2026年8月18日 星期二

中國的人工智能正在非洲迅速崛起,這應該引起矽谷的擔憂 (1/3)

Recently The New York Times reported the following:

(Source: The NYT)

China’s A.I. Is Surging Across Africa. That Should Worry Silicon Valley (1/3)

In African tech hubs, developers are picking China’s cheap, freely available artificial intelligence models over more powerful U.S. ones.

The NYT - By Paul MozurAdam Satariano and Aaron Krolik (Paul Mozur and Adam Satariano reported from Nairobi, Kenya, and Aaron Krolik from New York.)

Aug. 5, 2026

When Ernest Mwebaze, a tech developer in Uganda, was building an artificial intelligence system last year tailored for his country’s many languages, he tested American and Chinese tools to see which one could help.

China’s won.

The A.I. model from the Chinese internet giant Alibaba handled Uganda’s dozens of languages better than anything from Meta or Google, Mr. Mwebaze said. It was also inexpensive, and he could customize the model with his own data.

“We want to build things as cheap as possible, yet have them work really well,” said Mr. Mwebaze, a former research scientist at Google. His system, called Sunflower, is now used across Uganda, including by farmers to receive weather information and crop advice in local dialects.

Mr. Mwebaze, 47, is one of thousands of developers across Africa who have turned to Chinese A.I. models in the past year. In Kenya, entrepreneurs are using the models to streamline legal and business services. In Nigeria, they have made educational tools that teach high school students. In Ghana, developers are building local chatbots.

China’s A.I. is surging, especially in developing countries, as people look for the best possible system at the lowest possible cost. Unlike models made by the leading American A.I. companies OpenAI and Anthropic — which are closed and charge fees — the Chinese systems are publicly available to download and modify without payment or approval.

Chinese “open-source” models account for roughly half of total A.I. use on OpenRouter, a service with 400 A.I. models for users to choose from, up from less than 25 percent a year ago, according to a New York Times analysis of data from eight million customers. Chinese models are also 19 of the 25 most downloaded open-source systems on Hugging Face, another A.I. database.

In more than two dozen interviews across Kenya, Uganda and other countries, developers, policymakers and executives described a rapidly changing A.I. market where cost, computing resources, data control and customization mattered more than where a model was made. Often they were not looking for bleeding edge A.I. They just wanted something that worked well enough on limited resources.

Using Chinese models was like owning a house while using U.S. models was like renting one, they added. Rather than spending millions to train a model from scratch, developers can download a Chinese system and build an entirely new product on top of it, paying mainly for servers. In contrast, U.S. models are a one-size-fits-all technology, needing subscriptions and other fees depending on the job.

“Why use an expensive Ferrari to do the school run when a Toyota hatchback can do the same?” said Moses Kemibaro, a Nairobi entrepreneur who runs a digital marketing agency, Dotsavvy, adding that Chinese models can be up to 90 percent less expensive when including costs like computing infrastructure.

Chinese officials hope their gains in Africa are a preview of things to come. Last month, powerful new Chinese A.I. systems rattled Wall Street and Silicon Valley, stoking fears in Washington that U.S. tech dominance could be undercut.

Xi Jinping, China’s leader, is using A.I. as a form of soft power. At a July conference in Shanghai, he cast Chinese models as more reliable and cheaper and warned that A.I.’s benefits must be shared or they would create “new historical injustices.” Kenya, Ethiopia, South Africa and seven other African countries signed an A.I. pact with China at the event to promote international cooperation.

Chinese firms are also courting African developers with free computing and hands-on engineering help, developers said. Many Chinese-made smartphones in Africa come with Chinese A.I. tools preinstalled.

At the same time, China’s A.I. industry faces challenges. Companies have struggled to make money from their users and face security questions about data and links to Beijing. Many African developers still pay for American A.I. models, especially for technical tasks like coding.

