arXiv:2509.20394cs.CYcs.AI2025-09被引 4

用AI安全风险编号提升系统透明度,实现全生命周期治理

Blueprints of Trust: AI System Cards for End to End Transparency and Governance

  • 引入AI安全风险编号(ASH ID),与漏洞编号协同管理风险
  • 构建动态安全记录框架,统一追踪系统安全状态
  • 适合监管机构、开发者及合规团队使用

本文提出危险感知系统卡(HASC)框架,旨在提升人工智能系统开发与部署中的透明度与问责性。HASC在现有模型卡与系统卡基础上,整合了涵盖安全与防护状态的综合性动态记录。该框架引入新型AI安全风险标识(ASH ID),与现有安全标识如CVE互补,实现缺陷信息的清晰一致传递。通过提供单一可信的信息源,HASC使开发者与利益相关方能够基于全面信息,在系统全生命周期中做出更安全的决策。此外,本文还将HASC与ISO/IEC 42001:2023标准进行对比,探讨其互补应用潜力,以增强人工智能系统的透明度与问责机制。

原文摘要 · Abstract (English)

This paper introduces the Hazard-Aware System Card (HASC), a novel framework designed to enhance transparency and accountability in the development and deployment of AI systems. The HASC builds upon existing model card and system card concepts by integrating a comprehensive, dynamic record of an AI system's security and safety posture. The framework proposes a standardized system of identifiers, including a novel AI Safety Hazard (ASH) ID, to complement existing security identifiers like CVEs, allowing for clear and consistent communication of fixed flaws. By providing a single, accessible source of truth, the HASC empowers developers and stakeholders to make more informed decisions about AI system safety throughout its lifecycle. Ultimately, we also compare our proposed AI system cards with the ISO/IEC 42001:2023 standard and discuss how they can be used to complement each other, providing greater transparency and accountability for AI systems.

AI治理系统卡安全标识

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。