arXiv Science⌕ Search

arXiv subjects

Jakub Kryś

Publications and source records attributed to Jakub Kryś.

9 recordsLinked to original sources

Open Problems in AI Risk Modeling: Insights from a Workshop on the Technical Foundations of AI Risk Modeling

We investigate the design of robust risk models to assess societal risks posed by advanced AI systems, an emerging area in AI governance. Many regulatory proposals increasingly require systemic risk assessment, but in the absence of rigorous quantitative methods, the question remains what state of the art risk modeling should look like in practice. We identify the key methodological and institutional challenges that currently limit the adoption of risk modeling. We review five research traditions that inform this problem: probabilistic risk assessment, catastrophic AI risk analysis, cybersecurity risk quantification, Bayesian causal inference, and threshold-based governance. We compare two leading proposals, scenario-based risk estimation and Bayesian network-based threshold setting. Drawing on a workshop with 22 experts and subsequent analysis, we identify a structured agenda of open questions concerning model structure, scope, evidence integration, validation, and governance. We close by outlining priorities for progress, arguing that it will depend on integrating quantitative modeling with independent evaluation, transparent and tiered disclosure, and institutions capable of maintaining and updating risk models over time.

cs.CY↗

Exploring Systems-Thinking Approaches to Loss of Control Risk

Internal deployment of agentic AI systems for coding and research creates a sociotechnical control problem that extends beyond model behaviour. We treat internal-deployment Loss of Control as the inability to reliably constrain, audit, reverse, or halt AI-mediated changes to code, infrastructure, evaluation, or deployment processes in time to prevent serious organisational or societal harms. We ask whether established systems-safety methods can identify risks that model-level evaluations may miss. Using a generic frontier-lab coding-agent scenario reconstructed from public materials, we apply STECA, STPA, and FRAM. The analyses surface complementary findings: published frameworks can leave governance responsibilities and feedback loops externally unverifiable; delays in monitoring and intervention can make otherwise valid control actions ineffective; and routine operational variability can gradually erode the calibration and independence of safeguards. We argue that frontier-AI risk management should pair model-focused evaluations with systems-level hazard analysis and operational assurance that tracks whether controls remain effective over time.

cs.CY↗

Fingerprinting All AI Cluster I/O Without Mutually Trusted Processors

In preparation for potential international agreements on artificial intelligence, the development of verification infrastructure for AI data centres is vital. We propose a method for cryptographically committing all information entering and leaving a data centre: Hashes are computed by network taps placed on all the information-carrying wires between the cluster and the outside world, enabling an auditor to retroactively challenge the preimage data to be sent to a privacy-preserving verification facility performing compliance checks. Our goal is to make it infeasible to covertly exfiltrate the results of undisclosed workloads in the cluster through the tapped wires. To this end, we specify the architecture of a ``Secure Gateway Device'', which handles the erasure of covert channels that post-hoc verification on hashed data cannot address: analogue and timing side-channels, as well as steganography in network protocol headers. The architecture eliminates the need for any processors trusted by both the Prover and the Verifier, leveraging passive optical fibre splitters and coin-flip protocols for random number generation where needed. We expect development costs of a demonstration device to be roughly equivalent to the cost of a small team of engineers for a few months, with a comparatively small bill of materials.