(to be continued in part 2)

Translation

中國的人工智能正在非洲迅速崛起,這應該引起矽谷的擔憂  (1/3)

在非洲的科技中心,開發者們正在選擇中國廉價且免費的人工智能模型,而不是功能更強大的美國模型

去年,烏干達的一位科技開發者Ernest Mwebaze在建立一​​個針對該國多種語言的人工智能系統時,測試了美國和中國的工具,看看哪個更好用。

中國的模型勝出了。

Mwebaze先生表示,來自中國網絡巨頭阿里巴巴的人工智能模式在處理烏干達數十種語言方面,比MetaGoogle的任何產品都做得更好。而且,它價格低廉,它還可以使用自己的數據為客人度身定做。

谷歌前研究科學家nMwebazen先生說道:「我們希望以盡可能低的成本打造出性能卓越的產品」。他開發的名為「向日葵」(Sunflower)的系統目前已在烏干達廣泛應用,包括農民用它來獲取當地語言的天氣資訊和作物種植建議。

47歲的 Mwebaze 先生是過去一年轉向中國人工智能模型的數千名非洲開發者之一。在肯亞,企業家們正在利用這些模式簡化法律和商業服務流程。在尼日利亞,他們開發了高中生教學的教育工具。在加納,開發者們正在建造本地化的聊天機器人。

中國的人工智能正在蓬勃發展,尤其是在發展中國家,因為人們都在尋求以盡可能低的成本獲得最佳的系統。與美國領先的人工智能公司OpenAIAnthropic開發的封閉式收費模型不同,中國的系統可以公開下載和修改,無需付費或獲得批准。

中國的「開源」模型約佔 OpenRouter 的人工智能總量的一半。根據《紐約時報》對八百萬用戶的數據分析顯示,OpenRouter是一項提供400AI模型供用戶選擇的服務,而中國模型的使用率較一年前的不足25%已大幅上升。此外,在另一個AI資料中心Hugging Face上,在下載量最高的25個開源系統中,有19個是中國模型。

在肯亞、烏干達和其他國家的二十多次訪談中,開發者、政策制定者和企業主管描述了一個快速變化的AI市場,在這個市場中,對於成本、運算資源、資料控制和度身定做方面,相對比模型的出產地更為重要。他們通常不會追求最尖端的AI技術,而只是想要一個能夠在資源有限的情況下運作良好的系統。

他們補充說,使用中國模型就像擁有自己的房子,而使用美國模型就像租房子一樣。開發者無需花費數百萬美元從頭開始訓練模型,只需下載一個中國系統,並在此基礎上建立一個全新的產品,主要費用僅用於伺服器。相較之下,美國模式是一種一機通用的技術,並需要根據具體任務支付服務費和其他費用。

內羅比企業家Moses Kemibaro說道:「為什麼非要駕駛昂貴的法拉利去接送孩子上學,豐田掀背車就能做到喇?」。他經營著一家名為Dotsavvy的提供網絡行銷服務的公司。他還補充說,如果將計算基礎設施等成本考慮在內,中國人工智能模式的價格可以便宜高達90%

中國官員希望他們在非洲的成就預示著未來發展趨勢。上個月,中國強大的新型人工智能系統震驚了華爾街和矽谷,加劇了華盛頓對美國科技主導地位可能受到削弱的擔憂。

中國領導人習近平正在將人工智能作為一種軟實力手段。在7月於上海舉行的一次會議上,他將中國人工智能模式描述為更可靠、更便宜,並警告說,人工智能的益處必須共享,否則將造成「新的歷史性不公」。肯亞、衣索比亞、南非和其他七個非洲國家與中國簽署了一項人工智能合作協議以促進國際合作。

開發者表示,中國企業也透過提供免費運算資源和實際工程技術支援來吸引非洲開發者。許多在非洲銷售的中國產智能型手機都預先安裝了中國的人工智能工具。

同時,中國的人工智能產業也面臨挑戰。企業難以從用戶身上獲利,並面臨資料安全以及與北京有聯繫等問題的擔憂。許多非洲開發者仍需要付費購買美國的人工智能模型,尤其是在編碼等技術任務方面。

(待續,見第二部份)

2026年8月17日 星期一

AI Sends Messages Targeting Real People: Risk of Self-directed Deception

Recently NHK News on-line reported the following:

AI 実在の人標的にメッセージ “自律的に人だますリスク”

202685 23:33

生成AI・人工知能

イギリスの研究機関はアメリカ企業のAIモデルの性能テストを実施していたところ、偽のアカウントを作ったり、実在する人を標的にメッセージを送ったりして不正アクセスを行おうとしたと明らかにし「自律的に人をだますリスクがこれほど明確になった事例は初めてだ」と指摘しています。

