AI透明化要警惕'隐蔽安全'陷阱,借鉴网络安全经验。
The Pitfalls of "Security by Obscurity" And What They Mean for Transparent AI
- 对比网络安全中对'隐蔽安全'的批判,反思AI透明化必要性。
- 提出透明与风险平衡的三类关键经验,可类比AI治理。
- 案例分析匿名化研究,揭示透明对技术演进的影响。
AI系统透明化呼声日益高涨,来自监管者、研究者和用户等多方。计算机安全领域同样重视透明性,长期反对'隐蔽安全'——即通过隐藏系统机制来实现保护。尽管行业压力持续,安全界仍逐步建立平衡透明与潜在风险的实践规范。本文探讨安全界经验对AI透明化的启示,提炼出三大核心主题:透明的益处、风险权衡机制及实践路径。通过匿名化研究子领域的案例,分析透明如何影响技术发展。最后,指出现代AI系统在透明化方面存在区别于传统安全系统的独特挑战,引发安全与AI领域共同关注的开放问题。
原文摘要 · Abstract (English)
Calls for transparency in AI systems are growing in number and urgency from diverse stakeholders ranging from regulators to researchers to users (with a comparative absence of companies developing AI). Notions of transparency for AI abound, each addressing distinct interests and concerns. In computer security, transparency is likewise regarded as a key concept. The security community has for decades pushed back against so-called security by obscurity -- the idea that hiding how a system works protects it from attack -- against significant pressure from industry and other stakeholders. Over the decades, in a community process that is imperfect and ongoing, security researchers and practitioners have gradually built up some norms and practices around how to balance transparency interests with possible negative side effects. This paper asks: What insights can the AI community take from the security community's experience with transparency? We identify three key themes in the security community's perspective on the benefits of transparency and their approach to balancing transparency against countervailing interests. For each, we investigate parallels and insights relevant to transparency in AI. We then provide a case study discussion on how transparency has shaped the research subfield of anonymization. Finally, shifting our focus from similarities to differences, we highlight key transparency issues where modern AI systems present challenges different from other kinds of security-critical systems, raising interesting open questions for the security and AI communities alike.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。