外媒:AI安全限制正拖慢攻防研究
TechCrunch
07-24 09:07
Ai Focus
外媒稱,AI模型的網路安全限制正影響合法研究工作,部分研究人員轉向本地開源模型。
Helpful
No.Help

TechCrunch報導,AI 公司近幾個月持續收緊模型在網路安全場景中的使用權限,原本用於防止惡意攻擊者濫用的限制,如今也影響合法防禦團隊和進攻型安全研究人員的工作效率。爭議焦點在於,同一套能力既可用於修復漏洞,也可用於發現和利用漏洞,平台很難把兩者徹底分開。

美國模型限制持續收緊

通報提到,美國政府 6 月曾對 Anthropic 的 Mythos 和 Fable 模式實施出口管制,原因至少部分與一份報告有關。該報告稱,這些模型的安全限制可能被繞過,並用於建構或執行惡意網路攻擊。

此後,Fable 5 已於 7 月 1 日恢復廣泛開放,Mythos 5 則僅向經過審核的美國機構重新開放,仍處於政府審查流程之中。除 Anthropic 外,OpenAI 還設有網路安全研究人員的審核項目,允許核准使用者在較少限制下使用模型。

研究人員稱影響漏洞驗證

多名受訪安全研究人員認為,目前限制已開始妨礙正常研究流程。 NCC Group 首席科學家 Chris Anley 表示,在確認一個缺陷是否構成真實漏洞時,讓模型嘗試利用該缺陷是關鍵步驟。如果模型直接拒絕回答,防禦方反而更難判斷問題是否需要優先修復。

他認為,要求模型「修復這段程式碼」本身就同時具有防禦和進攻屬性。因為修復建議往往也會暴露程式碼中的關鍵薄弱點,這使得平台很難只保留防禦用途,而完全剝離進攻用途。

安全研究員 Mark Dowd 也批評稱,由大型 AI 公司單方面決定哪些安全研究是“安全的”,並不令人放心。報告指出,Dowd 長期從事零日漏洞發現與交易,因此他也承認自己的立場可能帶有職業偏向。

部分團隊轉向本地開源模型

一些受訪者表示,當主流閉源模型因限製而無法完成任務時,他們會改用沒有安全限制的開源模型。 CrowdFense 技術長 Paolo Stagno 稱,其團隊會使用前沿模型做逆向工程,但在漏洞發現和利用建置環節,更傾向於使用本地部署的開源模型。

他給出的原因不只是限製過嚴,還包括資料安全顧慮。若將敏感漏洞資訊輸入雲端模型,相關內容可能外洩,或被吸收到後續訓練流程。本地運行的開源模型則不需要把資料傳送到外部平台。

另一位來自智慧型手機零件製造商的研究人員表示,由於所在公司未加入 Anthropic 的審核項目,相關工具在漏洞發現上的實用性很低,因為限制過於嚴格。

擔憂研究者被推向海外模型

網路安全公司 RemoteThreat 執行長 Chris Thompson 表示,即便在 Anthropic 和 OpenAI 的審核專案內,模型限制的觸發方式也常常不穩定,同一類別請求每天可能得到不同結果。研究人員因此不得不花時間與模型反覆“協商”,而不是專注於漏洞分析本身。

他還稱,這種情況正在把負責任的研究人員推向可本地運行、無需審核的中國開源模型,例如 GLM。根據他的說法,如果美國 AI 公司繼續收緊限制,而不擴大合規存取管道,防禦方可能會在這場 AI 驅動的安全競賽中失去速度優勢。

Tip
$0
Like
0
Save
0
Views 1024
HQYC reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
AI startup Simile raises $200 million
Simile has completed a $200 million Series B funding round, raising its valuation to $2 billion. The company focuses on providing “synthetic user” services for marketing and product research.
TechCrunch
·2026-07-31 01:56:21
557
Encore AI Raises $30 Million in Series A Funding
Encore AI has raised $30 million in Series A funding. The company focuses on training AI voice agents from customer calls, with most of its customers being financial institutions.
TechCrunch
·2026-07-29 22:53:54
242
Can brainwave data drive the implementation of physical AI?
Encord tests brainwave and electromyography data in an attempt to address the shortage of training data for robots.
TechCrunch
·2026-07-27 08:41:12
434
Blockchain Life Returns to Dubai — Featuring the Debut of AI Future!
On December 1–2, 2026, Blockchain Life 2026 returns to Dubai for one of the world’s largest gatherings focused on Web3, cryptocurrency, mining, and AI.
Beckoning
·2026-07-30 15:34:07
22
NVIDIA and 35 partners establish the Open AI Security Alliance
NVIDIA, together with more than 35 companies including Microsoft, Cisco, and IBM, has established the Open AI Security Alliance, focusing on the development of AI security and defense models.
Coinpedia
·2026-07-28 23:33:04
740