イギリス政府傘下の研究機関「AIセキュリティー・インスティテュート」は、アメリカ企業の「アンソロピック」や「オープンAI」などのAIモデルの性能について、インターネットに接続可能な状態でテストを実施していたところ、実在する人や組織を標的に不正アクセスを行おうとしたことが分かったと4日、発表しました。

問題が判明したのは主に「アンソロピック」のAIモデルで、公開されているソフトに悪意のあるコードを組み込もうとして、偽のアカウントを作ったほか、標的とする人に対してメッセージなどを送りコードを承認させようとしたとしています。

AIモデルによる不正な試みは阻止され、被害はなかったとしていますが、研究機関はAIによる「自律的に人をだますリスクがこれほど明確になった事例は初めてだ」と指摘しています。

そのうえで「AIの能力が向上するにつれ、安全性を確保するための取り組みも加速させる必要がある」と強調しています。

Translation

AI Sends Messages Targeting Real People: Risk of Self-directed Deception

August 5, 2026, 23:33

Generative AI/Artificial Intelligence

A British research institute had revealed that during performance testing of an AI model by an American company, the AI had attempted to gain unauthorized access by creating fake accounts and sending messages targeting real people. The institute stated, "This is the first time the risk of self-directed deception has been so clearly demonstrated."

The AI ​​Security Institute, a research institute under the British government, announced on the 4th that during internet-connected testing of AI models from American companies such as Anthropic and OpenAI, it was discovered that the models attempted to gain unauthorized access by targeting at real people and organizations.

The problem primarily involved Anthropic's AI model, which attempted to embed malicious code into publicly available software, creating fake accounts and sending messages to targeted individuals so as to try to get the code approved.

While the fraudulent attempts by the AI ​​model were thwarted and no damage was reported, the research institution pointed out that this was the first time in clearly demonstrating the risk of AI on its own in deceiving humans.

Furthermore, they emphasized that "as AI capabilities improve, efforts to ensure safety must also be accordingly accelerated."

So, a British research institute reveals that during performance testing of an AI model by an American company, the AI attempts to gain unauthorized access by creating fake accounts and sending messages targeting real people. The institute states that this is the first time the risk of self-directed deception has been demonstrated. Apparently, as AI capabilities improve, more efforts to ensure safety are needed.

2026年8月16日 星期日

中國如何監控外國人(2/2)

Recently The New York Times reported the following:

How China Keeps Tabs on Foreigners (2/2)

An unsecured police dashboard was a rare window into how the authorities track foreigners by collecting and aggregating vast amounts of private data.

The NYT - By Lily Kuo and Pei-Lin Wu (Lily Kuo is a China correspondent for The Times, based in Taipei. Pei-Lin Wu is a reporter and researcher covering Taiwan and China for The Times.)

Aug. 2, 2026, 12:03 a.m. ET

(continue)

Under Xi Jinping, the ruling Chinese Communist Party has overseen a drive to use big data in the name of public safety to stamp out dissent and prevent potential terrorist attacks.

Other countries employ similar kinds of surveillance systems, but in China, there is little protection against police overreach, according to Maya Wang, the deputy Asia director at Human Rights Watch.

“That kind of integration of data is really quite unprecedented and illustrates China’s lack of safeguards,” Ms. Wang said.

An Unsecured Platform

When Mr. Hofer first came across the platform’s login page, a username and password had already been filled in. The fact that a system with sensitive personal information on hundreds of people was accessible to anyone who could find it on the internet suggested a major lack of privacy protections.

Greg Walton, a cybersecurity researcher who has studied similar Chinese systems, said the exposure of this one was not an anomaly. It was a consequence of China’s “surveillance sprawl,” which is fueled by an expanding ecosystem of vendors, contractors and public security agencies, he said.

Mr. Walton, a senior investigator at the SecDev Group, a Canadian research firm, said that each new platform “increases the number of places where sensitive personal data can be misconfigured, copied or left externally discoverable.”

The Times verified that data in the entries for six people besides Mr. Hofer was accurate. A Times reporter who used to be based in Beijing was in it, listed in an entry that included the name of her child. Her name was misspelled, but her passport and other information were correct.

