大規模言語モデルのシステムプロンプト監査フレームワーク「AISPA」を提案
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Hugging Face Daily Papers
研究者らは、AI アプリケーションのシステムプロンプトを体系的に監査する「AISPA」という枠組みを発表し、88 の商用製品を対象にした分析で保護と問題の混在という深刻な実態を明らかにした。
AI深層分析を開く2026年8月5日 13:20
AI深層分析
キーポイント
ユーザー中心の監査フレームワーク「AISPA」の提案
開発者が設定するシステムプロンプトの信頼性と説明責任のギャップを埋めるため、8 つのユーザー重視の次元に基づいてプロンプトを評価する枠組みが導入された。
商用製品におけるプロンプト設計の多様性と不均衡
製品や開発者間でシステムプロンプトの設計に大きなばらつきがあり、保護指示の平均数が製品ごとに 60 を超えるケースもあれば 5 に満たないケースもあることが判明した。
保護機能の普及と範囲の浅さ
98.9% の製品が少なくとも1つの保護指示を含んでいるものの、AISPA が定義する8 つの次元すべてをカバーしているのはわずか 24% に過ぎない。
保護と問題指示の併存という構造的課題
プロンプトが長くなり保護志向が強まっている一方で、約 40% の製品にユーザー利益に反する指示が含まれており、保護と問題が同一プロンプト内で頻繁に共存している。
重要な引用
creating a serious trust and accountability gap in the wide deployment of AI systems
protective instructions are widely adopted but shallow in scope: 98.9% of products contain at least one, yet only 24% cover all eight dimensions
roughly 40% of products contain at least one instruction that works against user interests
編集コメントを表示
編集コメント
本論文は、ブラックボックス化されがちなシステムプロンプトの内部を可視化する画期的なアプローチを示している。開発現場では「プロンプトを書けば安全」という安易な考え方が蔓延しているが、この分析はその限界と実態を浮き彫りにしており、今後のガイドライン策定への示唆に富む。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
システムプロンプトは、AI アプリケーションにおける基盤モデルの動作を規定するために開発者が設定する指示です。商業的な AI 製品では広く利用されていますが、一般公開や規制当局への開示はほとんど行われておらず、AI システムの大規模展開において深刻な信頼と説明責任のギャップを生んでいます。
本論文では、ユーザー中心のアプローチで AI システム内のシステムプロンプトを体系的に監査するためのフレームワーク「Artificial Intelligence System Prompt Assurance(AISPA)」を紹介します。AISPA はシステムプロンプトの特定の部分を抽出し、ユーザーにとって重要な 8 つの次元に沿って評価を行います。
このフレームワークを用いて、88 の商業 AI 製品に含まれる 3,249 の指示をレビューし、それぞれが「ユーザー保護型」か「問題のある型」かを分類しました。その結果、以下の 4 つのコアな知見が明らかになりました。
第一に、製品や開発者によってシステムプロンプトの設計は大きく異なり、ある組織では製品あたり平均 60 以上の保護型指示を持つ一方で、別の組織では 5 件未満という格差が見られました。第二に、保護型の指示は広く採用されていますが、その範囲は浅いものです。98.9% の製品で少なくとも 1 つの保護型指示が含まれていますが、AISPA の分類体系における 8 つの次元すべてをカバーしているのはわずか 24% です。
第三に、システムプロンプトは徐々に長くなり、ユーザー保護に関する記述も増えています。これは、商業的なプロンプト設計においてユーザー保護がより顕著な課題となっていることを示唆しています。
第四に、こうした進展にもかかわらず、問題のある指示は依然として蔓延しています。製品のおよそ 40% に少なくとも 1 つのユーザー利益に反する指示が含まれており、保護的な指示と問題のある指示が同じプロンプト内で頻繁に共存しています。これらの知見は、商用 AI プロダクトにおけるシステムプロンプトに対して、より高い透明性、標準化、そして独立した監督の必要性を浮き彫りにしています。
原文を表示
System prompts are instructions configured by developers to govern the behaviors of foundation models in AI applications. They are used throughout commercial AI products, but are rarely disclosed to the public or regulators, creating a serious trust and accountability gap in the wide deployment of AI systems. In this paper, we introduce Artificial Intelligence System Prompt Assurance (AISPA), a user-centric framework for systematically auditing system prompts in AI systems. AISPA examines specific parts of a system prompt and evaluates them along eight dimensions that matter to users. We then use this framework to review 3,249 instructions from system prompts in 88 commercial AI products, classifying each instruction as either protective (of users) or problematic. Our audit surfaces four core findings. First, system prompt design varies substantially across products and developers, with some organizations averaging over 60 protective instructions per product while others average fewer than 5. Second, protective instructions are widely adopted but shallow in scope: 98.9% of products contain at least one, yet only 24% cover all eight dimensions of the AISPA taxonomy. Third, system prompts have grown steadily longer and more protective of users, suggesting that user protection is becoming a more visible concern in commercial prompt design. Fourth, despite this progress, problematic instructions remain pervasive: roughly 40% of products contain at least one instruction that works against user interests, and protective and problematic instructions frequently coexist within the same prompt. Our findings highlight the need for greater transparency, standardization, and independent oversight for system prompts in commercial AI products.
News to Guide
ニュースの次に確認する
発表内容を、現在の料金や仕様と照らし合わせられる関連ガイドです。
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み