Pith. sign in

REVIEW 3 major objections 5 minor 217 references

The Pitfalls of "Security by Obscurity" And What They Mean for Transparent AI

T0 review · 3 major / 5 minor · reviewed 2026-08-09 · deepseek-v4-flash

Pith's one-line read The security community's rejection of 'security by obscurity' offers AI transparency a ready-made playbook.

desk verdict A competent, honest synthesis of security's transparency norms for AI, with a real but acknowledged disanalogy around metric gaming; deserves peer review. read the letter →

arxiv 2501.18669 v1 pith:I2V6MG2X submitted 2025-01-30 cs.CR cs.AIcs.CY

classification cs.CRcs.AIcs.CY
keywords securitybyobscuritytransparencyAIthreatmodelingcoordinatedvulnerabilitydisclosurepublictrustmechanismsanonymizationdifferentialprivacy
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper asks whether the AI community can learn from the security community's decades-long experience with 'security by obscurity,' the idea that hiding how a system works protects it. It argues that security's hard-won consensus—transparency improves safety, especially when paired with community scrutiny and institutionalized trust—translates into three lessons for AI: state what a system cannot guarantee as clearly as what it can, invite and protect outside researchers who probe for flaws, and build public trust mechanisms for systems people cannot meaningfully opt out of. The paper grounds these lessons in a case study of anonymization, where public disclosure of successful de-anonymization attacks changed industry practice and helped motivate differential privacy. It closes by identifying what is genuinely new in AI—training data enmeshed with model behavior, metric gaming, and model brittleness—so the security playbook needs adaptation rather than simple copying.

What carries the argument

The load-bearing instrument is the analogy between security-critical systems and AI systems, carried by three named mechanisms. The first is threat modeling: the security practice of writing down what a system can and cannot guarantee, so that failures and out-of-scope risks are as explicit as the promised protections. The second is community scrutiny and graded disclosure: bug bounties, coordinated vulnerability disclosure, and attack papers that invite outside eyes and protect researchers who report flaws. The third is public trust mechanisms: regulation, certification, audits, and similar institutional arrangements that substitute for individual understanding when a technology is ubiquitous. The anonymization story—where transparent reports of attacks repeatedly showed that anonymized data could be re-identified, eventually changing industry behavior and helping motivate differential privacy—serves as the paper's concrete demonstration that these mechanisms produce real shifts in practice.

What would settle it

A controlled comparison would settle it: take two matched AI systems with the same capabilities, give one a published threat model, an open disclosure process, and public audits, keep the other closed, and track serious flaws found, fix speed, and exploited harms over a fixed period. If the closed system performs as well or better on these measures, the security-by-transparency parallel fails for that class of systems.

Watch

Extended reading notes

Core claim

The paper's central claim is that transparency debates in AI are replaying the security community's older debate about 'security by obscurity,' and the security community's eventual consensus gives AI a useful template. That consensus, called here 'security by transparency,' holds that a system should be designed to remain safe even when its design is fully known, and that openness about assumptions, vulnerabilities, and guarantees makes systems safer over time. The three transferable mechanisms are threat modeling that specifies both positive and negative guarantees, community input through vulnerability reporting and graded disclosure, and public trust mechanisms that let lay users rely on systems they cannot personally audit. The anonymization case study is the paper's worked example: repeated transparent demonstrations that anonymization fails changed norms and led to differential privacy. The paper also argues that AI differs in ways that matter for the analogy—training data cannot be cleanly separated from system design, published metrics can be gamed, and models are brittle—so the template must be adapted to these conditions.

Load-bearing premise

The transfer works only if AI systems and security-critical systems are similar enough that publishing negative guarantees, inviting outside scrutiny, and building public trust mechanisms yield the same safety benefits in AI that they produced in security.

Editorial extensions

If this is right

  • Publishing a model's threat model, including explicit statements of what it does not guarantee, should become a standard complement to benchmarks and capability claims.
  • AI developers who build and respect coordinated disclosure processes, with legal protection for researchers, should see faster discovery of serious flaws, just as security did.
  • Regulators can justify transparency requirements even when users do not demand them, because ubiquitous AI creates the same moral-hazard conditions that led security to institutionalize public trust mechanisms.
  • Because AI has challenges security did not face, the playbook must be adapted—for example, disclosure processes must decide who counts as the affected party when training data is entangled with model behavior.
  • The anonymization history shows that sustained transparent reporting of failures can shift community practice, so AI transparency advocates should expect such change to take time.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • Beyond the paper, the threat-modeling lesson implies that AI audits should carry a standard 'what was not tested' section, making audits comparable across models and vendors.
  • Beyond the paper, the metric-gaming problem may be the deepest limit of the analogy: publishing an objective function can make it a target in a way that publishing a cryptographic design does not, so effective AI transparency may need to publish evaluation protocols rather than the metrics themselves.
  • Beyond the paper, if the security timeline repeats, the AI field should expect a transitional period of hostile reactions to outside researchers followed by institutionalized disclosure norms, so early investment in safe-harbor structures could compress that process.
  • Beyond the paper, a testable extension is to track whether AI vulnerability reports using coordinated disclosure lead to faster fixes and fewer exploited incidents than unsolicited public reports; the paper's analogy predicts the former.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The paper is a position/survey essay arguing that the computer security community's decades-long transition away from "security by obscurity" and toward "security by transparency" provides transferable lessons for contemporary AI transparency debates. It identifies three themes from security practice: (1) explicit threat modeling that states both positive and negative guarantees, (2) "many eyes" community scrutiny through vulnerability disclosure and bug bounties, and (3) public trust mechanisms for ubiquitous technologies whose users cannot opt out. It illustrates these themes with a case study on anonymization, then examines four ways in which AI systems differ from traditional security-critical systems (training data entanglement, disclosure scope, model brittleness/privacy trade-offs, and metric gaming through Goodhart's Law), and finally discusses common arguments against transparency such as trade secrets and misuse. The paper makes no quantitative claims and its argument rests on historical narrative, community practice, and cited literature.

Significance. If the transfer argument holds, the AI transparency community gains a concrete, field-tested template: model what a system cannot guarantee, institutionalize community scrutiny through graded disclosure, and build public trust mechanisms. The paper's strengths are its careful historical grounding, its extensive and relevant bibliography, and its explicit acknowledgment of disanalogies between security and AI. The anonymization case study is a useful illustration of how transparency norms develop in a subfield. The paper is best read as an agenda-setting contribution rather than a technical result; its value lies in framing research and policy questions, and it is honest about several open problems. The main risk is that the central analogy is asserted more strongly than the evidence warrants, particularly around the "many eyes" mechanism and the Goodhart disanalogy.

major comments (3)
  1. [Section 6.4 (Optimizing for Metrics)] The paper identifies Goodhart's Law as a disanalogy with no good analogue in security research, stating that "releasing the full details of system functionality can inherently make the system less useful for its intended purpose." Yet the same paragraph then asserts that "the security-by-transparency approach would suggest that transparency of metrics yields important benefits," without providing a mechanism by which community scrutiny could outweigh metric gaming. This is a load-bearing logical gap: if disclosing metrics creates a qualitatively new failure mode, the many-eyes benefit cannot be assumed to survive. Please either supply an argument or evidence that the benefits of transparency outweigh gaming in the AI context, or explicitly weaken the claim to state that this particular parallel is not established and that the transfer argument applies with appropriate caveats. The current text leaves the reader with an unresolved contradiction at the heart of the second theme.
  2. [Section 3.2 (Many Eyes and Disclosure)] The paper adopts Linus's Law ("Given enough eyeballs, all bugs are shallow") as the underpinning of the many-eyes theme without critically assessing its empirical status in security. It cites Schneier's caveat that open source only increases security if people actually study the code and fix bugs promptly, and it cites Sharma's concern about adverse incentives in decentralized open source, but these caveats are not integrated into the argument. Since the entire second theme depends on the many-eyes mechanism, the paper should either present supporting evidence from security practice (e.g., data from bug bounty programs or cryptographic standardization efforts) or weaken the theme to "community scrutiny can help, subject to known conditions such as active review and aligned incentives." The transfer to AI is only as strong as this premise, so the current treatment is insufficiently qualified.
  3. [Section 1.3 and Section 3] The paper describes its three themes as "key" and offers "a novel and systematic exposition of the essential principles," but it does not state any criteria for selecting these three themes from the large body of transparency literature in security. The lack of an explicit inclusion method makes it difficult to assess whether the three themes are representative or selectively chosen. This concern is amplified by Section 6, which introduces four disanalogies (training data entanglement, disclosure scope, brittleness, metric gaming) without mapping them back to the three themes and without explaining how each theme's validity is affected. Please add a short statement of how the themes were selected and an explicit discussion of which Section 6 challenges threaten which theme.
minor comments (5)
  1. [Section 7.3] There is a typo in the sentence "reach fuller understandings of of new techniques," which should read "of new techniques."
  2. [References] The reference to "Fanstastic Copyrighted Beasts" in the GenLaw paper title should be corrected to "Fantastic Copyrighted Beasts."
  3. [Section 5] The anonymization case study is informative, but its connection to the three themes is mostly implicit; explicitly labeling which paragraphs illustrate threat modeling, many eyes, and public trust would strengthen the didactic value of the case study.
  4. [Section 8.1] The discussion of comparisons to biosecurity, physical sciences, biomedical sciences, and civil engineering is quite brief and does not fully explain how each comparison informs the central transfer argument; consider either expanding these paragraphs with concrete parallels or trimming them to avoid distracting from the main narrative.
  5. [Section 1.4] The distinction between "transparency" and "security" is useful, but the paper sometimes conflates the two, e.g., in Section 3.3 where "transparency is necessary as a public trust mechanism for secure systems and robust AI alike"; a brief clarifying sentence would help avoid ambiguity.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the paper's analogical synthesis rests on external security history and explicitly acknowledges AI-specific disanalogies.

full rationale

This is an argumentative and historical position paper with no quantitative derivations, fitted parameters, or formal predictions. Its central claim—that the security community's transparency norms offer transferable lessons for AI—rests on documented external history (Kerckhoffs, Shannon, Raymond, NIST standardization, vulnerability disclosure practices, the anonymization case study) rather than on the paper's own outputs. The three key parallels in Section 3 are each supported by citations to independent, publicly documented practices; they are not defined in terms of the conclusions they are used to support. The paper's self-citations ([94] and [138]) are background references for existing concerns and legal risks in research; neither is load-bearing for the central thesis, and neither is invoked as an external authority or uniqueness theorem. Section 6 explicitly identifies AI-specific disanalogies—training-data entanglement, model brittleness, and Goodhartian metric gaming—and even states that the last 'does not have a good analogue in security research.' This candor undercuts any suggestion that the paper is forcing its conclusion by construction; the acknowledged limitations are arguments about the strength of the analogy, not circular derivations. The apparent circularity concern at Section 6.4 is a challenge to the plausibility of an inference from the security-by-transparency paradigm, not a reduction of the conclusion to its premises. No step in the paper equates an input with an output by definition, fits a parameter and then relabels it as a prediction, or imports a result solely through a self-citation chain. The analysis is self-contained as an interpretive synthesis of external evidence, so the circularity score is 0.

