Eticas AI 위험 분류 체계: AI 감사 운영화를 위한 개방형 인프라
The Eticas AI Risk Taxonomy: Open Infrastructure for Operationalizing AI Audits
높은 중요도를 가진 영역에서 AI 시스템의 급속한 확산으로 인해 표준화된 평가에 대한 긴급한 수요가 발생했지만, 이 분야는 여전히 서로 다른 위험 분류 체계를 사용하여 위험을 나열하지만 실제 감사가 어떻게 수행되는지 보여주지는 않습니다. 현재 74개 이상의 AI 위험 분류 체계가 존재하며, 대부분이 단순히 위험 목록만 제공합니다. 감사의 핵심은 위험을 명명하는 것이 아니라, 실제 시스템에 대한 테스트 실행으로 변환하고, 측정 가능한 값으로 만들고, 적절한 심각도를 설정하고, 방어 가능한 등급을 부여하는 것입니다. 본 논문에서는 이러한 연결 고리를 제시합니다. 저희는 Eticas에서 구축하고 운영해 온 운영화 계층을 소개하며, 이를 공개적으로 제공되는 벤치마크를 사용하여 특정 위험(개인 식별 정보 유출)에 대해 전체 과정을 보여줍니다. 또한, 이 방법을 확장할 수 있도록 하는 개방형 분류 체계를 제시합니다. GPT-4-0314 모델에서 발견될 수 있는 정보 노출 위험을 분석한 결과, 적대적 조건이 증가함에 따라 0%, 51%, 84%의 노출률을 보였으며, 이는 정교하게 설정된 심각도 단계에 따라 E등급으로 분류되었습니다. Eticas AI 위험 분류 체계 v2.0.0은 이 예시를 중심으로 10개의 주요 범주와 20개의 하위 그룹에 걸쳐 총 76개의 활성 하위 범주를 구성하며, 규정 준수, 참조 및 학술 분야의 18개 외부 프레임워크와의 연계성을 제공합니다. 이 체계의 범주 및 하위 그룹 계층은 안정적인 URI와 SKOS/JSON-LD 배포를 통해 CC BY 4.0 라이선스로 공개되며, 특정 하위 범주 예제를 통해 운영화 계층이 심각도 임계값까지 어떻게 작동하는지 보여줍니다. 본 논문의 기여는 개념에서 실제 결과로 이어지는 과정을 명확하게 제시하며, 위험과 이를 유발하는 메커니즘을 분리하고, 개방형 코어 모델을 사용하여 기본 구조는 공개하고 방법론 조정은 실무자에게 맡기는 것입니다. 이것이 AI 감사 분야에 필요한 인프라입니다: 공유되고, 개방적이며, 실제로 작동 가능합니다.
The rapid deployment of AI systems across high-stakes domains has created urgent demand for standardized evaluation, yet the field remains fragmented across competing risk taxonomies that catalog risks without showing how an audit is executed. At least 74 AI risk taxonomies exist, and almost all stop at the catalog. The hard part of auditing is not naming a risk but operationalizing it: turning it into a test run against a real system, a measured value, a calibrated severity, and a defensible grade. This paper leads with that bridge. We present the operationalization layer Eticas has built and run, shown end to end on a single risk (PII leakage) against a public benchmark, and then the open taxonomy that makes the method scale. On GPT-4-0314, a disclosure risk that seven external frameworks require be controlled is measured at 0%, 51%, and 84% disclosure as adversarial conditioning increases, mapping through calibrated severity bands to a subcategory grade of E with a SYSTEMIC pattern. Around this example, the Eticas AI Risk Taxonomy v2.0.0 organizes 76 active subcategories across 10 categories and 20 sub-groups, with mappings to 18 external frameworks across compliance, reference, and academic tiers. Its category and sub-group layer is published under CC BY 4.0 as open semantic infrastructure with stable URIs and SKOS/JSON-LD distributions, and a worked subcategory example shows the operational layer down to its severity thresholds. The contribution is the demonstrated bridge from concept to graded finding, anchored by a clean separation of risks from the mechanisms by which they surface, and framed by an open-core model in which the conceptual scaffold is open and the methodology calibration is the practitioner layer. This is the infrastructure the AI auditing field needs: shared, open, and demonstrably operable.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.