Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Cattell, Sven, Ghosh, Avijit, Kaffee, Lucie-Aimée
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866909268665434112
author Cattell, Sven
Ghosh, Avijit
Kaffee, Lucie-Aimée
author_facet Cattell, Sven
Ghosh, Avijit
Kaffee, Lucie-Aimée
contents Harm reporting in Artificial Intelligence (AI) currently lacks a structured process for disclosing and addressing algorithmic flaws, relying largely on an ad-hoc approach. This contrasts sharply with the well-established Coordinated Vulnerability Disclosure (CVD) ecosystem in software security. While global efforts to establish frameworks for AI transparency and collaboration are underway, the unique challenges presented by machine learning (ML) models demand a specialized approach. To address this gap, we propose implementing a Coordinated Flaw Disclosure (CFD) framework tailored to the complexities of ML and AI issues. This paper reviews the evolution of ML disclosure practices, from ad hoc reporting to emerging participatory auditing methods, and compares them with cybersecurity norms. Our framework introduces innovations such as extended model cards, dynamic scope expansion, an independent adjudication panel, and an automated verification process. We also outline a forthcoming real-world pilot of CFD. We argue that CFD could significantly enhance public trust in AI systems. By balancing organizational and community interests, CFD aims to improve AI accountability in a rapidly evolving technological landscape.
format Preprint
id arxiv_https___arxiv_org_abs_2402_07039
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities
Cattell, Sven
Ghosh, Avijit
Kaffee, Lucie-Aimée
Artificial Intelligence
Cryptography and Security
Computers and Society
Harm reporting in Artificial Intelligence (AI) currently lacks a structured process for disclosing and addressing algorithmic flaws, relying largely on an ad-hoc approach. This contrasts sharply with the well-established Coordinated Vulnerability Disclosure (CVD) ecosystem in software security. While global efforts to establish frameworks for AI transparency and collaboration are underway, the unique challenges presented by machine learning (ML) models demand a specialized approach. To address this gap, we propose implementing a Coordinated Flaw Disclosure (CFD) framework tailored to the complexities of ML and AI issues. This paper reviews the evolution of ML disclosure practices, from ad hoc reporting to emerging participatory auditing methods, and compares them with cybersecurity norms. Our framework introduces innovations such as extended model cards, dynamic scope expansion, an independent adjudication panel, and an automated verification process. We also outline a forthcoming real-world pilot of CFD. We argue that CFD could significantly enhance public trust in AI systems. By balancing organizational and community interests, CFD aims to improve AI accountability in a rapidly evolving technological landscape.
title Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities
topic Artificial Intelligence
Cryptography and Security
Computers and Society
url https://arxiv.org/abs/2402.07039