揭示大模型红队测试中数据构建的社交技术实践与潜在盲区。
Red Teaming LLMs as Socio-Technical Practice: From Exploration and Data Creation to Evaluation
- 基于22位从业者访谈,分析红队数据的设计与评估流程。
- 发现现有实践忽视上下文、交互类型和用户特异性等关键因素。
- 为人机交互研究者提供拓展红队测试概念与数据方法的三方面机会。
近年来,红队测试(red teaming)作为安全领域的传统方法,已成为评估生成式人工智能安全性与可靠性的关键手段。然而,多数现有工作聚焦于技术基准和攻击成功率,对红队数据如何定义、创建和评估这一社会技术实践缺乏深入探讨。本文基于对22位参与红队数据设计与评估从业者的访谈,考察支撑该工作的数据实践与标准。由于对抗性数据集决定了模型评估的范围与准确性,它们是衡量大语言模型潜在危害的关键产物。研究贡献包括:第一,提供从业者对红队测试及其数据集构建与评估的实证理解;第二,揭示从业者对风险的认知导致对上下文、交互类型及用户特定性的忽视;第三,提出三个面向人机交互研究者的机遇,以扩展红队测试的概念框架与数据实践。
原文摘要 · Abstract (English)
Recently, red teaming, with roots in security, has become a key evaluative approach to ensure the safety and reliability of Generative Artificial Intelligence. However, most existing work emphasizes technical benchmarks and attack success rates, leaving the socio-technical practices of how red teaming datasets are defined, created, and evaluated under-examined. Drawing on 22 interviews with practitioners who design and evaluate red teaming datasets, we examine the data practices and standards that underpin this work. Because adversarial datasets determine the scope and accuracy of model evaluations, they are critical artifacts for assessing potential harms from large language models. Our contributions are first, empirical evidence of practitioners conceptualizing red teaming and developing and evaluating red teaming datasets. Second, we reflect on how practitioners' conceptualization of risk leads to overlooking the context, interaction type, and user specificity. We conclude with three opportunities for HCI researchers to expand the conceptualization and data practices for red-teaming.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。