cs.CR↗

Toward Quantitative Modeling of Cybersecurity Risks Due to AI Misuse

Advanced AI systems offer substantial benefits but also introduce risks. In 2025, AI-enabled cyber offense has emerged as a concrete example. This technical report applies a quantitative risk modeling methodology (described in full in a companion paper) to this domain. We develop nine detailed cyber risk models that allow analyzing AI uplift as a function of AI benchmark performance. Each model decomposes attacks into steps using the MITRE ATT&CK framework and estimates how AI affects the number of attackers, attack frequency, probability of success, and resulting harm to determine different types of uplift. To produce these estimates with associated uncertainty, we employ both human experts, via a Delphi study, as well as LLM-based simulated experts, both mapping benchmark scores (from Cybench and BountyBench) to risk model factors. Individual estimates are aggregated through Monte Carlo simulation. The results indicate systematic uplift in attack efficacy, speed, and target reach, with different mechanisms of uplift across risk models. We aim for our quantitative risk modeling to fulfill several aims: to help cybersecurity teams prioritize mitigations, AI evaluators design benchmarks, AI developers make more informed deployment decisions, and policymakers obtain information to set risk thresholds. Similar goals drove the shift from qualitative to quantitative assessment over time in other high-risk industries, such as nuclear power. We propose this methodology and initial application attempt as a step in that direction for AI risk management. While our estimates carry significant uncertainty, publishing detailed quantified results can enable experts to pinpoint exactly where they disagree. This helps to collectively refine estimates, something that cannot be done with qualitative assessments alone.

cs.CY↗

Distributed and Decentralised Training: Technical Governance Challenges in a Shifting AI Landscape

Advances in low-communication training algorithms are enabling a shift from centralised model training to compute setups that are either distributed across multiple clusters or decentralised via community-driven contributions. This paper distinguishes these two scenarios - distributed and decentralised training - which are little understood and often conflated in policy discourse. We discuss how they could impact technical AI governance through an increased risk of compute structuring, capability proliferation, and the erosion of detectability and shutdownability. While these trends foreshadow a possible new paradigm that could challenge key assumptions of compute governance, we emphasise that certain policy levers, like export controls, remain relevant. We also acknowledge potential benefits of decentralised AI, including privacy-preserving training runs that could unlock access to more data, and mitigating harmful power concentration. Our goal is to support more precise policymaking around compute, capability proliferation, and decentralised AI development.

cs.CY↗

Lepton-pair scattering with an off-shell and an on-shell photon at two loops in massless QED

We compute the two-loop QED helicity amplitudes for the scattering of a lepton pair with an off-shell and an on-shell photon, $0\to\ell\bar\ellγγ^*$, using the approximation of massless leptons. We express all master integrals relevant for the scattering of four massless particles with a single external off-shell leg up to two loops in a basis of algebraically independent multiple polylogarithms, which guarantees an efficient numerical evaluation and compact analytic representations of the amplitudes. Analytic forms of the amplitudes are reconstructed from numerical evaluations over finite fields. Our results complete the amplitude-level ingredients contributing to the N$^3$LO predictions of electron-muon scattering $eμ\to eμ$, which are required to meet the precision goal of the future MUonE experiment.

hep-ph↗

Recent progress for five-particle two-loop scattering amplitudes with an off-shell leg

We report on the advances in the calculation of the two-loop scattering amplitudes for five-particle processes with one off-shell leg. Focusing on the production of a Higgs boson in association with a bottom quark pair, we outline how the newly developed technology allows us to overcome the computational bottlenecks. In particular, we discuss the use of finite field arithmetic and elucidate a convenient way to evaluate numerically the special functions appearing in the amplitudes.

hep-ph↗

Two-loop leading colour helicity amplitudes for $W^\pmγ+j$ production at the LHC

We present the two-loop leading colour QCD helicity amplitudes for the process $pp\to W(\to lν)γ+j$. We implement a complete reduction of the amplitudes, including the leptonic decay of the $W$-boson, using finite field arithmetic, and extract the analytic finite remainders using a recently identified basis of special functions. Simplified analytic expressions are obtained after considering permutations of a rational kinematic parametrisation and multivariate partial fractioning. We demonstrate efficient numerical evaluation of the two-loop colour and helicity summed finite remainders for physical kinematics, and hence the suitability for phenomenological applications.

hep-ph↗

Two-loop leading-colour QCD helicity amplitudes for Higgs boson production in association with a bottom-quark pair at the LHC

We compute the two-loop QCD helicity amplitudes for the production of a Higgs boson in association with a bottom-quark pair at a hadron collider. We take the approximations of leading colour and work in the five flavour scheme, where the bottom quarks are massless while the Yukawa coupling is non-zero. We extract analytic expressions from multiple numerical evaluations over finite fields and present the results in terms of an independent set of special functions that can be reliably evaluated over the full phase space.

hep-ph↗