AI红队评测能证明什么、不能证明什么
What AI Red-Team Evaluations Can and Cannot Prove
一项新研究为AI红队评测划定了可计算的证据上限,即固定测试预算下单一结果能改变信念的最大倍数,并以闭式解定位其边界。研究发现,在可计算的危害率之上,中等规模基准足以按既定证据标准认证某类别,且零失败记录比单次复现的失败更具说服力;低于该阈值则任何可行规模的被动基准都无法提供指定安全证据。对八个评测套件的审计显示,现有基准对高频危害类别充分,但对罕见灾难性危害类别仍差数个数量级。
用闭式解把安全评估的证据上限公式化后,论文算出现有基准对高频危害足够、对罕见灾难性危害差几个数量级——这为制定安全测试的预算和声明提供了数学依据。
Red-team evaluations of AI models support some claims and not others, and the boundary between the two is calculable rather than merely a matter of judgment. We define the evidential ceiling of an evaluation as the largest factor by which one result can move belief under a fixed testing budget, derive it in closed form for the benchmark null result, and use it to locate that boundary exactly. We find that above a calculable harm rate, a benchmark of modest size certifies a category to a stated evidentiary standard, and a clean sheet is then the stronger of the two possible observations, outweighing a single reproduced failure. Below that rate, no passive benchmark of feasible size provides the specified evidence of safety under the fixed scoring rule and approximately independent trial structure. The crossing between the two regimes has a closed form. The bound is not specific to benchmarks: written in terms of a procedure's hypothesis conditioned elicitation rates, it covers adaptive and automated red teaming as well, and shows that discrimination between the hypotheses rather than attack success is what determines evidential worth. Auditing eight evaluation suites against the boundary, we find that current benchmarks are adequate for high-frequency harm categories and several orders of magnitude short for rare, catastrophic ones. Safety benchmarks are not uninformative. They are informative about a specific and computable set of propositions, and the discipline they need is to state which.
来源:HuggingFace Daily Papers(社区热门论文) · arxiv.org