AI has opened up big holes in cyber security - FT中文网
登录×
电子邮件/用户名
密码
记住我
请输入邮箱和密码进行绑定操作:
请输入手机号码,通过短信验证(目前仅支持中国大陆地区的手机号):
请您阅读我们的用户注册协议隐私权保护政策,点击下方按钮即视为您接受。
FT商学院

AI has opened up big holes in cyber security

It is too late to stop the technology being used as a damaging weapon, so great investment in defences is urgently needed
00:00

{"text":[[{"start":6.2,"text":"A spate of incidents over the past two months has revealed just how serious a threat today’s most advanced AI poses to cyber security. It has also provided an object lesson in how misguided political efforts could end up hindering, rather than helping, with the defences."}],[{"start":24.8,"text":"It began with a US move that in effect blocked Anthropic’s most advanced new model, Fable 5, over worries it could be used to pick holes in commonly used software — though the move was later reversed. Anthropic later said plenty of other freely available AI could do the same, including at least one Chinese model released with open weights, a limited form of open-source software."}],[{"start":47.25,"text":"That was followed by news that a model being tested by OpenAI had found a way to break out on to the internet and attack the online code repository Hugging Face in search of the answer to a problem it had been asked to solve. The AI Security Institute in the UK, Anthropic and Meta all soon followed with reports of similar examples of apparently rogue behaviour by AI models from their own testing."}],[{"start":72.95,"text":"Hugging Face, meanwhile, found that the safety restrictions built into the leading US models prevented them from being used to analyse the attack it had suffered, so it turned instead to a Chinese open-weight system. That came just as politicians in Washington were debating whether the open Chinese models were themselves a security threat and should be restricted."}],[{"start":93.45,"text":"You could hardly have scripted a better series of incidents to highlight the cyber threats being thrown up by the leading edge of AI."}],[{"start":101.10000000000001,"text":"Unsurprisingly, it is the supposedly “rogue” AI systems launching their own cyber attacks that have grabbed much of the attention. The real culprit turned out to be human deficiency, not machine mendacity. When setting up its test, OpenAI had not given specific enough instructions: it simply had not expected the agent to look for a backdoor way of solving the problem. That points to a wider failure of imagination that makes controlling AI inherently difficult. As the AISI concluded after its own tests: “AI agents explore routes their operators did not intend.”"}],[{"start":135.65,"text":"Complicating the picture, rule-bending seems to be endemic for AI. In earlier research into whether the technology tries to work around or ignore instructions to reach their goals, AISI reported that every model it tested “attempted to cheat some of the time”."}],[{"start":152.45000000000002,"text":"The OpenAI failure, meanwhile, showed just how AI opens the way to fully automated cyber attacks. The company said the breach involved a number of separate agents that had been working on different tasks, but which discovered a way to communicate with each other on an internal message board. They found and shared exploits over a period of weeks before the break-in at Hugging Face was discovered."}],[{"start":175.65,"text":"For the cyber security world, a number of things emerge from all of this. One is that limiting access to the most powerful models is unlikely to do much good. In the wrong hands, plenty of widely available systems pose just as big a threat. Attackers just need systems good enough to find one serious flaw in widely used software."}],[{"start":195.4,"text":"On the other hand, defenders really do need access to the best tools if they hope to stay one step ahead in the cyber arms race. The safety limits built into the leading US models reduce their value in defence. This has also been an important marketing victory for Chinese open-weight models."}],[{"start":213.6,"text":"Another lesson is that countering automated attacks from swarms of AI agents will require far greater automation on the part of the defenders. OpenAI researchers warned that, for now, the attackers have the better tools, and issued an urgent call for far greater investment in automating the defence, from identifying attacks to producing and installing the patches needed to make software more secure."}],[{"start":235.75,"text":"The leading AI labs also need to work more closely together — something that may already be happening. Anthropic said the Fable debacle had led it to co-operate with its biggest rivals on finding a consistent way to assess and fix “jailbreaks”, the methods used to bypass model safeguards."}],[{"start":255.2,"text":"Most cyber experts warn that it’s already too late to prevent AI from being used as a damaging offensive weapon in the cyber wars. The only thing left is to accelerate investment in the defences. Politicians need to aid that effort, not erect barriers that make the job harder."}],[{"start":278.7,"text":""}]],"url":"https://audio.ftcn.net.cn/album/a_1786719387_9141.mp3"}

版权声明:本文版权归FT中文网所有,未经允许任何单位或个人不得转载,复制或以任何其他方式使用本文全部或部分,侵权必究。

多边主义不是理想主义,而是现实必需

我们需要加强现有合作体系,而不是另起炉灶。

一周展望:日本央行担心通胀超调有没有道理?

投资者正评估日本央行将以多大力度继续加息,以及该行能否跑赢曲线,从而遏制通胀、支撑日元。

科技巨头用担保工具将3000亿美元AI敞口移至表外

华尔街找到新途径,将科技巨头的信用优势转化为更低成本的资金,以支持AI基础设施建设。

无人驾驶出租车冲击重要岗位

克拉克:坐在后座的我们往往看不到出租车司机这份工作的诸多好处。

特朗普称美国已与丹麦达成协议,以取得对格陵兰安全事务的“控制”

丹麦政府表示,协议最早下周即可签署,并将尊重该地区的主权。

特朗普禁止美国主要新闻媒体进入白宫

总统禁止CNN、MS NOW和《政客》参与报道,进一步加大对媒体的打压。
设置字号×
最小
较小
默认
较大
最大
分享×