研究持续合规审计中的策略性博弈,揭示监管漏洞与防御机制。
A Benchmark for Strategic Auditee Gaming Under Continuous Compliance Monitoring

- 将持续审计建模为时间动态的斯塔克尔伯格博弈,分析监管方与被监管方的对抗。
- 发现静态审计设计存在覆盖与粒度无法同时优化的结构性缺陷。
- 提出可应对多种作弊策略的审计策略库和可复现的模拟工具,适合政策制定者使用。
新兴法规如欧盟《人工智能法案》和《数字服务法案》要求持续部署后的合规审计,催生了一类不同于以往一次性输入输出博弈的战略性游戏行为。受监管系统可通过延迟报告、在合理噪声范围内漂移数据、利用纵向样本流失,以及在模糊指标定义间选择性使用等方式规避审查。本文将连续审计形式化为审计方承诺时间策略、被审计方自适应响应的T轮斯塔克尔伯格博弈,并揭示:任何噪声感知的静态审计设计都存在‘覆盖间隙’与‘粒度间隙’无法同时弥补的结构性特征(观察1)。基于此,提出两种最小扩展策略:一种是考虑样本量的静态规则(周期下限法)可修复粒度失效,另一种是基于历史记录的怀疑升级策略可应对天真漂移策略的覆盖失效——二者均无法同时解决两类问题,符合预测。而一种利用斯塔克尔伯格承诺优势的审计外漂移策略(OffAuditDrift)则能击败两者。为支持实证研究,本文贡献了非加性危害分解(福利损失W、覆盖损失C),揭示样本流失如何将损害从监管可见区域转移至不可见区域;构建了五个被审计方策略(延迟、漂移、挑拣、流失、审计外漂移)与五个审计方策略的初始库,参数基于公开的DSA透明度数据库审计统计;并提供一个小型、可扩展的Python可复现模拟器。
原文摘要 · Abstract (English)
Continuous post-deployment compliance audits, mandated by emerging regulations such as the EU AI Act and Digital Services Act, create a class of strategic gaming distinct from the one-shot input/output gaming studied in prior work. Regulated systems can delay outcome reporting, drift their reports within plausible noise envelopes, exploit longitudinal sample attrition, and cherry-pick among ambiguous metric definitions. We formalize continuous auditing as a $T$-round Stackelberg game between an auditor that commits to a temporal policy and an adaptive auditee, and identify a structural feature of any noise-aware static-auditor design: a cover regime in which coverage gaps and granularity gaps cannot be closed simultaneously. We make this formal as Observation 1 and show that two minimal extension policies, each derived from the observation, close the regime along orthogonal axes: a sample-size-aware static rule (Periodic-with-floor) closes the granularity-failure case, while a history-conditioned suspicion-escalation policy closes the coverage-failure case for the naive Drift strategy -- and neither closes both, exactly as the observation predicts; an audit-aware OffAuditDrift strategy that exploits Stackelberg commitment defeats both. To support empirical study we contribute a non-additive harm decomposition (welfare loss $W$, coverage loss $C$) that exposes how attrition shifts harm from the regulator-accountable surface to a regulator-invisible one; an initial library of five auditee strategies (Delay, Drift, Cherry-pick, Attrition, OffAuditDrift) and five auditor policies, calibrated to summary statistics from published audits of the DSA Transparency Database; and a reproducible simulator with a small, extensible Python interface.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。