NLP Security and Ethics, in the Wild

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Lent, Heather, Galinkin, Erick, Chen, Yiyi, Pedersen, Jens Myrup, Derczynski, Leon, Bjerva, Johannes
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866910907309752320
author Lent, Heather
Galinkin, Erick
Chen, Yiyi
Pedersen, Jens Myrup
Derczynski, Leon
Bjerva, Johannes
author_facet Lent, Heather
Galinkin, Erick
Chen, Yiyi
Pedersen, Jens Myrup
Derczynski, Leon
Bjerva, Johannes
contents As NLP models are used by a growing number of end-users, an area of increasing importance is NLP Security (NLPSec): assessing the vulnerability of models to malicious attacks and developing comprehensive countermeasures against them. While work at the intersection of NLP and cybersecurity has the potential to create safer NLP for all, accidental oversights can result in tangible harm (e.g., breaches of privacy or proliferation of malicious models). In this emerging field, however, the research ethics of NLP have not yet faced many of the long-standing conundrums pertinent to cybersecurity, until now. We thus examine contemporary works across NLPSec, and explore their engagement with cybersecurity's ethical norms. We identify trends across the literature, ultimately finding alarming gaps on topics like harm minimization and responsible disclosure. To alleviate these concerns, we provide concrete recommendations to help NLP researchers navigate this space more ethically, bridging the gap between traditional cybersecurity and NLP ethics, which we frame as ``white hat NLP''. The goal of this work is to help cultivate an intentional culture of ethical research for those working in NLP Security.
format Preprint
id arxiv_https___arxiv_org_abs_2504_06669
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle NLP Security and Ethics, in the Wild
Lent, Heather
Galinkin, Erick
Chen, Yiyi
Pedersen, Jens Myrup
Derczynski, Leon
Bjerva, Johannes
Computation and Language
Artificial Intelligence
As NLP models are used by a growing number of end-users, an area of increasing importance is NLP Security (NLPSec): assessing the vulnerability of models to malicious attacks and developing comprehensive countermeasures against them. While work at the intersection of NLP and cybersecurity has the potential to create safer NLP for all, accidental oversights can result in tangible harm (e.g., breaches of privacy or proliferation of malicious models). In this emerging field, however, the research ethics of NLP have not yet faced many of the long-standing conundrums pertinent to cybersecurity, until now. We thus examine contemporary works across NLPSec, and explore their engagement with cybersecurity's ethical norms. We identify trends across the literature, ultimately finding alarming gaps on topics like harm minimization and responsible disclosure. To alleviate these concerns, we provide concrete recommendations to help NLP researchers navigate this space more ethically, bridging the gap between traditional cybersecurity and NLP ethics, which we frame as ``white hat NLP''. The goal of this work is to help cultivate an intentional culture of ethical research for those working in NLP Security.
title NLP Security and Ethics, in the Wild
topic Computation and Language
Artificial Intelligence
url https://arxiv.org/abs/2504.06669