关键基础设施安全部署人工智能框架(英)-35页_3mb
报告摘要
American critical infrastructure, vital to national safety and stability, faces transformative changes and risks due to artificial intelligence (AI). The U.S. Department of HomelandSecurity (DHS), collaborating with the Artificial Intelligence Safety and Security Board, developed the Roles and Responsibilities Framework for Artificial Intelligence in Critical Infrastructure, designed to guide entities in the AI ecosystem toward safety, security, and trustworthy deployment.
The framework adopts a voluntary framework with structured responsibilities tailored across five key roles:
- Cloud and Compute Infrastructure Providers: Focus on secure environments (vetting suppliers, access management), responsible model design, data governance (confidentiality, availability), security deployment, and performance monitoring.
- AI Developers: Emphasize responsible model development (Secure by Design, human-centric alignment, threat evaluation), data privacy, transparency, risk-based deployment, vulnerability reporting, testing, and monitoring.
- Critical Infrastructure Owners and Operators: Concentrate on securing IT/OT infrastructure, evaluating AI use cases, implementing safety mechanisms, protecting customer data, maintaining cyber hygiene, workforce training, incident response, performance tracking, validation, and system redundancy.
- Civil Society: Advocate for standards, educate policymakers, influence guiding values, support privacy tech, and contribute to research and ethical review (e.g., red-teaming standards).
- Public Sector: Oversee foundational research, enable development adoption, drive global norms, ensure legal protections, engage communities, and support transparency/emergency response.
Key principles include:
- Risk Mitigation: Responsibilities are categorized into securing environments, responsible design, data governance, safe deployment, and performance monitoring. Mitigations often involve technical controls, testing, transparency, accountability, and incident planning.
- Interdependence & Collaboration: Trust builds through transparency, information sharing, and cooperation between all roles. Risks associated with AI deployment span asset-level disruptions, sector-wide failures, systemic cross-sector impacts, and liabilities affecting national security or civil rights.
- Transparency & Accountability: Practices ensuring clarity in AI operations and liability mechanisms are emphasized. The framework highlights the need for continuous monitoring, diverse risk evaluations (proactive for high risk), and measures preventing adverse impacts.
- Dynamic Process: While protective measures are suggested, the framework reiterates AI's evolving nature requires ongoing assessment, adaptation, and research collaboration across entities and globally.
The framework seeks to harmonize practices, improve service resilience, enhance trust, foster research, and protect civil rights, advocating for a national and international collaborative approach to secure and benefit from AI in critical infrastructure.
试读结束,高清完整版pdf/doc/ppt,请点下载