arXiv:2606.00621cs.CRcs.AI2026-06

提出真实性债务概念,构建生成式AI内容可信治理框架

Authenticity Debt and the Synthetic Content Threat Landscape: A Layered Framework for Trust, Provenance, and IP Governance in the Generative AI Era

  • 引入真实性债务模型,系统化识别四层风险:真实、溯源、完整、责任
  • 发现现有水印、溯源等技术在对抗性环境下均存在失效风险
  • 适合企业合规与AI治理团队参考,尤其关注欧盟法案与零信任架构

生成式人工智能彻底改变了内容生产方式,使高保真文本、图像、音频和视频以近乎零边际成本创建、修改和传播。这一转变使企业与生态面临四大相互强化的真实性风险层——真实性、溯源性、完整性与责任性——传统单一控制手段难以应对。本文提出“真实性债务”概念:组织在未保留可验证的来源、完整性和责任性的情况下部署生成内容,将累积机构性法律责任,待监管、法律或市场审查时集中暴露。论文构建了生成式AI危害与攻击向量的多维分类体系,评估数字水印、溯源框架(C2PA、Adobe CAI)及检测技术的能力与失效模式,指出单一机制在开放、对抗与演化的环境中均不足。基于零信任架构与企业治理框架,提出融合密码溯源、人工审核与持续治理的分层参考架构,实现规模化可信保障。进一步分析欧盟《人工智能法案》、美国FTC与NIST AI RMF等监管环境,提出将真实性建设为组织基础设施的实践原则。

原文摘要 · Abstract (English)

Generative artificial intelligence has fundamentally changed how content is now produced. It has enabled how high-fidelity text, images, audio, and videos are created, modified, and redistributed at near-zero marginal cost. This shift exposes enterprises and ecosystems to a number of risks across four reinforcing authenticity layers -- authenticity, provenance, integrity, and accountability -- that traditional controls are inadequate to address in isolation. We introduce the concept of authenticity debt: the cumulative institutional liability that accumulates when organizations deploy AI-generated content without preserving verifiable origin, integrity, and accountability, deferring exposure that surfaces under regulatory, legal, or market scrutiny. This paper presents a comprehensive, multi-dimensional taxonomy of generative AI harms and attack vectors, surveys the capabilities and failure modes of technical controls including digital watermarking, provenance frameworks (C2PA, Adobe CAI), and detection technologies, and argues that no single mechanism is sufficient in open, adversarial, and evolving environments. Drawing on Zero Trust Architecture principles and enterprise governance frameworks, we propose a layered reference architecture that integrates cryptographic provenance, human-in-the-loop verification, and continuous governance to sustain defensible authenticity at scale. We further examine the regulatory landscape (EU AI Act, U.S.\ FTC, NIST AI RMF) and identify practical guiding principles for organizations seeking to build authenticity as institutional infrastructure rather than an afterthought.

AI治理真实性债务零信任合规

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。