Harm reporting in the field of Artificial Intelligence (AI) currently operates on an ad hoc basis, lacking a structured process for disclosing or addressing algorithmic flaws. In contrast, the Coordinated Vulnerability Disclosure (CVD) ethos and ecosystem play a pivotal role in software security and transparency. Globally, there are ongoing efforts to establish frameworks that promote transparency and collaboration in addressing AI-related issues, though challenges persist. Algorithmic flaws in machine learning (ML) models present distinct challenges compared to traditional software vulnerabilities, warranting a specialized approach. To address this gap, we propose the implementation of a dedicated Coordinated Flaw Disclosure (CFD) framework tailored to the intricacies of machine learning and artificial intelligence issues. This paper delves into the historical landscape of disclosures in ML, encompassing the ad hoc reporting of harms and the emergence of participatory auditing. By juxtaposing these practices with the well-established disclosure norms in cybersecurity, we argue that the broader adoption of CFD has the potential to enhance public trust through transparent processes that carefully balance the interests of both organizations and the community.
翻译:当前,人工智能(AI)领域的危害报告机制处于临时性运作状态,缺乏用于披露或处理算法缺陷的结构化流程。相比之下,协调漏洞披露(CVD)的理念与生态系统在软件安全性和透明度方面发挥着关键作用。全球范围内,尽管挑战依然存在,但各方正持续努力建立促进透明度与合作以应对AI相关问题的框架。与传统软件漏洞相比,机器学习(ML)模型中的算法缺陷呈现出独特的挑战,需要专门的处理方法。为弥补这一空白,我们提出实施一种专为机器学习和人工智能问题复杂性定制的协调缺陷披露(CFD)框架。本文深入探讨了机器学习领域披露机制的历史沿革,涵盖危害的临时性报告与参与式审计的兴起。通过将这些实践与网络安全领域成熟的披露规范进行对比分析,我们认为更广泛地采用CFD框架有望通过透明化流程——在机构利益与社区诉求间实现审慎平衡——从而提升公众信任度。