构建AI供应链风险分类体系,助力关键领域可信应用
Identifying the Supply Chain of AI for Trustworthiness and Risk Management in Critical Applications
- 提出针对数据、模型、服务等环节的供应链实体分类框架
- 帮助非专业人员系统识别组织内AI系统的依赖关系与风险点
- 聚焦医疗、交通等关键场景,推动可落地的AI风险管理
AI应用中的算法偏见、模型幻觉等风险已引发学界和用户广泛关注。然而,现代AI系统由数据源、预训练模型、智能体、服务等复杂组件构成,其供应链风险尚缺乏系统评估方法。这一缺口在食品供应、医疗、能源、法律、保险、交通等关键应用中尤为突出。本文调研了当前AI风险评估与管理现状,聚焦AI供应链及其对系统行为与输出的影响,提出一个专门用于分类AI供应链实体的框架。该框架使利益相关方,尤其是缺乏深度AI知识的人员,能“提出正确问题”,系统梳理组织内部AI系统的依赖关系。本研究弥合了现有AI治理与关键领域实际风险管控需求之间的差距。
原文摘要 · Abstract (English)
Risks associated with the use of AI, ranging from algorithmic bias to model hallucinations, have received much attention and extensive research across the AI community, from researchers to end-users. However, a gap exists in the systematic assessment of supply chain risks associated with the complex web of data sources, pre-trained models, agents, services, and other systems that contribute to the output of modern AI systems. This gap is particularly problematic when AI systems are used in critical applications, such as the food supply, healthcare, utilities, law, insurance, and transport. We survey the current state of AI risk assessment and management, with a focus on the supply chain of AI and risks relating to the behavior and outputs of the AI system. We then present a proposed taxonomy specifically for categorizing AI supply chain entities. This taxonomy helps stakeholders, especially those without extensive AI expertise, to "consider the right questions" and systematically inventory dependencies across their organization's AI systems. Our contribution bridges a gap between the current state of AI governance and the urgent need for actionable risk assessment and management of AI use in critical applications.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。