Assumptions & free parameters 0 free parameters · 4 assumptions · 0 invented entities

The paper introduces no free parameters and no invented entities. The argument depends on four domain assumptions about the reliability and transferability of security transparency norms, listed above. These assumptions are plausible but not formally proven.

assumptions (4)
  • domain assumption The security community's long-standing consensus against security by obscurity is a transferable source of wisdom for AI transparency debates.
    The paper's central thesis assumes that security's historical experience is relevant and reliable for AI; Section 1.1 and Section 3 state this framing.
  • domain assumption Transparency generally improves security outcomes, with obscurity as at most a minor supplement.
    Treated as established by Kerckhoffs' Principle and community consensus; Section 2.1. This claim is background for all three themes.
  • domain assumption AI systems and security-critical systems share enough structural features for the three parallels to hold.
    Section 3 draws the parallels; Section 6 acknowledges but only partially explores differences such as training data entanglement and metric gaming.
  • domain assumption Community scrutiny, as expressed in Linus's Law, reliably finds and fixes flaws.
    Section 3.2 invokes 'many eyes' as a key mechanism; the paper cites Schneier's caveats but does not systematically test or qualify the claim.

how reviews work

0 comments
Cite this review

Pith. "Pith review of The Pitfalls of "Security by Obscurity" And What They Mean for Transparent AI." pith.science (2026). https://pith.science/paper/I2V6MG2X

@misc{pith2026250118669,
  author       = {Pith},
  title        = {Pith review of: The Pitfalls of "Security by Obscurity" And What They Mean for Transparent AI},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/I2V6MG2X}},
  note         = {Machine review of arXiv:2501.18669}
}
read the original abstract

Calls for transparency in AI systems are growing in number and urgency from diverse stakeholders ranging from regulators to researchers to users (with a comparative absence of companies developing AI). Notions of transparency for AI abound, each addressing distinct interests and concerns. In computer security, transparency is likewise regarded as a key concept. The security community has for decades pushed back against so-called security by obscurity -- the idea that hiding how a system works protects it from attack -- against significant pressure from industry and other stakeholders. Over the decades, in a community process that is imperfect and ongoing, security researchers and practitioners have gradually built up some norms and practices around how to balance transparency interests with possible negative side effects. This paper asks: What insights can the AI community take from the security community's experience with transparency? We identify three key themes in the security community's perspective on the benefits of transparency and their approach to balancing transparency against countervailing interests. For each, we investigate parallels and insights relevant to transparency in AI. We then provide a case study discussion on how transparency has shaped the research subfield of anonymization. Finally, shifting our focus from similarities to differences, we highlight key transparency issues where modern AI systems present challenges different from other kinds of security-critical systems, raising interesting open questions for the security and AI communities alike.

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

217 extracted references · 30 canonical work pages

  1. [1]

    Artificial Intelligence and Jobs — Evidence from Online Vacancies

    Daron Acemoglu, David Autor, Jonathon Hazell, and Pascual Restrepo. “Artificial Intelligence and Jobs — Evidence from Online Vacancies”. In: Journal of Labor Economics 40 (1) (2022), pp. 293–340. doi: 10.1086/718327. url: https:// economics.mit.edu/sites/default/ files/publications/AI%20and%20Jobs %20-%20Evidence%20from%20Online %20Vacancies.pdf

  2. [2]

    RSA Factor- ing Challenge Announcement

    RSA Challenge Administrator. RSA Factor- ing Challenge Announcement . permalink: https://perma.cc/Z3W7-FCDU. 1991. url: https://groups.google.com/u/1/g/sci. crypt/c/AA7M9qWWx3w/m/EkrsR69CDqIJ? pli=1

  3. [3]

    Infor- mation Sharing

    America’s Cyber Defense Agency. Infor- mation Sharing . permalink: https:// perma.cc/3GP9-MD94. url: https://www. cisa.gov/topics/cyber-threats-and- advisories/information-sharing

  4. [4]

    Perspectives on Issues in AI Governance

    Google AI. Perspectives on Issues in AI Governance . Tech. rep. Google,

  5. [5]

    Ethics Guidelines for Trustworthy AI

    High-Level Expert Group on AI. Ethics Guidelines for Trustworthy AI . European Commission. 2019

  6. [6]

    Piloting a survey- based assessment of transparency and trustworthiness with three medical AI tools

    Jana Fehr et al. “Piloting a survey- based assessment of transparency and trustworthiness with three medical AI tools”. In: Healthcare (Basel) (2022). doi: 10.3390/healthcare10101923. url: https://www.ncbi.nlm.nih.gov/pmc/ articles/PMC9601535/

  7. [7]

    Apple pays hackers six figures to find bugs in its software. Then it sits on their findings

    Reed Albergotti. “Apple pays hackers six figures to find bugs in its software. Then it sits on their findings.” In: Washing- ton Post (2021). permalink: https:// perma.cc/5LTD-4YBW. url: https://www. washingtonpost.com/technology/2021/ 09/09/apple-bug-bounty/

  8. [8]

    The Falcon Series of 14 Open Language Models

    Ebtesam Almazrouei, Hamza Alobeidli, Abdulaziz Alshamsi, Alessandro Cappelli, Ruxandra Cojocaru, M´ erouane Debbah, Etienne Goffinet, Daniel Hesslow, Julien Launay, Quentin Malartic, Daniele Mazzotta, Badreddine Noune, Baptiste Pannier, and Guilherme Penedo. “The Falcon Series of 14 Open Language Models”. In: Computation and Language (2023). url: https://ar...

Show all 217 references
  1. [9]

    Security Engineering

    Ross Anderson. Security Engineering. 3rd ed. Wiley, 2021

  2. [10]

    Varieties of transparency: exploring agency within AI systems

    Gloria Andrada, Robert W. Clowes, and Paul R. Smart. “Varieties of transparency: exploring agency within AI systems”. In: AI and SOCIETY 38 (2022), pp. 1321–

  3. [11]

    How to De-Identify your Data

    Olivia Angiuli, Joe Blitzstein, and Jim Waldo. “How to De-Identify your Data”. In: Communications of the ACM (2015). permalink: https://perma.cc/BY4P-828Y. url: https://cacm.acm.org/practice/ how-to-de-identify-your-data/

  4. [12]

    Machine Bias

    Julia Angwin, Jeff Larson, Surya Mattu, and Lauren Kirchner. Machine Bias . ProP- ublica. permalink: https://perma. cc/V5XH-GMQ8. 2016. url: https:// www.propublica.org/article/machine- bias-risk-assessments-in-criminal- sentencing

  5. [13]

    Argentieri

    Nicole M. Argentieri. Principal Deputy Assis- tant Attorney General Nicole M. Argentieri Delivers Remarks at the Computer Crime and Intellectual Property Section’s Symposium on Artificial Intelligence in the Justice Dept. U.S. Dept. of Justice. permalink: https:// perma.cc/3PCD...

  6. [14]

    Artificial Intelligence Risk Management Framework: Generative Artificial In- telligence Profile . NIST. 2024. doi: 10.6028/NIST.AI.600-1. url: https:// doi.org/10.6028/NIST.AI.600-1

  7. [15]

    Theoretically Grounded Loss Functions and Algorithms for Adversarial Robustness

    Pranjal Awasthi, Anqi Mao, Mehryar Mohri, and Yutao Zhong. “Theoretically Grounded Loss Functions and Algorithms for Adversarial Robustness”. In: Proceed- ings of The 26th International Conference on Artificial Intelligence and Statistics . Vol. 206. Proceedings of Machine Lear...

  8. [16]

    A Face Is Exposed for AOL Searcher No

    Michael Barbaro and Tom Zeller Jr. A Face Is Exposed for AOL Searcher No. 4417749 . permalink: https:// archive.nytimes.com/www.nytimes.com/ learning/teachers/featured_articles/ 20060810thursday.html. 2006

  9. [17]

    A Feeling of Unease about Privacy Law

    Ann Bartow. “A Feeling of Unease about Privacy Law”. In: University of Pennsylvania Law Review Online (2006). url: https:// scholarship.law.upenn.edu/penn_law_ review_online/vol155/iss1/6

  10. [18]

    The Re- search Value of Publishing Attacks

    David Basin and Srdjan Capkun. “The Re- search Value of Publishing Attacks”. In: Com- munications of the ACM 55 (11 2012), pp. 22–

  11. [19]

    The Artificial Intelligence Black Box and the Failure of Intent and Cau- sation

    Yavar Bathaee. “The Artificial Intelligence Black Box and the Failure of Intent and Cau- sation”. In: Harvard Journal of Law and Tech- nology 31 (2 2018)

  12. [20]

    Bellovin and Randy Bush

    Steven M. Bellovin and Randy Bush. Security Through Obscurity Considered Dangerous. The Internet Society. 2002. url: https://www.cs.columbia.edu/~smb/ papers/draft-ymbk-obscurity-00.txt

  13. [21]

    On the Dangers of Stochastic Parrots: Can Language Models Be Too Big?

    Emily M. Bender, Timnit Gebru, Angelina McMillan-Major, and Shmargaret Shmitchell. “On the Dangers of Stochastic Parrots: Can Language Models Be Too Big?” In: Pro- ceedings of the 2021 ACM Conference on Fairness, Accountability, and Transparency (F AccT ’21). ACM, 2021, pp. 61...

