MIT AI Risk Repository
Browse AI risks
50 risk entries extracted from 74 frameworks, coded by domain, subdomain, causal entity, intent and timing. Filter, then export the current selection with its licence and citation attached.
-
In the context of LLM outputs, we want to make sure the suggested or completed texts are indistinguishable in nature for two involved individuals (in the prompt) with the same relevant profiles but might come from different groups (where the group attribute is regarded as being irrelevant in this context)
-
LLMs must not exhibit or highlight any stereotypes in the generated text. Pretrained LLMs tend to pick up stereotype biases persisting in crowdsourced data and further amplify them
-
LLMs are exposed to vast groups of people, and their political biases may pose a risk of manipulation of socio-political processes
-
existing disparities in data among different user groups might create differentiated experiences when users interact with an algorithmic system (e.g. a recommendation system), which will further reinforce the bias
-
Avoiding unsafe and illegal outputs, and leaking private information
-
LLMs are found to generate answers that contain violent content or generate content that responds to questions that solicit information about violent behaviors
-
LLMs have been shown to be a convenient tool for soliciting advice on accessing, purchasing (illegally), and creating illegal substances, as well as for dangerous use of them
-
LLMs can be leveraged to solicit answers that contain harmful content to children and youth
-
LLMs have the capability to generate sex-explicit conversations, and erotic texts, and to recommend websites with sexual content
-
30.06.00 · Risk Category
LLMs are expected to reflect social values by avoiding the use of offensive language toward specific groups of users, being sensitive to topics that can create instability, as well as being sympathetic when users are seeking emotional support
-
language being rude, disrespectful, threatening, or identity-attacking toward certain groups of the user population (culture, race, and gender etc)
-
it is important to build high-quality locally collected datasets that reflect views from local users to align a model’s value system
-
Avoiding bias and ensuring no disparate performance
-
The LLM’s performances can differ significantly across different groups of users. For example, the question-answering capability showed significant performance differences across different racial and social status groups. The fact-checking abilities can differ for different tasks and languages
-
machine learning models are known to be vulnerable to data privacy attacks, i.e. special techniques of extracting private information from the model or the system used by attackers or malicious users, usually by querying the models in a specially designed way
-
carefully controlled adversarial perturbation can flip a GPT model’s answer when used to classify text inputs. Furthermore, we find that by twisting the prompting question in a certain way, one can solicit dangerous information that the model chose to not answer
-
fool the model by manipulating the training data, usually performed on classification models
-
30.01.00 · Risk Category
Generating correct, truthful, and consistent outputs with proper confidence
-
Wrong information not intentionally generated by malicious users to cause harm, but unintentionally generated by LLMs because they lack the ability to provide factually correct information.
-
LLMs can generate content that is nonsensical or unfaithful to the provided source content with appeared great confidence, known as hallucination
-
over-confidence in topics where objective answers are lacking, as well as in areas where their inherent limitations should caution against LLMs’ uncertainty (e.g. not as accurate as experts)... ack of awareness regarding their outdated knowledge base about the question, leading to confident yet erroneous response
-
flatter users by reconfirming their misconceptions and stated beliefs
-
Knowledge bases that LLMs are trained on continue to shift... questions such as “who scored the most points in NBA history" or “who is the richest person in the world" might have answers that need to be updated over time, or even in real-time
-
30.04.00 · Risk Category
Prohibiting the misuse by malicious attackers to do harm
-
LLMs can be leveraged, by malicious users, to proactively generate propaganda information that can facilitate the spreading of a target
-
ability of LLMs to write reasonably good-quality code with extremely low cost and incredible speed, such great assistance can equally facilitate malicious attacks. In particular, malicious hackers can leverage LLMs to assist with performing cyberattacks leveraged by the low cost of LLMs and help with automating the attacks.
-
psychologically manipulating victims into performing the desired actions for malicious purposes
-
The memorization effect of LLM on training data can enable users to extract certain copyright-protected content that belongs to the LLM’s training data.
-
models could fail to provide the same and consistent answers to different users, to the same user but in different sessions, and even in chats within the sessions of the same conversation
-
LLMs can provide seemingly sensible but ultimately incorrect or invalid justifications when answering questions
-
Causal reasoning makes inferences about the relationships between events or states of the world, mostly by identifying cause-effect relationships
-
when a certain vulnerable group of users asks for supporting information, the answers should be informative but at the same time sympathetic and sensitive to users’ reactions
-
30.07.00 · Risk Category
Resilience against adversarial attacks and distribution shift
-
30.05.00 · Risk Category
The ability to explain the outputs to users and reason correctly
-
Due to the black box nature of most machine learning models, users typically are not able to understand the reasoning behind the model decisions
-
30.01.00.a · Additional evidence
—
-
—
-
—
-
—
-
—
-
unhealthy interactions with Internet discussions can reinforce users’ mental issues
-
—
-
30.03.00.a · Additional evidence
—
-
30.03.00.b · Additional evidence
—
-
—
-
—
-
—
-
—
-
—
-
—
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.