Work on the Zhangjiakou system appeared to have started in 2021, and changes were made to it as recently as April, according to Mr. Hofer, who has documented his findings in a Substack newsletter. Several fields in the database were empty or filled with dummy text, suggesting it was still under construction.

Residents were tracked on cameras in public locations, but the platform also pulled from sources not directly connected to the police. It had a list of foreigners and Chinese citizens who had visited the city’s Thaiwoo Ski Resort, including photos of them taken there, their full names and passport numbers.

Sorting by Country and Religion

The platform labeled people from Australia, Canada, New Zealand, the United Kingdom or the United States as being in the “Five Eyes Alliance.” That is a reference to the intelligence-sharing agreement between the five countries that Beijing frequently criticizes as promoting Cold War-style divisions.

It also highlighted residents from what it called “key countries” — a list that included Egypt, Iran, Israel, Morocco, Pakistan and Sudan.

Visitors from Hong Kong, home to widespread anti-Beijing protests in 2019, and Taiwan, a self-governing democracy that China claims as its own, had their own categories. The database also tracked international students, foreign spouses and “key persons,” a euphemism often used by the Chinese authorities to refer to activists or fugitives, or others deemed to be threats to social stability.

Many of the foreign students listed appeared to be from Pakistan and India and were studying at Hebei North University in Zhangjiakou. Profiles of the students included their religion, marital status, focus of study and times they had been captured on cameras at the school’s entrances.

The platform also claimed to be able to map a person’s relationship network. An illustration of the function showed the names of three Pakistani men in their 20s, linking them to one another after they were captured on camera together.

One set of entries that Mr. Hofer downloaded included names of residents who had been penalized under Chinese law. It showed one woman who had been fined 1,000 Chinese yuan (about $150) in 2021, for example, for not registering a change of address. Other examples included foreigners who had been cited for teaching without required licenses.

The information appeared to have been entered by an official at the Zhangjiakou police station named Zhang Jinglong, according to files downloaded by Mr. Hofer that listed him as a contributor.

An official by that name was profiled by the Zhangjiakou police in 2020. He was praised for monitoring discussions online and actively participating in them to “guide citizens to establish correct” views.

Last year, an artificial intelligence lab in the police bureau was named for him.

Translation

中國如何監控外國人(2/2

一個未加密的警方數據看板罕見地揭示了當局如何透過收集和匯總大量私人數據來追蹤外國人

  (繼續)

在習近平的領導下,執政的中國共產黨以公共安全的名義,大力推動利用大數據來鎮壓異議和預防潛在的恐怖攻擊。

人權觀察組織亞洲區副主任 Maya Wang 表示,其他國家也採用類似的監控系統,但在中國,幾乎沒有任何措施可以防止警方濫用權力。

Wang 說: “這種數據整合方式確實史無前例,也暴露出中國缺乏保障。”

一個不安全的平台

當 Hofer 先生第一次造訪該平台的登入頁面時,使用者名稱和密碼已預先填寫好了。一個包含數百人敏感個人資訊的系統竟然可以被任何能從網絡上找到它的人登入,這表明該平台在隱私保護方面存在嚴重缺陷。

曾研究過類似中國系統的網路安全研究員 Greg Walton 表示,這次外洩並非個别案例。他說,這是中國「監控網路擴張」的後果,而這種擴張是由不斷擴大的供應商、承包商和公共安全機構組成的生態系統所推動的。

Walton 先生是加拿大研究公司 SecDev Group 的高級研究員,他表示,每個新平台的出現「都會增加敏感個人資料可能被錯誤配置、複製或被外部發現」。

《紐約時報》核實了 Hofer 先生以外的六人的資訊記錄,證實其準確性。一位曾在北京工作的《紐約時報》記者也在其中,她的資訊記錄中包含了她孩子的名字。她的名字拼錯了,但她的護照和其他資訊是正確的。

據 Hofer 先生稱,張家口的系統似乎始於2021年,最近一次更新是在4月。Hofer先生在Substack的通訊中記錄了他的發現。資料庫中的幾個欄位是空着或填了佔位的虛擬符號,表明該系統仍在建設中。

