Abstract
This paper proposes CITRA (Consent & Dignity, Integrity, Traceability, Risk & Proportionality, Accountability & Remedy) design guidelines specialized for deepfakes, starting with the Ministry of Science and ICT's "Human-Centered AI Ethics Principles." By comparing and referencing norms, standards, and voluntary guidelines from the US, Europe, and Japan, and cross-analyzing consent, labeling/warnings, provenance, risk ratings, and accountability/remedy requirements based on the EU AI Act/DSA, NIST AI RMF and Generative AI Profile, Japanese government guidelines, C2PA (Content Credentials), and PAI recommendations, we reframe risks across the production-distribution-labeling stages along the CITRA axes and derive practical minimum compliance standards, including label visibility, persistence, and machine-readability; C2PA-based provenance; proportional controls in high-risk contexts; and service-level agreements (SLAs) for reporting, deletion, restoration, and support. This study presents key checkpoints and a blueprint for phased implementation that can be immediately applied in education, industry, and the public sector.
본 논문은 과학기술정보통신부의 '사람중심 AI 윤리 원칙'을 출발점으로, 딥페이크에 특화된 'CITRA; Consent & Dignity(동의 및 존엄성), Integrity(정직성/맥락보존), Traceability(추적 가능성), Risk & Proportionality(위험 및 비례성), Accountability & Remedy(책임 및 구제책)'디자인 가이드라인을 제안한다. 미국 유럽 일본의 규범·표준·자율 가이드를 비교 참조하고, EU의 AI Act/DSA, 미국의 NIST AI 위험관리 프레임워크 및 생성형 AI 프로파일, 일본 정부 지침, C2PA(Content Credentials), PAI 권고를 근거로 동의, 라벨링/경고, 출처성, 위험등급, 책임/구제 요구를 교차 분석하였다. 그 결과, 제작-유통-표시 단계의 위험을 CITRA 축으로 재구성하고, 라벨의 가시성·지속성·기계가독성, C2PA 기반 프로비넌스, 고위험 맥락의 비례 통제, 신고-삭제-복구-지원(SLA) 등 실천적 최소 준수선을 도출하였다. 본 연구는 교육·산업·공공 현장에서 즉시 적용 가능한 핵심 체크포인트와 단계적 도입 청사진을 제시한다.