arXiv · 2402.07039
Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities
Abstract
Harm reporting in Artificial Intelligence (AI) currently lacks a structured process for disclosing and addressing algorithmic flaws, relying largely on an ad-hoc approach. This contrasts sharply with the well-established Coordinated Vulnerability Disclosure (CVD) ecosystem in software security. While global efforts to establish frameworks for AI transparency and collaboration are underway, the unique challenges presented by machine learning (ML) models demand a specialized approach. To address this gap, we propose implementing a Coordinated Flaw Disclosure (CFD) framework tailored to the complexities of ML and AI issues. This paper reviews the evolution of ML disclosure practices, from ad hoc reporting to emerging participatory auditing methods, and compares them with cybersecurity norms. Our framework introduces innovations such as extended model cards, dynamic scope expansion, an independent adjudication panel, and an automated verification process. We also outline a forthcoming real-world pilot of CFD. We argue that CFD could significantly enhance public trust in AI systems. By balancing organizational and community interests, CFD aims to improve AI accountability in a rapidly evolving technological landscape.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Sven Cattell, Avijit Ghosh, Lucie-Aimée Kaffee. 2024-02-10. Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities. https://arxiv.org/abs/2402.07039
Cite the original work for its findings. Save a collection to share your selection of sources.