白盒、灰盒与黑盒访问下的人工智能取证:人工智能系统事后调查的过程模型与研究议程
AI Forensics Across White-, Grey-, and Black-Box Access: A Process Model and Research Agenda for Post-Incident Investigation of AI Systems
- University of Guelph(圭尔夫大学)
- Aalborg University(奥尔堡大学)
机构由 AI 辅助整理,请以论文原文为准。
AI总结:
本文以调查人员的访问权限为起点,区分白、灰、黑盒访问,提出人工智能取证过程模型矩阵,推导访问条件检查框架并确定多项开放研究问题,为AI系统事后调查提供研究议程。
AI中文摘要:
人工智能系统越来越多地参与到后续可能需要调查的决策与行动中。当发生与人工智能相关的事件时,调查人员需要重构系统的行为、其表现如此的原因,以及系统或供应链的哪一部分导致了该结果。现有的人工智能取证工作仍较为零散,通常聚焦于特定的系统类型、人工制品或分析技术。本文认为,调查人员的访问权限是组织该领域的有用起点,我们区分了白盒、灰盒与黑盒访问,并展示了每种访问级别如何改变可收集、保存、分析与报告的内容。基于此区分,我们提出了涵盖收集、保存、分析、报告四个阶段的人工智能取证过程模型矩阵,还引入了人工智能系统的易失性顺序,涵盖运行时状态、上下文窗口、日志、检索存储、模型人工制品与训练谱系。从该矩阵中,我们推导了一种访问条件下的检查框架,并确定了开放研究问题,包括黑盒保存、模型版本证明、基于代理分析的不确定性量化,以及可变人工智能人工制品的保管链。
英文摘要:
AI systems are increasingly involved in decisions and actions that may later require investigation. When an AI related incident occurs, investigators need to reconstruct what the system did, why it behaved that way, and which part of the system or supply chain contributed to the outcome. Existing work on AI forensics remains fragmented, often focusing on a specific system type, artifact, or analysis technique. This paper argues that investigator access is a useful starting point for organizing the field. We distinguish white box, grey box, and black box access and show how each access level changes what can be collected, preserved, analyzed, and reported. Based on this distinction, we propose a process model matrix for AI forensics across four phases: collection, preservation, analysis, and reporting. We also introduce an order of volatility for AI systems, covering runtime state, context windows, logs, retrieval stores, model artifacts, and training lineage. From this matrix, we derive an access conditioned examination framework and identify open research problems, including black box preservation, model version attestation, uncertainty quantification for surrogate based analysis, and chain of custody for mutable AI artifacts.