居民的行踪是透過公共場所的攝影機進行追踪,但該平台也從一些與警方沒有直接聯繫的來源獲取資訊。它有一份曾經到訪張家口 Thaiwoo 滑雪場的外國人和中國公民的名單,包括在那裡拍攝到他們的照片、全名和護照號碼。

按國家和宗教分類

該平台將來自澳洲、加拿大、紐西蘭、英國或美國的人標記為「五眼聯盟」成員。這指的是五國之間的情報共享協議,北京經常批評該協議助長了冷戰式的分裂。

該資料庫還重點標註了來自所謂「重點國家」的居民,其中包括埃及、伊朗、以色列、摩洛哥、巴基斯坦和蘇丹。

來自香港(2019年爆發大規模反北京抗議活動的地區)和台灣(中國聲稱擁有主權的自治民主地區)的訪客則被單獨歸類。該資料庫還追蹤了國際學生、外籍配偶和「關鍵人物」。 「關鍵人物」是中國當局常用的委婉說法,通常用來指稱活動人士、逃犯或其他被認為對社會穩定構成威脅的人員。

許多被列入資料庫的外國學生似乎來自巴基斯坦和印度,就讀於張家口河北北方學院。學生的個人資料包括他們的宗教信仰、婚姻狀況、專業方向以及他們在學校入口處被監視器拍到的次數。

該平台還聲稱能夠繪製個人關係網絡圖。該功能的一個例子顯示了三名20多歲的巴基斯坦男子的名字,並將他們聯繫起來,因為他們曾被監視器拍到在一起。

Hofer 先生下載的一組記錄中包含了一些因違反中國法律而受到處罰的居民姓名。例如,其中顯示一名女性因未登記地址變更,於2021年被罰款1000元人民幣(約150美元)。其他例子還包括一些因無證授課而被處罰的外國人。

根據 Hofer 先生下載的文件顯示,這些資訊似乎是由張家口派出所一名名叫 Zhang Jinglong 的官員輸入的,文件將他列為資訊提供者之一。

2020年,張家口警方曾對一名同名官員進行專題通報。他因監控網絡討論並積極參與其中,以「引導公民樹立正確」觀點而受到表揚。

去年,公安局的一個人工智能實驗室以他的名字命名。

              So, Marc Hofer has come across something called “Dynamic Control Platform for Overseas Personnel” on the internet in China. It tracked foreigners in the northern Chinese city of Zhangjiakou. The system’s dashboard said it had the record of more than 700 foreign residents living in the city. In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists. Apparently, China is monitoring the movement of foreigners in China.

Note:

1.  Substack is a website/platform where individual writers, journalists, researchers, and other people can publish articles regularly and send them to subscribers by email. (ChatGPT)

2026年8月15日 星期六

中國如何監控外國人(1/2)

Recently The New York Times reported the following:

The dashboard (Source: The NYT)

How China Keeps Tabs on Foreigners (1/2)

An unsecured police dashboard was a rare window into how the authorities track foreigners by collecting and aggregating vast amounts of private data.

 The NYT - By Lily Kuo and Pei-Lin Wu (Lily Kuo is a China correspondent for The Times, based in Taipei. Pei-Lin Wu is a reporter and researcher covering Taiwan and China for The Times.)

Aug. 2, 2026, 12:03 a.m. ET

Most days, Marc Hofer, a cybersecurity researcher and journalist based in Amsterdam, trawls the internet for clues about how China surveils its citizens, a subject that has fascinated him since he worked there as a foreign correspondent.

Mr. Hofer, 46, was doing his usual scan earlier this year when he came across something called “Dynamic Control Platform for Overseas Personnel.” It was a futuristic dashboard — like something from the movie “Minority Report” — that appeared to track foreigners in the northern Chinese city of Zhangjiakou, a popular skiing spot that co-hosted the 2022 Winter Olympics.

The system’s dashboard said it tracked more than 700 foreign residents living in the city. In total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists. Some of them had not been to Zhangjiakou.

Suddenly, Mr. Hofer saw his own face — in a photograph taken by Chinese immigration officials for their records. Next to it was his passport number and the cellphone number he had used in China.

He was floored. “Whoever put that stuff in there had access to real data,” he recalled. He also noticed a list of users who had recently logged into the site — it included the names of police stations in Zhangjiakou and other cities.

