arXiv:2502.03467cs.CYcs.AI2025-02被引 5

从航空系统安全工程看AI安全框架的短板与改进方向

Where AI Assurance Might Go Wrong: Initial lessons from engineering of critical systems

  • 以航空等关键系统为范本,梳理安全工程的系统化方法
  • 指出当前AI安全风险评估缺乏足够边界与可接受标准
  • 强调高可靠性需求下需用更严谨的保证案例支撑决策

本文基于在对社会至关重要的系统(如飞机飞行控制)中开展系统与软件安全保障及评估的经验,总结传统关键系统中的安全工程实践。分析这些经验如何支持人工智能安全框架的构建,从系统工程、安全与风险分析、决策分析与支持三方面展开。提出四个核心问题:系统是什么?需要达到多好?关键性如何影响开发?应信任到何种程度?识别出亟待深入讨论的议题:系统边界过窄、风险可接受性与性质未充分阐明、保证方法缺乏理论基础以确保行为可靠性。主张采用基于Assurance 2.0的保证案例,同时评估决策与系统的双重关键性。强调关键系统所需信心量级远高于日常系统,现有常规技术无法满足其严格要求。最后将研究发现映射至FAISC组织提出的两个问题,并指出关键系统工程通过开放多元讨论持续演进。期望本文所提议题能推动后续对话。

原文摘要 · Abstract (English)

We draw on our experience working on system and software assurance and evaluation for systems important to society to summarise how safety engineering is performed in traditional critical systems, such as aircraft flight control. We analyse how this critical systems perspective might support the development and implementation of AI Safety Frameworks. We present the analysis in terms of: system engineering, safety and risk analysis, and decision analysis and support. We consider four key questions: What is the system? How good does it have to be? What is the impact of criticality on system development? and How much should we trust it? We identify topics worthy of further discussion. In particular, we are concerned that system boundaries are not broad enough, that the tolerability and nature of the risks are not sufficiently elaborated, and that the assurance methods lack theories that would allow behaviours to be adequately assured. We advocate the use of assurance cases based on Assurance 2.0 to support decision making in which the criticality of the decision as well as the criticality of the system are evaluated. We point out the orders of magnitude difference in confidence needed in critical rather than everyday systems and how everyday techniques do not scale in rigour. Finally we map our findings in detail to two of the questions posed by the FAISC organisers and we note that the engineering of critical systems has evolved through open and diverse discussion. We hope that topics identified here will support the post-FAISC dialogues.

AI安全系统工程风险评估保证案例

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。