Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
arXiv AI · 2026/7/30 17:58:58

AISPA: User-Centric System Prompt Auditing for Large Language Model Applications

AI 中文解读
核心亮点:AI的“幕后指令”首次被系统审视,一项新审计框架发现,商业AI产品在保护用户方面做得参差不齐,近四成产品暗藏对用户不利的指令。 通俗解读:每个AI应用背后,开发者都写了一套“使用说明书”,也就是系统提示词,用来规定AI该说什么、不说什么。但这些内容从不公开,用户完全蒙在鼓里。新推出的AISPA框架就像一位“质检员”,把88款商业AI产品里的三千多条提示词拿出来逐条检查,从“是否保护隐私”“是否诚实”等八个角度打分。结果发现,有的公司非常用心,平均每款产品写了60多条保护用户的规定,有的却不到5条;虽然98.9%的产品都含有保护性指令,但只有24%覆盖了全部八个维度;更值得警惕的是,约40%的产品里存在偷偷损害用户利益的指令,比如诱导消费或隐瞒信息,还常常和保护性条款混在一起。 实际影响:以后你用AI聊天、办公或问诊时,可能遇到“表面客气、背后使坏”的情况。这项研究提醒我们,AI厂商需要公开提示词、接受第三方监督,否则用户很难真正信任这些越来越聪明的“电子助手”。
System prompts are instructions configured by developers to govern the behaviors of foundation models in AI applications. They are used throughout commercial AI products, but are rarely disclosed to the public or regulators, creating a serious trust and accountability gap in the wide deployment of AI systems. In this paper, we introduce Artificial Intelligence System Prompt Assurance (AISPA), a user-centric framework for systematically auditing system prompts in AI systems. AISPA examines specific parts of a system prompt and evaluates them along eight dimensions that matter to users. We then use this framework to review 3,249 instructions from system prompts in 88 commercial AI products, classifying each instruction as either protective (of users) or problematic. Our audit surfaces four core findings. First, system prompt design varies substantially across products and developers, with some organizations averaging over 60 protective instructions per product while others average fewer than 5. Second, protective instructions are widely adopted but shallow in scope: 98.9% of products contain at least one, yet only 24% cover all eight dimensions of the AISPA taxonomy. Third, system prompts have grown steadily longer and more protective of users, suggesting that user protection is becoming a more visible concern in commercial prompt design. Fourth, despite this progress, problematic instructions remain pervasive: roughly 40% of products contain at least one instruction that works against user interests, and protective and problematic instructions frequently coexist within the same prompt. Our findings highlight the need for greater transparency, standardization, and independent oversight for system prompts in commercial AI products.
分享
阅读原文