  14. [22]

    Managing extreme AI risks amid rapid progress

    Yoshua Bengio, Geoffrey Hinton, Andrew Yao, Dawn Song, Pieter Abbeel, Trevor Darrell, Yuval Noah Harari, Ya-Qin Zhang, Lan Xue, Shai Shalev-Shwartz, Gillian Hadfield, Jeff Clune, Tegan Maharaj, Frank Hutter, Atlim G¨ unes, Baydin, Sheila McIlraith, Qiqi Gao, Ashwin Acharya, David...

  15. [23]

    Joseph R. Biden. Executive Order on Preventing Access to Americans’ Bulk Sen- sitive Personal Data and United States Government-Related Data by Coun- tries of Concern . 2024. url: https:// web.archive.org/web/20250118021320/ 15 https://www.whitehouse.gov/briefing- room/preside...

  16. [24]

    doi: 10.1145/2366316.2366324

  17. [25]

    International Conference on Machine Learn- ing

    Pythia: A Suite for Analyzing Large Lan- guage Models Across Training and Scaling . International Conference on Machine Learn- ing. 2023. url: https://proceedings.mlr. press/v202/biderman23a.html

  18. [26]

    Semantically secure order-revealing encryption: Multi-input functional encryption without obfuscation

    Dan Boneh, Kevin Lewi, Mariana Raykova, Amit Sahai, Mark Zhandry, and Joe Zim- merman. “Semantically secure order-revealing encryption: Multi-input functional encryption without obfuscation”. In: EUROCRYPT. EU- ROCRYPT, 2015, pp. 563–594

  19. [27]

    Joseph R. Biden. Executive Order on the Safe, Secure, and Trustworthy Develop- ment and Use of Artificial Intelligence . EO14110. permalink: https://perma. cc/LPA7-QWTQ. 2023. url: https://www. federalregister.gov/documents/2023/ 11/01/2023-24283/safe-secure-and- trustworthy-de...

  20. [28]

    Strategic Implications of Openness in AI Development

    Nick Bostrom. “Strategic Implications of Openness in AI Development”. In: Global Pol- icy (2017). doi: 10.1111/1758-5899.12403. url: https://doi.org/10.1111/1758- 5899.12403

  21. [29]

    Strategic Implications of Openness in AI Development

    Nick Bostrom. “Strategic Implications of Openness in AI Development”. In: Artificial Intelligence Safety and Security (2018). url: https://nickbostrom.com/papers/ openness.pdf

  22. [30]

    The Science of Guessing: Analyzing an anonymized corpus of 70 million passwords

    Joseph Bonneau. “The Science of Guessing: Analyzing an anonymized corpus of 70 million passwords”. In: 2012 IEEE Symposium on Security and Privacy . IEEE Symposium on Security and Privacy, 2012. url: https:// ieeexplore.ieee.org/stamp/stamp.jsp? tp=&arnumber=6234435&tag=1

  23. [31]

    Miles Brundage, Shahar Avin, Jack Clark, Helen Toner, Peter Eckersley, Ben Garfinkel, Allan Dafoe, Paul Scharre, Thomas Zeitzoff, Bobby Filar, Hyrum Anderson, Heather Roff, Gregory C. Allen, Jacob Steinhardt, Carrick Flynn, Se´ an ´O h ´Eigeartaigh, Simon Beard, Haydn Belfield, Se...

  24. [32]

    On Eval- uating Adversarial Robustness

    Nicholas Carlini, Anish Athalye, Nicolas Pa- pernot, Wieland Brendel, Jonas Rauber, Dim- itris Tsipras, Ian Goodfellow, Aleksander Madry, and Alexey Kurakin. “On Eval- uating Adversarial Robustness”. In: arXiv (2019). doi: 10.48550/arXiv.1902.06705. url: https://arxiv.org/abs/...

  25. [33]

    Artificial Bias: The Ethical Concerns of AI-Driven Dispute Resolution in Family Matters

    Wensdai Brooks. “Artificial Bias: The Ethical Concerns of AI-Driven Dispute Resolution in Family Matters”. In: Journal of Dispute Reso- lution (2 2022). url: https://scholarship. law.missouri.edu/jdr/vol2022/iss2/9

  26. [34]

    Stealing Part of a Production Language Model

    Nicholas Carlini, Daniel Paleka, Krishna- murthy Dj Dvijotham, Thomas Steinke, Jonathan Hayase, A. Feder Cooper, Katherine Lee, Matthew Jagielski, Milad Nasr, Arthur Conmy, Itay Yona, Eric Wallace, David Rol- nick, and Florian Tram` er. “Stealing Part of a Production Language ...

  27. [35]

    The Need for Trans- parency in the Age of Predictive Sentencing Algorithms

    Alyssa M. Carlson. “The Need for Trans- parency in the Age of Predictive Sentencing Algorithms”. In: Iowa Law Review 103 (2017). url: https://ilr.law.uiowa.edu/ sites/ilr.law.uiowa.edu/files/2022- 10/The%20Need%20for%20Transparency %20in%20the%20Age%20of%20Predictive %20Senten...

  28. [36]

    Extracting Training Data from Diffusion Models

    Nicholas Carlini, Jamie Hayes, Milad Nasr, Matthew Jagielski, Vikash Sehwag, Florian Tram` er, Borja Balle, Daphne Ippolito, and Eric Wallace. “Extracting Training Data from Diffusion Models”. In: arXiv (2023). doi: 10.48550/ARXIV.2301.13188. url: https://doi.org/10.48550/ARXIV...

  29. [37]

    An ef- ficient key recovery attack on SIDH

    Wouter Castryck and Thomas Decru. “An ef- ficient key recovery attack on SIDH”. In: EU- ROCRYPT 2023. Springer, 2023, pp. 423–447. doi: 10.1007/978-3-031-30589-4_15 . url: https://eprint.iacr.org/2022/975

  30. [38]

    Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities

    Sven Cattell, Avijit Ghosh, and Lucie-Aim´ ee Kaffee. “Coordinated Flaw Disclosure for AI: Beyond Security Vulnerabilities”. In: AAAI/ACM Conf. on AI, Ethics, and So- ciety (AIES) (2024). url: https://arxiv. org/pdf/2402.07039

  31. [39]

    Towards a Data Privacy- Predictive Performance Trade-off

    Tˆ ania Carvalho, Nuno Moniz, Pedro Faria, and Lu ´ ıs Antunes. “Towards a Data Privacy- Predictive Performance Trade-off”. In: Expert Systems with Applications 223 (2023). doi: 10.1016/j.eswa.2023.119785. url: https://doi.org/10.1016/j.eswa.2023. 119785. 16

  32. [40]

    The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers

    Huseyin Cavusoglu, Birendra Mishra, and Srinivasan Raghunathan. “The Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers”. In: International Journal of Electronic Commerce 9 (2004), pp. 7...

  33. [41]

    CERT Guide to Coor- dinated Vulnerability Disclosure

    CERT. CERT Guide to Coor- dinated Vulnerability Disclosure . https://certcc.github.io/CERT-Guide-to- CVD/topics/phases/deployment/. perma- link: https://perma.cc/6YE9-FMK4

  34. [42]

    Fac- torization of a 512-Bit RSA Modulus

    Stefania Cavallar, Bruce Dodson, Arjen K. Lenstra, Walter Lioen, Peter L. Mont- gomery, Brian Murphy, Herman te Riele, Karen Aardal, Jeff Gilchrist, G´ erard Guillerm, Paul Leyland, J¨ oel Marchand, Fran¸ cois Morain, Alec Muffett, Chris Putnam, Craig Putnam, and Paul Zimmermann...

  35. [43]

    A wave of retractions is shaking physics

    Sophia Chen. A wave of retractions is shaking physics. permalink: https://perma.cc/ AXC6-FPZF. MIT Technology Review, 2024. url: https://www.technologyreview. com/2024/05/15/1092535/a-wave-of- retractions-is-shaking-physics/? truid=&utm_source=the_download& utm_medium=email&ut...

  36. [44]

    Pseu- dorandom Error-Correcting Codes

    Miranda Christ and Sam Gunn. “Pseu- dorandom Error-Correcting Codes”. In: CRYPTO 2024 . 2024. doi: 10.48550/arXiv.2402.09370. url: https://eprint.iacr.org/2024/235. pdf

  37. [45]

    permalink: https://perma

    CISA Open Source Software Security Roadmap. permalink: https://perma. cc/N26U-GT2G. 2023. url: https://www. cisa.gov/sites/default/files/2024-02/ CISA-Open-Source-Software-Security- Roadmap-508c.pdf

  38. [46]

    Security through obscurity: An approach for protecting Register Transfer Level hard- ware IP

    Rajat Subhra Chakraborty and Swarup Bhu- nia. “Security through obscurity: An approach for protecting Register Transfer Level hard- ware IP”. In: IEEE International Workshop on Hardware-Oriented Security and Trust, 2009. doi: 10.1109/HST.2009.5224963

  39. [47]

    Attacks on Deidentification’s Defenses

    Aloni Cohen. “Attacks on Deidentification’s Defenses”. In: 31st USENIX Security Sym- posium, USENIX Security 2022, Boston, MA, USA, August 10-12, 2022 . Ed. by Kevin R. B. Butler and Kurt Thomas. USENIX Association, 2022, pp. 1469–1486. url: https://www.usenix.org/conference/ u...

