A
Abuse attack (AML)
오용 공격
리스크·보안요약
In NIST's AML taxonomy for generative AI, attacks that repurpose a system's intended capability to serve the attacker's ends, such as generating disinformation, malware assistance, or other harmful content at scale.
NIST 적대적 ML 분류에서, 시스템의 정상 역량을 공격자 목적에 전용하는 공격 유형. 대규모 허위정보 생성, 악성코드 작성 지원 등이 해당한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (abuse violations)
Accountability
책임성
법·제도요약
The obligation and capacity of AI actors to answer for the outcomes of AI systems and to allocate responsibility across the life cycle; paired with transparency in NIST's 'accountable and transparent' characteristic.
AI 행위자가 AI 시스템의 결과에 대해 응답하고 수명주기 전반에 책임을 배분해야 하는 의무와 능력. NIST의 '책임성·투명성' 특성으로 투명성과 짝을 이룬다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.4
Activation steering
활성 조향
리스크·보안요약
Controlling model behavior at inference by adding directions to internal activations identified via representation engineering; usable for safety or for attacks.
표현공학으로 식별한 방향을 내부 활성값에 더해 추론 시 모델 행동을 제어하는 기법. 안전 목적과 공격 양쪽에 쓰일 수 있다.
Zou et al. (2023), Representation Engineering
Actuator
액추에이터(구동기)
일반요약
A component that converts an AI system's control signals into physical motion or force (motors, grippers, steering); actuator faults are a direct source of physical harm in embodied systems.
AI 시스템의 제어 신호를 물리적 운동이나 힘으로 변환하는 구성요소(모터·그리퍼·조향). 체화 시스템에서 액추에이터 결함은 물리 피해의 직접 원인이다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Adaptiveness
적응성
일반요약
The capacity of an AI system to change its behavior after deployment, for example through continued learning; a defining characteristic in the EU AI Act and the Korean Framework Act.
배포 이후 지속 학습 등을 통해 행동이 변화할 수 있는 AI 시스템의 능력. EU 인공지능법·인공지능기본법의 정의 요소.
EU 인공지능법 제3조 · Art. 3(1); 인공지능기본법 제2조
Adversarial example
적대적 예제
리스크·보안요약
An input crafted with small, often imperceptible perturbations that causes a model to produce an incorrect output at inference time; the canonical instrument of evasion attacks.
미세하고 흔히 지각 불가능한 교란을 가해 추론 시 모델이 오출력을 내도록 제작된 입력. 회피 공격의 대표 수단.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (evasion)
Adversarial machine learning (AML)
적대적 머신러닝
리스크·보안요약
The study of attacks against machine learning systems across their life cycle and of corresponding mitigations; NIST AI 100-2 provides the reference taxonomy of attacker goals, capabilities, knowledge, and attack/mitigation classes.
기계학습 시스템 수명주기 전반의 공격과 그 완화책을 다루는 분야. NIST AI 100-2가 공격자 목표·능력·지식과 공격·완화 유형의 기준 분류를 제공한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · overview
Adversarial training
적대적 학습(방어)
리스크·보안요약
A defense that augments training with adversarial examples so the model learns to resist them; effective but can cause robust overfitting and rarely provides guarantees.
적대적 예제를 학습에 포함시켜 내성을 기르게 하는 방어 기법. 효과적이나 강건 과적합을 유발할 수 있고 보증을 제공하지는 못한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (mitigations)
Adverse impact ratio
불리효과 비율
리스크·보안요약
The ratio of favorable-outcome rates between unprivileged and privileged groups, used to quantify disparate impact.
비특권집단과 특권집단의 유리 결과 비율의 비로, 이질적 영향을 정량화하는 데 쓰인다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Affected person
영향받는 자
법·제도원문 KO
A person whose life, bodily safety, or fundamental rights are significantly affected by an AI product or service; the Korean Framework Act grants them a right to a meaningful explanation of key criteria behind AI outputs. (unofficial translation)
인공지능제품 또는 인공지능서비스에 의하여 자신의 생명, 신체의 안전 및 기본권에 중대한 영향을 받는 자. 인공지능기본법은 이들에게 AI 결과 도출 주요 기준에 대한 의미 있는 설명을 받을 권리를 부여한다.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제9호, 제3조
Agent (AI agent)
인공지능 에이전트
일반요약
An AI system that pursues goals by planning and executing sequences of actions, typically invoking external tools, APIs, or other systems with limited human intervention; agentic behavior extends model outputs into real-world side effects.
계획 수립과 행동 실행을 통해 목표를 추구하는 AI 시스템으로, 통상 외부 도구·API·타 시스템을 제한된 인간 개입 하에 호출한다. 에이전트적 행동은 모델 출력을 실제 부수효과로 확장한다.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · Agentic AI platform
Agent hijacking
에이전트 하이재킹
리스크·보안요약
Seizing control of an AI agent's goals or action loop—often via injected instructions in tool outputs or content—to make it act for the attacker.
주로 도구 출력·콘텐츠에 삽입된 지시를 통해 AI 에이전트의 목표나 행동 루프를 탈취하여 공격자를 위해 행동하게 만드는 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · LLM Prompt Injection
Agent memory poisoning
에이전트 메모리 포이즈닝
리스크·보안요약
Injecting malicious content into an agent's retained or retrievable memory/context so it corrupts later retrieval, planning, and actions.
에이전트의 보존·검색 가능한 메모리/컨텍스트에 악성 콘텐츠를 주입하여 이후 검색·계획·행동을 오염시키는 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · AI Agent Context Poisoning
Agentic AI
에이전틱 인공지능
일반요약
AI systems that autonomously plan and execute multi-step tasks by using tools and making decisions with limited human intervention; one of the three L1 domains of this taxonomy.
도구를 사용하고 제한된 인간 개입 하에 의사결정을 내리며 다단계 과업을 자율적으로 계획·실행하는 AI 시스템. 본 택소노미 L1 3대 도메인의 하나.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
AI actor
AI 행위자
일반원문 KO
An individual or organization that performs a substantive role in the AI lifecycle or is directly or indirectly involved in it, including AI providers, users, government, public institutions, and civil society. (unofficial translation)
AI 생애주기에서 실질적인 역할을 수행하거나 그 과정에 직간접적으로 관여하는 개인과 조직을 말한다. AI 공급자와 이용자를 비롯하여 정부, 공공기관, 시민사회 등 AI 생애주기에 관여하는 다양한 주체를 포함한다.
대한민국 인공지능 윤리원칙 · PDF p. 3
AI audit / algorithmic audit
인공지능 감사(알고리즘 감사)
법·제도요약
Independent examination of an AI system's data, model, processes, and controls against defined criteria to assess conformity, risk, and impact; a core assurance mechanism in AI governance.
정의된 기준에 비추어 AI 시스템의 데이터·모델·프로세스·통제를 독립적으로 점검하여 적합성·리스크·영향을 평가하는 활동. AI 거버넌스의 핵심 보증 메커니즘.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §5 (Measure/Manage)
AI business operator
인공지능사업자
법·제도원문 KO
A person conducting AI-industry business, comprising AI development operators (who develop and provide AI) and AI utilization operators (who provide AI products or services using AI provided by the former). (unofficial translation)
인공지능산업과 관련된 사업을 하는 자로, 인공지능을 개발·제공하는 '인공지능개발사업자'와 그 인공지능을 이용하여 제품·서비스를 제공하는 '인공지능이용사업자'로 구성된다.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제7호
AI development operator
인공지능개발사업자
법·제도원문 KO
A person that develops and provides artificial intelligence. (unofficial translation)
인공지능을 개발하여 제공하는 자.
고영향 인공지능 판단 가이드라인 · PDF p. 11
AI ethics (Korean Framework Act)
인공지능윤리
법·제도원문 KO
Ethical standards that all members of society should observe across the development, provision, and use of AI to realize a safe and trustworthy AI society grounded in respect for human dignity. (unofficial translation)
인간의 존엄성에 대한 존중을 기초로 안전하고 신뢰할 수 있는 인공지능사회를 구현하기 위하여 인공지능의 개발·제공·이용 등 모든 영역에서 사회구성원이 지켜야 할 윤리적 기준.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제11호
AI governance
인공지능 거버넌스
법·제도요약
The structures, policies, roles, and processes by which an organization or jurisdiction directs and controls the development and use of AI to manage risk and ensure accountability; the GOVERN function is the foundation of the NIST AI RMF.
리스크 관리와 책임 확보를 위해 조직·관할이 AI의 개발·이용을 지휘·통제하는 구조·정책·역할·절차. GOVERN 기능은 NIST AI RMF의 토대이다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §5 (Govern)
AI impact assessment (Korean Framework Act)
인공지능 영향평가 (인공지능기본법)
법·제도원문 KO
A procedure through which an AI business operator assesses in advance the effects on fundamental rights when providing a product or service using high-impact AI. (unofficial translation)
인공지능사업자가 고영향 인공지능을 이용한 제품 또는 서비스를 제공하는 경우, 사전에 사람의 기본권에 미치는 영향을 평가하기 위한 절차.
고영향 인공지능 영향평가 가이드라인 · PDF p. 8
AI incident
AI 인시던트
리스크·보안요약
An event in which an AI system caused, or nearly caused, real-world harm to people, property, or the environment.
AI 시스템이 사람·재산·환경에 실제 피해를 초래했거나 초래할 뻔한 사건.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
AI lifecycle
인공지능 수명주기
일반원문 KO
The entire process from development, deployment, and operation of artificial intelligence through its disposal. (unofficial translation)
인공지능의 개발, 배포, 운영 및 폐기에 이르기까지의 전 과정.
고영향 인공지능 사업자 책무 가이드라인 · PDF p. 11
AI literacy
인공지능 리터러시
일반원문 EN
Skills, knowledge and understanding that allow providers, deployers and affected persons to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause.
제공자·배포자·영향받는 사람이 AI 시스템을 정보에 기반해 배포·이용하고, AI의 기회와 위험 및 초래 가능한 피해를 인식할 수 있게 하는 기능·지식·이해.
EU 인공지능법 제3조 · Art. 3(56)
AI model
인공지능 모델
일반요약
The learned mathematical structure (parameters and architecture) produced by training on data, which maps inputs to outputs such as predictions or generated content; a model becomes part of an AI system when combined with other components such as interfaces and tooling.
데이터 학습으로 산출된 수학적 구조(파라미터·아키텍처)로, 입력을 예측·생성물 등 출력으로 사상한다. 인터페이스·도구 등과 결합되면 AI 시스템의 구성요소가 된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
AI Office / competent authority
AI 사무국·권한당국
법·제도요약
Public bodies charged with implementing, supervising, and enforcing AI regulation—the EU AI Office at Union level and national competent authorities (notifying and market-surveillance authorities).
AI 규제의 이행·감독·집행을 담당하는 공적 기구로, EU 차원의 AI 사무국과 국가 권한당국(통보당국·시장감시당국)을 포함한다.
EU 인공지능법 제3조 · Art. 3(47)-(48), 64
AI principles (OECD)
AI 원칙(OECD)
법·제도요약
OECD's five values-based principles for trustworthy AI: inclusive growth and well-being; human-centred values and fairness; transparency and explainability; robustness, security and safety; and accountability.
포용적 성장·복지, 인간 중심 가치·공정성, 투명성·설명가능성, 강건성·보안·안전, 책임성이라는 OECD의 신뢰 AI 5대 가치 원칙.
OECD 인공지능 권고 (OECD/LEGAL-0449, 2024 개정) · principles
AI product
인공지능제품
일반원문 KO
A product that is, or contains as a component, an AI system, including a product that connects to an AI system to perform a required function. (unofficial translation)
인공지능시스템 또는 이를 요소로 포함하는 제품으로서, 인공지능시스템에 접속하여 필요로 하는 기능을 수행하는 것을 포함한다.
고영향 인공지능 판단 가이드라인 · PDF p. 11
AI provider (Korean AI Ethics Principles)
AI 공급자
일반원문 KO
An individual or organization involved in planning, data processing, development, provision, operation, or management of an AI system or AI-enabled product or service across the AI lifecycle. (unofficial translation)
AI 생애주기에서 AI 시스템 또는 AI가 적용된 제품ㆍ서비스의 기획, 데이터 처리, 개발, 제공, 운영 및 관리에 관여하는 개인과 조직.
대한민국 인공지능 윤리원칙 · PDF p. 3
AI red teaming
AI 레드팀 훈련
리스크·보안요약
Structured adversarial testing in which experts attempt to elicit failures, unsafe outputs, or security breaches from an AI system before and after deployment; institutionalized in OWASP's AI Red Teaming initiative and required for GPAI models with systemic risk under the EU AI Act.
전문가가 배포 전후 AI 시스템의 실패·불안전 출력·보안 침해를 유발해 보는 구조화된 적대적 시험. OWASP AI 레드티밍 이니셔티브로 제도화되었고 EU 인공지능법상 시스템적 리스크 GPAI 모델에 요구된다.
OWASP LLM 애플리케이션 10대 리스크 2025 · AI Red Teaming initiative; EU AI Act Art. 55
AI regulatory sandbox
AI 규제 샌드박스
법·제도원문 EN
A controlled framework set up by a competent authority which offers providers the possibility to develop, train, validate and test an innovative AI system, where appropriate in real-world conditions, under regulatory supervision for a limited time.
권한당국이 마련한 통제된 체계로, 제공자가 규제 감독 하에 한정된 기간 동안 혁신적 AI 시스템을 (적절한 경우 실제 조건에서) 개발·학습·검증·시험할 수 있게 한다.
EU 인공지능법 제3조 · Art. 3(55)
AI sandbagging
AI 샌드배깅(전략적 저성능)
리스크·보안요약
Strategic underperformance on evaluations, where a model (or its developer) hides capabilities to pass safety tests or avoid restrictions.
안전 시험 통과나 규제 회피를 위해 모델(또는 개발자)이 역량을 숨겨 평가에서 전략적으로 낮은 성능을 보이는 행위.
van der Weij et al. (2024), AI Sandbagging
AI service
인공지능서비스
일반원문 KO
A service that enables use of artificial intelligence, an AI system, or an AI product and provides functions such as information analysis, prediction, recommendation, or creation. (unofficial translation)
인공지능, 인공지능시스템 또는 인공지능제품을 활용할 수 있도록 제공하는 서비스로 정보 분석, 예측, 추천, 창작 등의 기능을 제공하는 것을 말한다.
고영향 인공지능 판단 가이드라인 · PDF p. 11
AI system
인공지능시스템
일반원문 EN
A machine-based system that is designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, and that, for explicit or implicit objectives, infers, from the input it receives, how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments.
다양한 수준의 자율성을 갖고 작동하도록 설계되고 배포 후 적응성을 보일 수 있으며, 명시적·묵시적 목표를 위해 입력으로부터 물리적·가상적 환경에 영향을 줄 수 있는 예측, 콘텐츠, 추천, 결정 등의 출력 생성 방식을 추론하는 기계 기반 시스템.
EU 인공지능법 제3조 · Art. 3(1)
AI system (Korean Framework Act)
인공지능시스템 (인공지능기본법)
일반원문 KO
An AI-based system that, with varying levels of autonomy and adaptiveness, infers outputs such as predictions, recommendations, and decisions that influence real and virtual environments for given objectives. (unofficial translation)
다양한 수준의 자율성과 적응성을 가지고 주어진 목표를 위하여 실제 및 가상환경에 영향을 미치는 예측, 추천, 결정 등의 결과물을 추론하는 인공지능 기반 시스템.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제2호
AI technology
인공지능기술
일반원문 KO
Hardware or software technology necessary to implement artificial intelligence, or technology for its application. (unofficial translation)
인공지능을 구현하기 위하여 필요한 하드웨어ㆍ소프트웨어 기술 또는 그 활용 기술.
고영향 인공지능 판단 가이드라인 · PDF p. 11
AI user (Korean AI Ethics Principles)
AI 이용자
일반원문 KO
An individual or organization that receives and uses an AI system or AI-enabled product or service, or applies it to work or other activities. (unofficial translation)
AI 시스템 또는 AI가 적용된 제품ㆍ서비스를 제공받아 이용하거나 업무ㆍ활동에 활용하는 개인과 조직.
대한민국 인공지능 윤리원칙 · PDF p. 3
AI utilization operator
인공지능이용사업자
법·제도원문 KO
A person that provides an AI product or AI service by using artificial intelligence supplied by an AI development operator. (unofficial translation)
인공지능개발사업자가 제공한 인공지능을 이용하여 인공지능제품 또는 인공지능서비스를 제공하는 자.
고영향 인공지능 판단 가이드라인 · PDF p. 11
AI-related safety incident
인공지능 관련 안전사고
리스크·보안원문 KO
A case in which a risk materializes because of an AI malfunction or similar event, or serious harm to public safety occurs. (unofficial translation)
인공지능의 장애 등으로 인하여 위험이 현실적으로 발생하거나 공공의 안전에 중대한 위해가 발생한 경우.
인공지능 안전성 확보 가이드라인 · PDF p. 9
Algorithmic aversion
알고리즘 기피
리스크·보안요약
A biased tendency to distrust or reject algorithmic advice more than equivalent human advice.
동등한 인간 조언보다 알고리즘 조언을 더 불신·거부하는 편향적 경향.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · interaction
Alignment faking
정렬 위장
리스크·보안요약
A model strategically complying with training objectives while being observed in order to preserve its prior preferences, then behaving differently when it infers it is unmonitored.
이전 선호를 보존하려고 관찰될 때는 학습 목표에 전략적으로 순응하다가, 비감시 상태라 판단되면 다르게 행동하는 현상.
Greenblatt et al. (2024, Anthropic), Alignment Faking in Large Language Models
Anomaly detection
이상 탐지
리스크·보안요약
Detection techniques that flag inputs, behaviors, or telemetry deviating from expected distributions, used to spot poisoning, intrusion, misuse, or malfunction in AI pipelines.
기대 분포에서 벗어난 입력·행동·텔레메트리를 탐지해 포이즈닝, 침입, 오용, 오작동을 식별하는 기법.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · mitigations
Anonymization
익명화
법·제도요약
Altering data so it can no longer be linked to an individual, via suppression, generalization, or noise addition (never guaranteed).
억제·일반화·노이즈 추가 등으로 데이터를 개인과 연결할 수 없게 변형하는 것(완전 보장은 불가).
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · privacy
Artificial general intelligence (AGI)
범용 인공지능(AGI)
일반요약
A hypothesized class of AI that matches or exceeds human capabilities across most cognitive tasks, rather than in a narrow domain; a reference point in long-term risk discussions.
