arXiv:2604.17413cs.CYcs.AI2026-04被引 1

开放模型权重反更安全,限制反而加剧风险

The Open-Weight Paradox: Why Restricting Access to AI Models May Undermine the Safety It Seeks to Protect

  • 用芯片级认证等硬件层技术替代单纯限制访问
  • 全球算力集中导致限制会加剧南北差距
  • 需多边机构保障开放安全,防止技术被滥用

开放权重人工智能模型的治理常被简化为开放即风险、限制即安全的二元对立。本文挑战这一框架,指出缺乏受控替代方案的访问限制可能只是转移风险而非消除风险。全球算力资源的高度集中使开放权重模型成为全球南方实现自主AI能力的可行路径;限制此类访问不仅加深不平等,还会推动技术在无监管环境中扩散。本文提出,通过芯片级认证(如FlexHEG)、可信执行环境、机密计算等硬件层治理手段,结合软件层防护,构建纵深防御体系。威胁模型分类法将滥用路径映射至硬件、软件、制度与责任层,表明单一机制无效。为落实该思路,文章主张建立类似国际原子能机构(IAEA)功能的多边治理架构,明确防范硬件控制被用于国内压制。核心政策问题在于:如何通过技术和制度设计让开放更安全,同时应对遗留硬件过渡、规模化认证及公民权利保护等现实挑战。

原文摘要 · Abstract (English)

The governance of open-weight artificial intelligence (AI) models has been framed as a binary choice: openness as risk, restriction as safety. This paper challenges that framing, arguing that access restrictions, without governed alternatives, may displace risks rather than reduce them. The global concentration of compute infrastructure makes open-weight models one of the most viable pathways to sovereign AI capacity in the Global South; restricting such access deepens asymmetries while driving proliferation into unsupervised settings. This analysis proposes that hardware-layer governance, including chip-level attestation mechanisms such as FlexHEG, trusted execution environments, confidential computing, and complementary software-layer safeguards, offers a defense-in-depth alternative to the current binary. A threat model taxonomy mapping misuse vectors to hardware, software, institutional, and liability layers illustrates why no single governance mechanism suffices. To operationalize this approach, the paper argues that effective AI governance as a dual-use technology will likely require a multilateral institutional architecture functionally analogous, though not identical, to the role performed by the IAEA in the nuclear domain, with explicit safeguards against the co-option of hardware controls for domestic repression. The relevant policy question is how to make openness safer through technical and institutional design while addressing the transition realities of legacy hardware, attestation at scale, and civil liberties protection.

AI治理开源模型硬件安全多边机制

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。