厘清AI审计所需访问权限,平衡安全与透明
From Transparency to Accountability and Back: A Discussion of Access and Evidence in AI Auditing
- 提出四种访问权限并分析其利弊,主张至少给予黑盒访问权
- 黑盒访问可兼顾商业秘密保护与审计效率,是最低必要条件
- 将审计建模为假设检验,为政策制定提供可解释框架
人工智能日益深度介入社会生活,引发对其未预见和未声明副作用的广泛关注。这促使人们关注人工智能审计问题:对AI系统及其开发过程与行为进行系统性评估,以符合既定标准。审计形式包括部署前风险评估、持续监控和合规测试,在保障开发者、用户等多方利益方面至关重要。然而,实际执行中存在诸多挑战。本文聚焦核心操作难题:开展有效审计需要何种系统访问权限?这一问题具有直接政策意义,可指导审计规范制定。我们分析审计员在选择访问权限时需权衡的因素,梳理四类访问方式的优劣。结论指出,至少应授予黑盒访问(即仅允许查询模型输出,不暴露内部实现),该方式在保护商业机密、数据隐私、审计标准化与效率间取得平衡。随后提出一个扩展访问权限的框架,将审计视为自然的假设检验,借鉴法律程序中的逻辑,认为此视角能为审计实施提供清晰且可理解的指引。
原文摘要 · Abstract (English)
Artificial intelligence (AI) is increasingly intervening in our lives, raising widespread concern about its unintended and undeclared side effects. These developments have brought attention to the problem of AI auditing: the systematic evaluation and analysis of an AI system, its development, and its behavior relative to a set of predetermined criteria. Auditing can take many forms, including pre-deployment risk assessments, ongoing monitoring, and compliance testing. It plays a critical role in providing assurances to various AI stakeholders, from developers to end users. Audits may, for instance, be used to verify that an algorithm complies with the law, is consistent with industry standards, and meets the developer's claimed specifications. However, there are many operational challenges to AI auditing that complicate its implementation. In this work, we examine a key operational issue in AI auditing: what type of access to an AI system is needed to perform a meaningful audit? Addressing this question has direct policy relevance, as it can inform AI audit guidelines and requirements. We begin by discussing the factors that auditors balance when determining the appropriate type of access, and unpack the benefits and drawbacks of four types of access. We conclude that, at minimum, black-box access -- providing query access to a model without exposing its internal implementation -- should be granted to auditors, as it balances concerns related to trade secrets, data privacy, audit standardization, and audit efficiency. We then suggest a framework for determining how much further access (in addition to black-box access) to grant auditors. We show that auditing can be cast as a natural hypothesis test, draw parallels hypothesis testing and legal procedure, and argue that this framing provides clear and interpretable guidance on audit implementation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。