别信标签:AI供应链中的许可证洗钱研究

Don't Trust the Label: License Laundering in AI Supply Chains

精选理由

这篇论文用大量真实数据告诉你,AI供应链里许可证有多混乱。看完你就知道为什么模型和数据集版权常出问题。

AI 摘要

论文追踪了Hugging Face和GitHub上232,270条数据集→模型→应用链,测量许可证义务的传播情况。研究发现62.3%的链条至少包含一个未声明许可证的制品(集中在少数基础数据集),且每个义务性许可证类别的端到端存活率低于7%,而宽松类别高达95.1%。作者据此为从业者、模型发布者、权利人和平台方提供了可操作建议。

原文 · arXiv cs.AI

Don't Trust the Label: License Laundering in AI Supply Chains

AI artifacts move through a multi-platform supply chain, spanning datasets and models on Hugging Face and applications on GitHub. While each artifact carries a license whose obligations should propagate through redistribution, no study has yet measured whether those obligations survive the chain or are stripped and replaced as artifacts move downstream. We trace 232,270 dataset$\rightarrow$model$\rightarrow$application chains and quantify two forms of license laundering: when artifacts with no declared license acquire definitive labels downstream, and when one declared license category replaces another during redistribution. We find that 62.3% of chains pass through at least one artifact with no declared license (concentrated in a small set of foundational datasets), and that every obligation-bearing license category falls below 7% end-to-end survival while the Permissive category reaches 95.1%. Based on these findings, we provide actionable recommendations for practitioners, model publishers, rights holders, and platform owners.

别信标签:AI供应链中的许可证洗钱研究 · AI 热点