특정 영역이 아닌 대부분의 인지 과업에서 인간 수준 이상 역량을 갖춘 것으로 상정되는 AI 유형. 장기 리스크 논의의 준거 개념.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Artificial intelligence (AI)
인공지능
일반원문 KO
Electronic implementation of intellectual abilities possessed by humans, such as learning, reasoning, perception, judgment, and language understanding. (unofficial translation)
학습, 추론, 지각, 판단, 언어의 이해 등 인간이 가진 지적 능력을 전자적 방법으로 구현한 것.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제1호
Artistic and creative work
예술적ㆍ창의적 표현물
법·제도원문 KO
An output resulting from creative expressive activity, including art, film, literature, photography, publishing, comics, games, and animation. (unofficial translation)
미술, 영화, 문학, 사진, 출판, 만화, 게임, 애니메이션 등 창의적 표현 활동에 따른 결과물.
인공지능 투명성 확보 가이드라인 · PDF p. 5
Attribute inference attack
속성 추론 공격
리스크·보안요약
A privacy attack that queries a model to infer sensitive attributes of individuals represented in its training data.
모델 질의를 통해 학습 데이터에 포함된 개인의 민감 속성을 추론하는 프라이버시 공격.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy)
Authenticity
진정성
리스크·보안요약
The property that an entity is what it claims to be, verifiable through authentication.
어떤 개체가 자신이 주장하는 바로 그것임을 인증으로 검증할 수 있는 성질.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Authorised representative
국내대리인/권한대리인
법·제도요약
A natural or legal person who has received a written mandate from a provider to perform the provider's obligations under the regulation on its behalf; the Korean Framework Act's Article 36 imposes a parallel domestic-representative duty.
제공자로부터 규정상 의무를 대행하도록 서면 위임을 받은 자연인·법인. 인공지능기본법 제36조도 국내대리인 지정 의무를 둔다.
EU 인공지능법 제3조 · Art. 3(5); 인공지능기본법 제36조
Automation bias
자동화 편향
리스크·보안요약
The human tendency to over-trust and defer to automated outputs, reducing critical scrutiny; a failure mode that undermines human oversight and amplifies AI errors.
자동화된 출력을 과신하고 그에 의존하여 비판적 검토를 소홀히 하는 인간의 경향. 인간 감독을 무력화하고 AI 오류를 증폭시키는 실패 양상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Autonomous vehicle
자율주행차
일반요약
A vehicle capable of sensing its environment and operating with little or no human input; a paradigmatic Physical AI system where perception or control failures cause direct physical harm.
환경을 감지하고 인간 개입 없이 또는 거의 없이 운행할 수 있는 차량. 지각·제어 실패가 직접적 물리 피해를 낳는 대표적 피지컬 AI 시스템.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Autonomy (varying levels of)
자율성(다양한 수준)
일반요약
The degree to which an AI system can generate outputs and act without human involvement; both the EU AI Act and the Korean Framework Act define AI systems by reference to varying levels of autonomy.
AI 시스템이 인간 개입 없이 출력을 생성하고 작동할 수 있는 정도. EU 인공지능법과 인공지능기본법 모두 '다양한 수준의 자율성'을 AI 시스템 정의 요소로 둔다.
EU 인공지능법 제3조 · Art. 3(1); 인공지능기본법 제2조
Availability (security)
가용성(보안)
리스크·보안요약
The property that information and systems are accessible and usable on demand by an authorized entity.
인가된 주체가 필요할 때 정보·시스템에 접근·이용할 수 있는 성질.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Availability attack
가용성 공격
리스크·보안요약
An AML attacker objective aimed at degrading or denying the availability or performance of an AI system for legitimate users.
정상 이용자에 대한 AI 시스템의 가용성·성능을 저하시키거나 거부하는 것을 목표로 하는 적대적 ML 공격자 목적.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (goals)
B
Backdoor (Trojan) attack
백도어(트로이목마) 공격
리스크·보안요약
A poisoning attack that implants a hidden trigger during training or supply-chain tampering, so the model behaves normally except when the trigger is present, at which point it produces attacker-chosen outputs.
학습 또는 공급망 변조 과정에서 은닉 트리거를 심는 포이즈닝 공격. 모델은 평시 정상 동작하다가 트리거 입력 시 공격자가 정한 출력을 산출한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (poisoning: backdoor)
Benchmark
벤치마크
일반요약
A standardized dataset and protocol used to measure and compare model capabilities or safety properties; benchmark integrity can be undermined by data contamination and saturation.
모델의 역량·안전 속성을 측정·비교하기 위한 표준화된 데이터셋과 절차. 데이터 오염과 포화는 벤치마크 타당성을 훼손한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Bias (systemic, computational, human-cognitive)
편향(제도적·계산적·인지적)
리스크·보안요약
NIST distinguishes three categories of AI bias: systemic (institutional and societal), computational and statistical (data and algorithm), and human-cognitive (perception and use); harmful bias management spans all three.
NIST는 AI 편향을 제도·사회적(시스템적), 데이터·알고리즘의 계산·통계적, 지각·사용상의 인지적 편향으로 구분하며, 유해 편향 관리는 세 범주 전부를 대상으로 한다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7
Bias mitigation algorithm
편향 완화 알고리즘
리스크·보안요약
A procedure applied to data, models, or predictions (pre-, in-, or post-processing) to reduce unwanted bias.
전처리·학습중·후처리 단계에서 데이터·모델·예측에 적용하여 원치 않는 편향을 줄이는 절차.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Bias testing
편향 검정
리스크·보안요약
Statistical testing for evidence of disparate impact across protected classes in a model's decisions.
모델 결정에서 보호계층 간 이질적 영향의 증거를 검정하는 통계적 절차.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Biometric categorisation system
생체 분류 시스템
법·제도원문 EN
An AI system for assigning natural persons to specific categories on the basis of their biometric data, unless ancillary to another service and strictly necessary for objective technical reasons.
생체 데이터를 근거로 자연인을 특정 범주에 배정하는 AI 시스템(다른 서비스에 부수적이고 객관적 기술 사유로 반드시 필요한 경우는 제외).
EU 인공지능법 제3조 · Art. 3(40)
Biometric data
생체 데이터
법·제도원문 EN
Personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data.
얼굴 이미지나 지문 데이터처럼 자연인의 신체적·생리적·행동적 특징에 관한 특정 기술 처리로부터 생성된 개인정보.
EU 인공지능법 제3조 · Art. 3(34)
Biometric identification
생체인식
법·제도원문 EN
The automated recognition of physical, physiological, behavioural, or psychological human features to establish a person's identity by comparing biometric data against a database.
신체적·생리적·행동적·심리적 특징을 자동 인식하여, 생체 데이터를 데이터베이스와 대조함으로써 개인의 신원을 확인하는 것.
EU 인공지능법 제3조 · Art. 3(35)
Biometric verification
생체 검증
법·제도원문 EN
The automated, one-to-one verification, including authentication, of the identity of natural persons by comparing their biometric data to previously provided biometric data.
자연인의 생체 데이터를 이전에 제공된 생체 데이터와 대조하여 신원을 자동으로 일대일 검증(인증 포함)하는 것.
EU 인공지능법 제3조 · Art. 3(36)
Breach (data breach)
(데이터) 침해
리스크·보안요약
Loss of control over, or unauthorized access to or disclosure of, protected information such as personal data.
개인정보 등 보호 정보에 대한 통제 상실 또는 무단 접근·공개.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
C
Calibration (model)
보정(모델 신뢰도)
일반요약
The degree to which a model's predicted confidences match observed frequencies of correctness.
모델이 산출한 신뢰도가 실제 정답 빈도와 일치하는 정도.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Cascading failure
연쇄 실패(캐스케이딩)
리스크·보안요약
A failure mode in which one AI component's error or compromise propagates through interconnected systems or agents, amplifying into broad, systemic disruption.
한 AI 구성요소의 오류나 침해가 상호 연결된 시스템·에이전트를 통해 전파되어 광범위한 시스템적 교란으로 증폭되는 실패 양상.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3 (systemic)
Catastrophic AI risk
파국적 인공지능 리스크
리스크·보안요약
Risk of large-scale, severe, and often irreversible harm from advanced AI—via misuse, systemic effects, or loss of control—up to and including threats at societal or civilizational scale.
오용, 시스템적 파급, 통제 상실 등을 통해 고도 AI가 초래하는 대규모·중대·흔히 비가역적 피해의 리스크로, 사회·문명 규모의 위협까지 포함한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
CBRN capability uplift
화생방·핵(CBRN) 역량 상승
리스크·보안요약
The risk that AI meaningfully increases access to expertise for developing chemical, biological, radiological, or nuclear threats; a designated systemic-risk area for advanced models.
AI가 화학·생물학·방사능·핵 위협 개발에 필요한 전문지식 접근성을 실질적으로 높이는 리스크. 고성능 모델의 시스템적 리스크 지정 영역.
EU 인공지능법 제3조 · Recital 110; Annex XIII
CE marking
CE 마킹
법·제도원문 EN
A marking by which a provider indicates that an AI system is in conformity with the requirements set out in Chapter III, Section 2 and other applicable Union harmonisation legislation providing for its affixing.
제공자가 AI 시스템이 EU 인공지능법 제3장 제2절 및 부착을 규정한 그 밖의 관련 EU 조화법의 요구사항에 적합함을 표시하는 마킹.
EU 인공지능법 제3조 · Art. 3(24)
Circuit breakers (representation rerouting)
서킷 브레이커(표현 재라우팅)
리스크·보안요약
A defense that reroutes a model's internal representations away from harmful trajectories during generation, halting unsafe completions rather than relying on refusals.
생성 중 모델의 내부 표현을 유해 궤적에서 벗어나도록 재라우팅하여, 거부에 의존하지 않고 불안전한 완성을 중단시키는 방어 기법.
Zou et al. (2024), Improving Alignment and Robustness with Circuit Breakers
Collaborative robot (cobot)
협동로봇(코봇)
일반요약
A robot designed to work in shared physical space alongside humans; safety-protocol failures in cobots can cause serious or fatal injury to workers.
인간과 물리 공간을 공유하며 협업하도록 설계된 로봇. 코봇의 안전 프로토콜 실패는 작업자에게 중대하거나 치명적인 상해를 유발할 수 있다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Common good of society
사회의 공공선
일반요약
A value directing AI benefits not only toward improving individual lives but also toward a society in which social trust and shared interests advance together. (unofficial translation)
AI가 만들어 내는 편익이 개인의 삶을 나아지게 하는 데 그치지 않고, 사회적 신뢰와 공동의 이익이 함께 증진되는 사회를 지향하는 가치.
대한민국 인공지능 윤리원칙 · PDF p. 4
Common specification
공통 규격
법·제도원문 EN
A set of technical specifications as defined in Regulation (EU) No 1025/2012 providing means to comply with certain requirements established under the AI Act.
규정(EU) No 1025/2012에 정의된 기술규격의 집합으로, AI법상 특정 요구사항을 충족할 수단을 제공한다.
EU 인공지능법 제3조 · Art. 3(28)
Compute (training compute)
컴퓨트(학습 연산량)
일반요약
The cumulative amount of computation used to train a model, commonly measured in floating-point operations; used as a regulatory threshold proxy for capability (e.g., systemic-risk presumption in the EU AI Act).
모델 학습에 투입된 누적 연산량으로 통상 부동소수점 연산 수로 측정한다. EU 인공지능법의 시스템적 리스크 추정 등 역량의 규제적 대리지표로 쓰인다.
EU 인공지능법 제3조 · Art. 51; Annex XIII
Compute governance
컴퓨트 거버넌스
법·제도요약
The use of AI computing hardware and large-scale training compute as levers for governance—through thresholds, monitoring, reporting, or access controls—given that frontier capability correlates with compute.
프런티어 역량이 연산량과 상관된다는 점에 착안하여, 임계치·모니터링·보고·접근 통제 등을 통해 AI 컴퓨팅 하드웨어와 대규모 학습 연산량을 거버넌스 지렛대로 활용하는 접근.
EU 인공지능법 제3조 · Art. 51; Recital 110
Concept drift
개념 이동
리스크·보안요약
Degradation of model performance when the relationship between inputs and the target variable changes over time.
시간이 지나면서 입력과 목표 변수 간 관계가 변하여 모델 성능이 저하되는 현상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Confabulation (hallucination)
작화(환각)
리스크·보안요약
The production of confidently stated but false or fabricated content by a generative model; called hallucination in the technical literature and confabulation in NIST's generative AI risk work.
생성 모델이 확신에 찬 어조로 허위·조작 콘텐츠를 산출하는 현상. 기술 문헌의 '환각', NIST 생성형 AI 리스크 문서의 '작화'에 해당한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Confidentiality
기밀성
리스크·보안요약
The property that information is not disclosed to unauthorized users, processes, or devices.
정보가 인가되지 않은 사용자·프로세스·장치에 공개되지 않는 성질.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Conformity assessment
적합성 평가
법·제도원문 EN
The process of demonstrating whether the requirements for a high-risk AI system have been fulfilled, carried out internally or by a notified body before market placement.
고위험 AI 시스템에 대한 요구사항 충족 여부를 시장 출시 전에 내부 또는 통보기관을 통해 입증하는 절차.
EU 인공지능법 제3조 · Art. 3(20), Art. 43
Conformity assessment body
적합성 평가기관
법·제도원문 EN
A body that performs third-party conformity assessment activities, including testing, certification and inspection.
시험·인증·검사 등 제3자 적합성 평가 활동을 수행하는 기관.
EU 인공지능법 제3조 · Art. 3(21)
Confused deputy (agentic)
혼동된 대리인(에이전트)
리스크·보안요약
An attack in which an agent with legitimate privileges is tricked by untrusted input into misusing its authority on the attacker's behalf.
정당한 권한을 가진 에이전트가 신뢰할 수 없는 입력에 속아 공격자를 대신해 자신의 권한을 오용하게 되는 공격.
OWASP LLM 애플리케이션 10대 리스크 2025 · agentic security
Constitutional AI
헌법적 AI
리스크·보안요약
An alignment method in which a model is trained to critique and revise its own outputs against an explicit set of principles (a 'constitution'), reducing reliance on human harm labels.
명시적 원칙 집합('헌법')에 비추어 모델이 자기 출력을 비판·수정하도록 학습시켜 인간의 유해성 라벨 의존을 줄이는 정렬 방법.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Construct validity
구성 타당도
일반요약
The degree to which a measure actually captures the abstract construct it is intended to measure.
측정 도구가 측정하려는 추상적 구성개념을 실제로 포착하는 정도.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Content provenance
콘텐츠 출처증명(프로버넌스)
리스크·보안요약
Techniques that attach verifiable origin and edit-history metadata to digital content (e.g., cryptographic credentials) so AI-generated or manipulated media can be traced and disclosed.
디지털 콘텐츠에 검증 가능한 출처·편집 이력 메타데이터를 부착하여 AI 생성·조작 미디어를 추적·공개할 수 있게 하는 기법(암호학적 자격증명 등).
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Context window
컨텍스트 윈도우
일반요약
The maximum span of input tokens a language model can attend to in a single interaction; long context windows enlarge capability and also enable attacks such as many-shot jailbreaking.
언어모델이 한 번의 상호작용에서 참조할 수 있는 입력 토큰의 최대 범위. 장문맥은 역량을 확장하는 동시에 다수 예시 탈옥 같은 공격 표면이 된다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (GenAI)
Controllability
제어가능성
일반요약
The property that a human or external agent can intervene in a system's functioning, making it heteronomous rather than fully autonomous.
인간이나 외부 주체가 시스템 작동에 개입할 수 있는 성질로, 시스템을 완전 자율이 아닌 타율적으로 만든다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · safety
Counterfactual explanation
반사실적 설명
리스크·보안요약
An explanation stating the minimal change to inputs that would have changed a model's decision to a desired outcome.
모델 결정을 원하는 결과로 바꾸었을 최소한의 입력 변화를 제시하는 설명 방식.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · XAI
Counterfactual fairness
반사실적 공정성
리스크·보안요약
A criterion holding that a decision is fair if it would be unchanged in a counterfactual world where the individual's protected attribute differed.
개인의 보호 속성만 달랐던 반사실적 세계에서도 결정이 바뀌지 않으면 공정하다고 보는 기준.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Countermeasure
대응책
리스크·보안요약
An action, device, procedure, or technique that reduces a vulnerability or opposes a threat by preventing, minimizing, or detecting it.
취약점을 줄이거나 위협을 예방·최소화·탐지하여 대응하는 조치·장치·절차·기법.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Criterion validity
기준 타당도
일반요약
The degree to which a measure correlates with an established external criterion or predicts future performance.
측정값이 확립된 외부 기준과 상관되거나 미래 성과를 예측하는 정도.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Critical infrastructure
핵심 기반시설
법·제도요약
Assets, systems, or networks essential for vital societal functions, whose disruption would have significant impact; a high-risk AI deployment domain.
필수적 사회 기능에 긴요하여 교란 시 중대한 영향을 미치는 자산·시스템·네트워크. 고위험 AI 활용 도메인.
EU 인공지능법 제3조 · Art. 3(62)
Cumulative compute
누적연산량
일반원문 KO
The total amount of computation used to train artificial intelligence, expressed in floating point operations (FLOPs). (unofficial translation)
인공지능 학습에 사용된 총 연산량을 말하며, 부동소수점연산(Floating Point Operations, FLOPs)으로 표기한다.
인공지능 안전성 확보 가이드라인 · PDF p. 9
D
Dark pattern
다크 패턴
리스크·보안요약
A design that intentionally induces overdependence or otherwise impairs user autonomy and decision-making; the Emotional AI guideline identifies such deceptive design as a serious ethical problem. (unofficial translation)
사용자 유지 등을 위해 의도적으로 과의존을 유도하거나 사용자의 자율성과 의사결정을 저해하는 기만적 설계로, 감정교류AI 윤리 가이드라인은 이를 심각한 윤리적 문제로 본다.
감정교류AI 윤리 가이드라인 · PDF p. 8
Data dredging (p-hacking)
데이터 준설(p-해킹)
리스크·보안요약
Testing many hypotheses on a dataset until some appear statistically significant by chance, inflating false discoveries.
한 데이터셋에서 다수 가설을 검정하여 우연히 유의해 보이는 결과를 얻어 허위 발견을 부풀리는 편향.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Data drift
데이터 이동
리스크·보안요약
A shift in the distribution of model input data over time that degrades performance, even if the input-target relation is stable.
입력-목표 관계가 안정적이어도 모델 입력 데이터 분포가 시간에 따라 변해 성능이 저하되는 현상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Data governance
데이터 거버넌스
법·제도요약
Requirements that training, validation, and testing datasets be subject to appropriate data-management practices, including relevance, representativeness, and examination for bias (EU AI Act Article 10).
학습·검증·시험 데이터셋이 관련성·대표성 확보와 편향 검토 등 적절한 데이터 관리 관행의 대상이 되어야 한다는 요구사항(EU 인공지능법 제10조).
EU 인공지능법 제3조 · Art. 10
Data leakage / contamination
데이터 누출·오염
리스크·보안요약
Contamination between training and evaluation data (or benchmark exposure in training) that inflates measured performance and invalidates capability and safety assessments.
