构建多层风险评分框架,评估高风险领域AI系统的漏洞与暴露程度。
CORTEX: Composite Overlay for Risk Tiering and Exposure in Operational AI Systems
- 基于1200+事故数据,将漏洞分为29类技术风险
- 融合法规、环境与动态模拟,生成可操作的综合风险分
- 适合监管机构和企业做模型审计与动态治理
随着人工智能系统在医疗、金融、教育、司法和基础设施等高风险领域的广泛应用,其失效带来的实际系统性风险日益凸显。本文提出CORTEX(复合风险分级与暴露框架),基于对AI事件数据库(AIID)中1200余起事故的实证分析,将故障模式划分为29个技术漏洞类别。该框架采用五层架构:(1)调整效用的损益乘积计算;(2)与欧盟AI法案、NIST RMF、OECD原则等法规对齐的治理与情境叠加;(3)覆盖漂移、可追溯性、对抗风险等暴露面的技术表面评分;(4)针对部署环境定制的环境与残余修正因子;(5)通过贝叶斯风险聚合与蒙特卡洛模拟进行多层评估,以建模波动性和长尾风险。最终生成的综合评分可用于AI风险登记、模型审计、合规检查及动态治理仪表板。
原文摘要 · Abstract (English)
As the deployment of Artificial Intelligence (AI) systems in high-stakes sectors - like healthcare, finance, education, justice, and infrastructure has increased - the possibility and impact of failures of these systems have significantly evolved from being a theoretical possibility to practical recurring, systemic risk. This paper introduces CORTEX (Composite Overlay for Risk Tiering and Exposure), a multi-layered risk scoring framework proposed to assess and score AI system vulnerabilities, developed on empirical analysis of over 1,200 incidents documented in the AI Incident Database (AIID), CORTEX categorizes failure modes into 29 technical vulnerability groups. Each vulnerability is scored through a five-tier architecture that combines: (1) utility-adjusted Likelihood x Impact calculations; (2) governance + contextual overlays aligned with regulatory frameworks, such as the EU AI Act, NIST RMF, OECD principles; (3) technical surface scores, covering exposure vectors like drift, traceability, and adversarial risk; (4) environmental and residual modifiers tailored to context of where these systems are being deployed to use; and (5) a final layered assessment via Bayesian risk aggregation and Monte Carlo simulation to model volatility and long-tail risks. The resulting composite score can be operationalized across AI risk registers, model audits, conformity checks, and dynamic governance dashboards.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。