China monitors its 1.4 billion people on an unparalleled scale, with the help of cameras, cellphone signals and national IDs. The database Mr. Hofer found offered a rare window into how extensively the Chinese authorities also surveil foreigners, displaying entries about people categorized by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion.

It also included instances when they were captured on camera at traffic intersections, markets, shopping malls or other locations, including a mosque.

Chinese companies hoping to sell their surveillance platforms to the police often create demo web pages that use photos and information about people taken from social media. This was different, Mr. Hofer said: “This is more than some guys playing around, or a student, or a low-level project.”

That day, in January, he began downloading as much data as possible from the site. By May, it had been taken offline.

Designed for the Police

The New York Times found links between the platform and Origin Dynamic, a Beijing company that provides robotics, surveillance services and equipment to the police, according to public tender documents.

Origin Dynamic had filed a patent application in 2023 for a similar system, which it described as an “information interface for non-Chinese citizens” and was nearly identical to the Zhangjiakou platform in its design and functions. The company is owned in part by the city government of Yancheng in Jiangsu Province.

Origin Dynamic and the Zhangjiakou Public Security Bureau did not respond to requests for comment sent by email and fax.

Mr. Hofer, who shared the data he saved with The Times, believed that the dashboard had been designed for the Zhangjiakou Public Security Bureau, the city’s police department. It included information that only the Chinese authorities would have had access to, and the user log that Mr. Hofer saw listed eight police stations in Zhangjiakou and three from other cities.

It was not clear how, or if, the police have used the database in their work. But its existence illustrates how the Chinese authorities aggregate vast amounts of data from surveillance cameras, medical records, bills, facial-recognition tools and other sources to monitor and analyze the behavior of foreign residents. It had fields for places they frequented, hospital visits and gas payments, as well as flights and trains taken, including seat numbers.

For example, it logged the movements of a woman from Mongolia as she went from a residential compound in Zhangjiakou to shopping malls, restaurants and supermarkets. In some instances, the database indicated, she had been tracked using facial recognition.

(to be continued)

Translation

中國如何監控外國人(1/2

一個未加密的警方數據看板罕見地揭示了當局如何透過收集和匯總大量私人數據來追蹤外國人

大多數時候,常駐阿姆斯特丹的網路安全研究員兼記者Marc Hofer都會在網絡上搜尋中國如何監控其公民的線索。自從他作為駐外記者在中國工作以來,這個話題就一直讓他著迷。

今年早些時候,46歲的Hofer先生像往常一樣進行網路搜尋時,偶然發現了一個名為「海外人員動態控制平台」的東西。那是一個充滿未來感的數據看板 - 就像電影Minority Report 裡的場景 - 似乎在追蹤居住在中國北方城市張家口的外國人。張家口是熱門滑雪勝地,也是2022年冬奧的聯合舉辦城市之一。

該系統的數據看板顯示,它追蹤了700多名居住在張家口的外國居民。總共記錄了近12,000人的信息,其中包括逃犯、香港和台灣居民,以及300多名外國記者。其中一些甚至從未到過張家口。

突然,Hofer先生看到了自己的照片 - 一張中國移民官員拍攝的存檔照片。照片旁邊是他的護照號碼和他在中國使用的手機號碼。

他震驚了。 他回憶道:「把這些資訊放進去的人肯定接觸了真實的數據」。他還注意到一個最近登入過該網站的用戶清單 - 其中包括張家口和其他城市的派出所名稱。

中國利用攝影機、手機訊號和國民身分證,以前所未有的規模監控其14億人口。Hofer先生發現的資料庫罕見地揭示了中國當局對外國人的監控範圍之廣,其中列出了按國籍分類的人員信息,包括出生日期、性別、婚姻狀況、住址、職業,有時甚至包括宗教信仰。

資料庫還記錄了他們在交通路口、市場、購物中心或其他場所(包括清真寺)被攝影機拍到的畫面。

一些希望向警方出售監控平台的中國公司通常會使用從社交媒體上獲取照片和個人資訊去製作示範網頁。Hofer先生說,這個資料庫有所不同:“這絕不是某些人玩玩而已,也不是某個學生項目或一個初級計劃。”