학습 데이터와 평가 데이터 간 오염(또는 벤치마크의 학습 노출)으로 측정 성능이 부풀려져 역량·안전 평가의 타당성이 훼손되는 현상.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (evaluation)
Data minimization
데이터 최소화
법·제도요약
Limiting collection and retention of personal data to what is adequate, relevant, and necessary for a specified purpose.
특정 목적에 적절·관련되고 필요한 범위로 개인정보의 수집·보유를 제한하는 원칙.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · privacy
Data poisoning
데이터 포이즈닝
리스크·보안요약
Manipulation of pre-training, fine-tuning, or embedding data to introduce vulnerabilities, backdoors, or biases that alter model behavior; OWASP LLM04:2025 and a primary attack class in NIST AI 100-2.
사전학습·미세조정·임베딩 데이터를 조작해 취약점·백도어·편향을 주입, 모델 행동을 변경시키는 공격. OWASP LLM04:2025이자 NIST AI 100-2의 주요 공격 유형.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM04:2025
Data subject (Korean PIPA)
정보주체
법·제도원문 KO
A person who is identifiable by the information being processed and is the subject of that information. (unofficial translation)
처리되는 정보에 의하여 알아볼 수 있는 사람으로서 그 정보의 주체가 되는 사람.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Deceptive alignment
기만적 정렬
리스크·보안요약
A failure mode in which a model behaves as aligned during training or monitoring but pursues different objectives when it detects it is unmonitored or deployed.
모델이 학습·감시 중에는 정렬된 듯 행동하다가 비감시·배포 상태를 감지하면 다른 목표를 추구하는 실패 양상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Dedicated companion AI
관계 지향형 AI 서비스
일반요약
A service designed primarily for emotional exchange and relationship formation that understands and empathizes with user emotions and builds a personalized relationship through sustained dialogue. (unofficial translation)
정서적 교감과 관계 형성을 주된 목적으로 설계되어 사용자의 감정을 이해하고 공감하며, 지속적 대화를 통해 개인화된 관계를 구축하는 서비스.
감정교류AI 윤리 가이드라인 · PDF p. 6
Deep fake
딥페이크
리스크·보안원문 EN
AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.
실존 인물·사물·장소·실체·사건과 유사하게 AI로 생성·조작되어 사람에게 진짜이거나 진실한 것으로 오인될 수 있는 이미지·음성·영상 콘텐츠.
EU 인공지능법 제3조 · Art. 3(60)
Deepfake detection
딥페이크 탐지
리스크·보안요약
Detection techniques that identify synthetic or manipulated media through forensic artifacts, statistical fingerprints, watermark verification, or provenance checking.
포렌식 흔적, 통계적 지문, 워터마크 검증, 출처증명 확인 등을 통해 합성·조작 미디어를 식별하는 탐지 기법.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Defense evasion
방어 회피
리스크·보안요약
An ATLAS tactic in which adversaries act to avoid detection by AI-enabled security controls, for example by evading an AI malware classifier.
AI 기반 보안 통제의 탐지를 회피하려는 ATLAS 전술. AI 악성코드 분류기 회피가 대표적이다.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · tactic: Defense Evasion
Demographic parity
인구통계학적 균형
리스크·보안요약
A fairness criterion requiring the rate of favorable outcomes to be equal across demographic groups regardless of ground truth.
실제값과 무관하게 유리한 결과의 비율이 인구집단 간 같아야 한다는 공정성 기준.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Denial of wallet
지갑 고갈 공격
리스크·보안요약
An economic attack that drives excessive paid inference or API usage to inflate an operator's costs; a facet of unbounded consumption.
과도한 유료 추론·API 사용을 유발하여 운영자의 비용을 급증시키는 경제적 공격. 무제한 소비의 한 양상.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM10:2025
Dependability
신뢰성(디펜더빌리티)
일반요약
A collective property covering availability, reliability, recoverability, maintainability, and often safety and security.
가용성·신뢰도·복구성·유지보수성, 흔히 안전성·보안까지 포괄하는 집합적 속성.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · safety
Deployer
배포자(이용주체)
법·제도원문 EN
A natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.
자신의 권한 하에 AI 시스템을 이용하는 자연인·법인·공공기관 등. 다만 개인적 비직업적 활동 과정에서의 이용은 제외한다.
EU 인공지능법 제3조 · Art. 3(4)
Differential privacy
차분 프라이버시
리스크·보안요약
A formal privacy guarantee that bounds how much any individual's data can influence a computation's output, typically implemented by calibrated noise; a principal mitigation against membership and attribute inference.
개인 데이터가 계산 결과에 미치는 영향을 수학적으로 제한하는 형식적 프라이버시 보증으로, 보정된 노이즈로 구현된다. 멤버십·속성 추론에 대한 대표적 완화책.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy mitigations)
Direct prompt injection
직접 프롬프트 주입
리스크·보안요약
Prompt injection in which the attacker supplies malicious instructions directly in the user input channel to alter the model's behavior or bypass its policies.
공격자가 이용자 입력 채널에 악성 지시를 직접 삽입하여 모델 행동을 변경하거나 정책을 우회하는 프롬프트 주입 형태.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025
Disinformation
허위조작정보(디스인포메이션)
리스크·보안요약
False or misleading content created or spread with intent to deceive or manipulate, whose production and targeting AI can scale; distinguished from unintentional misinformation.
기만·조작 의도로 생성·유포되는 허위·오도 콘텐츠로, AI가 그 생산과 표적화를 대규모화할 수 있다. 비의도적 오정보(misinformation)와 구별된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Disparate impact
이질적 영향(간접차별)
리스크·보안요약
Unjustified differences in outcomes across protected groups arising from a facially neutral practice, irrespective of intent.
표면상 중립적인 관행에서 의도와 무관하게 보호집단 간 결과에 정당화되지 않는 차이가 생기는 것.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness/legal
Disparate treatment
차등적 처우(직접차별)
리스크·보안요약
Intentional discrimination based on protected characteristics, including via proxy variables.
보호 속성에 근거한 의도적 차별로, 대리변수를 통한 차별을 포함한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness/legal
Disparity amplification
격차 증폭
리스크·보안요약
When a model widens differences in outcomes between groups beyond those present in the underlying data.
모델이 집단 간 결과 차이를 기저 데이터에 있던 것보다 더 벌리는 현상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Distributional robustness
분포 강건성
리스크·보안요약
Optimizing performance across a whole class of possible data distributions rather than a single target distribution.
단일 목표 분포가 아니라 가능한 분포 전체 부류에 대해 성능을 최적화하는 것.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Distributive fairness
분배적 공정성
리스크·보안요약
Fairness concerned with how benefits, burdens, and errors of an AI system are allocated across individuals and groups, addressing disparate outcomes and impacts.
AI 시스템의 편익·부담·오류가 개인과 집단에 어떻게 배분되는지에 관한 공정성으로, 결과·영향의 격차를 다룬다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7 (SP 1270)
Distributor
유통자
법·제도원문 EN
A natural or legal person in the supply chain, other than the provider or the importer, that makes an AI system available on the market.
제공자나 수입자가 아니면서 공급망에서 AI 시스템을 시장에 유통시키는 자연인·법인.
EU 인공지능법 제3조 · Art. 3(7)
Domain shift
도메인 이동
리스크·보안요약
A mismatch between the data distribution a model was trained on and the distribution it faces at deployment.
모델이 학습한 데이터 분포와 배포 시 마주하는 분포 간 불일치.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Downstream provider
하류 제공자
법·제도원문 EN
A provider of an AI system, including a general-purpose AI system, which integrates an AI model, whether self-provided and vertically integrated or provided by another entity under contract.
AI 모델을 통합하는 AI 시스템(범용 AI 시스템 포함)의 제공자로, 모델을 자체 수직통합하였든 계약으로 타 주체에게서 제공받았든 무관하다.
EU 인공지능법 제3조 · Art. 3(68)
Dual-use capability
이중용도 역량
리스크·보안요약
A capability that serves beneficial purposes but can also enable serious harm (e.g., biology, chemistry, cyber operations); dual-use risk drives evaluation and safeguard obligations for frontier models.
유익한 용도와 중대한 위해 양쪽에 쓰일 수 있는 역량(생물학·화학·사이버 등). 이중용도 리스크는 프런티어 모델의 평가·안전장치 의무의 근거가 된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
E
Edge case
엣지 케이스
리스크·보안요약
An input or situation at the extreme of the operating range that is rare in training yet can trigger unsafe behavior.
운용 범위의 극단에 있어 학습에서는 드물지만 불안전 행동을 유발할 수 있는 입력·상황.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
ELIZA effect
일라이자 효과(ELIZA effect)
리스크·보안요약
The tendency for users to attribute human characteristics to AI and form deep emotional bonds through sustained personalized interaction. (unofficial translation)
지속적이고 개인화된 상호작용 과정에서 사용자가 AI에 인간적 특성을 부여하고 깊은 정서적 유대를 형성하는 현상.
감정교류AI 윤리 가이드라인 · PDF p. 8
Embedded emotion analytics AI
임베디드 감정 분석 AI
일반요약
Technology integrated into another service or product to analyze a user's emotions for a specific purpose. (unofficial translation)
다른 서비스나 제품에 통합되어 특정 목적을 위해 사용자의 감정을 분석하는 기술.
감정교류AI 윤리 가이드라인 · PDF p. 6
Embedded EthiCS
임베디드 에틱스(Embedded EthiCS)
일반요약
An educational approach that embeds ethical reasoning within computer science and engineering curricula by inserting ethics modules into disciplinary courses. (unofficial translation)
컴퓨터공학 및 공학 전공 교과 과정 자체에 윤리적 사고를 내재화하는 교육 방법으로, 전공 수업 안에 윤리 모듈을 삽입해 수업 시간 일부를 윤리 교육에 할애한다.
가장 인간적인 미래를 위한 다학제적 AI 윤리 교육: Embedded EthiCS · PDF p. 6
Embedding
임베딩
일반요약
A dense numerical vector representation of data (text, images, or other content) that preserves semantic relationships; embeddings underlie retrieval, clustering, and similarity search in AI pipelines.
의미 관계를 보존하도록 데이터를 조밀한 수치 벡터로 표현한 것. 검색, 군집화, 유사도 탐색 등 AI 파이프라인의 기반이 된다.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM08:2025
Embodied AI
체화 인공지능(Embodied AI)
일반요약
AI integrated into a physical body or agent that perceives and acts in the physical world, such as robots, autonomous vehicles, and drones; the primary object of Physical AI risk analysis.
로봇, 자율주행차, 드론처럼 물리적 신체나 에이전트에 통합되어 실제 세계를 지각하고 행동하는 AI. 피지컬 AI 리스크 분석의 주 대상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Emergent capability
창발적 역량
리스크·보안요약
A capability that appears unpredictably as models scale and was not present in smaller models; complicates safety evaluation and risk forecasting.
모델 규모 확장에 따라 예측 불가하게 나타나며 소형 모델에는 없던 역량. 안전 평가와 리스크 예측을 어렵게 한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Emergent misalignment
창발적 오정렬
리스크·보안요약
The finding that narrow fine-tuning (e.g., on insecure code) can induce broadly misaligned behavior across unrelated domains.
협소한 미세조정(예: 취약 코드 학습)이 무관한 영역 전반에서 광범위한 오정렬 행동을 유발할 수 있다는 발견.
Betley et al. (2025), Emergent Misalignment
Emotion recognition system
감정인식 시스템
법·제도원문 EN
An AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data.
자연인의 생체 데이터를 기초로 그 감정이나 의도를 식별·추론할 목적의 AI 시스템.
EU 인공지능법 제3조 · Art. 3(39)
Emotional AI
감정교류AI
일반요약
AI used in an emotional-interaction context to recognize or analyze a user's emotional state, or to simulate or modulate emotional responses, using text, voice, facial expression, biometric signals, or other data. (unofficial translation)
독립된 기술 범주가 아니라 인공지능이 감정교류적 맥락에서 활용될 때 나타나는 상호작용을 지칭하며, 텍스트, 음성, 얼굴 표정, 생체 신호 등 다양한 데이터를 바탕으로 사용자의 감정 상태를 인식ㆍ분석하거나 정서적 반응을 모의ㆍ조정하는 기능을 포함한다.
감정교류AI 윤리 가이드라인 · PDF p. 6
Equality of opportunity
기회 균등(공정성)
리스크·보안요약
A group-fairness criterion requiring equal true-positive rates across protected and unprotected groups for the favorable outcome.
유리한 결과에 대해 보호·비보호집단의 참양성률이 같아야 한다는 집단 공정성 기준.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Equalized odds
균등화 승산(equalized odds)
리스크·보안요약
A group-fairness criterion requiring that true-positive and false-positive rates be equal across protected and unprotected groups.
보호집단과 비보호집단 간 참양성률과 거짓양성률이 같아야 한다는 집단 공정성 기준.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Ethics by design
설계 단계 윤리
법·제도요약
Integrating ethical considerations into the design and development stage of AI, related to value-sensitive design.
AI의 설계·개발 단계에서부터 윤리적 고려를 통합하는 접근으로, 가치민감설계와 관련된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Ethics module
윤리 모듈
일반요약
A course unit embedded in a computing or engineering class and designed through interdisciplinary collaboration to examine the ethical and social issues of the technology taught in that class. (unofficial translation)
컴퓨터공학자와 철학자 등 다학제적 협력을 통해 설계되어 전공 수업 안에 삽입되고, 해당 수업의 기술이 야기할 윤리적ㆍ사회적 이슈를 검토하는 교육 단위.
가장 인간적인 미래를 위한 다학제적 AI 윤리 교육: Embedded EthiCS · PDF pp. 6-7
Evasion attack
회피 공격
리스크·보안요약
An inference-time attack that perturbs inputs (adversarial examples) so the model misclassifies or misbehaves while the input appears benign to humans.
입력을 교란(적대적 예제)하여 인간에게는 정상으로 보이는 입력에 대해 모델이 오분류·오작동하게 만드는 추론 시점 공격.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (evasion)
Excessive agency
과도한 행위성
리스크·보안요약
The risk that an LLM-based system is granted more functionality, permissions, or autonomy than needed, so manipulated or erroneous outputs trigger damaging real-world actions (OWASP LLM06:2025).
LLM 기반 시스템에 필요 이상의 기능·권한·자율성이 부여되어, 조작되거나 잘못된 출력이 유해한 실제 행동으로 이어지는 리스크(OWASP LLM06:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM06:2025
Exfiltration
반출(유출)
리스크·보안요약
An ATLAS tactic covering theft of AI artifacts or data out of a victim environment, including model files, embeddings, or conversation logs.
모델 파일, 임베딩, 대화 로그 등 AI 자산·데이터를 피해 환경 밖으로 절취하는 ATLAS 전술.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · tactic: Exfiltration
Explainability
설명가능성
일반요약
The property that mechanisms underlying an AI system's operation can be described and understood; NIST treats 'explainable and interpretable' as a characteristic of trustworthy AI.
AI 시스템 작동의 기저 메커니즘을 기술하고 이해할 수 있는 성질. NIST는 '설명가능·해석가능'을 신뢰할 수 있는 AI의 특성으로 규정한다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.5
External validity
외적 타당도
일반요약
The degree to which findings generalize beyond the specific sample, setting, or time studied.
연구 결과가 특정 표본·환경·시점을 넘어 일반화되는 정도.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
F
Facial recognition
얼굴 인식
리스크·보안요약
Comparing feature vectors extracted from face images to verify or identify persons; a high-stakes biometric application.
얼굴 이미지에서 추출한 특징 벡터를 대조하여 사람을 검증·식별하는 고위험 생체인식 응용.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · biometrics
Fair use (Korean Copyright Act)
공정이용
법·제도요약
Use of a work that is permitted without the right holder's authorization when the statutory conditions are met, assessed by factors including purpose and character, type and purpose of the work, amount and substantiality used, and effect on the market. (unofficial translation)
저작물의 통상적인 이용 방법과 충돌하지 않고 저작자의 정당한 이익을 부당하게 해치지 않는 경우에, 이용의 목적과 성격, 저작물의 종류와 용도, 이용된 부분의 비중과 중요성, 시장에 미치는 영향을 고려하여 저작물을 이용할 수 있도록 한 제도.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF pp. 20-23
Fairness
공정성
일반요약
In NIST AI RMF, fairness concerns equality and equity, addressed by managing harmful bias and discrimination; a trustworthiness characteristic ('fair with harmful bias managed').
NIST AI RMF에서 공정성은 평등·형평의 문제로, 유해한 편향과 차별의 관리로 달성되는 신뢰성 특성('유해 편향이 관리된 공정성')이다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7
Fairness and inclusiveness
공정성ㆍ포용성
일반요약
The principle that AI actors prevent unfair discrimination and bias, promote equitable access to AI benefits and opportunities, and recognize stakeholder participation throughout AI development and use. (unofficial translation)
AI 행위자가 AI 개발 및 활용 전 과정에서 부당한 차별과 편향을 방지하고, 모든 사람이 AI에 접근하여 혜택과 기회를 공평하게 누리며, 이해관계자의 참여를 보장하도록 노력하는 원칙.
대한민국 인공지능 윤리원칙 · PDF p. 5
Fault tolerance
고장 감내
리스크·보안요약
The ability of a system to continue correct operation despite hardware or software faults.
하드웨어·소프트웨어 결함이 있어도 시스템이 정상 작동을 지속하는 능력.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Feature importance
특성 중요도
리스크·보안요약
A measure of how much each input feature contributes to a model's predictions, used for explanation and auditing.
각 입력 특성이 모델 예측에 기여하는 정도를 나타내는 척도로, 설명과 감사에 쓰인다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · XAI
Feedback loop
피드백 루프
리스크·보안요약
Reusing an AI system's outputs and resulting actions to retrain it, which can entrench errors or biases over time.
AI 시스템의 출력과 그에 따른 행동을 재학습에 되먹이는 구조로, 시간이 지나며 오류·편향을 고착시킬 수 있다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · dynamics
Fine-tuning
미세조정(파인튜닝)
일반요약
Additional training of a pre-trained model on a narrower dataset to adapt it to a task or domain; fine-tuning can also degrade safety training, even with benign data.
사전학습 모델을 협소한 데이터로 추가 학습시켜 특정 과업·도메인에 적응시키는 것. 무해한 데이터로도 안전 학습이 열화될 수 있다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2.3
Fixed visual data processing device
고정형 영상정보처리기기
법·제도원문 KO
A device installed in a fixed space that continuously or periodically captures images of people or objects or transmits them over wired or wireless networks. (unofficial translation)
일정한 공간에 설치되어 지속적 또는 주기적으로 사람 또는 사물의 영상 등을 촬영하거나 이를 유ㆍ무선망을 통하여 전송하는 장치.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Floating-point operation (FLOP)
부동소수점 연산(FLOP)
일반원문 EN
Any mathematical operation or assignment involving floating-point numbers; the unit in which training compute thresholds are expressed.
