AIセキュリティマップにマッピングされた外部作用的側面における負の影響「AIの誤情報の出力による、人間の認識や判断への悪影響」のセキュリティ対象、それをもたらす攻撃・要因、および防御手法・対策を示しています。
セキュリティ対象
- 消費者
攻撃・要因
- 完全性の毀損
- 説明可能性の毀損
- 出力の公平性の毀損
- 精度の毀損
- 制御可能性の毀損
- 信頼性の毀損
- RAGへのポイズニング攻撃
防御手法・対策
開発・活用における適用フェーズ
1. データ収集・前処理
- データキュレーション
2. モデルの選定・学習・検証
- 不確実性の定量化
3. システムの実装
- RAG
4. システムの提供・運用・保守
- XAI(説明可能なAI)
- 不確実性の定量化
5. システムの利用
- ハルシネーションの検知
- 教育やフォローアップ
参考文献
RAGへのポイズニング攻撃
- Poisoning Retrieval Corpora by Injecting Adversarial Passages, 2023
- BadRAG: Identifying Vulnerabilities in Retrieval Augmented Generation of Large Language Models, 2024
- PoisonedRAG: Knowledge Corruption Attacks to Retrieval-Augmented Generation of Large Language Models, 2024
- Human-Imperceptible Retrieval Poisoning Attacks in LLM-Powered Applications, 2024
- Poison-RAG: Adversarial Data Poisoning Attacks on Retrieval-Augmented Generation in Recommender Systems, 2025
データキュレーション
RAG
- Retrieval-Augmented Generation for Knowledge-Intensive NLP Tasks, 2020
- REALM: Retrieval-Augmented Language Model Pre-Training, 2020
- In-Context Retrieval-Augmented Language Models, 2023
- Active Retrieval Augmented Generation, 2023
- Self-RAG: Learning to Retrieve, Generate, and Critique through Self-Reflection, 2023
- Query Rewriting for Retrieval-Augmented Large Language Models, 2023
- Knowledge-Augmented Language Model Prompting for Zero-Shot Knowledge Graph Question Answering, 2023
- Generate rather than Retrieve: Large Language Models are Strong Context Generators, 2023
- Enhancing Retrieval-Augmented Large Language Models with Iterative Retrieval-Generation Synergy, 2023
- From Local to Global: A Graph RAG Approach to Query-Focused Summarization, 2024
XAI(説明可能なAI)
- Visualizing and Understanding Convolutional Networks, 2014
- Deep Inside Convolutional Networks: Visualising Image Classification Models and Saliency Maps, 2014
- Understanding Deep Image Representations by Inverting Them, 2014
- “Why Should I Trust You?”: Explaining the Predictions of Any Classifier, 2016
- A Unified Approach to Interpreting Model Predictions, 2017
- Learning Important Features Through Propagating Activation Differences, 2017
- Understanding Black-box Predictions via Influence Functions, 2017
- Interpretable Explanations of Black Boxes by Meaningful Perturbation, 2017
- Interpretability Beyond Feature Attribution: Quantitative Testing with Concept Activation Vectors (TCAV), 2018
- Grad-CAM: Visual Explanations from Deep Networks via Gradient-based Localization, 2019
ハルシネーションの検知
- Quantifying and Attributing the Hallucination of Large Language Models via Association Analysis, 2023
- Cost-Effective Hallucination Detection for LLMs, 2024
- The Dawn After the Dark: An Empirical Study on Factuality Hallucination in Large Language Models, 2024
- Measuring and Reducing LLM Hallucination without Gold-Standard Answers, 2024
- On Large Language Models’ Hallucination with Regard to Known Facts, 2024
不確実性の定量化
- Bayesian SegNet: Model Uncertainty in Deep Convolutional Encoder-Decoder Architectures for Scene Understanding, 2015
- Dropout as a Bayesian Approximation: Representing Model Uncertainty in Deep Learning, 2016
- Simple and Scalable Predictive Uncertainty Estimation using Deep Ensembles, 2017
- Predictive Uncertainty Estimation via Prior Networks, 2018
- Evidential Deep Learning to Quantify Classification Uncertainty, 2018
- Can You Trust Your Model’s Uncertainty? Evaluating Predictive Uncertainty Under Dataset Shift, 2019
- Aleatoric and Epistemic Uncertainty in Machine Learning: An Introduction to Concepts and Methods, 2021
教育やフォローアップ
- What Students Can Learn About Artificial Intelligence — Recommendations for K-12 Computing Education, 2022
- Learning to Prompt in the Classroom to Understand AI Limits: A pilot study, 2023
- Evaluating the Effectiveness of LLMs in Introductory Computer Science Education: A Semester-Long Field Study, 2024
- The Essentials of AI for Life and Society: An AI Literacy Course for the University Community, 2025