arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.27102cs.AIcs.CR

LAAF:面向大语言模型应用的分层问责架构框架

LAAF: A Layered Accountability Architecture Framework for LLM Applications

  • School of Computer Science Engineering and Technology, Bennett University(班尼特大学计算机科学与工程技术学院)
  • Centre for Sustainable Cyber Security (CS2), University of Greenwich(格林威治大学可持续网络安全中心)
  • School of Electrical Engineering, Computing & Mathematical Sciences, Curtin University(科廷大学电气工程、计算与数学科学学院)
  • Systems and Software Security (S3), University of Manchester(曼彻斯特大学系统与软件安全中心)

机构由 AI 辅助整理,请以论文原文为准。

Prachi Chaturvedi, Shahnawaz Ahmad, Ehsan Nowroozi, Muhammad Waqas, George Loukas, Alireza Jolfaei, Lucas Cordeiro, Pierre Dantas

AI总结:

本研究针对LLM应用问责问题,遵循PRISMA指南开展文献综述,整合四类问责机制与四层分类工具,提出LAAF架构,映射至相关法规标准,发现缺口与张力,为LLM问责提供综合方案。

AI中文摘要:

大语言模型(LLM)应用于医院、法庭、银行及公共服务台等场景,即便输出无依据或错误,流畅且自信的结果也被视为权威。当这类输出造成损害时,谁应承担责任,以及通过何种机制可追溯、解释并落实责任?本研究遵循PRISMA指南,于2022年1月至2026年3月检索5个数据库,针对4个综述问题开展研究;共识别出4512条记录,纳入122项主要研究,并分析12份监管与标准文件作为主要来源。该综述整合了社会技术视角下的问责制,将其视为行动者-论坛关系,分解为5个维度,综合了4类机制:技术控制、人工监督、组织治理、文档与可追溯性,每类机制均包含成熟度评估。研究 corpus 通过四层分类工具解读,涵盖来源、应用逻辑、人工监督、治理与救济,由可追溯性、角色清晰度、持续监测贯穿。上述内容均映射至《欧盟人工智能法案》(其高风险义务自2026年8月2日起适用)、NIST AI RMF及其生成式AI概要、ISO/IEC 42001,以及医疗、消费金融、教育、公共部门的行业指南。研究发现4个持续存在的缺口:人工监督规定不足、缺乏共享问责指标、学科脱节、实证评估有限,还有5种结构性张力,无任何受调查的工具可解决。该综述最终将分类工具整合为集成问责架构LAAF,其网络安全与OWASP LLM Top 10(2025)对齐;LAAF是受调查证据的综合,而非经验证的 artefact。

英文摘要:

Large Language Models (LLMs) operate in hospitals, courtrooms, banks, and public service desks, where fluent, confident outputs are treated as authoritative even when ungrounded or incorrect. When such an output contributes to harm, who is answerable, and through what mechanisms can responsibility be traced, explained, and acted upon? Following PRISMA guidance, five databases were searched from January 2022 to March 2026 against four review questions; of 4,512 records identified, 122 primary studies were included, together with 12 regulatory and standards documents analysed as primary sources. The review consolidates a sociotechnical account of accountability as an actor-forum relation resolved into five dimensions, and synthesises mechanisms across four families: technical controls, human oversight, organisational governance, and documentation and traceability, each with a maturity assessment. The corpus is read through a four-layer classification device spanning provenance, application logic, human oversight, and governance and redress, cross-cut by traceability, role clarity, and continuous monitoring. Both are mapped onto the EU AI Act, whose high-risk obligations have applied since 2 August 2026, the NIST AI RMF with its Generative AI Profile, ISO/IEC 42001, and sectoral guidance in healthcare, consumer finance, education, and the public sector. Four persistent gaps emerge: under-specification of human oversight, absence of shared accountability metrics, disciplinary disconnection, and limited empirical evaluation, alongside five structural tensions that no surveyed instrument resolves. The review closes by consolidating the classification device into an integrated accountability architecture, LAAF, with cybersecurity aligned to the OWASP LLM Top 10 (2025); it is a synthesis of the surveyed evidence rather than a validated artefact.

↑