 3:1 root-cause analysis diagram for AI agents. Layout: a chronological trace with nodes for goal, plan, tool selection, tool execution, observation, memory and stop condition. The earliest incorrect node is highlighted in Amber and labeled 'Root cause', while later nodes are labeled 'Triệu chứng'. Solid T5Edu Blue arrows show execution; dashed Amber paths show mock, replay, bypass and memory isolation. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Checklist quản trị rủi ro trước production

Release gate cần dựa trên mức tự chủ và hậu quả của hành động. Agent chỉ đọc dữ liệu có mức rủi ro khác agent được phép ghi dữ liệu, chuyển tiền hoặc thay đổi production.

Bốn mức hành động cần kiểm soát

Guardrail tăng theo hậu quả nếu agent sai.

Chỉ đọc

Kiểm soát quyền truy cập, PII, context và groundedness.

Tạo đề xuất

Yêu cầu evidence và cảnh báo khi thông tin chưa được xác minh.

Ghi dữ liệu

Bắt buộc idempotency, audit log, permission và rollback.

Hành động nghiêm trọng

Bắt buộc human approval, giới hạn phạm vi và kill switch.

Release gate tối thiểu

  • Tool chỉ có quyền tối thiểu.
  • Tool ghi dữ liệu hỗ trợ idempotency.
  • Có allowlist và denylist cho action.
  • Có step, time, token và cost limit.
  • Retry được phân loại theo loại lỗi.
  • PII và secret được mask.
  • Nội dung từ website, email, file và tool output được xem là dữ liệu không tin cậy.
  • Prompt injection không thể thay đổi system policy.
  • Hành động nghiêm trọng có human approval.
  • Có audit log, alert, rollback và kill switch.
  • Có regression suite cho các action rủi ro cao.
  • Có monitoring sau deployment.

NIST nhấn mạnh quản trị rủi ro cần diễn ra liên tục trong vòng đời hệ thống, không kết thúc tại thời điểm release. Với AI Agent, điều này đặc biệt quan trọng vì model, prompt, tool và dữ liệu có thể thay đổi độc lập.

Những control nào trực tiếp giảm side effect ngoài ý muốn?

Chọn nhiều đáp án

Câu hỏi thường gặp

Wide 3:1 production risk governance diagram for AI agents. Layout: four autonomy levels labeled 'Chỉ đọc', 'Đề xuất', 'Ghi dữ liệu', 'Nghiêm trọng', each connected to stronger controls including permission, evidence, idempotency, approval, audit, rollback and kill switch. Solid T5Edu Blue arrows show release progression; Amber gates block high-impact actions without approval. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Tổng kết

  • Kiểm thử AI Agent phải bao phủ goal, planning, tool, observation, memory, orchestration, guardrail và business outcome.
  • Test oracle cần đánh giá cả kết quả cuối, trajectory, evidence và side effect.
  • Root cause nên được tìm từ điểm sai lệch đầu tiên trong trace.
  • Quản trị rủi ro cần quyền tối thiểu, idempotency, approval gate, monitoring và regression test liên tục.

Nếu team đang phát triển AI Agent, hãy đưa Tester, QA, QC tham gia từ giai đoạn thiết kế tool contract, success criteria và risk register. Bạn có thể tham khảo thêm kiến thức nền tảng tại T5Edu ISTQB và các bài chuyên môn tại T5Edu Blogs.

Hành động nguy hiểm nhất mà AI Agent của bạn có thể tự thực hiện là gì, và test case nào đang chứng minh control tương ứng hoạt động đúng?

Wide 3:1 editorial summary diagram for AI agent quality assurance. Layout: four connected blocks labeled 'Hiểu hệ thống', 'Kiểm thử theo lớp', 'Tìm root cause', 'Quản trị rủi ro', ending in a verified production gate. Solid T5Edu Blue arrows connect the lifecycle, while Amber checkpoints appear at evidence validation, tool side effects and human approval. Minimalist flat vector UI design, premium professional EdTech editorial artwork, clean bento-grid composition with strong negative space, Paper White and Zinc-50 background #fafafa, Zinc-900 content #18181b, T5Edu Blue accent #1a73e8, Amber highlights #f59e0b, subtle one-pixel borders and restrained liquid-glass layers, simple flat icons and clean connector lines, no people, no faces, no hands, no 3D, no glossy plastic, no photorealism, no dramatic lighting, no purple, no violet, no pink, no neon, no logo, no watermark.

Tiến độ đọc0%
T5Edu Logo
T5.tester

Nền tảng học Testing dành cho người mới. Học qua bài tập thực hành, được chấm bài và nhận phản hồi chi tiết.

© 2026 T5Edu. D.T.Quyen

Xem thêm về blog lập trình