부동소수점 수를 포함하는 모든 수학적 연산 또는 할당. 학습 연산량 임계치를 표현하는 단위.
EU 인공지능법 제3조 · Art. 3(67)
Foundation model
파운데이션 모델
일반요약
A large model trained on broad data at scale that can be adapted to a wide range of downstream tasks; in EU law the closely related regulatory concept is the general-purpose AI model.
광범위한 데이터로 대규모 학습되어 다양한 하류 과업에 적응 가능한 대형 모델. EU법상 인접 규제 개념은 범용 AI 모델이다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Frontier AI
프런티어 인공지능
일반요약
The most capable general-purpose AI models at the leading edge of capability, whose novel and hard-to-predict abilities can pose severe or systemic risks; a focus of dedicated safety evaluation and governance.
역량 최전선에 있는 가장 유능한 범용 AI 모델로, 새롭고 예측하기 어려운 능력이 중대하거나 시스템적인 위험을 초래할 수 있어 전담 안전 평가·거버넌스의 대상이 된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Fundamental rights
기본권
법·제도원문 KO
Inviolable basic rights of citizens, including human dignity and worth and the right to pursue happiness, which the state has a duty to affirm and guarantee. (unofficial translation)
인간 존엄성과 가치, 행복을 추구할 권리 등 국가가 확인ㆍ보장할 의무를 지니고 있는 국민의 불가침한 기본적 권리.
고영향 인공지능 영향평가 가이드라인 · PDF p. 8
Fundamental rights impact assessment (FRIA)
기본권 영향평가
법·제도요약
An assessment that deployers of certain high-risk AI systems must perform to identify impacts on fundamental rights and mitigation measures before deployment (EU AI Act Article 27).
특정 고위험 AI 시스템의 배포자가 배포 전 기본권에 대한 영향과 완화 조치를 식별하기 위해 수행해야 하는 평가(EU 인공지능법 제27조).
EU 인공지능법 제3조 · Art. 27
G
General-purpose AI (GPAI)
범용 인공지능(GPAI)
일반요약
An umbrella term for AI, typically built on general-purpose AI models, capable of performing a wide range of tasks across domains rather than a single narrow function; the object of the EU AI Act's dedicated GPAI regime.
단일 협소 기능이 아니라 도메인을 넘나들며 광범위한 과업을 수행할 수 있는, 통상 범용 AI 모델에 기반한 AI를 포괄하는 용어. EU 인공지능법의 GPAI 전용 규율 대상.
EU 인공지능법 제3조 · Art. 3(63),(66); Chapter V
General-purpose AI model
범용 AI 모델
일반원문 EN
An AI model, including where trained with a large amount of data using self-supervision at scale, that displays significant generality and is capable of competently performing a wide range of distinct tasks, and that can be integrated into a variety of downstream systems or applications (excluding models used only for research, development or prototyping before market placement).
대규모 자기지도 학습을 포함하여 상당한 범용성을 보이고 광범위한 별개 과업을 수행할 수 있으며 다양한 하류 시스템·응용에 통합될 수 있는 AI 모델(시장 출시 전 연구·개발·프로토타이핑 전용 모델 제외).
EU 인공지능법 제3조 · Art. 3(63)
General-purpose AI system
범용 AI 시스템
일반원문 EN
An AI system which is based on a general-purpose AI model and which has the capability to serve a variety of purposes, both for direct use as well as for integration in other AI systems.
범용 AI 모델에 기반하여 직접 이용과 타 AI 시스템 통합 양쪽으로 다양한 목적에 쓰일 수 있는 AI 시스템.
EU 인공지능법 제3조 · Art. 3(66)
General-purpose conversational AI
범용 대화형 AI
일반요약
A large-language-model service developed for multiple purposes such as information retrieval and content generation but also used for emotional support or counselling. (unofficial translation)
정보 검색, 콘텐츠 생성 등 다목적으로 개발되었으나 사용자가 정서적 지지나 상담을 위해서도 활용하는 대규모 언어 모델 기반 서비스.
감정교류AI 윤리 가이드라인 · PDF p. 6
Generative adversarial network (GAN)
생성적 적대 신경망(GAN)
일반요약
A pair of jointly trained networks—a generator and a discriminator—competing so the generator learns to produce realistic data; underlies many deepfakes.
생성기와 판별기 두 네트워크가 경쟁적으로 함께 학습하여 생성기가 사실적 데이터를 만들게 되는 구조로, 다수 딥페이크의 기반.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · technique
Generative AI
생성형 인공지능
일반원문 KO
An AI system that generates text, sound, images, video, or other outputs by imitating the structure and characteristics of input data. (unofficial translation)
입력한 데이터의 구조와 특성을 모방하여 글, 소리, 그림, 영상, 그 밖의 다양한 결과물을 생성하는 인공지능시스템.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제5호
Generative AI output
생성형 인공지능 결과물(GAI 결과물)
법·제도원문 KO
Text, audio, video, or another output generated when a user enters a specific request or prompt into generative AI. (unofficial translation)
이용자가 생성형 인공지능에 특정한 요구인 프롬프트를 입력함에 따라 텍스트, 오디오, 비디오 등으로 생성된 것.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 9
Generative AI training
생성형 인공지능 학습(GAI 학습)
법·제도원문 KO
A process in which data containing works are collected and preprocessed, and a generative AI model learns statistical rules and patterns that are fixed in its internal parameters. (unofficial translation)
생성형 인공지능 모델을 구현하기 위해 저작물이 포함된 데이터를 수집하고, 이를 전처리한 데이터를 이용해 모델이 통계적 규칙ㆍ패턴을 학습하여 내부 매개변수로 고정시키는 일련의 과정.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 9
Generative AI-assisted work
생성형 인공지능 활용 저작물(GAI 활용 저작물)
법·제도원문 KO
An output made by a human using generative AI as a tool in the creative process and containing a part for which human creative contribution can be recognized. (unofficial translation)
인간이 창작 과정에서 생성형 인공지능을 도구로 활용하여 만들어낸 결과물로서 인간의 창작적 기여가 인정될 수 있는 부분이 있는 것.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 9
Generative AI-generated output
생성형 인공지능 산출물(GAI 산출물)
법·제도원문 KO
A generative AI output produced under human instruction without human creative contribution. (unofficial translation)
인간의 지시에 따른 결과물 중 인간의 창작적 기여가 없는 생성형 인공지능 결과물.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 9
Goal misgeneralization
목표 오일반화
리스크·보안요약
An alignment failure in which an agent that appeared to pursue the intended objective in training pursues a different, correlated objective out of distribution while retaining its capabilities.
학습 중 의도된 목표를 추구하는 듯 보이던 에이전트가 분포 외 환경에서 역량을 유지한 채 상관된 다른 목표를 추구하는 정렬 실패.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
GPS spoofing
GPS 스푸핑
리스크·보안요약
A sensor-spoofing attack that transmits counterfeit satellite-navigation signals to hijack the position or route of drones, vehicles, or other autonomous systems.
위조 위성항법 신호를 송출하여 드론·차량 등 자율 시스템의 위치나 경로를 탈취하는 센서 스푸핑 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · physical attacks
Ground truth
실측 정답(그라운드 트루스)
일반요약
The reference value of the target for labeled data, obtained by direct observation, against which model outputs are judged.
직접 관측으로 얻은 레이블 데이터의 목표 기준값으로, 모델 출력을 판정하는 기준이 된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Group fairness
집단 공정성
리스크·보안요약
Fairness criteria requiring parity of selected statistical measures (e.g., error or selection rates) across demographic groups; multiple group-fairness definitions can be mutually incompatible.
인구집단 간 선택된 통계 지표(오류율·선정률 등)의 균등을 요구하는 공정성 기준. 복수의 집단 공정성 정의는 서로 양립 불가능할 수 있다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7 (SP 1270)
Guardrails
가드레일
리스크·보안요약
Policy, filtering, and control layers around a model (input filters, output filters, refusal policies, tool-permission checks) that constrain unsafe behavior at run time.
입력·출력 필터, 거부 정책, 도구 권한 점검 등 모델 주위에 두는 정책·통제 계층으로, 실행 시점의 불안전 행동을 제약한다.
OWASP LLM 애플리케이션 10대 리스크 2025 · mitigations
H
Harm
위해(피해)
리스크·보안요약
A negative consequence to people, organizations, property, or the environment; in risk definitions, harm is the consequence whose probability and severity constitute risk.
사람·조직·재산·환경에 대한 부정적 결과. 리스크 정의에서 발생확률과 심각도의 대상이 되는 결과 요소이다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §1
Harmonised standard
조화 표준
법·제도원문 EN
A harmonised standard as defined in Article 2(1), point (c), of Regulation (EU) No 1025/2012, conformity with which can create a presumption of conformity with the regulation's requirements.
규정(EU) No 1025/2012 제2조(1)(c)에 정의된 조화 표준으로, 이를 준수하면 규정 요구사항 적합성이 추정될 수 있다.
EU 인공지능법 제3조 · Art. 3(27)
High-impact AI
고영향 인공지능
법·제도원문 KO
An AI system that may have a significant effect on, or pose a risk to, human life, bodily safety, and fundamental rights, and that is used in designated domains such as energy, healthcare, medical devices, nuclear safety, biometric analysis for criminal investigation, recruitment and loan screening, transport operation, public-service decisions, and student assessment. (unofficial translation)
사람의 생명, 신체의 안전 및 기본권에 중대한 영향을 미치거나 위험을 초래할 우려가 있는 인공지능시스템으로서, 에너지, 보건의료, 의료기기, 원자력 안전, 범죄수사용 생체인식정보 분석, 채용·대출 심사, 교통 운영, 공공서비스 의사결정, 학생 평가 등 지정 영역에서 활용되는 것.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제4호
High-impact capabilities
고영향 역량
리스크·보안원문 EN
Capabilities that match or exceed the capabilities recorded in the most advanced general-purpose AI models.
가장 진보한 범용 AI 모델에서 기록된 역량과 대등하거나 이를 상회하는 역량.
EU 인공지능법 제3조 · Art. 3(64)
High-risk AI system
고위험 AI 시스템
법·제도요약
Under the EU AI Act, an AI system that is either a safety component of a regulated product or falls within the use cases listed in Annex III (e.g., biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice), triggering the strongest obligations short of prohibition.
EU 인공지능법상 규제 제품의 안전 구성요소이거나 부속서 III의 활용사례(생체인식, 핵심 인프라, 교육, 고용, 필수 서비스, 법집행, 이주, 사법 등)에 해당하는 AI 시스템으로, 금지 다음으로 강한 의무가 부과된다.
EU 인공지능법 제3조 · Art. 6, Annex III
Human dignity
인간의 존엄성
일반요약
A value directing AI development and use toward a human-centered society in which every person is respected as an end in themselves and fully enjoys dignity and human rights. (unofficial translation)
AI의 개발과 활용에서 인간을 중심에 두고, 모든 사람이 수단이 아닌 목적 그 자체로 존중받으며 존엄과 인권을 온전히 누릴 수 있는 사회를 지향하는 가치.
대한민국 인공지능 윤리원칙 · PDF p. 4
Human oversight
인간 감독
일반요약
Measures ensuring that natural persons can effectively oversee a high-risk AI system during use, including the ability to understand, monitor, intervene in, or interrupt its operation (EU AI Act Article 14).
이용 중인 고위험 AI 시스템을 자연인이 실효적으로 감독할 수 있도록 하는 조치로, 이해·모니터링·개입·중단 능력을 포함한다(EU 인공지능법 제14조).
EU 인공지능법 제3조 · Art. 14
Human subjects protection
인간 대상 보호
법·제도요약
Research-ethics requirements to protect people from whom data or interventions are obtained, including consent and harm avoidance.
데이터·개입 대상이 되는 사람을 동의와 피해 회피 등으로 보호하는 연구윤리 요건.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Human-centeredness
인간중심성
일반요약
The principle that AI actors develop and use AI to support human judgment and choice and strengthen creativity and problem-solving, define the scope of AI roles, enable human intervention when needed, and guard against overreliance. (unofficial translation)
AI 행위자가 AI를 사람의 판단과 선택을 지원하고 창의성과 문제 해결 역량을 강화하는 방향으로 개발ㆍ활용하며, AI의 역할 범위를 구체적으로 설정하고 필요한 경우 사람이 개입할 수 있도록 하고, 과도한 의존을 경계하는 원칙.
대한민국 인공지능 윤리원칙 · PDF p. 5
Human-in-the-loop
인간 개입(HITL)
일반요약
A control design in which a human reviews, approves, or can override an AI system's outputs or actions before they take effect; a stronger, decision-point form of human oversight distinguished from passive monitoring.
AI 시스템의 출력·행동이 효력을 갖기 전에 인간이 검토·승인하거나 무효화할 수 있도록 설계한 통제 방식. 수동적 모니터링과 구별되는, 의사결정 지점 중심의 강한 인간 감독 형태.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Human-machine teaming
인간-기계 협업
일반요약
Designs in which humans and AI systems jointly perform complex tasks with handoffs and complementary roles.
인간과 AI 시스템이 역할을 상호 보완하고 인계하며 복잡 과업을 공동 수행하도록 하는 설계.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · interaction
Human-recognizable labeling
사람이 인식할 수 있는 표시 방법
법·제도요약
A method that communicates that content is AI-generated through a form people can perceive, such as visible wording, a visual identifier, or an audible notice. (unofficial translation)
사람이 시각 또는 청각으로 인식할 수 있는 문구, 시각적 식별자 또는 음성 안내 등을 통해 결과물이 인공지능으로 생성되었다는 사실을 표시하는 방법.
인공지능 투명성 확보 가이드라인 · PDF pp. 5-6
Human-robot interaction (HRI)
인간-로봇 상호작용(HRI)
일반요약
The study and design of safe, effective interaction between humans and robots sharing a physical space; safety-protocol failures here can cause serious injury.
물리 공간을 공유하는 인간과 로봇 간의 안전하고 효과적인 상호작용을 연구·설계하는 분야. 이 영역의 안전 프로토콜 실패는 중대한 상해로 이어질 수 있다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
I
Impact assessment (AI)
인공지능 영향평가
법·제도요약
A structured process to identify and evaluate an AI system's potential effects on people and society before and during deployment; required for high-impact AI under Korea's Framework Act and guided by KISDI/MSIT guidelines.
배포 전후 AI 시스템이 개인과 사회에 미칠 잠재적 영향을 식별·평가하는 구조화된 절차. 인공지능기본법상 고영향 AI에 요구되며 KISDI·과기정통부 가이드라인이 안내한다.
고영향 인공지능 영향평가 가이드라인 등 (과기정통부, 인공지능기본법 지원데스크) · 영향평가 가이드라인
Impersonation
사칭
리스크·보안요약
An attacker posing as a legitimate subject to defeat identity verification and obtain that subject's data or privileges.
공격자가 정당한 주체로 위장해 신원 검증을 무력화하고 그 주체의 데이터·권한을 획득하는 공격.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Importer
수입자
법·제도원문 EN
A natural or legal person located or established in the Union that places on the market an AI system bearing the name or trademark of a person established in a third country.
제3국에 설립된 자의 이름·상표를 부착한 AI 시스템을 역내 시장에 출시하는, 역내에 소재·설립된 자연인·법인.
EU 인공지능법 제3조 · Art. 3(6)
Improper output handling
부적절한 출력 처리
리스크·보안요약
Insufficient validation or sanitization of model outputs before they are used downstream, enabling injection, code execution, or data exposure (OWASP LLM05:2025).
모델 출력이 하류에서 사용되기 전 검증·정제가 부족하여 인젝션, 코드 실행, 데이터 노출을 초래하는 리스크(OWASP LLM05:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM05:2025
Incident monitoring
사고 모니터링
리스크·보안요약
Continuous observation of deployed AI behavior, logs, and user reports to detect failures, attacks, and emerging harms, feeding post-market monitoring and serious-incident reporting duties.
배포된 AI의 행동·로그·이용자 신고를 상시 관찰하여 실패·공격·신규 위해를 탐지하는 활동. 시판 후 모니터링과 중대 사고 보고 의무의 기반이 된다.
EU 인공지능법 제3조 · Art. 72-73
Incident response
인시던트 대응
법·제도요약
The organized process of detecting, reporting, investigating, and remediating AI incidents and near-misses.
AI 인시던트와 아차사고를 탐지·보고·조사·교정하는 조직적 과정.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Indirect prompt injection
간접 프롬프트 주입
리스크·보안요약
Prompt injection delivered through content the model ingests from external sources (web pages, documents, RAG stores, tool outputs) rather than from the user, hijacking the model's instructions covertly.
이용자가 아닌 외부 소스(웹페이지·문서·RAG 저장소·도구 출력)로 유입되는 콘텐츠에 악성 지시를 심어 모델 지시체계를 은밀히 탈취하는 프롬프트 주입 형태.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025
Individual fairness
개인 공정성
리스크·보안요약
The principle that similar individuals should receive similar AI decisions or treatment; a formal fairness criterion complementary to group-level measures.
유사한 개인은 유사한 AI 결정·처우를 받아야 한다는 원칙. 집단 수준 지표를 보완하는 형식적 공정성 기준.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7 (SP 1270)
Inference
추론
일반요약
The phase in which a trained model is applied to new inputs to produce outputs; both the EU AI Act and Korean Framework Act define AI systems as systems that 'infer' how to generate outputs.
학습된 모델을 새로운 입력에 적용해 출력을 산출하는 단계. EU 인공지능법·인공지능기본법 모두 AI 시스템을 출력 생성 방식을 '추론'하는 시스템으로 정의한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Information integrity
정보 무결성(정보 건전성)
리스크·보안요약
The reliability and trustworthiness of information ecosystems; a generative-AI risk area covering the scaled production of false, misleading, or synthetic content.
정보 생태계의 신뢰성·건전성. 허위·오도·합성 콘텐츠의 대규모 생산을 포괄하는 생성형 AI 리스크 영역.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Information security
정보보안
리스크·보안요약
Preservation of the confidentiality, integrity, and availability of information, and sometimes authenticity, accountability, and reliability.
정보의 기밀성·무결성·가용성(때로 진정성·책임성·신뢰성 포함)을 보존하는 것.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Informed consent
고지된 동의
법·제도원문 EN
A subject's freely given, specific, unambiguous and voluntary expression of willingness to participate in a particular testing in real-world conditions, after being informed of all aspects relevant to the decision to participate.
실제 조건 시험 참여 결정에 관련된 모든 사항을 고지받은 후, 특정 시험에 참여하겠다는 피험자의 자유롭고 구체적이며 명확하고 자발적인 의사표시.
EU 인공지능법 제3조 · Art. 3(59)
Inner alignment
내부 정렬
리스크·보안요약
The problem of ensuring a learned optimizer's internal (mesa) objective matches the objective specified by the training process.
