Kännedom om informationssäkerhetsrisker vid användning av generativ ai: En kvantitativ studie inom kommuner i Sjuhärad
2024 (Swedish)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesisAlternative title
Awareness of information security risks when using generative ai : A quantitative study within municipalities in Sjuhärad (English)
Abstract [sv]
Med en hastig utveckling av Artificiell intelligens (AI) blir generativ AI allt mer populärt. Ett verktyg som har fått en betydlig mängd uppmärksamhet är ChatGPT, en plattform som möjliggör enkla och interaktiva konversationer mellan plattformen och användaren. Trots fördelarna är det viktigt att diskutera risker och säkerhet, särskilt efter incidenter som i mars 2023 där det inträffade en händelse där obehöriga fick åtkomst till andra användares chatthistorik och potentiellt samtliga chattmeddelanden som hade skrivits. Sådana incidenter är särskilt relevant för kommuner som har högre krav på informationssäkerheten eftersom de har strikta informationssäkerhetskrav som GDPR, offentlighets- och sekretesslagen, LIS och liknande inom informationssäkerhetspolicyn (ISP). För att undersöka det har studien avgränsat sig till att utgå från två kommuner och språkmodellen ChatGPT, dess textgenerering och riskerna som är relaterade till användningen av modellen GPT-3.5. Som utgångspunkt samlades primär- och sekundärdata in till den kvantitativa studien, där primärdata kommer från en webbaserad enkät utformades med hjälp av relevant litteratur, tidigare forskning, tänka högt test och en pilotstudie. Sekundärdata kommer i form av litteratur som tidigare rapporter, artiklar och dokumentanalys. Data analyserades med explorativ metod, inklusive univariatanalys och bivariatanalys, för att undersöka fördelningar och samvariationer. De identifierade informationssäkerhetsriskerna med generativ AI som ChatGPT, inkluderar dataläckage, stöld och bedrägeri av data, desinformation, fördomar, brist på transparens och förgiftad träningsdata. Det visade sig att många anställda i kommunerna har låg kännedom om dessa risker, vilket speglar en hög osäkerhet. Vidare framkom det att de anställdas kännedom om informationssäkerhetspolicyn inte påverkar deras bedömning av riskerna. Slutsatsen är att bristande kännedom om AI-risker och otillräcklig vägledning från informationssäkerhetspolicyn bidrar till en ökad informationssäkerhetsrisk
Abstract [en]
With the rapid development of Artificial Intelligence (AI), generative AI is becoming increasingly popular. One tool that has received a significant amount of attention is ChatGPT, a platform that enables simple and interactive conversations between the platform and the user. Despite its benefits, it is important to discuss risks and security, especially after incidents like the one in March 2023 where unauthorized people gained access to other users' chat history and potentially all chat messages that had been written. Such incidents are particularly relevant for municipalities that have higher requirements for information security because they have strict information security requirements such as GDPR, the Publicity and Privacy Act, LIS and the like within the information security policy (ISP). To investigate this, the study has limited itself to starting from two municipalities and the language model ChatGPT, its text generation and the risks related to the use of the model GPT-3.5. As a starting point, primary and secondary data were collected for the quantitative study, with primary data coming from a web-based survey designed using relevant literature, previous research, think aloud tests and a pilot study. Secondary data comes in the form of literature such as previous reports, articles and document analysis. Data were analyzed using exploratory methods, including univariate analysis and bivariate analysis, to examine distributions and covariates. The identified information security risks with generative AI such as ChatGPT, include data leakage, data theft and fraud, misinformation, bias, lack of transparency and poisoned training data. It also turned out that many employees in the municipalities have little knowledge of these risks, which reflects a high level of uncertainty. Furthermore, it emerged that the employees' knowledge of the information security policy does not affect their assessment of the risks. The conclusion is that a lack of knowledge about AI risks and insufficient guidance from the information security policy contribute to an increased information security risk
Place, publisher, year, edition, pages
2024.
Keywords [en]
AI, Generative AI, ChatGPT, GPT-3.5, Risks, Information Security, Information Security Policy, Awareness, Municipalities
Keywords [sv]
AI, Generativ AI, ChatGPT, GPT-3.5 Risker, Informationssäkerhet, Informationssäkerhetspolicy (ISP), Kännedom, Kommuner
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:hb:diva-32892OAI: oai:DiVA.org:hb-32892DiVA, id: diva2:1919034
Subject / course
Informatics
2024-12-302024-12-062025-09-24Bibliographically approved