Skip to main content
QUICK REVIEW

[论文解读] Ethical Frameworks and Computer Security Trolley Problems: Foundations for Conversations

Tadayoshi Kohno, Yasemin Acar|arXiv (Cornell University)|Feb 28, 2023
Information and Cyber Security被引用 4
一句话总结

本文通过引入以计算机安全为主题的电车难题,促进安全研究社区内的伦理讨论。通过将后果主义与义务论伦理框架应用于现实情境——例如在无被利用风险的情况下披露漏洞——展示了不同道德推理方式如何导致截然不同的结论,主张在研究、评审和教育中开展基于框架的结构化讨论。

ABSTRACT

The computer security research community regularly tackles ethical questions. The field of ethics / moral philosophy has for centuries considered what it means to be "morally good" or at least "morally allowed / acceptable". Among philosophy's contributions are (1) frameworks for evaluating the morality of actions -- including the well-established consequentialist and deontological frameworks -- and (2) scenarios (like trolley problems) featuring moral dilemmas that can facilitate discussion about and intellectual inquiry into different perspectives on moral reasoning and decision-making. In a classic trolley problem, consequentialist and deontological analyses may render different opinions. In this research, we explicitly make and explore connections between moral questions in computer security research and ethics / moral philosophy through the creation and analysis of trolley problem-like computer security-themed moral dilemmas and, in doing so, we seek to contribute to conversations among security researchers about the morality of security research-related decisions. We explicitly do not seek to define what is morally right or wrong, nor do we argue for one framework over another. Indeed, the consequentialist and deontological frameworks that we center, in addition to coming to different conclusions for our scenarios, have significant limitations. Instead, by offering our scenarios and by comparing two different approaches to ethics, we strive to contribute to how the computer security research field considers and converses about ethical questions, especially when there are different perspectives on what is morally right or acceptable.

研究动机与目标

  • 通过基于真实世界安全情景的伦理困境,弥合计算机安全研究与道德哲学之间的鸿沟。
  • 解决安全研究中伦理决策缺乏共识的问题,特别是在存在冲突原则(如自主性与 beneficence)时。
  • 通过引入后果主义与义务论框架的对比分析,支持计算机安全社区开展更具信息量、结构化的伦理对话。
  • 为教育者提供可教学的、非指令性的伦理情境,以激发批判性思维,而不预设唯一正确答案。
  • 倡导将伦理反思制度化于研究流程中,例如在提交物中要求包含‘多框架伦理考量’部分,效仿现有的安全审查实践。

提出的方法

  • 设计三个原创的电车难题式伦理困境(场景 A、B 和 C),聚焦于计算机安全研究决策。
  • 对每个场景应用两种主要伦理框架——后果主义(如功利主义)与义务论(如康德伦理学),以比较结果与推理过程。
  • 使用简化、假设性的情境,将哲学与伦理维度与现实世界的复杂性分离,确保聚焦于道德推理。
  • 通过迭代讨论与专家反馈验证这些困境,确保其呈现真实的道德冲突且无明显解决方案。
  • 制作配套幻灯片和公共代码库(https://securityethics.cs.washington.edu),以支持社区使用并促进未来情境的开发。
  • 提出制度性变革建议,例如在互联网草案中要求增加‘多框架伦理考量’部分,效仿现有的安全审查实践。

实验结果

研究问题

  • RQ1如何将电车难题类比适配于反映计算机安全研究中的真实伦理张力?
  • RQ2在应用于安全研究困境时,后果主义与义务论伦理框架在多大程度上会产生不同的结论?
  • RQ3结构化的伦理框架在改善研究人员、评审者与教育者的决策中发挥何种作用?
  • RQ4计算机安全社区如何将多框架伦理反思制度化于研究流程与同行评审中?
  • RQ5哪些设计标准能使情境有效促进伦理讨论,同时不预设单一‘正确’答案?

主要发现

  • 所提出的三个情境——包括一个无法修补的医疗设备漏洞、一个可能被滥用的隐私保护系统,以及一个数据共享困境——各自呈现了真实存在的道德冲突,且无普遍认可的解决方式。
  • 后果主义与义务论框架在相同情境下常得出不同结论,表明伦理推理并非单一模式,而是依赖于基础假设。
  • 这些情境在教学中具有有效性,因其抗拒简单答案,能有效促进对自主性、 beneficence 与非伤害性等原则之间权衡的讨论。
  • 研究表明,安全研究中的伦理推理若能明确参与多种框架,而非默认采用单一伦理视角,将获益良多。
  • 作者主张将多框架伦理分析整合进研究工作流中,例如在提交物中要求设立专门的伦理考量部分,效仿现有的安全审查实践。
  • 该工作已通过专家评审与课堂应用得到验证,并建立了公共代码库,以支持持续的社区贡献与情境开发。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。