arXiv:2608.03520cs.CRcs.AI2026-08

提出AI事故调查的全流程框架,区分三种访问权限

AI Forensics Across White-, Grey-, and Black-Box Access: A Process Model and Research Agenda for Post-Incident Investigation of AI Systems

  • 按白盒、灰盒、黑盒访问分级构建调查流程
  • 建立AI系统挥发性顺序,指导证据保全优先级
  • 针对黑盒取证等难题提出开放研究方向

AI系统在决策中日益关键,事故发生后需重建其行为路径及责任归属。现有研究零散,多局限于特定系统或分析方法。本文以调查者访问权限为切入点,区分白盒、灰盒、黑盒三类访问模式,揭示不同权限下可采集、保存、分析与报告的内容差异。基于此,提出涵盖收集、保存、分析、报告四个阶段的AI取证过程模型矩阵,并引入AI系统挥发性顺序:运行时状态、上下文窗口、日志、检索存储、模型构件、训练谱系。由此衍生出条件化审查框架,识别出若干开放问题,包括黑盒系统的证据保全、模型版本验证、基于代理模型分析的不确定性量化,以及可变AI构件的保管链管理。

原文摘要 · Abstract (English)

AI systems are increasingly involved in decisions and actions that may later require investigation. When an AI related incident occurs, investigators need to reconstruct what the system did, why it behaved that way, and which part of the system or supply chain contributed to the outcome. Existing work on AI forensics remains fragmented, often focusing on a specific system type, artifact, or analysis technique. This paper argues that investigator access is a useful starting point for organizing the field. We distinguish white box, grey box, and black box access and show how each access level changes what can be collected, preserved, analyzed, and reported. Based on this distinction, we propose a process model matrix for AI forensics across four phases: collection, preservation, analysis, and reporting. We also introduce an order of volatility for AI systems, covering runtime state, context windows, logs, retrieval stores, model artifacts, and training lineage. From this matrix, we derive an access conditioned examination framework and identify open research problems, including black box preservation, model version attestation, uncertainty quantification for surrogate based analysis, and chain of custody for mutable AI artifacts.

AI审计取证可解释性安全

Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。