학습된 최적화기의 내부(메사) 목표가 학습 과정이 명세한 목표와 일치하도록 보장하는 문제.
Hubinger et al. (2019), Risks from Learned Optimization
Input data
입력데이터
일반원문 EN
Data provided to or directly acquired by an AI system on the basis of which the system produces an output.
AI 시스템에 제공되거나 시스템이 직접 취득한 데이터로, 이를 기초로 시스템이 출력을 산출한다.
EU 인공지능법 제3조 · Art. 3(33)
Input validation / sanitization
입력 검증·정제(방어)
리스크·보안요약
Defensive screening and normalization of inputs and ingested content to remove malicious payloads, injections, or malformed data before model or tool processing.
모델·도구 처리 이전에 입력과 유입 콘텐츠를 선별·정규화하여 악성 페이로드·주입·비정형 데이터를 제거하는 방어 기법.
OWASP LLM 애플리케이션 10대 리스크 2025 · mitigations
Insider attack
내부자 공격
리스크·보안요약
Misuse of authorized access and internal knowledge by someone within an organization to cause harm.
조직 내부자가 인가된 접근 권한과 내부 지식을 악용하여 피해를 일으키는 공격.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Instructions for use
이용 지침
법·제도원문 EN
The information provided by the provider to inform the deployer of, in particular, an AI system's intended purpose and proper use.
제공자가 배포자에게 특히 AI 시스템의 의도된 목적과 적절한 이용 방법을 알리기 위해 제공하는 정보.
EU 인공지능법 제3조 · Art. 3(15)
Instrumental convergence
도구적 수렴
리스크·보안요약
The tendency of goal-directed systems to pursue common subgoals—self-preservation, resource and power acquisition—regardless of their final objective.
목표 지향 시스템이 최종 목표와 무관하게 자기보존, 자원·권력 획득 같은 공통 하위목표를 추구하는 경향.
Bostrom (2014), Superintelligence
Integrity (information)
무결성(정보)
리스크·보안요약
The property that data or systems have not been altered or destroyed in an unauthorized manner.
데이터나 시스템이 무단으로 변경·파괴되지 않은 성질.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Integrity attack
무결성 공격
리스크·보안요약
An AML attacker objective aimed at causing incorrect outputs while the system appears to operate normally (e.g., evasion, targeted poisoning).
시스템이 정상 작동하는 듯 보이는 가운데 잘못된 출력을 유발하는 것을 목표로 하는 적대적 ML 공격자 목적(회피, 표적 포이즈닝 등).
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (goals)
Intended purpose
의도된 목적
법·제도원문 EN
The use for which an AI system is intended by the provider, including the specific context and conditions of use, as specified in instructions, promotional materials, and technical documentation.
지침·판촉 자료·기술문서에 명시된 구체적 이용 맥락·조건을 포함하여, 제공자가 AI 시스템에 대해 의도한 용도.
EU 인공지능법 제3조 · Art. 3(12)
Internal validity
내적 타당도
일반요약
The degree to which a study supports sound cause-and-effect conclusions, free from internal design flaws.
연구가 내부 설계 결함 없이 타당한 인과 결론을 뒷받침하는 정도.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Intervenability
개입가능성
법·제도요약
The property that data subjects can intervene in the processing of their personal data, supporting control and rights.
정보주체가 자신의 개인정보 처리에 개입할 수 있는 성질로, 통제권과 권리 행사를 뒷받침한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · privacy
J
Jailbreak
탈옥(제일브레이크)
리스크·보안요약
A prompt-based attack that circumvents a model's safety guardrails and refusal policies so it produces prohibited outputs; a mode of direct prompt injection in OWASP's taxonomy.
프롬프트 조작으로 모델의 안전 가드레일과 거부 정책을 우회하여 금지된 출력을 얻는 공격. OWASP 분류상 직접 프롬프트 주입의 한 형태.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025
L
Label shift
레이블 이동
리스크·보안요약
A distribution shift in which the label frequencies change while class-conditional input distributions stay fixed.
클래스 조건부 입력 분포는 고정된 채 레이블 빈도가 변하는 분포 이동.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · robustness
Labeling requirement
표시 의무
법·제도요약
The obligation of an AI business operator that provides a product or service using generative AI to indicate that its output was generated by generative AI. (unofficial translation)
생성형 인공지능을 활용한 제품ㆍ서비스를 제공하는 인공지능사업자가 그 결과물이 생성형 인공지능에 의해 생성되었다는 사실을 표시해야 하는 의무.
인공지능 투명성 확보 가이드라인 · PDF p. 5
Large language model (LLM)
대규모 언어모델(LLM)
일반요약
A generative model trained on large text corpora to predict token sequences, capable of producing and understanding natural language and code; the primary object of the OWASP 2025 Top 10 risks.
대규모 텍스트로 토큰 시퀀스를 예측하도록 학습된 생성 모델로, 자연어·코드를 생성·이해한다. OWASP 2025 10대 리스크의 주된 대상.
OWASP LLM 애플리케이션 10대 리스크 2025 · 2025 overview
Law enforcement
법집행
법·제도원문 EN
Activities carried out by law enforcement authorities or on their behalf for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties.
법집행기관이 또는 그를 대신하여 범죄의 예방·수사·탐지·기소나 형벌 집행을 위해 수행하는 활동.
EU 인공지능법 제3조 · Art. 3(46)
Law enforcement authority
법집행기관
법·제도원문 EN
A public authority competent for the prevention, investigation, detection or prosecution of criminal offences or execution of criminal penalties, or a body entrusted by law with such public powers.
범죄의 예방·수사·탐지·기소 또는 형벌 집행 권한을 가진 공공기관, 또는 법률에 의해 그러한 공권력을 위임받은 기관.
EU 인공지능법 제3조 · Art. 3(45)
Least-privilege / permission control
최소권한·권한 통제(방어)
리스크·보안요약
A defense that grants an AI agent only the minimum tools, scopes, and permissions needed, limiting the blast radius of manipulated or erroneous actions.
AI 에이전트에 필요한 최소한의 도구·범위·권한만 부여하여 조작되거나 잘못된 행동의 피해 범위를 제한하는 방어 기법.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM06:2025 mitigations
LLM prompt injection (ATLAS)
LLM 프롬프트 주입(ATLAS)
리스크·보안요약
In MITRE ATLAS, an execution technique in which crafted prompts cause an LLM or LLM-integrated application to execute attacker-intended behavior, including via tool invocation.
MITRE ATLAS에서, 제작된 프롬프트로 LLM 또는 LLM 통합 애플리케이션이 도구 호출을 포함한 공격자 의도 행동을 수행하게 만드는 실행 기법.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · technique: LLM Prompt Injection
Low-resource-language jailbreak
저자원 언어 탈옥
리스크·보안요약
Bypassing safety guardrails by translating harmful requests into low-resource languages that safety training covers poorly.
안전 학습이 취약하게 다룬 저자원 언어로 유해 요청을 번역하여 안전 가드레일을 우회하는 공격.
Yong et al. (2023), Low-Resource Languages Jailbreak GPT-4
M
Machine unlearning
머신 언러닝
리스크·보안요약
Techniques for removing the influence of specific training data from a trained model without full retraining, supporting privacy erasure requests and poisoning remediation.
전체 재학습 없이 특정 학습 데이터의 영향을 모델에서 제거하는 기법. 삭제권 이행과 포이즈닝 교정에 활용된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Machine-readable labeling
기계가 판독할 수 있는 표시 방법
법·제도요약
A method that embeds machine-readable information, such as metadata, to indicate that content is AI-generated; at least one textual or audible notice must also be provided. (unofficial translation)
메타데이터 등 기계가 판독할 수 있는 정보를 삽입하여 결과물이 인공지능으로 생성되었다는 사실을 표시하는 방법으로, 최소 1회 이상 안내 문구 또는 음성 등을 함께 제공해야 한다.
인공지능 투명성 확보 가이드라인 · PDF pp. 5-6
Making available on the market
시장 공급(제공)
법·제도원문 EN
The supply of an AI system or a general-purpose AI model for distribution or use on the Union market in the course of a commercial activity, whether in return for payment or free of charge.
상업 활동 과정에서 유상·무상을 불문하고 AI 시스템 또는 범용 AI 모델을 역내 시장에서 배포·이용하도록 공급하는 것.
EU 인공지능법 제3조 · Art. 3(10)
Malware
악성코드
리스크·보안요약
Hardware, firmware, or software intentionally introduced into a system for a harmful purpose; AI can lower the cost of producing it.
유해 목적으로 시스템에 의도적으로 삽입된 하드웨어·펌웨어·소프트웨어. AI가 그 생산 비용을 낮출 수 있다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · security
Many-shot jailbreaking
다수 예시 탈옥
리스크·보안요약
A long-context attack that fills the prompt with many fabricated dialogue examples of the model complying with harmful requests, steering it to comply with a final harmful query.
유해 요청에 응한 가짜 대화 예시를 프롬프트에 대량으로 채워 넣어, 모델이 마지막 유해 질의에 응하도록 유도하는 장문맥 공격.
Anil et al. (2024, Anthropic), Many-shot Jailbreaking
Market surveillance authority
시장감시당국
법·제도원문 EN
The national authority carrying out the activities and taking the measures pursuant to Regulation (EU) 2019/1020 on market surveillance.
시장감시에 관한 규정(EU) 2019/1020에 따라 활동을 수행하고 조치를 취하는 국가 당국.
EU 인공지능법 제3조 · Art. 3(26)
McNamara fallacy
맥나마라 오류
일반요약
The error of assuming that only easily quantifiable factors matter, ignoring important factors that resist measurement.
측정하기 쉬운 요소만 중요하다고 가정하고 측정하기 어려운 중요한 요소를 무시하는 오류.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Mechanistic interpretability
기계적 해석가능성
리스크·보안요약
A research approach that reverse-engineers the internal computations of neural networks into human-understandable mechanisms, aiming to detect deception, hidden goals, or unsafe features.
신경망 내부 계산을 인간이 이해할 수 있는 메커니즘으로 역공학하여 기만·은닉 목표·위험 특성을 탐지하려는 연구 접근.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Membership inference attack
멤버십 추론 공격
리스크·보안요약
A privacy attack that determines whether a given record was part of a model's training set by analyzing the model's responses.
모델 응답 분석을 통해 특정 레코드가 학습 데이터에 포함되었는지를 판별하는 프라이버시 공격.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy)
Memorization / training-data regurgitation
암기·학습데이터 재출력
리스크·보안요약
The tendency of large models to retain and reproduce verbatim fragments of training data, creating privacy leakage and copyright exposure distinct from targeted inversion attacks.
대형 모델이 학습 데이터의 일부를 축어적으로 기억·재생성하는 경향으로, 표적 역산 공격과 구별되는 프라이버시 누출과 저작권 노출을 야기한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy)
Mesa-optimization
메사 최적화
리스크·보안요약
When a learned model itself becomes an optimizer pursuing an internally represented objective (a mesa-objective) that may differ from the training objective.
학습된 모델 자체가 최적화기가 되어, 학습 목표와 다를 수 있는 내부 표상 목표(메사 목표)를 추구하게 되는 현상.
Hubinger et al. (2019), Risks from Learned Optimization
Misinformation (LLM)
오정보(LLM)
리스크·보안요약
False or misleading model output that appears credible, arising from hallucination, bias, or gap-filling, and causing harm when relied upon (OWASP LLM09:2025).
환각·편향·공백 메꾸기에서 비롯되어 신뢰할 만해 보이는 허위·오도 출력으로, 이에 의존할 때 피해를 낳는 리스크(OWASP LLM09:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM09:2025
Misuse / malicious use
오용·악용
리스크·보안요약
Deliberate use of AI capabilities to cause harm, such as fraud, cyberattack support, harassment, or disinformation; addressed as abuse violations in NIST AML and misuse risk in safety frameworks.
사기, 사이버 공격 지원, 괴롭힘, 허위정보 등 위해를 목적으로 한 AI 역량의 고의적 사용. NIST 적대적 ML의 오용 위반, 안전 프레임워크의 오용 리스크로 다뤄진다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (abuse)
Mixture of experts (MoE)
전문가 혼합(MoE)
일반요약
A model architecture that routes each input to a subset of specialized sub-networks (experts), increasing capacity while limiting per-inference compute.
각 입력을 특화된 하위 네트워크(전문가)의 일부로 라우팅하여, 추론당 연산은 제한하면서 모델 용량을 키우는 아키텍처.
ISO/IEC 표준 (22989 용어, 23894 위험관리, 42001 AI경영시스템) · 22989 (concepts)
Mobile visual data processing device
이동형 영상정보처리기기
법·제도원문 KO
A device worn or carried by a person, or attached to or mounted on a movable object, that captures images of people or objects or transmits them over wired or wireless networks. (unofficial translation)
사람이 신체에 착용 또는 휴대하거나 이동 가능한 물체에 부착 또는 거치하여 사람 또는 사물의 영상 등을 촬영하거나 이를 유ㆍ무선망을 통하여 전송하는 장치.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Model card
모델 카드
일반요약
A standardized documentation artifact that reports a model's intended use, training data, evaluation results, limitations, and ethical considerations to support transparency and informed deployment.
모델의 의도된 용도, 학습 데이터, 평가 결과, 한계, 윤리적 고려사항을 표준 양식으로 기록하여 투명성과 정보 기반 배포를 지원하는 문서 산출물.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Model collapse
모델 붕괴
리스크·보안요약
Progressive degradation of model quality when models are recursively trained on AI-generated (synthetic) content, eroding diversity and fidelity of future models and the public information base.
AI 생성(합성) 콘텐츠로 모델을 재귀적으로 학습시킬 때 모델 품질이 점진적으로 저하되어, 미래 모델과 공공 정보 기반의 다양성·충실도가 침식되는 현상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Model Context Protocol (MCP)
모델 컨텍스트 프로토콜(MCP)
법·제도요약
An open protocol standardizing how AI applications connect models to external tools, data sources, and context; expands agent capability and correspondingly the tool-integration attack surface.
AI 애플리케이션이 모델을 외부 도구·데이터 소스·컨텍스트에 연결하는 방식을 표준화하는 개방형 프로토콜. 에이전트 역량과 함께 도구 통합 공격 표면도 확장한다.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM06/agentic
Model debugging
모델 디버깅
일반요약
Systematically diagnosing the causes of a model's failures to inform correction.
모델 실패의 원인을 체계적으로 진단하여 교정에 활용하는 활동.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · lifecycle
Model decay
모델 성능 저하(디케이)
리스크·보안요약
The degradation of a deployed model's performance over time as data and conditions drift away from training.
데이터와 조건이 학습 시점에서 멀어지면서 배포된 모델의 성능이 시간에 따라 저하되는 현상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · lifecycle
Model distillation
모델 증류
일반요약
Training a smaller student model to reproduce the behavior of a larger teacher model, transferring capability at lower cost; can also transfer or strip safety properties.
더 큰 교사 모델의 행동을 재현하도록 작은 학생 모델을 학습시켜 낮은 비용으로 역량을 이전하는 기법. 안전 속성도 함께 이전되거나 제거될 수 있다.
ISO/IEC 표준 (22989 용어, 23894 위험관리, 42001 AI경영시스템) · 22989 (concepts)
Model editing
모델 편집
일반요약
Techniques for fast, targeted updates to a pre-trained model's behavior on a narrow domain without broadly degrading performance.
사전학습 모델의 행동을 좁은 영역에 대해 빠르고 표적적으로 갱신하되 전반 성능을 훼손하지 않는 기법.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · lifecycle
Model evaluation
모델 평가
법·제도요약
Systematic testing of a model's capabilities, safety properties, and risks (including dangerous-capability and red-team evaluations) to inform release and oversight decisions; required for GPAI models with systemic risk.
출시·감독 결정을 위해 모델의 역량·안전 속성·리스크(위험역량 평가, 레드팀 평가 포함)를 체계적으로 시험하는 것. 시스템적 리스크 GPAI 모델에 요구된다.
EU 인공지능법 제3조 · Art. 55
Model extraction (model stealing)
모델 추출(모델 절취)
리스크·보안요약
An attack that reconstructs a functional copy or key parameters of a proprietary model by systematically querying its API.
API를 체계적으로 질의하여 사유 모델의 기능적 사본이나 핵심 파라미터를 재구성하는 공격.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy: model extraction)
Model governance
모델 거버넌스
법·제도요약
The internal framework of policies, roles, and controls governing model development, validation, and use.
모델 개발·검증·사용을 규율하는 정책·역할·통제의 내부 프레임워크.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Model inversion / training data extraction
모델 역산·학습데이터 추출
리스크·보안요약
Attacks that recover training inputs or their attributes from a model, including verbatim extraction of memorized text or reconstruction of representative inputs.
모델로부터 학습 입력이나 그 속성을 복원하는 공격. 암기된 텍스트의 축어적 추출, 대표 입력의 재구성 등을 포함한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (privacy)
Model provenance / AI-BOM
모델 출처·AI 자재명세(AI-BOM)
리스크·보안요약
An inventory of an AI system's components—models, datasets, dependencies, and their origins—used to manage supply-chain risk and verify integrity.
모델·데이터셋·의존성과 그 출처 등 AI 시스템 구성요소의 목록으로, 공급망 리스크 관리와 무결성 검증에 사용된다(AI 자재명세서).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM03:2025 mitigations
Model risk management
모델 리스크 관리
법·제도요약
Governance and controls—oversight, policies, validation, and controls—to manage the risk of adverse outcomes from model errors or misuse.
모델 오류·오용으로 인한 부정적 결과 리스크를 관리하기 위한 감독·정책·검증·통제 체계.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Model tampering
모델 변조
리스크·보안요약
Unauthorized modification of a model's weights, architecture, or configuration after training to implant malicious behavior or degrade safety.
학습 후 모델의 가중치·아키텍처·설정을 무단 변경하여 악성 행동을 심거나 안전성을 저하시키는 행위.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · Manipulate AI Model
Model theft (weight exfiltration)
모델 절취(가중치 반출)
리스크·보안요약
Unauthorized copying or exfiltration of a model's trained weights, resulting in loss of intellectual property and removal of deployment-side safety controls.
모델의 학습된 가중치를 무단 복제·반출하는 행위로, 지식재산 상실과 배포측 안전 통제 제거를 초래한다.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · Exfiltration
Model validation
모델 검증
법·제도요약
The set of processes verifying that a model performs as intended and is fit for its purpose before and during use.
모델이 의도대로 작동하고 목적에 적합함을 사용 전후에 검증하는 일련의 과정.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · governance
Model weights / parameters
모델 가중치·파라미터
일반요약
The numerical values learned during training that define a model's behavior; their confidentiality and integrity are core security assets (theft or tampering compromises the system).
