검색 상세

An Integrated Lifecycle Framework for AI Risk Management and Trustworthiness Assurance

초록/요약

Artificial Intelligence (AI) systems are exposed to various forms of technical, regulatory, and operational risks throughout their entire lifecycle, spanning planning, design, development, deployment, operation, and improvement. Consequently, international standards and regulatory frameworks for AI trustworthiness assurance are being continuously proposed. However, these frameworks have evolved around different stages and perspectives, and the continuous consistency and integrated application methodology between them remain unclear. For instance, while the NIST AI RMF emphasizes a risk-based management approach, ISO/IEC 42001 focuses on establishing management systems, and the EU AI Act highlights legal compliance, there is a lack of empirical discussion on how these elements should be organically connected throughout the AI system lifecycle. To address these limitations, this study proposes the Cross-Lifecycle Integrated Framework (CLIF), which aligns international standards and regulatory requirements from a lifecycle perspective to verify and enhance AI trust in a stepwise manner. CLIF is not a framework that adds new security techniques or regulatory metrics; rather, its purpose lies in restructuring existing validated structural, regulatory, and operational research outcomes into a single, continuous trust verification lifecycle. To this end, this dissertation integrates three prior studies from the perspective of CLIF. First, the AI Multi-Layered Architecture (AI-MLA) empirically demonstrates that decomposing an AI system into a hierarchical structure can suppress the structural transition and amplification of risks. Second, Cross-Assessment & Verification (CAVe) reduces the requirements of NIST AI RMF, EU AI Act, ISO/IEC 23894, and ISO/IEC 42001 into quantitative metrics and clearly evaluates regulatory compliance prior to deployment through the Cross-Compliance Index. Third, the Availability Assurance Framework (RMF-A) evaluates the maintenance of trust in actual operational environments by quantifying availability and resilience based on operational logs and failure data. The core contribution of this research lies in integrating these individual verification results into a single framework through CLIF and redefining AI trust not as a single evaluation result at a specific point in time, but as a dynamic property where the securing of structural safety, regulatory approval, and the maintenance of trust during operation are continuously accumulated. In particular, through empirical analysis using the NASA C-MAPSS dataset, it was confirmed that the CLIF-based Cross-Compliance Index can detect risks earlier and secure a meaningful Safety Golden Time compared to existing model performance-based approaches. This study empirically demonstrates that AI trust verification should not remain confined to fragmentary metrics or static certifications but must be performed in a linked and stepwise manner across the entire lifecycle. The proposed CLIF provides an integrated verification perspective and practical criteria for the design and operation of trustworthiness in high-risk or mission-critical AI systems.