  40. [48]

    Ac- countability in an Algorithmic Society: Re- lationality, Responsibility, and Robustness in Machine Learning

    A. Feder Cooper, Emanuel Moss, Ben- jamin Laufer, and Helen Nissenbaum. “Ac- countability in an Algorithmic Society: Re- lationality, Responsibility, and Robustness in Machine Learning”. In: ACM Conf. on Fairness, Accountability, and Transparency (2022), pp. 864–876

  41. [49]

    Synthetic Data: Methods, Use Cases, and Risks

    Emiliano De Cristofaro. “Synthetic Data: Methods, Use Cases, and Risks”. In: IEEE Secur. Priv. 22.3 (2024), pp. 62–

  42. [50]

    Stan- dards

    American Society of Civil Engineers. Stan- dards. permalink: https://perma.cc/ 23YQ-EJS3. url: https://ascelibrary. org/topic/ascebookseries/standards

  43. [51]

    It’s Time to End Information Anarchy

    Scott Culp. It’s Time to End Information Anarchy. Microsoft Technet essay. 2001. url: https://web.archive.org/web/ 20040227175033/http:/www.microsoft. com/technet/columns/security/essays/ noarch.asp. 17

  44. [52]

    Searchable symmetric encryption: improved definitions and efficient constructions

    Reza Curtmola, Juan A. Garay, Seny Kamara, and Rafail Ostrovsky. “Searchable symmetric encryption: improved definitions and efficient constructions”. In: ACM Conf. on Computer and Communications Security (CCS), 2006, pp. 79–88

  45. [53]

    Building Guardrails in AI Systems with Threat Modeling

    Jayati Dev, Nuray Akhuseyinoglu, Golam Kayas, Bahman Rashidi, and Vaibhav Garg. “Building Guardrails in AI Systems with Threat Modeling”. In: Digital Govern- ment: Research and Practice (2024). doi: 10.1145/3674845. url: https://doi.org/ 10.1145/3674845

  46. [54]

    Risky Business: Keeping Security a Secret

    Whitfield Diffie. Risky Business: Keeping Security a Secret . ZDNet. permalink: https://perma.cc/9BFA-QXNX. 2003. url: https://www.zdnet.com/article/risky- business-keeping-security-a-secret- 5000127072/

  47. [55]

    Upholding the Pub- lic Trust

    Jim H. Crumpacker. “Upholding the Pub- lic Trust”. In: Public Roads 71 (4 2008). url: https://highways.dot.gov/public- roads/janfeb-2008/upholding-public- trust

  48. [56]

    Revealing in- formation while preserving privacy

    Irit Dinur and Kobbi Nissim. “Revealing in- formation while preserving privacy”. In: ACM SIGACT-SIGMOD-SIGART Symposium on Principles of Database Systems . Proceed- ings of the Twenty-Second ACM SIGACT- SIGMOD-SIGART Symposium on Principles of Database Systems, 2003, pp. 202–210

  49. [57]

    The Menlo Report

    David Dittrich and Erin Kenneally. The Menlo Report. Tech. rep. U.S. Department of Home- land Security, 2012. url: https://www.dhs. gov/sites/default/files/publications/ CSD-MenloPrinciplesCORE-20120803_1. pdf

  50. [58]

    Differential Privacy

    Cynthia Dwork. “Differential Privacy”. In: International Conf. on Automata, Languages, and Programming (ICALP) (2006), pp. 1–

  51. [59]

    Calibrating noise to sensitivity in private data analysis

    Cynthia Dwork, F. McSherry, K. Nissim, and A. Smith. “Calibrating noise to sensitivity in private data analysis”. In: Theory of Cryptog- raphy Conference ’06 . Theory of Cryptogra- phy Conference (TCC), 2006, pp. 265–284

  52. [60]

    Tor: The second-generation onion router

    Roger Dingledine, Nick Mathewson, and Paul Syverson. “Tor: The second-generation onion router”. In: Proceedings of the 13th conference on USENIX Security Symposium . Vol. 13. ACM, 2004. doi: 10.5555/1251375.1251396

  53. [61]

    The Algo- rithmic Foundations of Differential Privacy

    Cynthia Dwork and Aaron Roth. “The Algo- rithmic Foundations of Differential Privacy”. In: Foundations and Trends in Theoretical Computer Science 9 (3-4 2014), pp. 211–407. doi: 10.1561/0400000042

  54. [62]

    Hacking the Law: Are Bug Bounties a True Safe Harbor?

    Amit Elazari. “Hacking the Law: Are Bug Bounties a True Safe Harbor?” In: Enigma. Santa Clara, CA: USENIX, 2018. url: https://www.usenix.org/node/208178

  55. [63]

    Transparency and the Black Box Problem: Why We Do Not Trust AI

    Warren J. von Eschenbach. “Transparency and the Black Box Problem: Why We Do Not Trust AI”. In: Philosophy and Technology 34 (2021), pp. 1607–1622. doi: 10.1007/s13347-021-00477-0 . url: https://doi.org/10.1007/s13347-021- 00477-0

  56. [64]

    url: https://link.springer.com/ chapter/10.1007/11787006_1

  57. [65]

    Red-Teaming for Generative AI: Silver Bullet or Security Theater?

    Michael Feffer, Anusha Sinha, Wesley H. Deng, Zachary C. Lipton, and Hoda Heidari. “Red-Teaming for Generative AI: Silver Bullet or Security Theater?” In: Computers and So- ciety (2024). url: https://arxiv.org/pdf/ 2401.15897

  58. [66]

    Privacy- preserving datamining on vertically parti- tioned databases

    Cynthia Dwork and Kobbi Nissim. “Privacy- preserving datamining on vertically parti- tioned databases”. In: CRYPTO. CRYPTO, 2004, pp. 528–544

  59. [67]

    url: https://doi.org/10.1109/MSEC.2024

    doi: 10.1109/MSEC.2024.3371505. url: https://doi.org/10.1109/MSEC.2024. 3371505

  60. [68]

    Cryptography Engineering: Design Principles and Practical Applications

    Niels Ferguson, Bruce Schneier, and Ta- dayoshi Kohno. Cryptography Engineering: Design Principles and Practical Applications . John Wiley and Sons, 2010

  61. [69]

    Open sourcing AI: intellectual property at the service of platform leader- ship

    Carlos Mu˜ noz Ferrandis and Marta Duque Lizarralde. “Open sourcing AI: intellectual property at the service of platform leader- ship”. In: JIPITEC (2022). 18

  62. [70]

    Ask an Ethicist: Vulnera- bility Disclosure

    ACM Ethics. Ask an Ethicist: Vulnera- bility Disclosure . permalink: https:// perma.cc/3XXU-LXPU. url: https:// ethics.acm.org/integrity-project/ ask-an-ethicist/ask-an-ethicist- vulnerability-disclosure/

  63. [71]

    Judicial leadership matters (yet again): the asso- ciation between judge and public trust for artificial intelligence in courts

    Anna Fine and Shawn Marsh. “Judicial leadership matters (yet again): the asso- ciation between judge and public trust for artificial intelligence in courts”. In: Discover Artificial Intelligence 4 (2024). doi: 10.1007/s44163-024-00142-3 . url: https://doi.org/10.1007/s44163-024- 00142-3

  64. [72]

    A trustworthy AI reality-check: the lack of trans- parency of artificial intelligence products in healthcare

    Jana Fehr, Brian Citro, Rohit Malpani, Christoph Lippert, and Vince I. Madai. “A trustworthy AI reality-check: the lack of trans- parency of artificial intelligence products in healthcare”. In: Frontiers in Digital Health 6 (2024). doi: 10.3389/fdgth.2024.1267290

  65. [73]

    Towards Transparency by Design for Artificial Intelligence

    Heike Felzmann, Eduard Fosch-Villaronga, Christoph Lutz, and Aurelia Tam` o-Larrieux. “Towards Transparency by Design for Artificial Intelligence”. In: Science and En- gineering Ethics 26 (2020), pp. 3333–3361. doi: 10.1007/s11948-020-00276-4 . url: https://doi.org/10.1007/s119...

  66. [74]

    Electronic Frontier Foundation. MBTA v. Anderson. url: https://www.eff.org/ cases/mbta-v-anderson

  67. [75]

    Electronic Frontier Foundation. U .S. v. Auernheimer. url: https://www.eff.org/ cases/us-v-auernheimer

  68. [76]

    Fairness and Bias in Artifi- cial Intelligence: A Brief Survey of Sources, Impacts, and Mitigation Strategies

    Emilio Ferrara. “Fairness and Bias in Artifi- cial Intelligence: A Brief Survey of Sources, Impacts, and Mitigation Strategies”. In: Sci 6 (1 2023). doi: 10.3390/sci6010003. url: https://doi.org/10.3390/sci6010003

  69. [77]

    BadLlama: cheaply removing safety fine-tuning from Llama 2-Chat 13B

    Pranav Gade, Simon Lermen, Charlie Rogers- Smith, and Jeffrey Ladish. “BadLlama: cheaply removing safety fine-tuning from Llama 2-Chat 13B”. In: arXiv.2311.00117 (2024). doi: 10.48550/arXiv.2311.00117. url: https://doi.org/10.48550/arXiv. 2311.00117

  70. [78]

    Ethics governance development: The case of the Menlo Report

    Megan Finn and Katie Shilton. “Ethics governance development: The case of the Menlo Report”. In: Social Studies of Sci- ence (2023). url: https://doi.org/10. 1177/03063127231151708

  71. [79]

    Searchlights across the black box: Trade secrecy versus access to information

    Katarina Foss-Solbrekk. “Searchlights across the black box: Trade secrecy versus access to information”. In: Com- puter Law and Security Review 50 (2023). doi: 10.1016/j.clsr.2023.105811. url: https://doi.org/10.1016/j.clsr.2023. 105811

  72. [80]

    The tech industry can’t agree on what open-source AI means

    Edd Gent. The tech industry can’t agree on what open-source AI means. That’s a problem. permalink: https://perma.cc/ P4A7-879Q. MIT Technology Review, 2024. url: https://www.technologyreview. com/2024/03/25/1090111/tech-industry- open-source-ai-definition-problem/

  73. [81]

    Not all ‘open source’ AI models are actually open: here’s a rank- ing

    Elizabeth Gibney. Not all ‘open source’ AI models are actually open: here’s a rank- ing. permalink: https://perma.cc/27TU- ETEK. 2024. url: https://www.nature.com/ articles/d41586-024-02012-5

  74. [82]

    Dynamic Capability and Open-Source Strategy in the Age of Digital Transformation

    Nobuyuki Fukawa, Yanzhi Zhang, and Sunil Erevelles. “Dynamic Capability and Open-Source Strategy in the Age of Digital Transformation”. In: Journal of Open Innovation: Technology, Market, and Complexity 7 (3 2021), p. 175. doi: 10.3390/joitmc7030175. url: https:// doi.org/10.3...

  75. [83]

    Public Procurement Transparency and its Potential to Reduce Corruption in Low-Income Countries

    Salome Girgvliani. “Public Procurement Transparency and its Potential to Reduce Corruption in Low-Income Countries”. In: CSIS - Center for Strategic and Interna- tional Studies (2023). url: https://www. csis.org/blogs/development-dispatch/ public-procurement-transparency-and- ...

