arXiv:2607.02201cs.CYcs.AI2026-07被引 1

提出可落地的AI审计框架,让风险评估从清单变成可执行测试。

The Eticas AI Risk Taxonomy: Open Infrastructure for Operationalizing AI Audits

  • 构建风险操作化层,将抽象风险转化为可测试、可评分的具体指标。
  • 在GPT-4上测出隐私数据泄露风险随攻击强度升至84%,评为系统性严重等级。
  • 开源完整风险分类体系,支持多标准对接,适合审计机构与合规团队使用。

AI系统在高风险领域快速部署,迫切需要标准化评估,但现有至少74个风险分类体系大多仅停留在风险清单层面,缺乏实际审计操作方法。真正的难点在于将风险“操作化”:转化为对真实系统的测试、可测量的数值、可校准的严重程度分级和可辩护的评估结果。本文展示埃蒂卡斯(Eticas)已构建并运行的这一操作层,以一个风险(个人身份信息泄露)为例,在公开基准上端到端演示,并推出可扩展的开放分类体系。在GPT-4-0314上,随着对抗性条件增强,该风险披露率分别达0%、51%和84%,对应严重度分级为E级,模式为系统性。埃蒂卡斯AI风险分类体系v3.0.0涵盖10大类、21个子组、70个活跃子类别,映射18个外部框架(涵盖合规、参考和学术层级)。其核心结构——类别、子组及32个已确立子类别——以CC BY 4.0协议开源,提供稳定URI及SKOS/JSON-LD格式,附带完整子类别示例,明确严重度阈值。贡献在于实现从概念到分级发现的闭环验证,通过风险与暴露机制的清晰分离,以及开核模型(概念框架开放,方法校准由实践者掌握),为整个AI审计领域提供共享、开放且可验证的基础设施。

原文摘要 · Abstract (English)

The rapid deployment of AI systems across high-stakes domains has created urgent demand for standardized evaluation, yet the field remains fragmented across competing risk taxonomies that catalog risks without showing how an audit is executed. At least 74 AI risk taxonomies exist, and almost all stop at the catalog. The hard part of auditing is not naming a risk but operationalizing it: turning it into a test run against a real system, a measured value, a calibrated severity, and a defensible grade. This paper leads with that bridge. We present the operationalization layer Eticas has built and run, shown end to end on a single risk (PII leakage) against a public benchmark, and then the open taxonomy that makes the method scale. On GPT-4-0314, a disclosure risk that seven external frameworks require be controlled is measured at 0%, 51%, and 84% disclosure as adversarial conditioning increases, mapping through calibrated severity bands to a subcategory grade of E with a SYSTEMIC pattern. Around this example, the Eticas AI Risk Taxonomy v3.0.0 organizes 70 active subcategories across 10 categories and 21 sub-groups, with mappings to 18 external frameworks across compliance, reference, and academic tiers. Its established layer - categories, sub-groups, and the 32 established subcategories - is published under CC BY 4.0 as open semantic infrastructure with stable URIs and SKOS/JSON-LD distributions, and a worked subcategory example shows the operational layer down to its severity thresholds. The contribution is the demonstrated bridge from concept to graded finding, anchored by a clean separation of risks from the mechanisms by which they surface, and framed by an open-core model in which the conceptual scaffold is open and the methodology calibration is the practitioner layer. This is the infrastructure the AI auditing field needs: shared, open, and demonstrably operable.

AI审计风险分类可操作化

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。