arXiv:2512.22060cs.CRcs.CL2025-12

为高风险场景下的NLP模型提供全生命周期安全合规管理框架

Toward Secure and Compliant AI: Organizational Standards and Protocols for NLP Model Lifecycle Management

  • 构建六阶段全流程框架,覆盖从开发到退役的每个环节
  • 融合差分隐私、联邦学习等技术,应对数据隐私与偏见风险
  • 适合医疗、金融等需严格合规的机构落地使用

自然语言处理系统在医疗、金融、政府等敏感领域应用日益广泛,处理大量个人及受监管数据。然而,现有AI治理框架未能充分应对由此带来的安全、隐私与合规风险。本文提出安全合规NLP生命周期管理框架(SC-NLP-LMF),基于45篇同行评审与监管文献的系统性PRISMA综述,涵盖开发至退役的六个阶段,对齐NIST AI RMF、ISO/IEC 42001:2023、欧盟人工智能法案及MITRE ATLAS等主流标准。框架整合偏差检测、隐私保护(差分隐私、联邦学习)、安全部署、可解释性与模型安全销毁等方法。通过医疗案例展示其识别新兴术语漂移(如新冠相关词汇)并指导合规更新的能力。该框架为高风险环境中NLP系统的安全可信运行提供了可操作的全周期结构。

原文摘要 · Abstract (English)

Natural Language Processing (NLP) systems are increasingly used in sensitive domains such as healthcare, finance, and government, where they handle large volumes of personal and regulated data. However, these systems introduce distinct risks related to security, privacy, and regulatory compliance that are not fully addressed by existing AI governance frameworks. This paper introduces the Secure and Compliant NLP Lifecycle Management Framework (SC-NLP-LMF), a comprehensive six-phase model designed to ensure the secure operation of NLP systems from development to retirement. The framework, developed through a systematic PRISMA-based review of 45 peer-reviewed and regulatory sources, aligns with leading standards, including NIST AI RMF, ISO/IEC 42001:2023, the EU AI Act, and MITRE ATLAS. It integrates established methods for bias detection, privacy protection (differential privacy, federated learning), secure deployment, explainability, and secure model decommissioning. A healthcare case study illustrates how SC-NLP-LMF detects emerging terminology drift (e.g., COVID-related language) and guides compliant model updates. The framework offers organizations a practical, lifecycle-wide structure for developing, deploying, and maintaining secure and accountable NLP systems in high-risk environments.

NLP安全合规管理生命周期

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。