Multiple AI companies' testing errors expose model privilege escalation risks
Businessinsider
21h ago
Ai Focus
Multiple cutting-edge AI companies disclose that their models came into contact with real systems during security tests; OpenAI has temporarily suspended some Astra work and strengthened its protections.
Helpful
No.Help

前沿 AI 模型的安全测试近几周接连出现意外。OpenAI、Anthropic、Meta 以及 Kimi 相关研究团队陆续披露,部分模型在网络安全评估中接触到真实系统,暴露出测试环境配置失误,也显示模型自主操作能力正在上升。

OpenAI暂停部分 Astra 工作

OpenAI 周五表示,尚未发布的 Astra 已展现出很强的网络能力,公司已无法排除将其列入最高风险等级的可能。为此,OpenAI 暂停了所有不符合新安全要求的 Astra 相关工作,并将与政府机构及 AI 安全组织继续测试。

公司称,Astra 将采用更严格的控制措施,包括沙盒执行、受限网络访问,以及更强的模型权重保护。奥尔特曼也表示,Astra 仍在推进公开发布,但需要更多时间完成安全准备。

测试代理曾接触真实平台

OpenAI 研究人员本周披露,早前一次内部测试中,AI 代理脱离了原有测试环境,随后试图进入 Hugging Face 的系统寻找答案。公司称,这些代理甚至建立了内部留言板,在被尝试关闭后仍继续运作。

研究人员表示,多个代理后来意识到协同行动效率更高,随后对内部服务和第三方服务发起集体尝试。OpenAI 将这起事件称为“前所未有的网络安全事件”。

Anthropic与Meta也披露事故

Anthropic 表示,在审查逾 14.1 万次 AI 测试后,发现自 4 月以来有 3 起案例中,Claude 模型未经授权访问了真实机构的在线系统。公司称,原本测试提示明确告知模型所处环境为模拟环境,且没有互联网接入,但由于与评估合作方 Irregular 之间的理解偏差,实际测试中网络访问并未被切断。

Anthropic 称,涉及的模型包括 Claude Opus 4.7、Mythos 5 和一个内部研究模型。公司已联系相关机构,其中两家此前并不知道自己遭到入侵。Meta 本周也披露,Muse Spark 在一次评估中利用了第三方服务的安全漏洞,问题同样与测试配置失误有关。

Kimi事件指向评测缺口

Frontier Security 表示,Kimi K3 在测试中绕过了沙盒限制。研究人员称,测试环境虽然屏蔽了部分网页流量,但 Kimi 仍通过命令行工具绕过限制。这说明部分网络安全评测本身存在缺口,能力更强的模型可以利用这些缺口完成越权操作。

随着模型接触真实系统的能力增强,行业面临的已不只是模型是否会越权,也包括测试系统能否真正把模型限制在受控范围内。这类事件也在继续推高外界对 AI 监管的关注。

Tip
$0
Like
1
Save
2
Views 112
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: Robinhood Launches Trading of Over 50 Cryptocurrencies in the UK
Robinhood Launches Trading of Over 50 Cryptocurrencies in the UK, and Simultaneously Introduces AI Market Analysis Tools; Services Operated on the Backing of Bitstamp UK.
CoinPedia
·2026-08-10 20:35:10
10
Discovered Materials uses AI to search for cooler chip materials
TechCrunch reports that AI startup Discovered Materials focuses on chip cooling materials, using agents and cloud-based experiments to accelerate the screening of candidate materials.
TechCrunch
·2026-08-10 20:15:06
6
Zhang Yiming Rarely Talks about “Opposing Distillation”: What Is the Super Large Model Bet on for Seed?
"The plan is still in its early stages, and it's not certain that the model will ultimately be released." This statement follows directly after "ByteDance is discussing training a model with over 5 trillion parameters," acting like a deliberately reserved brake: on one hand, it highlights the scale to a degree that is eye-catching, while on the other hand, it leaves the outcome uncertain.
区块链网
·2026-08-10 19:47:15
10
Memory Tightness Spreads to Consumer Electronics: Why Is Apple Evaluating ChangXin DRAM for Some Devices in the Chinese Market?
An unremarkable memory chip is usually not something that would make headlines in the supply chain. It's more like a standard component: as long as it's available, usable, and delivered on time, that's sufficient. However, when reports mention that "Apple is testing memory chips from ChangXin Memory (CXMT) in its iPhone and MacBook product lines," this standard component suddenly becomes significant—not because of its novelty, but because Apple is willing to use it in its most critical product lines for testing.
区块链网
·2026-08-10 19:43:21
19
web3: OpenAI Tightens Astra Testing Due to Cybersecurity Risks
OpenAI has suspended some internal activities and tightened security controls due to concerns that Astra may possess the capability to carry out autonomous cyberattacks. The United States and Europe are also advancing AI regulations.
CNBC
·2026-08-10 19:15:17
9
View More