AI 中文总结
研究针对人工智能辅助和数据转换工作流程中证据追溯及防篡改问题,提出轻量级Python库AuditWeave,它能将工作流程步骤记录到哈希链接账本,通过链验证检测篡改,评估了其记录开销等性能,保证了事件完整性。
AI 中文摘要
人工智能系统越来越多地用于协助审计、金融和医疗等受监管领域的重大决策。这带来了一项反复出现的义务:组织必须能够事后重建得出给定结论所依据的证据,并证明该推理记录未被更改。现有工具解决的是相关但不同的问题,如模型可观测性、漂移监测、治理报告等,是为操作机器学习系统的工程师构建的,而非为必须将特定结论追溯到其支持证据的审查者构建。我们提出了AuditWeave,这是一个轻量级的Python库,无运行时依赖项,它将人工智能辅助和数据转换工作流程的步骤记录到一个仅追加、哈希链接的账本中。一个小型的、与系统无关的事件词汇表涵盖了检索增强生成(RAG)管道和表格/湖仓转换,因此可以通过一条记录对两者得出的结论进行端到端追溯。在密封账本中,通过链验证可检测到事件的任何修改、重新排序、插入或删除。我们描述了设计并评估了参考实现中的记录开销、可扩展性和篡改检测的正确性。完整性保证每个事件成本为几十微秒,并且如哈希链构建所暗示的,在2000多次随机试验中,验证标记了四个突变类别的每一个注入突变。
英文摘要
AI systems are increasingly used to assist consequential decisions in regulated domains such as auditing, finance, and healthcare. This creates a recurring obligation: an organization must be able to reconstruct, after the fact, which evidence informed a given conclusion, and to show that the record of that reasoning was not altered. Existing tools address related but distinct problems - model observability, drift monitoring, governance reporting - and are built for the machine-learning engineer operating a system, not the reviewer who must trace one specific conclusion back to its supporting evidence. We present AuditWeave, a lightweight Python library, with no runtime dependencies, that records the steps of AI-assisted and data-transformation workflows into a single append-only, hash-chained ledger. A small, system-agnostic event vocabulary spans both retrieval-augmented generation (RAG) pipelines and tabular/lakehouse transformations, so a conclusion that draws on both can be traced end-to-end through one record. Within a sealed ledger, any modification, reordering, insertion, or deletion of events is detectable through chain verification. We describe the design and evaluate recording overhead, scalability, and tamper-detection correctness on the reference implementation. The integrity guarantees cost tens of microseconds per event, and, as the hash-chain construction implies, verification flagged every injected mutation across four mutation classes over 2,000 randomized trials.
Comments8 pages, 3 figures, open-source implementation at pypi.org/project/auditweave