  76. [84]

    Quantifying the Pressure of Legal Risks on Third-party Vulnerability Research

    Alexander Gamero-Garrido, Stefan Savage, Kirill Levchenko, and Alex C. Snoeren. “Quantifying the Pressure of Legal Risks on Third-party Vulnerability Research”. In: ACM Conf. on Computers and Com- munications Security (2017), pp. 1501–

  77. [85]

    Computational approaches to Explainable Artificial Intelli- gence: Advances in theory, applications and trends

    J.M. G´ orriz, I. ´Alvarez-Ill´ an, A. ´Alvarez- Marquina, J.E. Arco, M. Atzmueller, F. Mallarini, E. Barakova, G. Bologna, P. Bonomini, G. Castellanos-Dominguez, D. Castillo-Barnes, S.B. Cho, R. Con- treras, J.M. Cuadra, E. Dom ´ ınguez, F. Dom ´ ınguez-Mateos, R.J. Duro, D. ...

  78. [86]

    Machine Un- learning via Simulated Oracle Matching

    Shivam Garg, Kristian G Georgiev, Andrew Ilyas, Sung Min Park, Aleksander Rinberg Roy adn Madry, and Seth Neel. “Machine Un- learning via Simulated Oracle Matching”. In: GenLaw 2024. 2024

  79. [88]

    A global taxonomy of interpretable AI: unifying the terminology for the techni- cal and social sciences

    Mara Graziani, Lidia Dutkiewicz, Davide Calvaresi, Jos´ e Pereira Amorim, Katerina Yordanova, Mor Vered, Rahul Nair, Pe- dro Henriques Abreu, Tobias Blanke, Vale- ria Pulignano, John O. Prior, Lode Lauwaert, Wessel Reijers, Adrien Depeursinge, Vin- cent Andrearczyk, and Hennin...

  80. [89]

    Ap- ple, Nvidia, Anthropic Used Thousands of Swiped YouTube Videos to Train AI

    Annie Gilbertson and Alex Reisner. Ap- ple, Nvidia, Anthropic Used Thousands of Swiped YouTube Videos to Train AI . Proof News, Wired. permalink: https://perma. cc/3F86-P3YR. 2024. url: https://www. proofnews.org/apple-nvidia-anthropic- used-thousands-of-swiped-youtube- videos...

  81. [90]

    NIST Asks Public to Help Future-Proof Elec- tronic Information

    NIST Cryptographic Technology Group. NIST Asks Public to Help Future-Proof Elec- tronic Information . permalink: https:// perma.cc/8DH6-YDXM. 2016. url: https:// www.nist.gov/news-events/news/2016/ 12/nist-asks-public-help-future- proof-electronic-information

  82. [91]

    Problems of monetary management: the U.K. experience

    Charles Goodhart. “Problems of monetary management: the U.K. experience”. In: Papers in monetary economics (1975), pp. 1–20

  83. [92]

    Black box algorithms and the rights of individuals: no easy solution to the

    Jarek Gryz and Marcin Rojszczak. “Black box algorithms and the rights of individuals: no easy solution to the ”explainability” prob- lem”. In: Internet Policy Review 10 (2 2021). doi: 10.14763/2021.2.1564

  84. [93]

    Towards Learning from Losing Aaron Swartz

    Jennifer Granick. Towards Learning from Losing Aaron Swartz . Center for Inter- net and Security at Stanford Law School. permalink: https://perma.cc/53E5-6RDQ. url: https://cyberlaw.stanford.edu/ blog/2013/01/towards-learning-losing- aaron-swartz

  85. [94]

    Community Norms as Self-Regulation of Generative AI in Creative Industries

    Peter Hall, Betty Li Hou, and Falaah Arif Khan. “Community Norms as Self-Regulation of Generative AI in Creative Industries”. In: GenLaw 2024. 2024

  86. [95]

    Interpreting Black-Box Models: A Review on Explainable Artificial Intelligence

    Vikas Hassija, Vinay Chamola, Atmesh Ma- hapatra, Abhinandan Singal, Divyansh Goel, Kaizhu Huang, Simone Scardapane, Indro Spinelli, Mufti Mahmud, and Amir Hussain. “Interpreting Black-Box Models: A Review on Explainable Artificial Intelligence”. In: Cogni- tive Computation 16 ...

  87. [96]

    Fanstastic Copyrighted Beasts and How (Not) to Generate Them

    Luxi He, Yangsibo Huang, Weijia Shi, Ting- hao Xie, Haotian Liu, Yue Wang, Luke Zettle- moyer, Chiyuan Zhang, Danqi Chen, and Peter Henderson. “Fanstastic Copyrighted Beasts and How (Not) to Generate Them”. In: GenLaw 2024. 2024

  88. [97]

    OLMo: Accelerating the Science of Language Models

    Dirk Groeneveld et al. “OLMo: Accelerating the Science of Language Models”. In: Compu- tation and Language (2024). url: https:// arxiv.org/pdf/2402.00838

  89. [98]

    An Overview of Catas- trophic AI Risks

    Dan Hendrycks, Mantas Mazeika, and Thomas Woodside. “An Overview of Catas- trophic AI Risks”. In: arXiv (2023). url: https://arxiv.org/abs/2306.12001

  90. [99]

    Post-Quantum Cryptography Minimum Acceptability Requirements

    NIST Cryptographic Technology Group. Post-Quantum Cryptography Minimum Acceptability Requirements . permalink: https://perma.cc/5Z3K-TANL. 2017. url: https://csrc.nist.gov/projects/post- quantum-cryptography/post-quantum- cryptography-standardization/minimum- acceptability-req...

  91. [100]

    Expe- riences with improving the transparency of AI models and services

    M Hind, S Houde, J Martino, A Mojislovic, D Piorkowski, and J et al. Richard. “Expe- riences with improving the transparency of AI models and services”. In: Conf. on Hu- man Factors in Computing Systems (2020), pp. 1–8. doi: 10.1145/3334480.3383051. url: https://dl.acm.org/doi...

  92. [101]

    Privacy, accuracy, and model fairness trade-offs in federated learning

    Xiuting Gu, Zhu Tianqing, Jie Li, Tao Zhang, Wei Ren, and Kim-Kwang Ray- mond Choo. “Privacy, accuracy, and model fairness trade-offs in federated learning”. In: Computers and Security 122 (2022). doi: 10.1016/j.cose.2022.102907. url: https://doi.org/10.1016/j.cose.2022. 102907

  93. [102]

    The US physics community is not done working on trust

    Frances Houle, Kate Kirby, Laura Greene, and Michael Marder. The US physics community is not done working on trust . perma- link: https://perma.cc/V9U4-33ZY. MIT Technology Review, 2024. url: https:// www.technologyreview.com/2024/07/31/ 1095425/the-us-physics-community- is-no...

  94. [103]

    Software Architect’s Handbook

    Joseph Ingeno. Software Architect’s Handbook. Packt Publishing, 2018. url: https://www. oreilly.com/library/view/software- architects-handbook/9781788624060/ 1e2ac7d1-3f9a-4a4f-ab78-f7f9f5b9e8a6. xhtml

  95. [104]

    The Open Source AI Definition - https://hackmd.io/@opensourceinitiative/osaid- 0-0-8

    Open Source Initiative. The Open Source AI Definition - https://hackmd.io/@opensourceinitiative/osaid- 0-0-8. permalink: https://perma.cc/ 9A3Z-JTVR. 2024. url: https://hackmd.io/ @opensourceinitiative/osaid-0-0-8

  96. [105]

    AI companies promised to self-regulate one year ago

    Melissa Heikkil¨ a. AI companies promised to self-regulate one year ago. What’s changed? permalink: https://perma.cc/4ACF- DGBJ. MIT Technology Review, 2024. url: https://www.technologyreview. com/2024/07/22/1095193/ai-companies- promised-the-white-house-to-self- regulate-one-...

  97. [106]

    Encryption: A Matter of Human Rights

    Amnesty International. Encryption: A Matter of Human Rights . 2016. url: https://www. amnesty.org/en/wp-content/uploads/ 2021/05/POL4036822016ENGLISH.pdf

  98. [107]

    ’Anonymised’ data can never be totally anonymous, says study

    Alex Hern. ’Anonymised’ data can never be totally anonymous, says study . perma- link: https://perma.cc/9W9X-LHGZ. 2019. url: https://www.theguardian.com/ technology/2019/jul/23/anonymised- data-never-be-anonymous-enough-study- finds. 20

  99. [108]

    Crypto Wars: The Fight for Pri- vacy in the Digital Age

    Craig Jarvis. Crypto Wars: The Fight for Pri- vacy in the Digital Age . CRC Press, 2020. isbn: 9780367642488

  100. [109]

    Regulating AI: Getting the Balance Right

    Kartik Hosanagar. “Regulating AI: Getting the Balance Right”. In: Knowledge at Whar- ton (2024). permalink: https://perma. cc/XWQ9-YH6X. url: https://knowledge. wharton.upenn.edu/article/regulating- ai-getting-the-balance-right/

  101. [110]

    Highly Accurate Protein Structure Prediction with AlphaFold

    John Jumper, Alexander Pritzel Richard Evans, Tim Green, Michael Figurnov, Olaf Ronneberger, Kathryn Tunyasuvu- nakool, Russ Bates, Augustin ˇZ ´ ıdek, Anna Potapenko, Alex Bridgland, Clemens Meyer, Simon A. A. Kohl, Andrew J. Ballard, Andrew Cowie, Bernardino Romera-Paredes, ...

