AI审计需关注系统集成风险,否则再强的模型也易出问题。
A Chain Is Only as Strong as Its Weakest Link: A Scoping Review of System Integration Audits in AI

- 从组件、环境、多系统三方面评估AI集成风险
- 仅58篇文献聚焦集成审计,多数缺乏针对性措施
- 适合关注AI系统整体安全性的研究者和从业者
随着AI系统广泛嵌入各类应用,仅关注模型本身的审计已无法应对组件间交互与部署环境带来的风险。尽管系统集成在航空航天等安全关键领域长期是软件审计的核心,但在AI审计中仍鲜有研究。我们筛选4,259篇文献,识别出58篇将系统集成作为核心评估维度的AI审计研究。通过反思性主题分析,发现该领域处于萌芽但碎片化状态:现有措施极少针对集成特定风险;未能满足传统审计预期的缺口显著;信息与资源可得性极大影响审计设计。然而,集成审计可划分为三个层面(组件间、系统-环境、多系统),分别承担风险探索、风险判定、协调与程序规范功能。此类审计关注兼容性、完整性与监督等集成特性。本综述呼吁学界将系统集成纳入核心审计策略,发展能覆盖组件、环境、系统间失效的审计方法。
原文摘要 · Abstract (English)
As AI systems become increasingly integrated into diverse interfaces and applications, model-centric audits are insufficient to address risks arising from interactions among system components and deployment environments. System integration has long been central to software audits in safety-critical domains such as aerospace. However, its role in AI auditing remains underexplored. Scanning through 4,259 documents, we present a scoping review of AI audits that treat system integration as a core tenet of evaluation (n = 58). Using reflexive thematic analysis, we analyze their elements, actors, enablers, and constraints. We find that the corpus represents an emerging yet still fragmented form of AI auditing: few existing measures target integration-specific risks; large gaps remain in meeting traditional audit expectations; and access to necessary information and resources significantly influences audit design. Nonetheless, integration can be categorized across three sites (inter-component, system-environment, and multi-system), each serving the functions of risk exploration, risk determination, coordination, and procedural regularity. Deviating from other types of evaluations, these audits assess qualities specific to system integration, including compatibility, completeness, and oversight. This review calls on the AI community to prioritize system integration as a core strategy for addressing AI risk, and to develop audit practices capable of capturing failures across components, environments, and systems beyond the reach of component-level evaluation.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。