more

목차

I. Introduction 1
A. Research Background 1
B. Limitations of Existing Approaches and Problem Definition 2
C. Research Objectives and Research Questions 4
D. Research Scope and Methodology 6
E. Organization of the Dissertation 8
II. Analysis of International AI Governance and Related Research 10
A. Evolution of AI Governance and Risk Management 10
B. NIST AI Risk Management Framework Analysis 13
C. Analysis of the EU AI Act 17
D. Analysis of ISO/IEC 23894 and ISO/IEC 42001 21
E. Comparative Analysis of International Frameworks and Derivation of Common Requirements 26
1. Establishment of Comparative Perspectives 26
2. Differences Between Frameworks 27
3. Derivation of Intersections Among Common Requirements 29
4. Limitations of Derived Common Requirements and Research Gaps 32
F. Research Trends in AI Security, Privacy, Fairness, and Robustness 34
1. Research Trends in AI Security 34
2. Research Trends in Privacy Protection 35
3. Research Trends in Fairness and Bias 36
4. Research Trends in Robustness and Reliability 37
5. Limitations of Research Trends and the Necessity of Integration 37
6. Positioning of This Dissertation Relative to Existing Research 38
III. Technical Layer-Based Structural Model of AI Systems 40
A. Necessity of Hierarchical Structuring in AI Systems 40
B. Technical Layer Design Principles 41
C. Overview of AI-MLA Layer Definitions 42
1. Layer L1: Physical (Physical/Infrastructure) Layer 46
2. Layer L2: Model Layer 47
3. Layer L3: Data (VectorDB/Knowledge) Layer 48
4. Layer L4: Orchestration (Policy) Layer 49
5. Layer L5: Session (Context) Layer 49
6. Layer L6: Agent (Agent/Interaction) Layer 50
7. Layer L7: Application (Application/Service) Layer 51
D. Cross-layer Risk Propagation Mechanisms in AI-MLA 51
E. Layer Definitions and Scope of Application 53
1. Detailed Formal Definitions of the Seven AI-MLA Layers 53
2. ZTA Structural Correspondence: L4 as PDP and L5 as PEP 55
3. Scope of Application and Declaration of Consistency 60
F. Structural Risk Propagation Types 61
1. Information Distortion-Based Risk Propagation 62
2. Control Bypass-Based Risk Propagation 63
3. Action Amplification-Based Risk Propagation 63
4. Implications of Structural Risk Propagation 64
G. Layer Boundaries and Risk Interception Logic 64
H. Risk Amplification Mechanisms in Transition Zones 66
IV. Integrated Structure for the Entire AI Risk Management Lifecycle 68
A. Necessity of a Lifecycle Perspective 68
1. The Stage-Silo Failure and Risk Amplification 68
2. Why AI Systems Require Lifecycle Governance 70
B. Conceptual Definition of CLIF 71
1. How CLIF Differs from ISO/IEC 5338 and NIST AI RMF 73
C. Risk Characteristics Across the Entire Lifecycle 76
1. Risk Characteristics of the Planning Phase 78
2. Risk Characteristics of the Design Phase 80
3. Risk Characteristics of the Development Phase 81
4. Risk Characteristics of the Verification Phase 83
5. Risk Characteristics of the Deployment Phase 85
6. Risk Characteristics of the Operation Phase 87
7. Risk Characteristics of the Improvement Phase 89
D. Relationship with Existing Frameworks 90
1. Relationship with NIST AI RMF: Transitioning from Functions to Stages 91
2. Relationship with the EU AI Act: Engineering Interpretation of Regulatory Compliance 91
3. Relationship with ISO/IEC Management Systems: Bridging Governance and Technology 92
4. The Value of CLIF as an Integrated Framework 93
E. Theoretical Significance of the Integrated Structure 93
1. Expansion of the AI Risk Management Perspective 93
2. Linking Technical Architecture with Management Frameworks 94
3. Providing a Basis for Transition to Quantitative Risk Management 94
4. Practical Support for Regulatory and Standard Compliance 94
5. Summary of Research Contributions 95
F. Repeatability and Recurrence Characteristics 95
V. Cross-Assessment & Verification for Evaluation Framework (CAVe) 98
A. Limitations of Quantitative Metric-Centered Approaches 98
B. Concept of the Structural Context-Based Integrated Evaluation Framework 100
C. Core Components of the Integrated Evaluation Framework 102
1. Definition and Role of the Evaluation Unit (EU) 102
2. Concept of Risk Propagation Rules 103
3. Risk Accumulation and Buffering Mechanisms 104
4. Linking Evaluation Results to Decision-Making 104
D. Step-by-Step Evaluation Flow of the Integrated Framework 105
1. Stage 1: Setting the Evaluation Scope and Target 105
2. Stage 2: Collection and Basic Analysis of Quantitative Metrics 105
