用信息流视角定义可解释性,兼顾透明与隐私保护。
An Information-Flow Perspective on Explainability Requirements: Specification and Verification
- 用带反事实因果量化的时序知识逻辑建模信息流动
- 可验证系统是否满足让用户获知原因的可解释要求
- 适合研究可解释性与隐私平衡的系统设计者
可解释系统向交互主体披露某些现象发生的原因信息。我们主张这种正向信息流需被明确定义、验证,并与可能破坏隐私保障的负向信息流相权衡。由于可解释性与隐私均涉及对知识的推理,本文采用扩展了反事实因果量化的时序知识逻辑来处理这些问题。该方法可形式化指定多智能体系统是否暴露足够信息,使各主体获得对某结果成因的知识。我们展示了如何将可解释性作为系统级需求进行规范,并提供针对有限状态模型的验证算法。通过原型实现与多个基准测试,验证了该方法能有效区分可解释与不可解释系统,并支持附加隐私约束的表达。
原文摘要 · Abstract (English)
Explainable systems expose information about why certain observed effects are happening to the agents interacting with them. We argue that this constitutes a positive flow of information that needs to be specified, verified, and balanced against negative information flow that may, e.g., violate privacy guarantees. Since both explainability and privacy require reasoning about knowledge, we tackle these tasks with epistemic temporal logic extended with quantification over counterfactual causes. This allows us to specify that a multi-agent system exposes enough information such that agents acquire knowledge on why some effect occurred. We show how this principle can be used to specify explainability as a system-level requirement and provide an algorithm for checking finite-state models against such specifications. We present a prototype implementation of the algorithm and evaluate it on several benchmarks, illustrating how our approach distinguishes between explainable and unexplainable systems, and how it allows to pose additional privacy requirements.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。