厘清安全评估的科学标准,避免无效测试
What Makes an Evaluation Useful? Common Pitfalls and Best Practices
- 从威胁建模出发设计评估方案,确保针对性
- 明确评估需具备可重复性、覆盖性和灵敏度
- 适合研究者与开发者构建可信评估体系
近年来人工智能能力迅速提升,引发对潜在安全风险的关注。为支持人工智能系统安全使用与发展的决策,亟需高质量的能力评估。尽管已有若干尝试,但“优质评估”的标准尚未达成共识。本文基于模型评估的既有研究,结合网络安全案例,提出一套实践指南。首先梳理评估设计的初始思考流程,将威胁建模与评估方案相衔接;其次阐明使评估具有实用价值的特征与参数;最后探讨从单个评估到构建完整评估套件的扩展考量。本指南旨在推动更可靠、可比且有意义的安全评估实践。
原文摘要 · Abstract (English)
Following the rapid increase in Artificial Intelligence (AI) capabilities in recent years, the AI community has voiced concerns regarding possible safety risks. To support decision-making on the safe use and development of AI systems, there is a growing need for high-quality evaluations of dangerous model capabilities. While several attempts to provide such evaluations have been made, a clear definition of what constitutes a "good evaluation" has yet to be agreed upon. In this practitioners' perspective paper, we present a set of best practices for safety evaluations, drawing on prior work in model evaluation and illustrated through cybersecurity examples. We first discuss the steps of the initial thought process, which connects threat modeling to evaluation design. Then, we provide the characteristics and parameters that make an evaluation useful. Finally, we address additional considerations as we move from building specific evaluations to building a full and comprehensive evaluation suite.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。