Skip to main content
QUICK REVIEW

[論文レビュー] Chat Control or Child Protection?

Ross Anderson|arXiv (Cornell University)|Oct 11, 2022
Homicide, Infanticide, and Child Abuse被引用数 6
ひとこと要約

この論文は、児童の性的虐待やテロリズム的プロセスを検出するために、暗号化されたメッセージのクライアント側スキャンを義務付ける英国およびEUの立法案を批判している。ロス・アンドリューセンは、こうした監視がエンド・ツー・エンド暗号を損なうおそれがあり、誤用のリスクを伴い、人権に基づき現実の警察活動と連携した、現地主導の多 Stakeholder の子供保護アプローチに注意をそらすと指摘する。

ABSTRACT

Ian Levy and Crispin Robinson's position paper "Thoughts on child safety on commodity platforms" is to be welcomed for extending the scope of the debate about the extent to which child safety concerns justify legal limits to online privacy. Their paper's context is the laws proposed in both the UK and the EU to give the authorities the power to undermine end-to-end cryptography in online communications services, with a justification of preventing and detecting of child abuse and terrorist recruitment. Both jurisdictions plan to make it easier to get service firms to take down a range of illegal material from their servers; but they also propose to mandate client-side scanning - not just for known illegal images, but for text messages indicative of sexual grooming or terrorist recruitment. In this initial response, I raise technical issues about the capabilities of the technologies the authorities propose to mandate, and a deeper strategic issue: that we should view the child safety debate from the perspective of children at risk of violence, rather than from that of the security and intelligence agencies and the firms that sell surveillance software. The debate on terrorism similarly needs to be grounded in the context in which young people are radicalised. Both political violence and violence against children tend to be politicised and as a result are often poorly policed. Effective policing, particularly of crimes embedded in wicked social problems, must be locally led and involve multiple stakeholders; the idea of using 'artificial intelligence' to replace police officers, social workers and teachers is just the sort of magical thinking that leads to bad policy. The debate must also be conducted within the boundary conditions set by human rights and privacy law, and to be pragmatic must also consider reasonable police priorities.

研究の動機と目的

  • エンド・ツー・エンド暗号化されたメッセージのクライアント側スキャンを義務付ける立法案の背後にある技術的および倫理的仮定に反論すること。
  • 子供の安全を名目にした国家的および企業主導の監視に、強固な暗号技術を損なうリスクを提示すること。
  • 知的財産庁やテック企業の視点から、暴力の被害にあうおそれのある子供たちの視点に政策議論を転換すること。
  • 複雑な社会的犯罪に対処する際、AIが警察官、社会福祉士、教育者を代替するのを反対すること。
  • 効果的な子供保護は、現地主導で多 Stakeholder 参与が不可欠であり、人権およびプライバシー法に拘束されるべきであることを強調すること。

提案手法

  • エンド・ツー・エンド暗号化されたメッセージのクライアント側スキャンが、テキストベースのプロセスやテロリズム的プロモーションを検出する技術的妥当性とリスクを分析する。
  • 暗号化の前段階でユーザーのコンテンツをスキャンするようサービスプロバイダーに義務付ける、英国およびEUの法案の影響を検討する。
  • 実際の児童虐待や過激化の事例を援用し、こうした犯罪が複雑な社会的問題に根ざしており、洗練された人間主導の対応が不可欠であると主張する。
  • 自動化されたシステムが、虐待やプロセスの兆候を特定する際、専門的判断を代替できると仮定する考えを批判する。
  • プライバシーを守る設計の重要性と、たとえ児童保護を目的としても、バックドアの存在がもたらす危険性を強調する。
  • 政策は人権法に従い、現実の法執行警察の優先順位と能力と整合的でなければならないと強調する。

実験結果

リサーチクエスチョン

  • RQ1エンド・ツー・エンド暗号化メッセージングプラットフォームにおけるクライアント側スキャンの義務化が、技術的およびシステム的リスクをもたらすのはどのような点か?
  • RQ2子供保護のための提案された監視モデルは、効果的で現地主導の多 Stakeholder のアプローチと比べて、どのように異なるか?
  • RQ3児童虐待やテロリズムが政治的・イデオロギー的対象化されることで、法執行警察や子供保護の有効性がどのように損なわれるか?
  • RQ4プライバシーを侵害したり誤検出を引き起こしたりしない限り、人工知能や自動化システムが、プロセスや過激化を信頼できる範囲ですべて検出できるのか?
  • RQ5子供の安全を脅かすリスクに直面する子供たちの実際のニーズに合った形で、子供保護政策を国家的および企業主導の監視から再構築できるか?

主な発見

  • エンド・ツー・エンド暗号化されたメッセージのクライアント側スキャンは、悪用や敵対者による利用、全体のシステムセキュリティの弱体化といった重大な技術的リスクを伴う。
  • 提案された法制度は、悪戯に疑われる者だけでなく、すべてのユーザーのプライバシーと安全を守るために不可欠なエンド・ツー・エンド暗号を損なうリスクをはらんでいる。
  • 自動化されたシステムは、警察官、社会福祉士、教師といった訓練を受けた専門家が虐待やプロセスの兆候を特定・対応する際の洗練された判断を代替できない。
  • 子供保護は、技術的命令によるトップダウンの対応ではなく、現地主導で多 Stakeholder 参与が不可欠な複雑で根深い社会的問題である。
  • 議論は、知的財産庁や監視請負業者の優先順位ではなく、被害にあうおそれのある子供たちの実際の体験に基づくべきである。
  • あらゆる政策は人権法の範囲内に留まり、現実の法執行警察の優先順位と能力と整合的でなければならない。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。