arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~

关于人工智能系统工程中的人工智能安全与保障技术债务

On AI Safety and Security Technical Debt in Engineering AI-Enabled Systems

Muhammad Tukur, Hayatullahi B. Adeyemo, Tao Chen, Nour Ali, Anis Zarrad, Rick Kazman, Marco Agus, Rami Bahsoon

arXiv 2607.23365首次发表:更新:

发表机构

University of Birmingham; HBKU; Bournemouth University; Brunel University London; University of Hawaii; College of Science and Engineering, HBKU(伯明翰大学; 哈马德·本·哈利法大学; 伯恩茅斯大学; 伦敦布鲁内尔大学; 夏威夷大学; 哈马德·本·哈利法大学科学与工程学院)

机构由 AI 辅助整理,请以论文原文为准。

AI 中文总结

研究人工智能系统工程中的安全与保障技术债务,通过系统综述识别31种AITD并分类,分析其与信任问题的关联,合成34条指南,引入AITD - MAP框架,助工程师应对AITDs。

AI 中文摘要

人工智能系统越来越多地部署在医疗、自动驾驶、金融和教育等高风险领域。其复杂性、快速演变及对动态数据管道的依赖带来了人工智能技术债务(AITDs)。AITDs源于数据治理、模型实施等多方面。许多AITDs是潜在的,会导致维护挑战等问题。本研究以人工智能信任、风险和安全管理原则为指导,通过可信度维度重新诠释技术债务。对60项主要研究进行系统综述,识别出31种不同类型的AITD并分类。分析其与18个信任相关问题的关联,合成34条可操作指南。在此基础上引入AITD - MAP框架,旨在帮助人工智能软件工程师识别、理解并减轻AITDs。

英文摘要

Artificial intelligence (AI) systems are increasingly deployed in high-stakes domains such as healthcare, autonomous driving, finance, and education. While these systems offer powerful data-driven and adaptive capabilities, their complexity, rapid evolution, and dependence on dynamic data pipelines introduce new forms of engineering liability collectively referred to as AI Technical Debts (AITDs). AITDs arise from root causes spanning data governance, model implementation, algorithm design, architectural decisions, operational processes, documentation practices, and testing adequacy. Unlike conventional technical debt, many AITDs are latent and propagate across tightly coupled AI pipelines, leading to maintenance challenges, reliability degradation, and heightened safety or security risks. Guided by the principles of AI Trust, Risk, and Security Management (AI TRiSM), this study reinterprets technical debt through the interconnected dimensions of trustworthiness, focusing on AI safety and security technical debts. We conduct a systematic review of 60 primary studies and identify 31 distinct types of AITD, which are organized into a root-cause-oriented taxonomy comprising seven classes. The analysis examines how these debts map to 18 trust-related concerns, including 6 safety hazards and 12 security vulnerabilities. To support mitigation, the review synthesizes 34 actionable guidelines (8 safety and 26 security) targeting the prevention, detection, and reduction of AITDs across the AI lifecycle. Building on these findings, we introduce AITD-MAP, an integrated framework that connects the AITD taxonomy, quality and risk impacts, and mitigation strategies into a unified structure for risk-aware AI engineering. The framework aims to assist AI software engineers in making AI safety and security technical debts visible, understanding their root causes, and mitigating their presence.

Comments64 pages, 7 figures, 8 tables, submitted to ACM Transactions on Software Engineering and Methodology (TOSEM)

论文原文

arXiv 摘要页 · PDF 原文 · HTML 原文

↑