对不起,Dave:传统人事安全领域如何为新兴的人工智能内部风险提供启示
I'm Sorry Dave: How the old world of personnel security can inform the new world of AI insider risk
摘要 Abstract
组织正在迅速采用人工智能(AI)工具来执行原本由人员完成的任务,其潜在益处巨大。此外,一些组织部署了人事安全措施以减轻来自可信赖的人类内部人员的安全风险。然而,人工智能领域快速发展的同时,与传统人事安全领域之间缺乏有意义的互动,这是一个问题。尽管经过数十年的努力,人类内部人员带来的复杂风险仍然难以理解和管理,而来自人工智能内部人员的新兴安全风险则更加模糊不清。双方都需要尽可能多的帮助。在处理人类内部人员时证明有用的某些概念和方法同样适用于应对人工智能内部人员带来的新兴风险。此外,人工智能还可以用于防御性地保护免受人类和人工智能内部人员的风险。
Organisations are rapidly adopting artificial intelligence (AI) tools to perform tasks previously undertaken by people. The potential benefits are enormous. Separately, some organisations deploy personnel security measures to mitigate the security risks arising from trusted human insiders. Unfortunately, there is no meaningful interplay between the rapidly evolving domain of AI and the traditional world of personnel security. This is a problem. The complex risks from human insiders are hard enough to understand and manage, despite many decades of effort. The emerging security risks from AI insiders are even more opaque. Both sides need all the help they can get. Some of the concepts and approaches that have proved useful in dealing with human insiders are also applicable to the emerging risks from AI insiders. Furthermore, AI can be used defensively to protect against both human and AI insiders.