Pith. sign in

REVIEW 4 cited by

Black-Box Access is Insufficient for Rigorous AI Audits

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2401.14446 v3 pith:VIGEA2AM submitted 2024-01-25 cs.CY cs.AIcs.CR

classification cs.CYcs.AIcs.CR
keywords accessauditsauditorsblack-boxoutside-the-boxallowsauditdeployment
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

External audits of AI systems are increasingly recognized as a key mechanism for AI governance. The effectiveness of an audit, however, depends on the degree of access granted to auditors. Recent audits of state-of-the-art AI systems have primarily relied on black-box access, in which auditors can only query the system and observe its outputs. However, white-box access to the system's inner workings (e.g., weights, activations, gradients) allows an auditor to perform stronger attacks, more thoroughly interpret models, and conduct fine-tuning. Meanwhile, outside-the-box access to training and deployment information (e.g., methodology, code, documentation, data, deployment details, findings from internal evaluations) allows auditors to scrutinize the development process and design more targeted evaluations. In this paper, we examine the limitations of black-box audits and the advantages of white- and outside-the-box audits. We also discuss technical, physical, and legal safeguards for performing these audits with minimal security risks. Given that different forms of access can lead to very different levels of evaluation, we conclude that (1) transparency regarding the access and methods used by auditors is necessary to properly interpret audit results, and (2) white- and outside-the-box access allow for substantially more scrutiny than black-box access alone.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 4 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Exposure is not manifestation: measurement target and output resolution jointly determine which behavioural-faithfulness evaluator wins

    cs.CL 2026-07 conditional novelty 6.0 of 10

    Small hyperbolic models (146M–3B) report 100% creative-seed preference, 90.7% compliance-gap detection, and a selective-gating skeleton–wallpaper memory pilot as a companion-AI stack.

  2. Regulation of Language Models With Interpretability Will Likely Result In A Performance Trade-Off

    cs.LG 2024-12 conditional novelty 6.0 of 10

    Forcing an LLM to classify using only human-specified legal concepts costs about 7.34% accuracy, but can speed up human decision-making despite the loss.

  3. Declare and Justify: Explicit assumptions in AI evaluations are necessary for effective regulation

    cs.AI 2024-11 conditional novelty 5.0 of 10

    AI evaluation-based regulation should require developers to state and justify key assumptions, and halt development when those justifications are inadequate.

  4. What AI evaluations for preventing catastrophic risks can and cannot do

    cs.CY 2024-11 conditional novelty 4.0 of 10

    AI evaluations can establish lower bounds on capabilities but cannot establish upper bounds, forecast future capabilities robustly, or assess misalignment risk, so they should not be the primary basis for AI safety decisions.

Pith tools