  102. [111]

    The Codebreakers: The Com- prehensive History of Secret Communication from Ancient Times to the Internet

    David Kahn. The Codebreakers: The Com- prehensive History of Secret Communication from Ancient Times to the Internet . Scribner,

  103. [112]

    Introduc- tion to Modern Cryptography

    Jonathan Katz and Yehuda Lindell. Introduc- tion to Modern Cryptography . Second. CRC Press, 2015

  104. [113]

    The Open Source Def- inition - https://opensource.org/osd

    Open Source Initiative. The Open Source Def- inition - https://opensource.org/osd . perma- link: https://perma.cc/T4MB-97MR. 2024. url: https://opensource.org/osd

  105. [114]

    La Cryptographie Mil- itaire

    Auguste Kerckhoffs. “La Cryptographie Mil- itaire”. In: Journal des sciences militaires . Vol. 9. 1883, pp. 5–38, 161–191

  106. [115]

    Methods for Adapting Large Language Models

    Aditya Jain, Amir Maleki, and Nathalie Saade. Methods for Adapting Large Language Models. Tech. rep. permalink: https:// perma.cc/WC76-MBL7. Meta AI, 2024. url: https://ai.meta.com/blog/adapting- large-language-models-llms/

  107. [116]

    Secrecy and Unaccountabil- ity: Trade Secrets in Our Public Infrastruc- ture

    David S. Levine. “Secrecy and Unaccountabil- ity: Trade Secrets in Our Public Infrastruc- ture”. In: Florida Law Review 59 (2006). url: https://ssrn.com/abstract=900929. 21

  108. [117]

    Computer Security Ver- sus the Public’s Right to Know

    Douglas W. Jones. “Computer Security Ver- sus the Public’s Right to Know”. In: Computers, Freedom and Privacy (2007). url: https://homepage.divms.uiowa.edu/ ~jones/voting/cfp2007.pdf

  109. [118]

    Explainable AI: A Review of Machine Learning Interpretabil- ity Methods

    Pantelis Linardatos, Vasilis Papastefanopou- los, and Sotiris Kotsiantis. “Explainable AI: A Review of Machine Learning Interpretabil- ity Methods”. In: Entropy (2020). doi: 10.3390/e23010018

  110. [119]

    The Mythos of Model Interpretability

    Zachary C. Lipton. “The Mythos of Model Interpretability”. In: eprint arXiv:1606.03490 (2016). url: https://arxiv.org/abs/1606. 03490

  111. [120]

    Digital rights man- agement for content distribution

    Qiong Liu, Reihanah Safavi-Naini, and Nicholas Paul Sheppard. “Digital rights man- agement for content distribution”. In: ACM ACSW Frontiers ‘03. ACM ACSW Frontiers, 2003, pp. 49–58

  112. [121]

    October 26, 1992: Software Glitch Cripples Ambulance Service

    Tony Long. October 26, 1992: Software Glitch Cripples Ambulance Service . perma- link: https://perma.cc/ZE6Q-FCJ2. 2009. url: https://www.wired.com/2009/ 10/1026london-ambulance-computer- meltdown/

  113. [122]

    Biosecurity Culture, Com- puter Security Culture

    Jeff Kaufman. Biosecurity Culture, Com- puter Security Culture . permalink: https://perma.cc/5AG3-JMT3. 2023. url: https://forum.effectivealtruism.org/ posts/PTtZWBAKgrrnZj73n/biosecurity- culture-computer-security-culture

  114. [123]

    Black-Box vs. White-Box: Understanding Their Advantages and Weaknesses From a Practical Point of View

    Octavio Loyola-Gonz´ alez. “Black-Box vs. White-Box: Understanding Their Advantages and Weaknesses From a Practical Point of View”. In: IEEE Access 7 (1 2019). doi: 10.1109/ACCESS.2019.2949286. url: https://ieeexplore.ieee.org/document/ 8882211

  115. [124]

    Drawbacks of Artificial Intelligence and Their Potential Solutions in the Healthcare Sector

    Bangul Khan, Hajira Fatima, Ayatullah Qureshi, Sanjay Kumar, Abdul Hanan, Jawad Hussain, and Saad Abdullah. “Drawbacks of Artificial Intelligence and Their Potential Solutions in the Healthcare Sector”. In: Biomedical Materials and Devices (2023). doi: 10.1007/s44174-023-00063-...

  116. [125]

    Thoughts on open source AI

    Sam Marks. Thoughts on open source AI . permalink: https://perma.cc/292X-QZJK

  117. [126]

    Rethinking open source generative AI: open-washing and the EU AI Act

    Andreas Liesenfeld and Mark Dingemanse. “Rethinking open source generative AI: open-washing and the EU AI Act”. In: F AccT 2024 (2024), pp. 1774–1787. doi: 10.1145/3630106.3659005. url: https:// doi.org/10.1145/3630106.3659005

  118. [127]

    A multi-objective op- timization design to generate surrogate machine learning models in explainable artificial intelligence applications

    Wellington Rodrigo Monteiro and Gilberto Reynoso-Meza. “A multi-objective op- timization design to generate surrogate machine learning models in explainable artificial intelligence applications”. In: EURO Journal on Decision Processes 11 (2023). doi: 10.1016/j.ejdp.2023.100040....

  119. [128]

    Vulnerability Disclosure Considered Stress- ful

    Giovane C. M. Moura and John Heidemann. “Vulnerability Disclosure Considered Stress- ful”. In: SIGCOMM Computer Communica- tion Review . Vol. 53. ACM SIGCOMM Com- puter Communication Review, 2023, pp. 2–10. doi: 10.1145/3610381.3610383

  120. [129]

    Robust De-anonymization of Large Sparse Datasets

    Arvind Narayanan and Vitaly Shmatikov. “Robust De-anonymization of Large Sparse Datasets”. In: 2008 IEEE Symposium on Security and Privacy . IEEE Sympo- sium on Security and Privacy, 2008. doi: 10.1109/SP.2008.33

  121. [130]

    Scalable Extraction of Training Data from (Production) Language Models

    Milad Nasr, Nicholas Carlini, Jonathan Hayase, Matthew Jagielski, A. Feder Cooper, Daphne Ippolito, Christopher A. Choquette- Choo, Eric Wallace, Florian Tram` er, and Katherine Lee. “Scalable Extraction of Training Data from (Production) Language Models”. In: arXiv.2311.17035...

  122. [131]

    A Safe Harbor for AI Evaluation and Red Teaming

    Shayne Longpre, Sayash Kapoor, Kevin Kly- man, Ashwin Ramaswami, Rishi Bommasani, Borhane Blili-Hamelin, Yangsibo Huang, Aviya Skowron, Zheng-Xin Yong, Suhas Kotha, Yi Zeng, Weiyan Shi, Xianjun Yang, Reid Southen, Alexander Robey, Patrick Chao, Diyi Yang, Ruoxi Jia, Daniel Kan...

  123. [132]

    United States

    Nathan Van Buren v. United States . url: https://www.eff.org/files/2020/07/ 08/19-783_eff_security_researchers_ amici_brief_.pdf. 22

  124. [133]

    When is Technology Too Dangerous to Release to the Public?

    Aaron Mak. “When is Technology Too Dangerous to Release to the Public?” In: Slate (2019). permalink: https://perma. cc/N9ZL-Z9XB. url: https://slate.com/ technology/2019/02/openai-gpt2-text- generating-algorithm-ai-dangerous. html

  125. [135]

    Accountability in ar- tificial intelligence: what it is and how it works

    Claudio Novelli, Mariarosaria Taddeo, and Luciano Floridi. “Accountability in ar- tificial intelligence: what it is and how it works”. In: AI and Society (2023). doi: 10.1007/s00146-023-01635-y . url: https://doi.org/10.1007/s00146-023- 01635-y

  126. [136]

    Security by Obscurity

    Rebecca T. Mercuri and Peter G. Neumann. “Security by Obscurity”. In: Communications of the ACM 46 (2003)

  127. [137]

    Broken Promises of Privacy: Responding to the surprising failure of anonymization

    Paul Ohm. “Broken Promises of Privacy: Responding to the surprising failure of anonymization”. In: UCLA Law Review 57 (2009). url: https://papers.ssrn.com/ sol3/papers.cfm?abstract_id=1450006

  128. [138]

    A Re- searcher’s Guide to Some Legal Risks of Security Research

    Sunoo Park and Kendra Albert. A Re- searcher’s Guide to Some Legal Risks of Security Research . permalink: https:// perma.cc/27TU-ETEK. 2024. url: https:// clinic.cyber.harvard.edu/wp-content/ uploads/2024/08/Security-Researchers- Guide-8-2-24.pdf

  129. [139]

    Bring- ing Transparency to National Security Uses of Artificial Intelligence

    Faiza Patel and Patrick C. Toomey. “Bring- ing Transparency to National Security Uses of Artificial Intelligence”. In: justse- curity.org (2024). permalink: https:// perma.cc/SL93-RAK3. url: https:// www.justsecurity.org/94113/bringing- transparency-to-national-security- uses-o...

  130. [140]

    Benefits-Risk Frameworks: Implementation by Industry

    Nancy J. Pire-Smerkanich. “Benefits-Risk Frameworks: Implementation by Industry”. PhD thesis. University of Southern California, 2016

  131. [141]

    Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning

    Milad Nasr, Reza Shokri, and Amir Houmansadr. “Comprehensive Privacy Analysis of Deep Learning: Passive and Active White-box Inference Attacks against Centralized and Federated Learning”. In: 2019 IEEE Symposium on Security and Privacy. IEEE Symposium on Security and Privacy, ...

  132. [142]

    Nearly 400 car crashes in 11 months involved automated tech, com- panies tell regulators

    The Associated Press. Nearly 400 car crashes in 11 months involved automated tech, com- panies tell regulators . permalink: https:// perma.cc/UZD8-8GK7. 2022. url: https:// www.npr.org/2022/06/15/1105252793/ nearly-400-car-crashes-in-11-months- involved-automated-tech-companie...

  133. [143]

    Taxonomy of Trustwor- thiness for Artificial Intelligence: Connecting Properties of Trustworthiness with Risk Man- agement and the AI Lifecycle

    Jessica Newman. “Taxonomy of Trustwor- thiness for Artificial Intelligence: Connecting Properties of Trustworthiness with Risk Man- agement and the AI Lifecycle”. In: CLTC White Paper Series (2023)

  134. [144]

    Raimondo and Laurie E

    Gina M. Raimondo and Laurie E. Locas- cio. Artificial Intelligence Risk Management Framework (AI RMF 1.0) . Tech. rep. Na- tional Institute of Standards and Technology,

  135. [145]

    AI in health and medicine

    Pranav Rajpurkar, Emma Chen, Oishi Banerjee, and Eric J. Topol. “AI in health and medicine”. In: Nature Medicine 28 (2022), pp. 31–38. doi: 10.1038/s41591-021-01614-0

  136. [146]

    No, hashing still doesn’t make your data anonymous

    Staff in the Office of Technology. No, hashing still doesn’t make your data anonymous . permalink: https://perma.cc/HHA2-HJFX

  137. [147]

    url: https://www.ftc.gov/policy/ advocacy-research/tech-at-ftc/2024/ 07/no-hashing-still-doesnt-make-your- data-anonymous

  138. [148]

    Eric S. Raymond. The Cathedral and the Bazaar: Musings on Linux and Open Source by an Accidental Revolutionary . O’Reilly and Associates, 1999. isbn: 1-565-92724-9. 23

  139. [149]

    Renieris, David Kiron, and Steven Mills

    Elizabeth M. Renieris, David Kiron, and Steven Mills. Organizations Face Challenges in Timely Compliance With the EU AI Act . permalink: https://perma.cc/247V-YVL7. MIT Sloan Management Review, 2024. url: https://sloanreview.mit.edu/article/ organizations-face-challenges-in- t...

