arXiv:2506.11023cs.AIcs.SE2025-06

用知识图谱管理安全论证,让系统可靠性评估更智能、可维护。

OntoGSN: An Ontology-Based Framework for Semantic Management and Extension of Assurance Cases

  • 基于本体构建可查询的论证知识图谱,支持自动更新与验证。
  • 严格遵循GSN标准3.0规范,通过FAIR原则与社区反馈验证。
  • 适合需要动态维护系统安全论证的研究者与工程团队。

安全论证(AC)是建立对系统安全性或鲁棒性等属性信心的常见工具。尽管现有工具在静态文档化应用中提供支持,但针对动态场景(如自动驾驶)的管理仍具挑战。现有方法难以应对知识随变化而维护的高成本问题,易导致开发人员放弃或生成质量低下的论证,反而造成虚假信心。为此,本文提出OntoGSN:一个基于本体的框架,用于管理符合目标结构符号(GSN)标准的保证案例。OntoGSN采用OWL本体形式化表达GSN标准v3,并结合SWRL规则实现知识推理;提供解析器以集成主流工具,构建可查询图谱与自动化更新机制;配套设计决策仓库、SPARQL查询库及原型界面。该本体严格遵循标准文本,经由FAIR原则、OOPS框架、能力问题与社区反馈评估。其他中间件开发持续响应社区需求并接受评估。为验证实用性,我们在大型语言模型对抗鲁棒性保障的案例中展示了动态论证管理的能力。

原文摘要 · Abstract (English)

Assurance cases (ACs) are a common artifact for building and maintaining confidence in system properties such as safety or robustness. Constructing an AC can be challenging, although existing tools provide support in static, document-centric applications and methods for dynamic contexts (e.g., autonomous driving) are emerging. Unfortunately, managing ACs remains a challenge, since maintaining the embedded knowledge in the face of changes requires substantial effort, in the process deterring developers - or worse, producing poorly managed cases that instill false confidence. To address this, we present OntoGSN: an ontology and supporting middleware for managing ACs in the Goal Structuring Notation (GSN) standard. OntoGSN offers a knowledge representation and a queryable graph that can be automatically populated, evaluated, and updated. Our contributions include: a 1:1 formalization of the GSN Community Standard v3 in an OWL ontology with SWRL rules; a helper ontology and parser for integration with a widely used AC tool; a repository and documentation of design decisions for OntoGSN maintenance; a SPARQL query library with automation patterns; and a prototypical interface. The ontology strictly adheres to the standard's text and has been evaluated according to FAIR principles, the OOPS framework, competency questions, and community feedback. The development of other middleware elements is guided by the community needs and subject to ongoing evaluations. To demonstrate the utility of our contributions, we illustrate dynamic AC management in an example involving assurance of adversarial robustness in large language models.

安全论证本体知识图谱AI可信

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。