AISPA: 사용자 중심 시스템 프롬프트 감사 - 대규모 언어 모델 애플리케이션
AISPA: User-Centric System Prompt Auditing for Large Language Model Applications
시스템 프롬프트는 개발자가 인공지능 애플리케이션에서 기반 모델의 동작을 제어하도록 구성하는 지시문입니다. 이들은 상업용 AI 제품 전반에 걸쳐 사용되지만, 공개되거나 규제 기관에 보고되는 경우는 드물어, 광범위하게 배포되는 AI 시스템에서 심각한 신뢰 및 책임성 격차를 야기합니다. 본 논문에서는 인공지능 시스템 프롬프트 보증(AISPA)이라는 사용자 중심의 체계적인 시스템 프롬프트 감사 프레임워크를 소개합니다. AISPA는 시스템 프롬프트의 특정 부분을 검토하고, 사용자와 관련된 8가지 측면에서 평가합니다. 우리는 이 프레임워크를 사용하여 88개의 상업용 AI 제품에 포함된 3,249개의 지시문을 검토하고, 각 지시문을 사용자 보호적인지 또는 문제가 있는지 분류했습니다. 우리의 감사는 다음과 같은 네 가지 주요 결과를 보여줍니다. 첫째, 시스템 프롬프트 설계는 제품 및 개발자 간에 상당한 차이를 보이며, 일부 조직은 제품당 평균 60개 이상의 사용자 보호 지시문을 포함하는 반면 다른 조직은 5개 미만을 포함합니다. 둘째, 사용자 보호적인 지시문은 광범위하게 채택되지만 범위가 제한적입니다. 98.9%의 제품에 최소 하나 이상의 사용자 보호 지시문이 포함되어 있지만, AISPA 분류의 8가지 모든 측면을 다루는 제품은 24%에 불과합니다. 셋째, 시스템 프롬프트는 꾸준히 길어지고 사용자 보호적인 내용이 더 많이 포함되는 경향을 보이며, 이는 상업용 프롬프트 설계에서 사용자 보호가 점점 더 중요한 문제로 인식되고 있음을 시사합니다. 넷째, 이러한 발전에도 불구하고 문제가 있는 지시문은 여전히 만연해 있습니다. 약 40%의 제품에 사용자의 이익에 반하는 최소 한 가지 이상의 지시문이 포함되어 있으며, 사용자 보호적인 지시문과 문제가 있는 지시문이 동일한 프롬프트 내에서 공존하는 경우가 많습니다. 우리의 연구 결과는 상업용 AI 제품의 시스템 프롬프트에 대한 더 큰 투명성, 표준화 및 독립적인 감독이 필요하다는 점을 강조합니다.
System prompts are instructions configured by developers to govern the behaviors of foundation models in AI applications. They are used throughout commercial AI products, but are rarely disclosed to the public or regulators, creating a serious trust and accountability gap in the wide deployment of AI systems. In this paper, we introduce Artificial Intelligence System Prompt Assurance (AISPA), a user-centric framework for systematically auditing system prompts in AI systems. AISPA examines specific parts of a system prompt and evaluates them along eight dimensions that matter to users. We then use this framework to review 3,249 instructions from system prompts in 88 commercial AI products, classifying each instruction as either protective (of users) or problematic. Our audit surfaces four core findings. First, system prompt design varies substantially across products and developers, with some organizations averaging over 60 protective instructions per product while others average fewer than 5. Second, protective instructions are widely adopted but shallow in scope: 98.9% of products contain at least one, yet only 24% cover all eight dimensions of the AISPA taxonomy. Third, system prompts have grown steadily longer and more protective of users, suggesting that user protection is becoming a more visible concern in commercial prompt design. Fourth, despite this progress, problematic instructions remain pervasive: roughly 40% of products contain at least one instruction that works against user interests, and protective and problematic instructions frequently coexist within the same prompt. Our findings highlight the need for greater transparency, standardization, and independent oversight for system prompts in commercial AI products.
No Analysis Report Yet
This paper hasn't been analyzed by Gemini yet.
Log in to request an AI analysis.