当前位置:首页 > 报告详情

肯德拉·阿尔伯特与乔纳森·彭尼与拉姆·尚卡尔·希瓦·库马尔_忽略你的生成式AI安全指示违反CFAA.pdf

上传人: 张** 编号:175517 2024-09-13 23页 543.96KB

1、1 Ignore Safety Directions.Violate the CFAA?Kendra Albert(Harvard Law School);Jonathon Penney(Osgoode Hall Law School/Harvard Berkman Klein Center);and Ram Shankar Siva Kumar(Harvard Berkman Klein Center)*Introduction In March,twenty-three artificial intelligence(AI)experts publicly released a worki

2、ng paper calling for legal and technical protections for researchers engaged in good faith evaluation and“red teaming”of AI systems.1 The co-authors,including experts from Massachusetts Institute of Technology,Stanford,Georgetown,University of Pennsylvania,and Brown,among othersargued that uncertain

3、ty in how existing laws like the Computer Fraud and Abuse Act(“CFAA”)apply to generative AI platforms like ChatGPT creates unreasonable legal risks for researchers2 that will have a chilling effect on AI safety and security research.3 In theory,the CFAA could allow AI firms to sue researchers for ac

4、cessing AI platforms in unintended ways or uncovering previously unknown vulnerabilities,and enable federal prosecutors to launch criminal investigations for the same.4 Since the paper was released,more than 350 additional researchers *Equal Contribution.Acknowledgements TK.1 Shayne Longpre et al.,A

5、 Safe Harbor for AI Evaluation and Red Teaming,(2024),http:/arxiv.org/abs/2403.04893(last visited Jul 20,2024).In security research,“red teams”refer to groups authorized to act as adversarial attackers against an organizations computer systems;sometimes also referred to as“penetration testing”.“Red

6、teams”can include in some contexts third party hackers who are testing the security of publicly accessible systems without explicit consent from the developers.See id.at 2.2 Id.at 7.3 Alexander Gamero-Garrido et al.,Quantifying the Pressure of Legal Risks on Third-Party Vulnerability Research,in PRO

word格式文档无特别注明外均可编辑修改,预览文件经过压缩,下载原文更清晰!
三个皮匠报告文库所有资源均是客户上传分享,仅供网友学习交流,未经上传用户书面授权,请勿作商用。
本文主要探讨了在《计算机欺诈和滥用法案》(CFAA)下,对大型语言模型(LLM)进行提示注入攻击的法律风险。文章首先介绍了CFAA的背景和应用,以及Van Buren案对CFAA解释的影响。然后,文章分析了直接和间接提示注入攻击在CFAA下可能面临的法律风险,包括获取信息、改变模型行为、损害系统等。文章还探讨了可能的宪法第一修正案抗辩。最后,文章提出了法律和政策建议,呼吁为善意的研究者提供法律保护,以避免对安全研究产生寒蝉效应。
如何在CFAA下评估AI系统的安全性? 如何在Van Buren裁决后进行AI系统的红队测试? 如何保护AI安全研究免受法律风险?
客服
商务合作
小程序
服务号
折叠