外媒:AI安全限制正拖慢攻防研究
TechCrunch
07-24 09:07
Ai Focus
外媒称,AI模型的网络安全限制正影响合法研究工作,部分研究人员转向本地开源模型。
Helpful
No.Help

TechCrunch报道称,AI 公司近几个月持续收紧模型在网络安全场景中的使用权限,原本用于防止恶意攻击者滥用的限制,如今也在影响合法防御团队和进攻型安全研究人员的工作效率。争议焦点在于,同一套能力既可用于修复漏洞,也可用于发现和利用漏洞,平台很难把两者彻底分开。

美国模型限制持续收紧

报道提到,美国政府 6 月曾对 Anthropic 的 Mythos 和 Fable 模型实施出口管制,原因至少部分与一份报告有关。该报告称,这些模型的安全限制可能被绕过,并被用于构建或执行恶意网络攻击。

此后,Fable 5 已于 7 月 1 日恢复广泛开放,Mythos 5 则仅向经过审核的美国机构重新开放,仍处于政府审查流程之中。除 Anthropic 外,OpenAI 也设有面向网络安全研究人员的审核项目,允许获批用户在较少限制下使用模型。

研究人员称影响漏洞验证

多名受访安全研究人员认为,当前限制已开始妨碍正常研究流程。NCC Group 首席科学家 Chris Anley 表示,在确认一个缺陷是否构成真实漏洞时,让模型尝试利用该缺陷是关键步骤。如果模型直接拒绝回答,防御方反而更难判断问题是否需要优先修复。

他认为,要求模型“修复这段代码”本身就同时具有防御和进攻属性。因为修复建议往往也会暴露代码中的关键薄弱点,这使得平台很难只保留防御用途,而完全剥离进攻用途。

安全研究员 Mark Dowd 也批评称,由大型 AI 公司单方面决定哪些安全研究是“安全的”,并不令人放心。报道指出,Dowd 长期从事零日漏洞发现与交易,因此他也承认自己的立场可能带有职业偏向。

部分团队转向本地开源模型

一些受访者表示,当主流闭源模型因限制无法完成任务时,他们会改用没有安全限制的开源模型。CrowdFense 首席技术官 Paolo Stagno 称,其团队会使用前沿模型做逆向工程,但在漏洞发现和利用构建环节,更倾向于使用本地部署的开源模型。

他给出的原因不只是限制过严,还包括数据安全顾虑。若将敏感漏洞信息输入云端模型,相关内容可能外泄,或被吸收到后续训练流程中。本地运行的开源模型则不需要把数据发送到外部平台。

另有一名来自智能手机零部件制造商的研究人员表示,由于所在公司未加入 Anthropic 的审核项目,相关工具在漏洞发现上的实用性很低,因为限制过于严格。

担忧研究者被推向海外模型

网络安全公司 RemoteThreat 首席执行官 Chris Thompson 表示,即便在 Anthropic 和 OpenAI 的审核项目内,模型限制的触发方式也常常不稳定,同一类请求每天可能得到不同结果。研究人员因此不得不花时间与模型反复“协商”,而不是专注于漏洞分析本身。

他还称,这种情况正在把负责任的研究人员推向可本地运行、无需审核的中国开源模型,例如 GLM。按他的说法,如果美国 AI 公司继续收紧限制,而不扩大合规访问渠道,防御方可能会在这场 AI 驱动的安全竞赛中失去速度优势。

Tip
$0
Like
0
Save
0
Views 184
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
AI startup Simile raises $200 million
Simile has completed a $200 million Series B funding round, raising its valuation to $2 billion. The company focuses on providing “synthetic user” services for marketing and product research.
TechCrunch
·2026-07-31 01:56:21
542
Encore AI Raises $30 Million in Series A Funding
Encore AI has raised $30 million in Series A funding. The company focuses on training AI voice agents from customer calls, with most of its customers being financial institutions.
TechCrunch
·2026-07-29 22:53:54
234
Can brainwave data drive the implementation of physical AI?
Encord tests brainwave and electromyography data in an attempt to address the shortage of training data for robots.
TechCrunch
·2026-07-27 08:41:12
427
Blockchain Life Returns to Dubai — Featuring the Debut of AI Future!
On December 1–2, 2026, Blockchain Life 2026 returns to Dubai for one of the world’s largest gatherings focused on Web3, cryptocurrency, mining, and AI.
Beckoning
·2026-07-30 15:34:07
17
NVIDIA and 35 partners establish the Open AI Security Alliance
NVIDIA, together with more than 35 companies including Microsoft, Cisco, and IBM, has established the Open AI Security Alliance, focusing on the development of AI security and defense models.
Coinpedia
·2026-07-28 23:33:04
732