arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.04921cs.SEcs.AI

链条的强度取决于最薄弱的环节:AI中系统集成审计的范围综述

A Chain Is Only as Strong as Its Weakest Link: A Scoping Review of System Integration Audits in AI

Leah Davis, Dominic Martin, AJung Moon

首次发表
浏览论文内容

中文总结 AI 辅助

本研究对4259篇文献中58篇以系统集成为核心的AI审计文献开展范围综述,分析其要素等内容,指出需将系统集成作为AI风险应对核心策略以完善审计实践。

中文摘要 AI 辅助

随着AI系统日益集成到各类界面和应用中,以模型为中心的审计不足以应对系统组件间交互及部署环境带来的风险。系统集成长期以来一直是航空航天等安全关键领域软件审计的核心,但它在AI审计中的作用仍未得到充分探索。我们扫描了4259篇文献,对以系统集成作为评估核心原则的AI审计开展范围综述(共纳入58篇文献)。采用反思性主题分析法,我们分析了这些审计的要素、参与者、促成因素和制约因素。研究发现,该文献集代表了一种新兴但仍碎片化的AI审计形式:现有措施中针对集成特定风险的很少;在满足传统审计期望方面仍存在巨大差距;获取必要信息和资源的机会显著影响审计设计。尽管如此,集成可分为三个场景(组件间、系统-环境间及多系统间),每个场景都具备风险探索、风险判定、协调和程序规范性的功能。与其他类型的评估不同,这些审计评估系统集成特有的属性,包括兼容性、完整性和监督。本综述呼吁AI界将系统集成作为应对AI风险的核心战略,并开发能够捕获组件级评估无法覆盖的组件、环境和系统层面故障的审计实践。

英文摘要

As AI systems become increasingly integrated into diverse interfaces and applications, model-centric audits are insufficient to address risks arising from interactions among system components and deployment environments. System integration has long been central to software audits in safety-critical domains such as aerospace. However, its role in AI auditing remains underexplored. Scanning through 4,259 documents, we present a scoping review of AI audits that treat system integration as a core tenet of evaluation (n = 58). Using reflexive thematic analysis, we analyze their elements, actors, enablers, and constraints. We find that the corpus represents an emerging yet still fragmented form of AI auditing: few existing measures target integration-specific risks; large gaps remain in meeting traditional audit expectations; and access to necessary information and resources significantly influences audit design. Nonetheless, integration can be categorized across three sites (inter-component, system-environment, and multi-system), each serving the functions of risk exploration, risk determination, coordination, and procedural regularity. Deviating from other types of evaluations, these audits assess qualities specific to system integration, including compatibility, completeness, and oversight. This review calls on the AI community to prioritize system integration as a core strategy for addressing AI risk, and to develop audit practices capable of capturing failures across components, environments, and systems beyond the reach of component-level evaluation.

发表机构

  • McGill University(麦吉尔大学)

机构由 AI 辅助整理,请以论文原文为准。

↑