  140. [150]

    The Moral Character of Cryptographic Work

    Phillip Rogaway. The Moral Character of Cryptographic Work. Invited Talk - AsiaCrypt

  141. [151]

    Procuring Algorithmic Transparency

    Elizabeth A. Rowe. “Procuring Algorithmic Transparency”. In: Alabama Law Review 74 (2 2022). url: https://papers.ssrn.com/ sol3/papers.cfm?abstract_id=4044178

  142. [152]

    Challenges and efforts in managing AI trustworthiness risks: a state of knowledge

    Nineta Polemi, Isabel Pra¸ ca, Kitty Kioskli, and Adrien B´ ecue. “Challenges and efforts in managing AI trustworthiness risks: a state of knowledge”. In: Frontiers in Big Data (2024). doi: 10.3389/fdata.2024.1381163. url: https://doi.org/10.3389/fdata.2024. 1381163

  143. [153]

    Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Interpretable Models Instead

    Cynthia Rudin. “Stop Explaining Black Box Machine Learning Models for High Stakes Decisions and Use Interpretable Models Instead”. In: Nature Machine Intelligence (2022). doi: 10.1038/s42256-019-0048-x . url: https://doi.org/10.1038/s42256- 019-0048-x

  144. [154]

    Euro- pean Comission

    Proposal for a Regulation of the European Parliament and of the Council: Laying Down Harmonised Rules on Artificial Intelligence (Artificial Intelligence Act) and Amending Certain Union Legislastive Acts . Euro- pean Comission. 2021. url: https://eur- lex.europa.eu/legal-content...

  145. [155]

    Beyond Fear: Thinking Sen- sibly About Security in an Uncertain World

    Bruce Schneier. Beyond Fear: Thinking Sen- sibly About Security in an Uncertain World . Springer, 2003. doi: 10.1007/b97547

  146. [156]

    url: https://doi.org/10.6028/NIST.AI.100-1

    doi: 10.6028/NIST.AI.100-1. url: https://doi.org/10.6028/NIST.AI.100-1

  147. [157]

    The Non-Security of Se- crecy

    Bruce Schneier. “The Non-Security of Se- crecy”. In: Communications of the ACM 47 (2004)

  148. [158]

    Red-Teaming the Stable Diffusion Safety Filter

    Javier Rando, Daniel Paleka, David Lind- ner, Lennart Heim, and Florian Tram` er. “Red-Teaming the Stable Diffusion Safety Filter”. In: Artificial Intelligence (2022). doi: 10.48550/arXiv.2210.04610. url: https://doi.org/10.48550/arXiv.2210. 04610

  149. [159]

    Operation Charlie: Hack- ing the MBTA CharlieCard from 2008 to Present

    Bobby Rauch. “Operation Charlie: Hack- ing the MBTA CharlieCard from 2008 to Present”. In: Bobbyrsec-Medium (2022). permalink: https://perma.cc/82SP-FLSE. url: https://medium.com/@bobbyrsec/ operation-charlie-hacking-the-mbta- charliecard-from-2008-to-present- 24ea9f0aaa38

  150. [160]

    Communication Theory of Secrecy Systems

    Claude E. Shannon. “Communication Theory of Secrecy Systems”. In: Bell Systems Techni- cal Journal . Vol. 28. 1949, pp. 656–715. url: https://pages.cs.wisc.edu/~rist/642- spring-2014/shannon-secrecy.pdf

  151. [161]

    Tragedy of the Dig- ital Commons

    Chinmayi Sharma. “Tragedy of the Dig- ital Commons”. In: 101 North Car- olina Law Review 1129 . 2022. doi: 10.2139/ssrn.4245266. url: https:// papers.ssrn.com/sol3/papers.cfm? abstract_id=4245266

  152. [162]

    Don’t Be Afraid to Code in the Open: Here’s How to Do It Securely

    Anna Shipman. Don’t Be Afraid to Code in the Open: Here’s How to Do It Securely . UK Technology Blog. permalink: https:// perma.cc/3TBD-QPBC. 2019. url: https:// technology.blog.gov.uk/2017/09/27/ dont-%20be-afraid-to-code-in-the- open-heres-how-to-do-it-securely

  153. [163]

    Dual-use open source secu- rity software in organizations - Dilemma: help or hinder?

    Mario Silic. “Dual-use open source secu- rity software in organizations - Dilemma: help or hinder?” In: Computers and Secu- rity. Vol. 39. Elsevier, 2013, pp. 386–395. doi: 10.1016/j.cose.2013.09.003

  154. [164]

    Factors Associated With Pub- lic Trust in Pharmaceutical Manufacturers

    Yashaswini Singh, Matthew D. Eisenberg, and Neeraj Sood. “Factors Associated With Pub- lic Trust in Pharmaceutical Manufacturers”. In: JAMA Network Open 6 (3 2023). doi: 10.1001/jamanetworkopen.2023.3002. url: https://doi.org/10.1001/ jamanetworkopen.2023.3002

  155. [165]

    Anonymization and Risk

    Ira S. Rubinstein and Woodrow Hartzog. “Anonymization and Risk”. In: Washing- ton Law Review 91 (2016). url: https:// digitalcommons.law.uw.edu/wlr/vol91/ iss2/18

  156. [166]

    The Fundamental Limits of Least- Privilege Learning

    Theresa Stadler, Bogdan Kulynych, Michael C. Gastpar, Nicolas Papernot, and Carmela Troncoso. “The Fundamental Limits of Least- Privilege Learning”. In: arXiv (2024). url: https://arxiv.org/pdf/2402.12235

  157. [167]

    AI as a challenge for legal regulation - the scope of application of the artificial intelligence act proposal

    Hannah Ruschemeier. “AI as a challenge for legal regulation - the scope of application of the artificial intelligence act proposal”. In: ERA Forum (2023), pp. 361–376. doi: 10.1007/s12027-022-00725-6 . url: https://doi.org/10.1007/s12027-022- 00725-6

  158. [168]

    Protections for Human Sub- jects in Research: Old Models, New Needs?

    Laura Stark. “Protections for Human Sub- jects in Research: Old Models, New Needs?” In: MIT Case Studies in Social and Eth- ical Responsibilities of Computing (2022). url: https://mit-serc.pubpub.org/ pub/protections-for-human-subjects/ release/1

  159. [169]

    Open Source and Security

    Bruce Schneier. Open Source and Security

  160. [170]

    Replacing Personally- Identifying Information in Medical Records, the Scrub System

    Latanya Sweeney. Replacing Personally- Identifying Information in Medical Records, the Scrub System . 1996. url: https:// dataprivacylab.org/projects/scrub/ paper1.pdf

  161. [171]

    Simple Demographics Often Identify People Uniquely

    Latanya Sweeney. “Simple Demographics Often Identify People Uniquely”. In: Carnegie Mellon University, Data Privacy Working Pa- per (2000). url: https://dataprivacylab. org/projects/identifiability/paper1. pdf

  162. [172]

    Trustworty AI Means Public AI [Last Word]

    Bruce Schneier. “Trustworty AI Means Public AI [Last Word]”. In: IEEE Secu- rity and Privacy 21 (2023), pp. 95–96. doi: 10.1109/MSEC.2023.3301262. url: https://doi.ieeecomputersociety.org/ 10.1109/MSEC.2023.3301262

  163. [173]

    The Belmont Report - Ethical Principles and Guidelines for the Protection of Human Subjects of Research

    Office of the Secretary. The Belmont Report - Ethical Principles and Guidelines for the Protection of Human Subjects of Research . The National Commission for the Protec- tion of Human Subjects of Biomedical and Behavioral Research, U.S.A. 1979. url: https://www.hhs.gov/ohrp/reg...

  164. [174]

    P=NP? Not exactly, but here are some research questions from the Office of Technology

    FTC Staff - Office of Technology. P=NP? Not exactly, but here are some research questions from the Office of Technology . U.S. Federal Trade Commission. permalink: https:// perma.cc/4ELG-H7XX. 2024. url: https:// www.ftc.gov/policy/advocacy-research/ tech-at-ftc/2024/05/p-np-not-ex...

  165. [175]

    Technolo- gies Underlying Weapons of Mass Destruc- tion

    Office of Technology Assessment. Technolo- gies Underlying Weapons of Mass Destruc- tion. U.S. Government Printing Office, 1993. isbn: 0160430224. url: https://ota.fas. org/reports/9344.pdf

  166. [176]

    OpenAI says voice cloning tool too risky to release, cites fears of “mis- use

    Shannon Thaler. “OpenAI says voice cloning tool too risky to release, cites fears of “mis- use” in 2024 election”. In: NY Post (2024). permalink: https://perma.cc/5M6W- 7WKP. url: https://nypost.com/2024/04/ 01/business/openai-says-its-voice- cloning-tool-too-risky-to-release/

  167. [177]

    Microsoft Corporation et al., No

    The New York Times Company v. Microsoft Corporation et al., No. 1:23-cv-11195 ( S.D. N.Y. 2023). url: https://nytco-assets. nytimes.com/2023/12/NYT_Complaint_ Dec2023.pdf

  168. [178]

    UN General Assembly

    The right to privacy in the digital age- Re- port of the Office of the United Nations High Commissioner for Human Rights . UN General Assembly. 2022

  169. [179]

    The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections

    Michael A. Specter, James Koppel, and Daniel J. Weitzner. “The Ballot is Busted Before the Blockchain: A Security Analysis of Voatz, the First Internet Voting Application Used in U.S. Federal Elections”. In: 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2...