3. Stage 3: Structural Location-Based Metric Interpretation 106
4. Stage 4: Evaluation of Risk Propagation Scenarios 106
5. Stage 5: Judgment of Cumulative Risk and Thresholds 106
6. Stage 6: Decision-Making and Response Selection 107
7. Application through Conceptual Scenarios 107
8. Scenario Expansion by Risk Level 108
E. Core Evaluation Axes and Cross-Structure of the CAVe Framework 109
1. Characteristics of CAVe’s Four Core Evaluation Axes 109
2. Reconstruction of Risk through Cross-Structures 111
F. From Cross-Assessment to Quantitative Indices: The CAVe–CCI/AAI Bridge 112
1. Why Cross-Assessment Results Require Quantitative Summarization 112
2. Two Complementary Quantitative Indices 113
3. Design Principles Governing CCI and AAI 114
VI. Integrated Quantitative Evaluation Model 116
A. Cross-Compliance Index: Concept, Formula, and Adjustment Factors 116
1. CCI Computational Algorithm 118
2. Interpretation Principles and Application of CCI 118
B. Availability Assurance Index and the Risk Management Framework for Availability 119
1. Motivation: Operational Risk as a Distinct Governance Domain 119
2. Availability Evidence Model (AEM) 120
3. AAI Formal Definition and Computational Algorithm 121
4. Interpretation of AAI Authorization Outcomes 122
C. Dual-Axis Evaluation Model: CCI and AAI as Complementary Governance Signals 123
1. CCI as a Regulatory Compliance Signal 123
2. AAI as an Operational Assurance Signal 124
3. Temporal Complementarity and Mutual Constraint 124
4. Co-Degradation Early Warning 125
5. Risk Quadrant Analysis 126
6. The CLIF Integrated Score 126
D. Coupling Structure of CCI and AAI with AI-MLA and CLIF Lifecycle 127
1. Risk Signal Function at the AI-MLA Architecture Level 128
2. Role as State Variables Based on the CLIF Lifecycle 128
3. Value as an Integrated Mediator of Structure and Time 129
E. Stage-Wise Verification Scenarios for CCI and AAI 129
1. Development Stage: Identifying Design Alignment and Structural Deviation 130
2. Verification Stage: Integrated Reliability Assurance and Cross-Checking 130
3. Operation Stage: Dynamic State Monitoring and Risk Propagation Detection 131
4. Improvement Stage: Root-Cause Traceability and Lifecycle Re-entry 131
5. Integrated Implications of Stage-Wise Verification 132
F. Alignment with International Standards and Academic Contribution 132
1. Alignment with NIST Frameworks 132
2. Structural Linkage with ISO/IEC Standards 133
3. Alignment with the EU AI Act 133
4. Comprehensive Implications of Standard and Regulatory Alignment 134
5. Academic Contribution and Differentiation from Existing Research 134
VII. Scenario-Based Verification and Effectiveness Analysis of the Integrated Framework 141
A. Redefining the Verification Perspective: Limitations of Single-Effect Verification 141
B. Validation and Integrated Reinterpretation of the Structural Model 142
1. Empirical Validation of Structural Risk Transition Suppression Effects 142
2. Reinterpretation from the CLIF Perspective: Structural Safety as a Prerequisite 143
C. Integrated Expansion of the Regulatory Evaluation Model 145
D. Integrated Expansion of the Operational Assurance Model 146
E. Scenario-Based Effectiveness Analysis of CLIF Application in AI-Driven Manufacturing Process Control Systems 150
1. Definition of Virtual Scenario and Core Risk Factors 150
2. Possibility of Structural Verification via CLIF Application 151
3. Possibility of Regulatory Verification via CLIF Application 151
4. Possibility of Operational Phase Verification via CLIF Application 153
5. Summary of Scenario-Based CLIF Effects 155
F. CLIF Framework Verification Using NASA C-MAPSS Dataset 156
1. Experimental Setup and Assumptions 156
2. CLIF-Based Compliance Evaluation 156
3. Detection Threshold and Safety Golden Time 157
4. Experimental Results 158
5. Discussion 159
G. Implications and Significance of Enhanced Verification from the CLIF Perspective 160
1. Re-evaluating the Roles and Limitations of Individual Frameworks 161
2. Quantitative and Temporal Implications of CLIF-Based Integrated Verification 161
VIII. Limitations of the Framework and Future Research Directions 163
A. Abstraction and Loss of Contextual Information in the Quantification Process 163
B. Subjectivity in Evaluation Axis Definition and Consistency Issues 163
C. Operational Overhead in Large-Scale System Application 164
D. Adaptability and Meta-Design for Dynamic AI Environments 164
IX. Conclusion 165
Reference 167
Definition of Terminology 189

more