揭露投票建议应用的11种攻击方式,提出增强其抗操纵能力的方法
Recommender Systems for Democracy: Toward Adversarial Robustness in Voting Advice Applications
- 识别11种针对投票建议系统的操纵策略
- 修改匹配算法可使政党推荐率上升105%
- 适合关注数字民主与AI安全的研究者和政策制定者
投票建议应用(VAAs)帮助数百万选民了解哪些政党和候选人最符合自身立场。本文探讨了当此类应用被恶意实体攻击时对民主进程带来的潜在风险。我们揭示了11种操纵策略,并利用瑞士主要VAA Smartvote在最近两次全国选举中的数据评估其影响。结果显示,调整应用参数(如匹配方法)可使某政党的推荐频率提升最高达105%;挑选特定问卷题项可使推荐频率增加超过261%;对政党或候选人回答进行细微修改,也能导致推荐率上升248%。为应对这些漏洞,我们提出了VAA应具备的对抗鲁棒性特征,引入评估不同匹配方法韧性的实证指标,并提出未来研究方向以减轻操纵影响。本框架对确保未来AI驱动的投票建议系统安全可靠至关重要。
原文摘要 · Abstract (English)
Voting advice applications (VAAs) help millions of voters understand which political parties or candidates best align with their views. This paper explores the potential risks these applications pose to the democratic process when targeted by adversarial entities. In particular, we expose 11 manipulation strategies and measure their impact using data from Switzerland's primary VAA, Smartvote, collected during the last two national elections. We find that altering application parameters, such as the matching method, can shift a party's recommendation frequency by up to 105%. Cherry-picking questionnaire items can increase party recommendation frequency by over 261%, while subtle changes to parties' or candidates' responses can lead to a 248% increase. To address these vulnerabilities, we propose adversarial robustness properties VAAs should satisfy, introduce empirical metrics for assessing the resilience of various matching methods, and suggest possible avenues for research toward mitigating the effect of manipulation. Our framework is key to ensuring secure and reliable AI-based VAAs poised to emerge in the near future.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。