Securing the Artificial Intelligence (AI)-Enabled Election Software Stack
摘要
In recent years, political organizations’ operations have been increasingly impacted by artificial intelligence (AI), as they leverage it to perform data-driven campaigning (e.g., custom-generated content for constituents). The adoption of AI in election campaigns has been facilitated by open-source software (OSS). AI-enabled election software stacks incorporate machine learning OSS (MLOSS) tools to facilitate critical analysis for data-driven campaigning. While OSS has made AI-enabled election software stacks accessible to more government organizations, it has also introduced a new set of security issues. In this chapter, we review campaign software OS AI assets, their vulnerabilities, and how associated risks can be mitigated. We present a generalized framework for securing AI-enabled election software stacks and illustrate the analysis it enables through five example OS AI campaign tools. The framework consists of identifying critical software stack assets, selecting appropriate vulnerability assessment tools, and understanding the risks that identified vulnerabilities pose. Lastly, we demonstrate the value of our framework through a case study, examining two organizations (the Hungarian National Government and the National Hispanic Voter Educational Foundation) that have used OS AI tools. The case study illustrates critical vulnerabilities identified in the technologies both organizations adopted, including code injection, and highlights their potential impact.