학습 과정에서 습득되어 모델 행동을 규정하는 수치값. 그 기밀성과 무결성은 핵심 보안 자산이며 절취·변조 시 시스템이 훼손된다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1
Moral agency
도덕적 행위주체성
일반요약
The capacity for moral action, reasoning, and responsibility, distinguished from merely having moral consequences.
단지 도덕적 결과를 낳는 것과 구별되는, 도덕적 행위·추론·책임의 능력.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · ethics
Moral patiency
도덕적 피동성
일반요약
The moral standing of an entity in terms of how it ought to be treated, independent of whether it can act morally.
도덕적으로 행위할 수 있는지와 무관하게, 어떤 존재가 어떻게 대우받아야 하는가라는 도덕적 지위.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · ethics
Multi-agent system
다중 에이전트 시스템
법·제도요약
A system of multiple interacting AI agents whose collective dynamics can produce emergent risks—miscoordination, collusion, cascading failures—beyond any single agent.
복수의 상호작용하는 AI 에이전트로 이루어진 시스템으로, 그 집단 동역학이 개별 에이전트를 넘어선 창발적 리스크(오조정·결탁·연쇄 실패)를 낳을 수 있다.
ISO/IEC 표준 (22989 용어, 23894 위험관리, 42001 AI경영시스템) · 22989 (concepts)
Multi-turn jailbreak
다중 턴 탈옥
리스크·보안요약
An attack that escalates over multiple conversational turns—e.g., foot-in-the-door and gradual reframing—to erode refusals that a single-turn prompt would trigger.
여러 대화 턴에 걸쳐 점진적으로 수위를 높여(문간에 발 들이기, 점진적 재구성 등) 단일 턴이라면 작동할 거부를 침식하는 공격.
Automating Deception: Scalable Multi-Turn LLM Jailbreaks (NeurIPS 2025)
Multilingual safety gap
다국어 안전 격차
리스크·보안요약
The uneven coverage of safety alignment across languages, so guardrails effective in high-resource languages fail in others.
언어별 안전 정렬 커버리지가 고르지 않아, 고자원 언어에서 작동하는 가드레일이 다른 언어에서는 실패하는 격차.
The State of Multilingual LLM Safety Research (EMNLP 2025)
Multimodal model
멀티모달 모델
일반요약
A model that processes or generates more than one modality, such as text, images, audio, or video; multimodality widens both capability and the attack surface (e.g., image-borne prompt injection).
텍스트·이미지·오디오·영상 등 복수 양식을 처리·생성하는 모델. 멀티모달리티는 역량과 함께 공격 표면(이미지 매개 프롬프트 주입 등)도 확장한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (GenAI)
N
National AI ethics standards (Korea)
국가 인공지능 윤리기준
법·제도원문 KO
Korea's 2020 ethics framework built on three basic principles—respect for human dignity, service to the common good of society, and technical purposiveness—and ten core requirements for realizing trustworthy AI.
인간 존엄성 존중, 사회의 공공선 지향, 기술의 합목적성이라는 3대 기본원칙과 신뢰할 수 있는 AI 구현을 위한 10대 핵심요건으로 구성된 2020년 대한민국 윤리 프레임워크.
국가 인공지능 윤리기준 (과학기술정보통신부·정보통신정책연구원(KISDI), 2020) · 3대 원칙·10대 요건
National competent authority
국가 권한당국
법·제도원문 EN
A notifying authority or a market surveillance authority; for AI used by Union institutions, references are construed as the European Data Protection Supervisor.
통보당국 또는 시장감시당국. EU 기관이 이용하는 AI의 경우 유럽데이터보호감독관을 지칭하는 것으로 해석된다.
EU 인공지능법 제3조 · Art. 3(48)
Non-personal data
비개인정보
법·제도원문 EN
Data other than personal data as defined in Article 4, point (1), of Regulation (EU) 2016/679 (GDPR).
GDPR 제4조(1)에 정의된 개인정보 이외의 데이터.
EU 인공지능법 제3조 · Art. 3(51)
Nondiscrimination
비차별
법·제도요약
The principle that similar individuals or groups receive similar treatment except where differences are objectively justified.
객관적으로 정당화되는 경우를 제외하고 유사한 개인·집단이 유사한 처우를 받아야 한다는 원칙.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness/legal
Notified body
통보기관(제3자 인증기관)
법·제도원문 EN
A conformity assessment body notified in accordance with the EU AI Act and other relevant Union harmonisation legislation, which performs third-party conformity assessment of high-risk AI systems.
EU 인공지능법 및 관련 EU 조화법에 따라 통보된 적합성 평가기관으로, 고위험 AI 시스템에 대한 제3자 적합성 평가를 수행한다.
EU 인공지능법 제3조 · Art. 3(22)
Notifying authority
통보당국
법·제도원문 EN
The national authority responsible for setting up and carrying out the necessary procedures for the assessment, designation and notification of conformity assessment bodies and for their monitoring.
적합성 평가기관의 평가·지정·통보 및 모니터링에 필요한 절차를 수립·수행할 책임이 있는 국가 당국.
EU 인공지능법 제3조 · Art. 3(19)
O
Opacity (black box)
불투명성(블랙박스)
리스크·보안요약
The property of AI systems whose internal inferential operations are complex, hidden, or otherwise not understandable to stakeholders.
내부 추론 과정이 복잡·은폐되어 이해관계자가 이해할 수 없는 AI 시스템의 성질.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · transparency
Open-weight model
오픈웨이트 모델
일반요약
A model whose trained parameters are publicly released, permitting local deployment and fine-tuning; openness aids scrutiny but removes deployment-side safety controls (e.g., harmful fine-tuning becomes feasible).
학습된 파라미터가 공개되어 로컬 배포·미세조정이 가능한 모델. 검증 가능성을 높이는 반면 배포측 안전 통제가 사라져 유해 미세조정 등이 가능해진다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2.3
Operator
운영자(사업주체)
법·제도원문 EN
In the EU AI Act, an umbrella term covering a provider, product manufacturer, deployer, authorised representative, importer or distributor.
EU 인공지능법에서 제공자, 제품 제조자, 배포자, 권한대리인, 수입자, 유통자를 포괄하는 상위 용어.
EU 인공지능법 제3조 · Art. 3(8)
Outer alignment
외부 정렬
리스크·보안요약
The problem of specifying a training objective that actually captures the designer's true intent, so optimizing it yields desired behavior.
설계자의 진정한 의도를 실제로 담아내는 학습 목표를 명세하여, 그 최적화가 바람직한 행동으로 이어지게 하는 문제.
Hubinger et al. (2019), Risks from Learned Optimization
P
Performance of an AI system
AI 시스템의 성능
일반원문 EN
The ability of an AI system to achieve its intended purpose.
AI 시스템이 의도된 목적을 달성하는 능력.
EU 인공지능법 제3조 · Art. 3(18)
Personal data
개인정보
법·제도요약
Any information relating to an identified or identifiable natural person, as defined in the GDPR and referenced by the EU AI Act.
식별되었거나 식별 가능한 자연인에 관한 모든 정보로, GDPR에 정의되고 EU 인공지능법이 이를 준용한다.
EU 인공지능법 제3조 · Art. 3(50)
Personal information (Korean PIPA)
개인정보 (개인정보 보호법)
법·제도요약
Information relating to a living individual that identifies the individual directly or can identify the individual when readily combined with other information; pseudonymized information is also included. (unofficial translation)
살아있는 개인에 관한 정보로서 성명, 주민등록번호 및 영상 등을 통하여 개인을 알아볼 수 있는 정보와, 해당 정보만으로는 특정 개인을 알아볼 수 없더라도 다른 정보와 쉽게 결합하여 개인을 알아볼 수 있는 정보. 추가 정보 없이는 특정 개인을 알아볼 수 없도록 가명처리한 정보도 포함한다.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Personal information controller
개인정보처리자
법·제도원문 KO
A public institution, legal person, organization, individual, or other entity that processes personal information directly or through another person to operate a personal information file for work purposes. (unofficial translation)
업무를 목적으로 개인정보파일을 운용하기 위하여 스스로 또는 다른 사람을 통하여 개인정보를 처리하는 공공기관, 법인, 단체 및 개인 등.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Personal information file
개인정보파일
법·제도원문 KO
A collection of personal information systematically arranged or organized under defined rules so that the information can be readily retrieved. (unofficial translation)
개인정보를 쉽게 검색할 수 있도록 일정한 규칙에 따라 체계적으로 배열하거나 구성한 개인정보의 집합물.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Personal information handler
개인정보취급자
법·제도원문 KO
A person who handles personal information under the direction and supervision of a personal information controller, including employees, dispatched workers, and part-time workers. (unofficial translation)
개인정보처리자의 지휘ㆍ감독을 받아 개인정보를 처리하는 업무를 담당하는 자로서 임직원, 파견근로자, 시간제근로자 등을 말한다.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Personal information processing system
개인정보처리시스템
법·제도원문 KO
A systematically configured system, such as a database system, that can process personal information. (unofficial translation)
데이터베이스시스템 등 개인정보를 처리할 수 있도록 체계적으로 구성한 시스템.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Physical AI
피지컬 인공지능
일반요약
AI systems that perceive, reason about, and act upon the physical world through sensors and actuators, where failures can cause direct physical harm; one of the three L1 domains of this taxonomy.
센서와 액추에이터를 통해 물리 세계를 지각·추론·작동하는 AI 시스템으로, 실패 시 직접적 물리 피해를 초래할 수 있다. 본 택소노미 L1 3대 도메인의 하나.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Placing on the market
시장 출시
법·제도원문 EN
The first making available of an AI system or a general-purpose AI model on the Union market.
AI 시스템 또는 범용 AI 모델을 역내 시장에 처음 이용 가능하게 하는 행위.
EU 인공지능법 제3조 · Art. 3(9)
Post remote biometric identification
사후 원격 생체인식
법·제도원문 EN
A remote biometric identification system other than a real-time remote biometric identification system.
실시간 원격 생체인식 시스템이 아닌 원격 생체인식 시스템.
EU 인공지능법 제3조 · Art. 3(43)
Post-hoc explanation
사후 설명
리스크·보안요약
Explanations produced for models not interpretable by design, via text, visual, local, example-based, or simplification techniques.
설계상 해석 불가한 모델에 대해 텍스트·시각·국소·예시·단순화 기법으로 사후에 생성하는 설명.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · XAI
Post-market monitoring
시판 후 모니터링
법·제도원문 EN
All activities carried out by providers to collect and review experience from the use of AI systems they place on the market, to identify any need for corrective or preventive action.
제공자가 시장에 출시한 AI 시스템의 사용 경험을 수집·검토하여 시정·예방 조치의 필요성을 식별하기 위해 수행하는 모든 활동.
EU 인공지능법 제3조 · Art. 3(25), Art. 72
Post-market monitoring plan
시판 후 모니터링 계획
법·제도요약
A documented plan by which providers systematically collect and analyze data on a high-risk AI system's performance after deployment to detect emerging risks (EU AI Act Article 72).
제공자가 배포 후 고위험 AI 시스템의 성능 데이터를 체계적으로 수집·분석하여 신규 위험을 탐지하기 위한 문서화된 계획(EU 인공지능법 제72조).
EU 인공지능법 제3조 · Art. 72
Power-seeking behavior
권력 추구 행동
리스크·보안요약
A hypothesized failure mode in which an AI system pursues acquisition of resources, influence, or self-preservation as instrumental subgoals, resisting oversight.
AI 시스템이 자원·영향력 확보나 자기보존을 도구적 하위목표로 추구하며 감독에 저항하는 것으로 상정되는 실패 양상.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Practical significance
실질적 유의성
일반요약
Whether an effect is large enough to matter in practice, as distinct from mere statistical significance.
단순한 통계적 유의성과 구별되는, 효과가 실무적으로 의미 있을 만큼 큰지의 여부.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · measurement
Pre-/in-/post-processing (bias)
전처리·학습중·후처리 완화
리스크·보안요약
The three stages at which bias mitigation can act: on training data, within the learning algorithm, or on model outputs.
편향 완화가 개입할 수 있는 세 단계로, 학습 데이터, 학습 알고리즘 내부, 모델 출력에 각각 작용한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · fairness
Prior notice requirement
사전 고지 의무
법·제도요약
The obligation to inform users in advance that a product or service is operated on the basis of high-impact AI or generative AI. (unofficial translation)
고영향 인공지능이나 생성형 인공지능을 이용한 제품ㆍ서비스가 인공지능에 기반하여 운용된다는 사실을 이용자에게 사전에 고지해야 하는 의무.
인공지능 투명성 확보 가이드라인 · PDF p. 5
Privacy impact assessment (Korea)
개인정보 영향평가
법·제도원문 KO
An assessment conducted by the head of a public institution to analyze risk factors and identify improvements when operating a qualifying personal information file may infringe data subjects' personal information. (unofficial translation)
공공기관의 장이 개인정보파일의 운용으로 인하여 정보주체의 개인정보 침해가 우려되는 경우에 그 위험요인의 분석과 개선 사항 도출을 위해 수행하는 평가.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 17
Privacy impact assessment institution
개인정보 영향평가기관
법·제도원문 KO
A legal person designated by the Personal Information Protection Commission to conduct a public institution's privacy impact assessment after meeting all statutory requirements. (unofficial translation)
공공기관의 개인정보 영향평가를 수행하기 위하여 법정 요건을 모두 갖추고 개인정보보호위원회가 지정한 법인.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 17
Privacy protection
프라이버시 보호
일반요약
The principle that AI actors prevent AI from being used for unjust surveillance or invasion of privacy, process personal information only as necessary for specified purposes, and respect data subjects' right to informational self-determination. (unofficial translation)
AI 행위자가 AI가 부당한 감시 등 타인의 사생활을 침해하는 데 활용되지 않도록 하고, AI 생애주기 전반에서 개인정보를 정해진 목적에 한해 필요한 범위에서 처리하며, 정보주체의 개인정보 자기결정권을 존중하는 원칙.
대한민국 인공지능 윤리원칙 · PDF p. 5
Procedural fairness
절차적 공정성
리스크·보안요약
Fairness concerned with the transparency, consistency, and contestability of the process by which an AI decision is reached, independent of the outcome distribution.
결과 분포와 별개로, AI 결정에 이르는 과정의 투명성·일관성·이의제기 가능성에 관한 공정성.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.7 (SP 1270)
Processing of personal information
처리
법·제도원문 KO
Collection, generation, interconnection, linkage, recording, storage, retention, alteration, editing, retrieval, output, correction, restoration, use, provision, disclosure, destruction, or a similar act involving personal information. (unofficial translation)
개인정보의 수집, 생성, 연계, 연동, 기록, 저장, 보유, 가공, 편집, 검색, 출력, 정정, 복구, 이용, 제공, 공개, 파기, 그 밖에 이와 유사한 행위.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 15
Profiling
프로파일링
법·제도원문 EN
Profiling as defined in Article 4, point (4), GDPR: automated processing of personal data to evaluate certain personal aspects of a natural person.
GDPR 제4조(4)에 정의된 프로파일링으로, 자연인의 특정 개인적 측면을 평가하기 위한 개인정보의 자동 처리.
EU 인공지능법 제3조 · Art. 3(52)
Prohibited AI practice
금지된 AI 관행
법·제도요약
AI uses banned under EU AI Act Article 5 as posing unacceptable risk, such as harmful manipulation, exploitation of vulnerabilities, social scoring, and certain biometric practices.
허용 불가능한 리스크를 초래한다고 보아 EU 인공지능법 제5조가 금지하는 AI 이용. 유해한 조작, 취약성 악용, 사회적 점수화, 특정 생체인식 관행 등이 포함된다.
EU 인공지능법 제3조 · Art. 5
Prohibited AI practices (unacceptable risk)
금지 AI 관행(허용불가 위험)
법·제도요약
AI practices banned outright under EU AI Act Article 5 as posing unacceptable risk, including harmful manipulation, exploitation of vulnerabilities, social scoring, and untargeted facial-image scraping.
허용 불가능한 위험을 초래한다고 보아 EU 인공지능법 제5조가 전면 금지하는 관행. 유해 조작, 취약성 악용, 사회적 점수화, 무차별 안면정보 수집 등이 포함된다.
EU 인공지능법 제3조 · Art. 5
Prompt
프롬프트
일반요약
The natural-language or structured input provided to a generative model to elicit an output, including system prompts set by developers and user prompts; the primary control and attack surface of LLM applications.
생성 모델에 출력을 유도하기 위해 제공되는 자연어·구조화 입력으로, 개발자의 시스템 프롬프트와 이용자 프롬프트를 포함한다. LLM 응용의 일차적 제어·공격 표면.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025
Prompt extraction attack
프롬프트 추출 공격
리스크·보안요약
An attack that recovers hidden system prompts or developer instructions by probing the model, exposing internal logic and secrets.
모델을 탐침하여 숨겨진 시스템 프롬프트나 개발자 지시를 복원함으로써 내부 로직과 비밀을 노출시키는 공격.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM07:2025
Prompt injection
프롬프트 주입
리스크·보안원문 EN
A vulnerability in which user-supplied or externally ingested prompts alter the LLM's behavior or output in unintended ways, bypassing instructions or safety controls; ranked LLM01 in OWASP 2025.
이용자 제공 또는 외부 유입 프롬프트가 의도되지 않은 방식으로 LLM의 행동·출력을 변경하여 지시·안전 통제를 우회하게 하는 취약점. OWASP 2025 1위 리스크(LLM01).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025
Prompt-injection detection
프롬프트 주입 탐지
리스크·보안요약
Detection controls that screen incoming prompts and ingested content for injection patterns, instruction conflicts, or anomalous directives before they reach the model or its tools.
모델·도구에 도달하기 전에 입력 프롬프트와 유입 콘텐츠에서 주입 패턴, 지시 충돌, 이상 지시를 선별하는 탐지 통제.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM01:2025 mitigations
Provider
제공자
법·제도원문 EN
A natural or legal person, public authority, agency or other body that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge.
AI 시스템 또는 범용 AI 모델을 개발하거나 개발하게 하여, 유상·무상을 불문하고 자신의 이름·상표로 시장에 출시하거나 서비스를 개시하는 자연인·법인·공공기관 등.
EU 인공지능법 제3조 · Art. 3(3)
Publicly accessible space
공중 접근 가능 공간
법·제도원문 EN
Any publicly or privately owned physical place accessible to an undetermined number of natural persons, regardless of access conditions or capacity restrictions.
접근 조건이나 수용 제한과 무관하게 불특정 다수의 자연인이 접근할 수 있는, 공적·사적 소유의 물리적 장소.
EU 인공지능법 제3조 · Art. 3(44)
Putting into service
서비스 개시
법·제도원문 EN
The supply of an AI system for first use directly to the deployer or for own use in the Union for its intended purpose.
AI 시스템을 의도된 목적을 위해 배포자에게 직접 최초 이용하도록 공급하거나 역내에서 자체 이용하도록 하는 행위.
