提出强制部署后AI事故报告制度,防范前沿AI对国家安全的威胁
AI threats to national security can be countered through an incident regime
- 定义'安全关键'领域,要求部署前沿AI前提交国家安全评估
- 建立三阶段事故响应机制,强制企业上报并配合政府整改
- 借鉴核能航空等领域的监管经验,适用于高风险AI系统
近期人工智能能力的进展引发了对其可能威胁国家安全的担忧,例如使恶意行为者更容易攻击关键国家基础设施,或因自主AI系统失控造成风险。与此同时,美国联邦立法者提出了初步的‘人工智能事故制度’以应对类似威胁。本文整合这两项趋势,提出一项法律强制的、针对部署后的人工智能事故制度,旨在应对人工智能系统带来的潜在国家安全威胁。首先,我们引入‘安全关键’概念,界定对国家安全构成极端风险的领域,包括民用核能、航空、生命科学双重用途敏感研究以及前沿人工智能研发。随后,详细阐述我们的事故制度提案,并通过与美国其他安全关键领域既有事故制度的类比,论证各组成部分的合理性。最后,通过一个假设场景展示该制度如何应对一起人工智能网络攻击事件。该制度分为三个阶段:第一阶段涉及对‘人工智能事故’的新型操作化定义,建议前沿人工智能提供商在部署前必须提交‘国家安全评估’;第二和第三阶段要求人工智能提供商向政府机构报告事故,并由政府介入修订其安全与防护规程,以应对未来潜在威胁。
原文摘要 · Abstract (English)
Recent progress in AI capabilities has heightened concerns that AI systems could pose a threat to national security, for example, by making it easier for malicious actors to perform cyberattacks on critical national infrastructure, or through loss of control of autonomous AI systems. In parallel, federal legislators in the US have proposed nascent 'AI incident regimes' to identify and counter similar threats. In this paper, we consolidate these two trends and present a timely proposal for a legally mandated post-deployment AI incident regime that aims to counter potential national security threats from AI systems. We start the paper by introducing the concept of 'security-critical' to describe sectors that pose extreme risks to national security, before arguing that 'security-critical' describes civilian nuclear power, aviation, life science dual-use research of concern, and frontier AI development. We then present in detail our AI incident regime proposal, justifying each component of the proposal by demonstrating its similarity to US domestic incident regimes in other 'security-critical' sectors. Finally, we sketch a hypothetical scenario where our proposed AI incident regime deals with an AI cyber incident. Our proposed AI incident regime is split into three phases. The first phase revolves around a novel operationalization of what counts as an 'AI incident' and we suggest that AI providers must create a 'national security case' before deploying a frontier AI system. The second and third phases spell out that AI providers should notify a government agency about incidents, and that the government agency should be involved in amending AI providers' security and safety procedures, in order to counter future threats to national security.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。