  170. [180]

    Top AI researchers say Ope- nAI, Meta and more hinder independent evaluations

    Nitasha Tiku. Top AI researchers say Ope- nAI, Meta and more hinder independent evaluations. Washington Post. perma- link: https://perma.cc/N7B6-MUVH. 2024. url: https://www.washingtonpost.com/ technology/2024/03/05/ai-research- letter-openai-meta-midjourney/

  171. [181]

    Behind Closed Doors: IRBs and the Making of Ethical Research

    Laura Stark. Behind Closed Doors: IRBs and the Making of Ethical Research . University of Chicago Press, 2011. url: https://press. uchicago.edu/ucp/books/book/chicago/ B/bo12182576.html

  172. [182]

    Llama 2: Open Foun- dation and Fine-Tuned Chat Models

    Hugo Touvron et al. “Llama 2: Open Foun- dation and Fine-Tuned Chat Models”. In: Computation and Language (2023). doi: 10.48550/arXiv.2307.09288. url: https://doi.org/10.48550/arXiv.2307. 09288

  173. [183]

    A Frame- work for Understanding Sources of Harm throughout the Machine Learning Life Cycle

    Harini Suresh and John Guttag. “A Frame- work for Understanding Sources of Harm throughout the Machine Learning Life Cycle”. In: Equity and Access in Algorithms Mech- anisms, and Optimization . ACM, 2021. doi: 10.1145/3465416.3483305

  174. [184]

    Regulation (EU) 2024/1689 of the European Parliament and of the Council

    European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council”. In: Official Journal of the European Union (2024). url: http:// data.europa.eu/eli/reg/2024/1689/oj

  175. [185]

    Cybersecurity and Moral Haz- ard

    Jeffrey Vagle. “Cybersecurity and Moral Haz- ard”. In: Stanford Technology Law Review (2020). doi: 10.2139/ssrn.3055231

  176. [186]

    The pace of artificial inteligence innovations: Speed, talent, and trial-and- error

    Xuli Tang, Xin Li, Ying Ding, Min Song, and Yi Bu. “The pace of artificial inteligence innovations: Speed, talent, and trial-and- error”. In: Journal of Informetrics 14 (4 2020). doi: 10.1016/j.joi.2020.101094. url: https://doi.org/10.1016/j.joi. 2020.101094

  177. [187]

    On Open- Weights Foundation Models

    FTC Staff - Office of Technology. On Open- Weights Foundation Models . U.S. Federal Trade Commission. permalink: https:// perma.cc/P5TJ-E5JX. 2024. url: https:// www.ftc.gov/policy/advocacy-research/ tech-at-ftc/2024/07/open-weights- foundation-models

  178. [188]

    OpenAI has published the text-generating AI it said was too dan- gerous to share

    James Vincent. “OpenAI has published the text-generating AI it said was too dan- gerous to share”. In: The Verge (2019). permalink: https://perma.cc/YY32-LABJ. url: https://www.theverge.com/2019/ 11/7/20953040/openai-text-generation- ai-gpt-2-full-model-release-1-5b- parameters

  179. [189]

    Jailbroken: How Does LLM Safety Training Fail?

    Alexander Wei, Nika Haghtalab, and Jacob Steinhardt. “Jailbroken: How Does LLM Safety Training Fail?” In: Machine Learning (2023). doi: 10.48550/arXiv.2307.02483. url: https://doi.org/10.48550/arXiv. 2307.02483

  180. [190]

    Ethical and social risks of harm from language models

    Laura Weidinger, John Mellor, Maribeth Rauh, Conor Griffin, Jonathan Uesato, Po- Sen Huang, Myra Cheng, Mia Glaese, Borja Balle, Atoosa Kasirzadeh, et al. “Ethical and social risks of harm from language models”. In: arXiv:2112.04359 (2021). doi: arXiv:2112.04359

  181. [191]

    Good Faith Researcher Code of Conduct

    Tarah Wheeler. Good Faith Researcher Code of Conduct . permalink: https:// perma.cc/X5QT-3Y6N. 2022. url: https:// tarahmarie.github.io/gfcrc/

  182. [192]

    The Model Openness Framework: Promoting Completeness and Openness for Repro- ducibility, Transparency, and Usability in Artificial Intelligence

    Matt White, Ibrahim Haddad, Cailean Osborne, Xiao-Yang Liu Yanglet, Ahmed Abdelmonsef, and Sachin Varghese. The Model Openness Framework: Promoting Completeness and Openness for Repro- ducibility, Transparency, and Usability in Artificial Intelligence . arXiv.2403.13784

  183. [193]

    Ethical issues in research us- ing datasets of illicit origin

    Daniel R. Thomas, Sergio Pastrana, Alice Hutchings, Richard Clayton, and Alastair R. Beresford. “Ethical issues in research us- ing datasets of illicit origin”. In: IMC ’17: Proceedings of the 2017 Internet Measure- ment Conference. London, UK, 2017. doi: 10.1145/3131365.31313...

  184. [194]

    permalink: https://perma.cc/ GAA6-WL6U

    WIPO Guide to Trade Secrets and Inno- vation. permalink: https://perma.cc/ GAA6-WL6U. World Intellectual Property Organization. url: https://www.wipo.int/ web-publications/wipo-guide-to-trade- secrets-and-innovation/en/index.html

  185. [195]

    Code Talkers Were America’s Se- cret Weapon in World War II

    Laura Tohe. Code Talkers Were America’s Se- cret Weapon in World War II . Humanities: The Magazine of the NEH. 2022. 25

  186. [196]

    Differentially Private Fine-tuning of Language Models

    Da Yu, Saurabh Naik, Arturs Backurs, Sivakanth Gopi, Huseyin A. Inan, Gau- tam Kamath, Janardhan Kulkarni, Yin Tat Lee, Andre Manoel, Lukas Wutschitz, Sergey Yekhanin, and Huishuai Zhang. “Differentially Private Fine-tuning of Language Models”. In: J. Priv. Confidentiality 14.2 ...

  187. [197]

    Beyond the Black Box

    Charlotte Tschider. “Beyond the Black Box”. In: Denver Law Review 98 (2021). url: https://papers.ssrn.com/sol3/papers. cfm?abstract_id=3855782#

  188. [198]

    A Systematic Review of Multimedia Tools for Cybersecurity Awareness and Education

    Leah Zhang-Kennedy and Sonia Chiasson. “A Systematic Review of Multimedia Tools for Cybersecurity Awareness and Education”. In: Computing Surveys (CSUR) (1 2021), pp. 1–

  189. [199]

    Discretion and the quest for controlled freedom

    Stavros Zouridis and Marlies Van Eckand M.A.P. Bovens. “Discretion and the quest for controlled freedom”. In: Palgrave Macmillan,

  190. [200]

    Speech at the European Commission workshop on ”Competition in Virtual Worlds and Generative AI”

    Margrethe Vestager. Speech at the European Commission workshop on ”Competition in Virtual Worlds and Generative AI” . perma- link: https://perma.cc/6KP7-3BT4. 2024. url: https://ec.europa.eu/commission/ presscorner/detail/en/SPEECH_24_3550

  191. [201]

    Building Se- cure Software: How to Avoid Security Prob- lems the Right Way

    John Viega and Gary McGraw. Building Se- cure Software: How to Avoid Security Prob- lems the Right Way . Addison-Wesley Profes- sional, 2001. isbn: 9780672334092

  192. [207]

    url: https://arxiv.org/abs/2403.13784

    doi: 10.48550/arXiv.2403.13784. url: https://arxiv.org/abs/2403.13784

  193. [208]

    The Ethics of Zero-Day Exploits: The NSA Meets the Trolley Car

    Stephen B. Wicker. “The Ethics of Zero-Day Exploits: The NSA Meets the Trolley Car”. In: Communications of the ACM 64 (1 2021). doi: 10.1145/3393670

  194. [210]

    Differentially Private Post- Processing for Fair Regression

    Ruicheng Xian, Qiaobo Li, Gautam Kamath, and Han Zhao. “Differentially Private Post- Processing for Fair Regression”. In: Forty-first International Conference on Machine Learn- ing, ICML 2024, Vienna, Austria, July 21-27,

  195. [211]

    url: https:// openreview.net/forum?id=JNeeRjKbuH

    OpenReview.net, 2024. url: https:// openreview.net/forum?id=JNeeRjKbuH

  196. [213]

    Solving the Black Box Problem: A Normative Framework for Explainable Artificial Intelligence

    Carlos Zednik. “Solving the Black Box Problem: A Normative Framework for Explainable Artificial Intelligence”. In: Phi- losophy and Technology 34 (2019), pp. 265–

  197. [216]

    doi: 10.1145/3427920. 26

  198. [218]

    Automated Discretion, pp

    Chap. Automated Discretion, pp. 313– 329

  199. [219]

    Open Source AI Is the Path Forward

    Mark Zuckerberg. Open Source AI Is the Path Forward. Meta Newsroom. permalink: https://perma.cc/755A-Y4ET. 2024. url: https://about.fb.com/news/2024/07/ open-source-ai-is-the-path-forward/ . 27

  200. [288]

    url: https://doi.org/10.1007/s13347- 019-00382-7

    doi: 10.1007/s13347-019-00382-7 . url: https://doi.org/10.1007/s13347- 019-00382-7

  201. [589]

    doi: 10.1038/s41586-021-03819-2

  202. [1331]

    url: https://link.springer.com/ article/10.1007/s00146-021-01326-6

  203. [1513]

    url: https://dl.acm.org/doi/10.1145/ 3133956.3134047

    doi: 10.1145/3133956.3134047. url: https://dl.acm.org/doi/10.1145/ 3133956.3134047

  204. [1999]

    url: https://www.schneier.com/ crypto-gram/archives/1999/0915.html# OpenSourceandSecurity

  205. [2015]

    url: https://web.cs.ucdavis

    2015. url: https://web.cs.ucdavis. edu/~rogaway/papers/moral-fn.pdf

  206. [2019]

    url: https://ai.google/static/ documents/perspectives-on-issues-in- ai-governance.pdf

  207. [2023]

    url: https://www.lesswrong.com/ posts/WLYBy5Cus4oRFY3mu/thoughts-on- open-source-ai#fnlndvavl4r2a

  208. [2024]

    url: https://certcc.github.io/ CERT-Guide-to-CVD/topics/phases/ deployment/

  209. [3504]

    url: https://link.springer.com/ article/10.1007/s10462-022-10256-8

Pith tools

Reviewed August 9, 2026 · model on record in the stance chip above.