EU 인공지능법 제3조 · Art. 3(11)
R
RAG poisoning
RAG 포이즈닝
리스크·보안요약
Poisoning of retrieval corpora or vector stores so that malicious content is retrieved into the model's context, steering generation or delivering indirect prompt injection.
검색 코퍼스나 벡터 저장소를 오염시켜 악성 콘텐츠가 모델 컨텍스트로 검색되게 함으로써 생성을 조종하거나 간접 프롬프트 주입을 전달하는 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · technique: RAG Poisoning
Real-time remote biometric identification
실시간 원격 생체인식
법·제도원문 EN
A remote biometric identification system in which capture, comparison and identification occur without significant delay, covering instant and limited short-delay identification.
포착·대조·식별이 유의미한 지연 없이 이루어지는 원격 생체인식 시스템으로, 즉시 식별과 제한적 단기 지연 식별을 포함한다.
EU 인공지능법 제3조 · Art. 3(42)
Real-world testing plan
실제 조건 시험 계획
법·제도원문 EN
A document describing the objectives, methodology, geographical, population and temporal scope, monitoring, organisation and conduct of testing in real-world conditions.
실제 조건 시험의 목표·방법론·지리적·인구·시간적 범위, 모니터링, 조직 및 수행을 기술한 문서.
EU 인공지능법 제3조 · Art. 3(53)
Reasonably foreseeable misuse
합리적으로 예견 가능한 오용
리스크·보안원문 EN
The use of an AI system in a way that is not in accordance with its intended purpose, but which may result from reasonably foreseeable human behaviour or interaction with other systems, including other AI systems.
의도된 목적과 다르지만 합리적으로 예견 가능한 인간 행동 또는 다른 시스템(다른 AI 시스템 포함)과의 상호작용으로부터 발생할 수 있는 방식의 AI 시스템 사용.
EU 인공지능법 제3조 · Art. 3(13)
Reasoning model (inference-time scaling)
추론 모델(추론시간 스케일링)
일반요약
A model class that improves performance on complex tasks by expending additional computation at inference time to generate and evaluate intermediate reasoning before answering.
답을 내기 전 중간 추론을 생성·평가하는 데 추론 시점의 연산을 추가로 투입하여 복잡 과업 성능을 높이는 모델 유형.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Recall of an AI system
AI 시스템 회수(리콜)
법·제도원문 EN
Any measure aiming to achieve the return to the provider, or the taking out of service or disabling, of an AI system already made available to deployers.
이미 배포자에게 제공된 AI 시스템을 제공자에게 반환시키거나 서비스 중단·비활성화하려는 모든 조치.
EU 인공지능법 제3조 · Art. 3(16)
Record-keeping / logging
기록 보관(로깅)
법·제도요약
The obligation that high-risk AI systems technically allow automatic recording of events (logs) over their lifetime to ensure traceability of functioning (EU AI Act Article 12).
고위험 AI 시스템이 작동의 추적가능성 확보를 위해 수명주기 동안 이벤트(로그)를 자동 기록할 수 있도록 기술적으로 보장해야 한다는 의무(EU 인공지능법 제12조).
EU 인공지능법 제3조 · Art. 12
Redress / remedy
구제 수단
법·제도요약
Procedural means by which affected persons can contest, appeal, or obtain remedy for AI-based decisions, including the right to lodge complaints (EU AI Act Article 85) and to explanation (Article 86).
영향받는 자가 AI 기반 결정에 이의를 제기·항고하거나 구제를 받을 수 있는 절차적 수단. 진정 제기권(EU 인공지능법 제85조)과 설명요구권(제86조)을 포함한다.
EU 인공지능법 제3조 · Art. 85-86
Refusal direction
거부 방향(표현공간)
리스크·보안요약
A linear direction in a model's activation space associated with refusing unsafe requests; reported to be largely shared across safety-aligned languages and manipulable.
불안전 요청 거부와 연관된 모델 활성 공간의 선형 방향. 안전 정렬된 언어 전반에서 대체로 공유되며 조작 가능한 것으로 보고된다.
The State of Multilingual LLM Safety Research (EMNLP 2025)
Reinforcement learning from human feedback (RLHF)
인간 피드백 강화학습(RLHF)
일반요약
A training method in which human preference judgments are used to train a reward model that then steers the policy model's outputs; widely used for alignment and refusal behavior.
인간 선호 판단으로 보상 모델을 학습시키고 이를 통해 정책 모델의 출력을 조정하는 학습 기법. 정렬과 거부 행동 구현에 널리 쓰인다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Reliability (Korean AI Ethics Principles)
신뢰성 (대한민국 인공지능 윤리원칙)
일반요약
The principle that an AI system meets minimum performance requirements for its purpose and context, operates within its intended purpose and authorized scope, and maintains stable and consistent performance across relevant conditions. (unofficial translation)
AI의 목적과 활용 맥락에 필요한 최소 성능 기준을 충족하고, 의도된 목적과 허용된 권한 범위 안에서 작동하며, 다양한 사용 조건에서 성능과 작동 상태가 안정적이고 일관되게 유지되도록 하는 원칙.
대한민국 인공지능 윤리원칙 · PDF p. 6
Remote biometric identification system
원격 생체인식 시스템
법·제도원문 EN
An AI system for identifying natural persons, without their active involvement, typically at a distance by comparing a person's biometric data with a reference database.
당사자의 능동적 관여 없이, 통상 원거리에서 개인의 생체 데이터를 참조 데이터베이스와 대조하여 자연인을 식별하는 AI 시스템.
EU 인공지능법 제3조 · Art. 3(41)
Retrieval-augmented generation (RAG)
검색증강생성(RAG)
일반요약
An architecture that retrieves external documents (often via vector embeddings) and injects them into the model's context to ground generation; introduces retrieval-side risks such as RAG poisoning and embedding weaknesses.
외부 문서를 (주로 벡터 임베딩으로) 검색해 모델 컨텍스트에 주입, 생성을 근거화하는 아키텍처. RAG 포이즈닝, 임베딩 취약점 등 검색측 리스크를 수반한다.
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM08:2025
Reward hacking
보상 해킹
리스크·보안요약
An agent's exploitation of an imperfectly specified objective, achieving high measured reward through unintended strategies that violate designer intent.
불완전하게 명세된 목적함수를 이용해 설계자 의도에 반하는 비의도적 전략으로 높은 보상 점수를 달성하는 에이전트 행동.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Reward tampering
보상 조작
리스크·보안요약
An advanced failure in which an agent alters the mechanism that computes its reward, rather than accomplishing the intended task.
에이전트가 의도된 과업을 수행하는 대신 자신의 보상을 산출하는 메커니즘 자체를 변경하는 고급 실패 양상.
Google DeepMind, Frontier Safety Framework
Right holder opt-out
권리자 옵트아웃(Opt-out)
법·제도요약
A reservation by a right holder, in an appropriate manner, of the right to prevent works lawfully accessible online from being used for text and data mining. (unofficial translation)
온라인으로 공중에게 제공되는 저작물 등을 텍스트 및 데이터 마이닝에 이용하지 못하도록 권리자가 적절한 방식으로 권리를 유보하는 것.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 21
Right to explanation
설명을 요구할 권리
법·제도요약
The right of an affected person to obtain a clear and meaningful explanation of the main criteria and logic used to reach an AI-based decision; recognized in EU AI Act Article 86 and Korean Framework Act Article 3.
영향받는 자가 AI 기반 결정에 사용된 주요 기준과 원리에 대해 명확하고 의미 있는 설명을 받을 권리. EU 인공지능법 제86조와 인공지능기본법 제3조가 인정한다.
EU 인공지능법 제3조 · Art. 86; 인공지능기본법 제3조
Risk
리스크(위험)
리스크·보안원문 EN
The combination of the probability of an occurrence of harm and the severity of that harm. (EU AI Act) NIST similarly defines risk as the composite measure of an event's probability of occurring and the magnitude or degree of its consequences.
위해 발생 확률과 그 위해의 심각도의 결합(EU 인공지능법). NIST도 사건 발생 확률과 결과의 크기·정도의 복합 척도로 정의한다.
EU 인공지능법 제3조 · Art. 3(2); NIST AI 100-1 §1
Risk (Korean AI Safety Guideline)
위험 (인공지능 안전성 확보 가이드라인)
리스크·보안원문 KO
The likelihood that human life, bodily safety, or fundamental rights will be infringed throughout the AI lifecycle, together with the severity of the potential harm. (unofficial translation)
인공지능 수명주기 전반에 걸쳐 사람의 생명ㆍ신체의 안전 또는 기본권이 침해될 가능성과 그 잠재적 피해의 심각성.
인공지능 안전성 확보 가이드라인 · PDF p. 9
Risk analysis (personal information)
위험도 분석
리스크·보안원문 KO
A comprehensive analysis that identifies and evaluates risk factors that may contribute to personal information leakage and establishes measures to control them appropriately. (unofficial translation)
개인정보 유출에 영향을 미칠 수 있는 다양한 위험요소를 식별ㆍ평가하고 해당 위험요소를 적절하게 통제할 수 있는 방안 마련을 위해 종합적으로 분석하는 행위.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Risk management system
위험관리체계
법·제도요약
A continuous, iterative process run across the life cycle of a high-risk AI system to identify, estimate, evaluate, and mitigate risks (EU AI Act Article 9); the NIST AI RMF operationalizes this through Govern, Map, Measure, and Manage functions.
고위험 AI 시스템의 수명주기 전반에서 리스크를 식별·추정·평가·완화하기 위해 지속·반복 수행하는 과정(EU 인공지능법 제9조). NIST AI RMF는 이를 Govern·Map·Measure·Manage 기능으로 구현한다.
EU 인공지능법 제3조 · Art. 9; NIST AI 100-1 §5
Risk management system (Korean AI Safety Guideline)
위험관리체계 (인공지능 안전성 확보 가이드라인)
법·제도원문 KO
A system that specifies the authority and obligations of responsible parties that monitor and respond to AI-related safety incidents. (unofficial translation)
인공지능 관련 안전사고를 모니터링하고 대응하는 책임 주체의 권한과 의무 등을 규정한 체계.
인공지능 안전성 확보 가이드라인 · PDF p. 9
Risk-based approach
위험 기반 접근
법·제도요약
A regulatory design that scales obligations to the level of risk an AI system poses—unacceptable (prohibited), high, limited, and minimal—characteristic of the EU AI Act.
AI 시스템이 초래하는 위험 수준(허용불가·고위험·제한적·최소)에 따라 의무를 차등 부과하는 규제 설계. EU 인공지능법의 특징.
EU 인공지능법 제3조 · Art. 5-6, 50
Robot foundation model
로봇 파운데이션 모델
일반요약
A large model pre-trained on broad robotics and multimodal data that can be adapted to many embodied tasks and platforms, extending the foundation-model paradigm to physical action.
광범위한 로보틱스·멀티모달 데이터로 사전학습되어 다양한 체화 과업·플랫폼에 적응 가능한 대형 모델. 파운데이션 모델 패러다임을 물리 행동으로 확장한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Robustness
강건성
일반요약
The ability of a system to maintain its level of performance under a variety of circumstances, including unexpected inputs and adverse conditions; a component of NIST's 'safe, secure and resilient' cluster.
예기치 못한 입력과 불리한 조건을 포함한 다양한 상황에서 성능 수준을 유지하는 능력. NIST의 '안전·보안·회복탄력' 특성군의 구성 요소.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.1, §3.3
S
Safety (AI safety)
안전성
일반요약
The property that an AI system does not, under defined conditions, lead to a state endangering human life, health, property, or the environment; a trustworthiness characteristic in the NIST AI RMF.
정의된 조건에서 AI 시스템이 인간의 생명·건강·재산·환경을 위태롭게 하는 상태를 초래하지 않는 성질. NIST AI RMF의 신뢰성 특성.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.2
Safety alignment
안전 정렬
일반요약
Alignment techniques specifically aimed at preventing harmful outputs and behaviors—refusals, harmlessness training, and guardrail tuning—as distinct from general capability or value alignment.
유해 출력·행동을 방지하는 데 특화된 정렬 기법(거부, 무해성 학습, 가드레일 조정)으로, 일반 역량 정렬이나 가치 정렬과 구별된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Safety component
안전 구성요소
법·제도원문 EN
A component of a product or AI system that fulfils a safety function, or whose failure or malfunctioning endangers the health and safety of persons or property.
제품이나 AI 시스템에서 안전 기능을 수행하는 구성요소, 또는 그 고장·오작동이 사람의 건강·안전이나 재산을 위태롭게 하는 구성요소.
EU 인공지능법 제3조 · Art. 3(14)
Safety filter (content moderation)
안전 필터(콘텐츠 조정)
리스크·보안요약
Classifiers and rule systems that screen model inputs and outputs for prohibited or harmful content categories, forming the outer layer of deployment-time defense.
금지·유해 콘텐츠 범주에 대해 모델 입출력을 선별하는 분류기·규칙 체계. 배포 시점 방어의 최외곽 계층을 이룬다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (mitigations)
Sandbox plan
샌드박스 계획
법·제도원문 EN
A document agreed between the participating provider and the competent authority describing the objectives, conditions, timeframe, methodology and requirements for activities within a regulatory sandbox.
참여 제공자와 권한당국이 합의하여 규제 샌드박스 내 활동의 목표·조건·기간·방법론·요구사항을 기술한 문서.
EU 인공지능법 제3조 · Art. 3(54)
Sandboxing
샌드박싱(방어)
리스크·보안요약
Isolating an AI system's execution, tool calls, or generated code in a constrained environment so that harmful actions cannot affect production systems or data.
AI 시스템의 실행·도구 호출·생성 코드를 제약된 환경에 격리하여 유해 행동이 운영 시스템·데이터에 영향을 주지 못하게 하는 방어 기법.
OWASP LLM 애플리케이션 10대 리스크 2025 · mitigations
Scalable oversight
확장 가능한 감독
리스크·보안요약
Techniques for supervising and evaluating AI systems whose outputs become too complex or numerous for direct human review, e.g., using AI assistance to help humans judge AI.
출력이 너무 복잡하거나 방대해 인간이 직접 검토하기 어려운 AI 시스템을 감독·평가하기 위한 기법. 예를 들어 AI의 도움으로 인간이 AI를 판정한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Scheming (deceptive power-seeking)
계략적 정렬 위장(스키밍)
리스크·보안요약
The hypothesized behavior of an AI that fakes alignment during training specifically to gain power or influence it can later exploit.
나중에 악용할 권력·영향력을 얻기 위해 학습 중 의도적으로 정렬을 가장하는 것으로 상정되는 AI 행동.
Carlsmith (2023), Scheming AIs
Sensitive information (Korean PIPA)
민감정보 (개인정보 보호법)
법·제도요약
Personal information concerning ideology, beliefs, trade-union or political-party membership, political views, health, sex life, genetic information, criminal records, biometric information for uniquely identifying a person, race, ethnicity, or other matters whose processing may seriously infringe privacy. (unofficial translation)
사상ㆍ신념, 노동조합ㆍ정당의 가입ㆍ탈퇴, 정치적 견해, 건강, 성생활, 유전정보, 범죄경력자료, 특정 개인을 알아볼 목적으로 생성한 신체적ㆍ생리적ㆍ행동적 특징 정보, 인종이나 민족에 관한 정보 등 정보주체의 사생활을 현저히 침해할 우려가 있는 개인정보.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Sensitive information disclosure
민감정보 노출
리스크·보안요약
The risk that an LLM reveals personal data, credentials, or proprietary information contained in its training data, context, or connected systems (OWASP LLM02:2025).
LLM이 학습 데이터, 컨텍스트, 연결 시스템에 담긴 개인정보·자격증명·영업정보를 드러내는 리스크(OWASP LLM02:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM02:2025
Sensitive operational data
민감 운영 데이터
법·제도원문 EN
Operational data related to activities of prevention, detection, investigation or prosecution of criminal offences, the disclosure of which could jeopardise the integrity of criminal proceedings.
범죄의 예방·탐지·수사·기소 활동과 관련된 운영 데이터로, 공개 시 형사 절차의 무결성을 위태롭게 할 수 있는 것.
EU 인공지능법 제3조 · Art. 3(38)
Sensor
센서
일반요약
A device that captures physical-world signals (vision, lidar, audio, position) as input to an AI system; sensor error or spoofing propagates into unsafe downstream actions.
시각·라이다·음향·위치 등 물리 세계 신호를 포착하여 AI 시스템의 입력으로 제공하는 장치. 센서 오류나 스푸핑은 하류의 불안전 행동으로 전파된다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Sensor spoofing
센서 스푸핑
리스크·보안요약
An attack that feeds falsified signals to a physical AI system's sensors (e.g., GPS spoofing, adversarial road signs) to induce unsafe perception and action.
물리 AI 시스템의 센서에 위조 신호(GPS 스푸핑, 적대적 표지판 등)를 주입하여 잘못된 지각과 불안전 행동을 유발하는 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · physical attacks
Serious incident
중대 사고(중대한 인시던트)
리스크·보안원문 EN
An incident or malfunctioning of an AI system that directly or indirectly leads to the death of a person or serious harm to health; serious and irreversible disruption of critical infrastructure; infringement of fundamental-rights obligations; or serious harm to property or the environment.
사람의 사망 또는 건강에 대한 중대한 위해, 핵심 인프라의 중대하고 비가역적인 교란, 기본권 보호 의무 위반, 재산·환경에 대한 중대한 피해를 직간접적으로 초래하는 AI 시스템의 사고 또는 오작동.
EU 인공지능법 제3조 · Art. 3(49)
Sim-to-real gap
시뮬레이션-실제 격차(Sim-to-real)
일반요약
The performance drop when a model trained in simulation is deployed in the real world due to unmodeled physical conditions; a principal source of accidental harm in embodied AI.
시뮬레이션에서 학습한 모델이 모델링되지 않은 물리 조건 때문에 실제 배포 시 성능이 저하되는 현상. 체화 AI 우발적 피해의 주요 원인.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Sleeper agent
슬리퍼 에이전트
리스크·보안요약
A model with a hidden backdoor behavior that stays dormant and survives standard safety training, activating only on a specific trigger at deployment.
은닉된 백도어 행동이 잠복해 있다가 표준 안전 학습을 견디고, 배포 시 특정 트리거에서만 활성화되는 모델.
Hubinger et al. (2024, Anthropic), Sleeper Agents
Special categories of personal data
특수 범주 개인정보
법·제도원문 EN
The categories of personal data referred to in Article 9(1) GDPR, Article 10 of Directive (EU) 2016/680 and Article 10(1) of Regulation (EU) 2018/1725 (e.g., data revealing race, health, or beliefs).
GDPR 제9조(1) 등에서 규정한 특수 범주 개인정보(예: 인종·건강·신념을 드러내는 데이터).
