arXiv:2503.01470cs.CYcs.AI2025-03被引 5

保护双方隐私才能有效评估私有AI系统

Position: Ensuring mutual privacy is necessary for effective external evaluation of proprietary AI systems

  • 提出互保隐私框架,兼顾开发者与评估者隐私
  • 现有评估方法普遍忽视评估方隐私保护
  • 建议用密码学与硬件方案解决隐私矛盾

外部评估对理解AI系统的潜在风险日益重要,但实践中需在评估者访问需求与开发者隐私安全之间取得平衡。同时,评估者也需保护自身隐私,例如确保保留测试集的完整性。本文将此双重隐私保障问题定义为‘互保隐私’挑战。我们主张:(i) 解决该挑战是实现有效外部评估的必要前提;(ii) 当前评估方法未能充分应对这一问题,尤其在保护评估者隐私方面存在明显不足。本文形式化了互保隐私问题,分析了模型所有者与评估者的隐私及访问需求,并探讨了包括密码学与硬件技术在内的潜在解决方案。

原文摘要 · Abstract (English)

The external evaluation of AI systems is increasingly recognised as a crucial approach for understanding their potential risks. However, facilitating external evaluation in practice faces significant challenges in balancing evaluators' need for system access with AI developers' privacy and security concerns. Additionally, evaluators have reason to protect their own privacy - for example, in order to maintain the integrity of held-out test sets. We refer to the challenge of ensuring both developers' and evaluators' privacy as one of providing mutual privacy. In this position paper, we argue that (i) addressing this mutual privacy challenge is essential for effective external evaluation of AI systems, and (ii) current methods for facilitating external evaluation inadequately address this challenge, particularly when it comes to preserving evaluators' privacy. In making these arguments, we formalise the mutual privacy problem; examine the privacy and access requirements of both model owners and evaluators; and explore potential solutions to this challenge, including through the application of cryptographic and hardware-based approaches.

AI评估隐私保护互保隐私

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。