Skip to main content
QUICK REVIEW

[论文解读] Governing Through the Cloud: The Intermediary Role of Compute Providers in AI Regulation

Lennart Heim, Tim Fist|arXiv (Cornell University)|Mar 13, 2024
Blockchain Technology Applications and Security被引用 4
一句话总结

本文提出,云计算提供商(如 AWS、Google Cloud 和 Microsoft Azure)应作为人工智能监管的中介,利用其对基础设施数据的技术访问权限来强制执行合规性。该文概述了四种治理角色:安全提供者、记录保存者、验证者和执行者,通过使用非机密的遥测数据(如计算小时数、功耗和带宽)对工作负载进行分类,并在不损害隐私的前提下监控高风险人工智能开发。

ABSTRACT

As jurisdictions around the world take their first steps toward regulating the most powerful AI systems, such as the EU AI Act and the US Executive Order 14110, there is a growing need for effective enforcement mechanisms that can verify compliance and respond to violations. We argue that compute providers should have legal obligations and ethical responsibilities associated with AI development and deployment, both to provide secure infrastructure and to serve as intermediaries for AI regulation. Compute providers can play an essential role in a regulatory ecosystem via four key capacities: as securers, safeguarding AI systems and critical infrastructure; as record keepers, enhancing visibility for policymakers; as verifiers of customer activities, ensuring oversight; and as enforcers, taking actions against rule violations. We analyze the technical feasibility of performing these functions in a targeted and privacy-conscious manner and present a range of technical instruments. In particular, we describe how non-confidential information, to which compute providers largely already have access, can provide two key governance-relevant properties of a computational workload: its type-e.g., large-scale training or inference-and the amount of compute it has consumed. Using AI Executive Order 14110 as a case study, we outline how the US is beginning to implement record keeping requirements for compute providers. We also explore how verification and enforcement roles could be added to establish a comprehensive AI compute oversight scheme. We argue that internationalization will be key to effective implementation, and highlight the critical challenge of balancing confidentiality and privacy with risk mitigation as the role of compute providers in AI regulation expands.

研究动机与目标

  • 解决新兴人工智能法规(如欧盟人工智能法案和美国第14110号行政命令)中缺乏有效执行机制的问题。
  • 提出云计算提供商因其对基础设施级数据的独特访问权限,应作为人工智能治理中的关键中介。
  • 识别并分析云计算提供商可履行的四种治理能力:安全提供者、记录保存者、验证者和执行者。
  • 评估利用非机密且已收集的遥测数据进行监管监督的技术可行性,同时保护隐私。
  • 探讨国际协调与隐私保护技术如何在风险缓解与数据保护之间取得平衡。

提出的方法

  • 分析现有监管框架(如美国第14110号行政命令),识别对云计算提供商的记录保存要求。
  • 将可观察的基础设施属性(如请求的硬件配置、计算小时数、功耗和网络带宽)映射到工作负载分类和资源消耗。
  • 评估使用性能计数器、内存访问模式和权重更新频率来推断模型训练与推理工作负载的可行性。
  • 评估使用可信计算等隐私保护技术来收集敏感数据(如训练数据集、超参数)的可行性,且需获得客户同意。
  • 提出分层监督模型,使云计算提供商向监管机构报告高层次遥测数据,同时最小化数据暴露。
  • 设计一个监管生态系统,使云计算提供商作为监管机构与人工智能开发者之间的中介,减轻合规负担并增强执行能力。

实验结果

研究问题

  • RQ1如何在法律和伦理上将云计算提供商整合为人工智能监管框架中的中介?
  • RQ2从基础设施遥测中提取的哪些技术信号可可靠指示人工智能工作负载的类型和规模(如训练与推理)而不损害隐私?
  • RQ3在多大程度上可将现有遥测数据(如计算小时数、功耗和带宽)重新用于监管监督?
  • RQ4将云计算提供商的角色扩展至包括验证和执行时,其在隐私与安全方面存在哪些权衡?
  • RQ5国际协调与标准化技术工具如何实现可扩展、注重隐私的人工智能治理?

主要发现

  • 云计算提供商已收集非机密遥测数据,如计算小时数、硬件配置和功耗,这些数据可用于工作负载类型的分类和资源消耗的估算。
  • AI加速器之间及内部的网络带宽利用率与工作负载特性密切相关,可有效区分训练与推理工作负载。
  • 内存带宽和核心利用率模式可区分训练(高且稳定)与推理(可变)工作负载,为工作负载分类提供技术依据。
  • 通过数值精度区分的性能计数器可将人工智能工作负载与科学计算或游戏工作负载区分开来,为计算强度提供直接代理指标。
  • 内存中模型权重的修改是训练活动的强指标,其频率和幅度与计算消耗密切相关。
  • 尽管某些信号(如训练数据集或超参数的访问)需要新的数据收集,但通过客户同意的可信计算技术,可实现隐私保护。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。