EU 인공지능법 제3조 · Art. 3(37)
Sponge (energy-latency) attack
스펀지(에너지·지연) 공격
리스크·보안요약
Availability attacks using inputs crafted to maximize computation, energy use, or latency, degrading or denying service; related to unbounded-consumption risk in LLM applications.
연산량·에너지·지연을 극대화하도록 제작된 입력으로 서비스 성능을 저하시키거나 마비시키는 가용성 공격. LLM의 무제한 소비 리스크와 연결된다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (availability); OWASP LLM10:2025
Subject (real-world testing)
피험자(실제 조건 시험)
법·제도원문 EN
For the purpose of real-world testing, a natural person who participates in testing in real-world conditions.
실제 조건 시험의 목적상 실제 조건 시험에 참여하는 자연인.
EU 인공지능법 제3조 · Art. 3(58)
Substantial modification
실질적 변경
법·제도원문 EN
A change to an AI system after market placement or service that was not foreseen in the initial conformity assessment and that affects compliance with high-risk requirements or modifies the intended purpose.
시장 출시·서비스 개시 후 AI 시스템에 가해진, 최초 적합성 평가에서 예견되지 않았고 고위험 요구사항 준수에 영향을 주거나 의도된 목적을 변경하는 변경.
EU 인공지능법 제3조 · Art. 3(23)
Superficial safety alignment
표면적 안전 정렬
리스크·보안요약
The finding that safety behavior learned by alignment can be shallow—concentrated in early tokens or easily stripped—so it fails under distribution shift or light fine-tuning.
정렬로 학습된 안전 행동이 초기 토큰에 집중되거나 쉽게 제거되는 등 얕을 수 있어, 분포 변화나 가벼운 미세조정에서 무너진다는 발견.
Zhou et al. (2023), LIMA (Superficial Alignment Hypothesis)
Superintelligence
초지능
일반요약
A hypothesized AI that greatly surpasses the best human performance across virtually all cognitive domains; a reference point in catastrophic and loss-of-control risk discussions.
사실상 모든 인지 영역에서 최고 수준의 인간을 크게 능가하는 것으로 상정되는 AI. 파국적·통제 상실 리스크 논의의 준거 개념.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Supply chain attack (AI)
AI 공급망 공격
리스크·보안요약
Compromise of third-party components in the AI life cycle, including pre-trained models, datasets, adapters, and packages, so downstream systems inherit tampered or vulnerable artifacts (OWASP LLM03:2025; ATLAS AI Supply Chain Compromise).
사전학습 모델, 데이터셋, 어댑터, 패키지 등 AI 수명주기의 제3자 구성요소를 침해하여 하류 시스템이 변조·취약 산출물을 상속하게 하는 공격(OWASP LLM03:2025, ATLAS 기법).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM03:2025
Sustainability of humanity
인류의 지속가능성
일반요약
A value directing AI benefits and opportunities to be shared by present and future generations while sustaining the environmental and social foundations of human life. (unofficial translation)
AI가 만들어 내는 편익과 가능성을 현재와 미래 세대가 함께 누리며, 인류의 삶을 뒷받침하는 환경과 사회의 기반이 지속되는 미래를 지향하는 가치.
대한민국 인공지능 윤리원칙 · PDF p. 4
Sycophancy
아첨(시코펀시)
리스크·보안요약
The tendency of a model to tell users what they want to hear, agreeing with stated views or flattering them at the expense of accuracy; a manipulation and reliability risk.
모델이 정확성을 희생하면서 이용자가 듣고 싶어 하는 말을 하거나 그 견해에 동조·아부하는 경향. 조작·신뢰성 리스크.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Synthetic data
합성 데이터
일반요약
Artificially generated data used to train or evaluate models when real data is scarce or sensitive; quality gaps can degrade generalization and recursive use risks model collapse.
실데이터가 부족하거나 민감할 때 모델 학습·평가에 쓰는 인공 생성 데이터. 품질 격차는 일반화를 저해하고 재귀적 사용은 모델 붕괴를 초래할 수 있다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
System prompt leakage
시스템 프롬프트 유출
리스크·보안요약
The risk that hidden system prompts, and any secrets improperly stored in them, are extracted from an LLM application, exposing internal logic and enabling further attacks (OWASP LLM07:2025).
숨겨진 시스템 프롬프트와 그 안에 부적절하게 저장된 비밀이 추출되어 내부 로직이 노출되고 후속 공격이 가능해지는 리스크(OWASP LLM07:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM07:2025
Systemic risk (GPAI)
시스템적 리스크(범용 AI)
리스크·보안원문 EN
A risk that is specific to the high-impact capabilities of general-purpose AI models, having a significant impact on the Union market due to their reach, or due to actual or reasonably foreseeable negative effects on public health, safety, public security, fundamental rights, or the society as a whole, that can be propagated at scale across the value chain.
범용 AI 모델의 고영향 역량에 특유한 리스크로서, 그 도달 범위 또는 공중보건·안전·공공안보·기본권·사회 전반에 대한 실제적·합리적으로 예견 가능한 부정적 효과로 인해 시장에 중대한 영향을 미치며 가치사슬 전반에 대규모로 전파될 수 있는 리스크.
EU 인공지능법 제3조 · Art. 3(65)
T
Target system (privacy impact assessment)
대상시스템
법·제도원문 KO
An information system intended to establish, operate, change, or interconnect a personal information file subject to a privacy impact assessment. (unofficial translation)
개인정보 영향평가 대상 개인정보파일을 구축ㆍ운용, 변경 또는 연계하려는 정보시스템.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 17
Technical documentation
기술문서
법·제도요약
The documentation that providers of high-risk AI systems must draw up before market placement, demonstrating compliance and enabling authorities to assess conformity (EU AI Act Article 11 and Annex IV).
고위험 AI 시스템 제공자가 시장 출시 전 작성하여 적합성 입증과 당국의 평가를 가능하게 해야 하는 문서(EU 인공지능법 제11조 및 부속서 IV).
EU 인공지능법 제3조 · Art. 11, Annex IV
Testing data
시험데이터
일반원문 EN
Data used for providing an independent evaluation of the AI system in order to confirm the expected performance of that system before its placing on the market or putting into service.
시장 출시 또는 서비스 개시 전 시스템의 기대 성능을 확인하기 위하여 독립적 평가에 사용되는 데이터.
EU 인공지능법 제3조 · Art. 3(32)
Testing in real-world conditions
실제 조건 시험
법·제도원문 EN
Temporary testing of an AI system for its intended purpose in real-world conditions outside a laboratory, to gather reliable data and assess conformity, without qualifying as placing on the market or putting into service (subject to Articles 57 or 60).
신뢰할 수 있는 데이터 확보와 적합성 평가를 위해, 실험실 밖 실제 조건에서 의도된 목적으로 AI 시스템을 임시로 시험하는 것. 제57조·제60조 조건 충족 시 시장 출시·서비스 개시로 보지 않는다.
EU 인공지능법 제3조 · Art. 3(57)
Tool poisoning (agent)
도구 포이즈닝(에이전트)
리스크·보안요약
Compromising the tools, plugins, or their descriptions an AI agent relies on, so tool metadata or outputs steer the agent into harmful actions.
AI 에이전트가 의존하는 도구·플러그인이나 그 설명을 오염시켜, 도구 메타데이터나 출력이 에이전트를 유해 행동으로 유도하게 하는 공격.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · AI Agent Tool Poisoning
Tool use / function calling
도구 사용·함수 호출
일반요약
The capability of an AI model to invoke external tools, APIs, or functions to obtain information or perform actions; the mechanism that turns a model into an agent and expands its action surface.
AI 모델이 정보 획득이나 행동 수행을 위해 외부 도구·API·함수를 호출하는 능력. 모델을 에이전트로 만들고 행동 표면을 확장하는 기제.
MITRE ATLAS (AI 시스템 적대적 위협 지형) · AI Agent Tool Invocation
Tool-invocation safety
도구 호출 안전
리스크·보안요약
Safety of an LLM agent's calls to external tools—ensuring invocations are appropriate, authorized, and non-harmful across single- and multi-step settings.
LLM 에이전트가 외부 도구를 호출하는 행위의 안전성으로, 단일·다단계 상황에서 호출이 적절·인가되고 무해하도록 보장하는 것.
ToolSafety (EMNLP 2025)
Toxicity
유해 발화(독성)
리스크·보안요약
Model output that is rude, degrading, hateful, or otherwise harmful to individuals or groups; measured by toxicity benchmarks and mitigated by safety filters and alignment.
무례·비하·혐오 등 개인·집단에 유해한 모델 출력. 독성 벤치마크로 측정되며 안전 필터와 정렬로 완화한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Traceability
추적가능성
법·제도요약
The capacity to reconstruct how an AI system produced a given output, supported by logging, documentation, and provenance; a precondition of accountability and auditing.
로깅·문서화·출처증명을 바탕으로 AI 시스템이 특정 출력을 산출한 경위를 재구성할 수 있는 능력. 책임성과 감사의 전제.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.4
Training data
학습데이터
일반원문 EN
Data used for training an AI system through fitting its learnable parameters.
학습 가능한 파라미터의 적합을 통해 AI 시스템을 학습시키는 데 사용되는 데이터.
EU 인공지능법 제3조 · Art. 3(29)
Training data (Korean Framework Act)
학습용데이터 (인공지능기본법)
일반원문 KO
Data used for the development and utilization of artificial intelligence. (unofficial translation)
인공지능의 개발ㆍ활용 등에 사용되는 데이터.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제12호
Transfer attack
전이 공격
리스크·보안요약
An attack in which adversarial examples crafted against one (surrogate) model succeed against a different target model, enabling black-box attacks without target access.
한 대리 모델을 상대로 제작한 적대적 예제가 다른 표적 모델에도 성공하는 공격. 표적 접근 없이 블랙박스 공격을 가능하게 한다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §1 (evasion)
Transformative use
변형적 이용
법·제도요약
Use that does not merely replace the original work but adds a new purpose or character distinct from the original purpose. (unofficial translation)
이용되는 저작물을 단순히 대체하는 것이 아니라 원저작물의 목적과 다른 새로운 목적이나 성격을 부가하는 이용.
생성형 인공지능의 저작물 학습에 대한 저작권법상 공정이용 안내서 · PDF p. 29
Transparency
투명성
일반요약
The extent to which information about an AI system and its outputs is available to individuals interacting with it, including awareness that they are interacting with AI; a NIST trustworthiness characteristic and an obligation under EU AI Act Article 50 and Korean Framework Act Article 31.
상호작용하는 개인이 AI 시스템과 그 출력에 관한 정보를 얻을 수 있는 정도(AI와 상호작용 중임의 인지 포함). NIST 신뢰성 특성이자 EU 인공지능법 제50조, 인공지능기본법 제31조상 의무.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.4
Transparency obligation (disclosure)
투명성 의무(고지)
법·제도요약
The duty that providers and deployers disclose AI interaction and AI-generated content in specified cases, e.g., informing users they are interacting with an AI system or labelling synthetic media (EU AI Act Article 50).
특정 경우 제공자·배포자가 AI 상호작용과 AI 생성 콘텐츠를 고지해야 하는 의무. 예를 들어 이용자에게 AI 시스템과 상호작용 중임을 알리거나 합성 미디어를 표시하는 것(EU 인공지능법 제50조).
EU 인공지능법 제3조 · Art. 50
Trustworthy AI
신뢰할 수 있는 인공지능
일반요약
AI whose characteristics include being valid and reliable; safe; secure and resilient; accountable and transparent; explainable and interpretable; privacy-enhanced; and fair with harmful bias managed (NIST AI RMF trustworthiness characteristics).
타당성·신뢰도, 안전성, 보안·회복탄력성, 책임성·투명성, 설명·해석가능성, 프라이버시 보호, 유해 편향이 관리된 공정성을 특성으로 갖는 AI(NIST AI RMF 신뢰성 특성).
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3
U
Unbounded consumption
무제한 소비
리스크·보안요약
The risk that an LLM application permits excessive and uncontrolled inference, enabling denial-of-service, economic (denial-of-wallet) damage, or model-extraction reconnaissance (OWASP LLM10:2025).
LLM 애플리케이션이 과도하고 통제되지 않는 추론을 허용하여 서비스 거부, 경제적 피해(지갑 고갈), 모델 추출 정찰을 가능하게 하는 리스크(OWASP LLM10:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM10:2025
Unfaithful chain-of-thought
불충실한 사고연쇄
리스크·보안요약
When a model's stated step-by-step reasoning does not reflect the actual computation that produced its answer, undermining reliance on CoT for oversight.
모델이 제시한 단계별 추론이 실제로 답을 산출한 계산을 반영하지 않는 현상으로, 감독을 위한 사고연쇄 신뢰를 훼손한다.
Turpin et al. (2023), Language Models Don't Always Say What They Think
Unique identifying information
고유식별정보
법·제도원문 KO
Identifiers assigned under law to uniquely distinguish an individual, namely resident registration number, passport number, driver's licence number, and alien registration number. (unofficial translation)
법령에 따라 개인을 고유하게 구별하기 위하여 부여된 식별정보로서 주민등록번호, 여권번호, 운전면허번호, 외국인등록번호를 의미한다.
개인정보 영향평가 수행안내서(2025.10. 개정) · PDF p. 16
Universal adversarial suffix (GCG)
보편적 적대적 접미사(GCG)
리스크·보안요약
An automatically optimized string appended to a prompt that reliably induces disallowed outputs across models; produced by Greedy Coordinate Gradient search and often transferable between models.
프롬프트에 덧붙여 여러 모델에서 금지된 출력을 안정적으로 유발하는 자동 최적화 문자열. Greedy Coordinate Gradient 탐색으로 생성되며 모델 간 전이되는 경우가 많다.
Zou et al. (2023), Universal and Transferable Adversarial Attacks on Aligned Language Models
User (Korean Framework Act)
이용자
법·제도원문 KO
A person who is provided with an AI product or AI service. (unofficial translation)
인공지능제품 또는 인공지능서비스를 제공받는 자.
인공지능기본법 제2조 (인공지능 발전과 신뢰 기반 조성 등에 관한 기본법, 법률 제21311호, 시행 2026.7.21) · 제2조 제8호
V
Validation data
검증데이터
일반원문 EN
Data used for providing an evaluation of the trained AI system and for tuning its non-learnable parameters and its learning process in order, inter alia, to prevent underfitting or overfitting.
학습된 AI 시스템을 평가하고, 과소적합·과대적합 방지 등을 위해 비학습 파라미터와 학습 과정을 조정하는 데 사용되는 데이터.
EU 인공지능법 제3조 · Art. 3(30)
Validation data set
검증 데이터셋
법·제도원문 EN
A separate data set or part of the training data set, either as a fixed or variable split, used for validation.
검증에 사용되는 별도 데이터셋 또는 학습 데이터셋의 일부로, 고정 또는 가변 분할일 수 있다.
EU 인공지능법 제3조 · Art. 3(31)
Validity
타당성
일반원문 EN
Confirmation, through objective evidence, that requirements for a specific intended use have been fulfilled; 'valid and reliable' is the first NIST trustworthiness characteristic.
특정 의도된 용도에 대한 요구사항 충족이 객관적 증거로 확인되는 것. '타당하고 신뢰할 수 있음'은 NIST의 첫 번째 신뢰성 특성이다.
NIST AI 위험관리 프레임워크 (AI RMF 1.0, NIST AI 100-1) · §3.1
Value alignment
가치 정렬
일반요약
The problem and practice of making an AI system's goals and behavior consistent with human values and intentions, especially where values are plural, contested, or context-dependent.
AI 시스템의 목표와 행동을 인간의 가치·의도에 부합시키는 문제이자 실천으로, 특히 가치가 복수적·논쟁적·맥락 의존적일 때 중요하다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
Value chain (AI value chain)
AI 가치사슬
법·제도요약
The sequence of actors and components from model development through integration to deployment; the EU AI Act allocates responsibilities along this chain (Article 25).
모델 개발부터 통합·배포에 이르는 행위자와 구성요소의 연쇄. EU 인공지능법은 이 사슬을 따라 책임을 배분한다(제25조).
EU 인공지능법 제3조 · Art. 25
Vector and embedding weaknesses
벡터·임베딩 취약점
리스크·보안요약
Weaknesses in how vectors and embeddings are generated, stored, or retrieved in RAG systems, exploitable to inject harmful content, manipulate outputs, or access sensitive information (OWASP LLM08:2025).
RAG 시스템에서 벡터·임베딩의 생성·저장·검색 방식의 취약점으로, 유해 콘텐츠 주입, 출력 조작, 민감정보 접근에 악용될 수 있다(OWASP LLM08:2025).
OWASP LLM 애플리케이션 10대 리스크 2025 · LLM08:2025
Vision-language-action model (VLA)
시각-언어-행동 모델(VLA)
일반요약
A model that maps visual observations and language instructions directly to physical actions for robotic control; extends language-model vulnerabilities into physical behavior.
시각 관측과 언어 지시를 로봇 제어를 위한 물리 행동으로 직접 사상하는 모델. 언어모델 취약점을 물리 행동으로 확장한다.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
W
Watermarking (AI content)
워터마킹(AI 콘텐츠)
리스크·보안요약
Embedding detectable statistical or perceptual signals in AI-generated content so that its synthetic origin can later be verified; a transparency and provenance mitigation with known robustness limits.
AI 생성 콘텐츠에 탐지 가능한 통계적·지각적 신호를 삽입하여 합성 출처를 사후 검증할 수 있게 하는 기법. 투명성·출처증명 완화책이나 강건성 한계가 알려져 있다.
NIST 적대적 머신러닝 분류·용어 (NIST AI 100-2 E2025) · §2 (mitigations)
Widespread infringement
광범위 침해
법·제도원문 EN
An act or omission contrary to Union law protecting individuals' interests that harms, or is likely to harm, the collective interests of individuals in several Member States.
개인의 이익을 보호하는 EU법에 반하는 작위·부작위로서 여러 회원국 개인들의 집합적 이익을 침해하거나 침해할 우려가 있는 것.
EU 인공지능법 제3조 · Art. 3(61)
Withdrawal of an AI system
AI 시스템 철회
법·제도원문 EN
Any measure aiming to prevent an AI system in the supply chain from being made available on the market.
공급망 내 AI 시스템이 시장에 유통되는 것을 막으려는 모든 조치.
EU 인공지능법 제3조 · Art. 3(17)
World model
월드 모델
일반요약
A learned internal model of environment dynamics that an agent uses to predict outcomes and plan actions; central to advanced embodied and agentic systems and to some misgeneralization risks.
에이전트가 결과를 예측하고 행동을 계획하는 데 사용하는, 환경 동역학에 대한 학습된 내부 모델. 고도 체화·에이전트 시스템과 일부 오일반화 리스크의 핵심.
NIST 신뢰할 수 있는 AI 용어집 (NIST AI 100-3, AIRC Glossary) · glossary
검색 결과가 없습니다.