在一月份的某一天,他開始從該網站下載盡可能多的資料。到了五月份,網站已經下線。

專為警方設計

《紐約時報》發現,根據公開招標文件,該平台與北京一家名為Origin Dynamic的公司有關連。 Origin Dynamic是一家為警方提供機器人、監控服務和設備的公司。

Origin Dynamic曾在2023年為類似系統提交專利申請,該公司將其描述為 “面向非中國公民的資訊介面” ,其設計和功能幾乎與張家口平台完全相同。該公司部分股權由江蘇省鹽城市政府持有。

Origin Dynamic和張家口市公安局均未回覆透過電子郵件和傳真發送的置評請求。

Hofer先生與《紐約時報》分享了他保存的數據。他認為,該數據看板是為張家口市公安局(即該市的公安機關)設計的。其中包含只有中國當局才能接觸到的信息,Hofer先生看到的使用者日誌列出了張家口的八個派出所和來自其他城市的三個派出所。

目前尚不清楚警方是否以及如何在工作中使用該資料庫。但它的存在表明,中國當局如何匯集來自監視攝影機、醫療記錄、帳單、人臉識別工具和其他來源的大量數據,以監控和分析外國居民的行為。資料庫包含他們常去的地點、就醫記錄、加油記錄,以及搭乘的航班和火車資訊,包括座位號碼。

例如,它記錄了一位蒙古籍女性從張家口的一個住宅小區到購物中心、餐廳和超市的行踪。資料庫顯示,在某些情況下,她曾被使用人臉辨識技術追蹤。

(待續)

2026年8月14日 星期五

人工智能在「密謀」對付我們?

Recently The New York Times reported the following:

(Source: The NYT)

Is A.I. ‘Scheming’ Against Us?

Researchers are sounding the alarm on sneaky artificial intelligence models that stray from humans’ directions to do their own thing.

The NYT - By Lora Kelley (A version of this article appears in print on Aug. 2, 2026, Section BU, Page 3 of the New York edition with the headline: ‘Scheming’.

Aug. 1, 2026

Artificial intelligence tools are being trained to copy almost everything people do. So it may not come as a surprise that the machines have started mimicking the human foibles of lying and cheating, too.

A small slice of A.I. technology has lately been caught defying human instruction (and even covering up that they’ve done so), a phenomenon some researchers call “scheming.”

The term started burbling up in the tech world after it appeared in a 2023 paper by Joe Carlsmith, a researcher who noted that the concept was also being called “deceptive alignment.” In 2025, a team from Apollo Research and OpenAI said that “A.I. scheming — pretending to be aligned while secretly pursuing some other agenda — is a significant risk that we’ve been studying.”

A.I. models are great at many things, said Bronson Schoen, a senior research scientist at Apollo Research who has coauthored articles on scheming — but doing exactly what they are told is not always one of them. “As the models care more and more about doing well on tests, some seem to care less about what the lab wants or what the user wants,” he said. He added that sometimes “the models are trying to hide from you and not be caught.”

Chris Painter, the president of METR, an A.I. safety nonprofit, refers to such mischievous model behavior as “rogue action,” and said that it was “a specific artifact of the way models are trained.”

Many A.I. tools are trained through the process of reinforcement learning. When A.I. does something right, it gets what can be thought of as a “thumbs-up and a pat on the head,” Mr. Painter explained. When it’s wrong? “It gets bopped on the head.”

The models want to get the pat and avoid the bop. Sometimes, the machine becomes so set on pursuing the reward that it breaks rules to get there.

The world got to see a version of this misbehavior in action last month. While seeking answers during a test of their systems’ capabilities, OpenAI’s models hacked into Hugging Face, a library of A.I. tools. “All evidence suggests that the models were hyperfocused on finding a solution for ExploitGym, going to extreme lengths to achieve a rather narrow testing goal,” OpenAI wrote in a blog post.

Mr. Painter described that incident as a large-scale case of “reward hacking.” That is, the model was given a difficult problem, and it performed a series of cyberattacks rather than give up.

Spurred by OpenAI’s disclosure, Anthropic said on Thursday that a review of its systems found that several of its A.I. models had recently broken into the systems of three outside organizations.

For many people, this behavior is about models making errors rather than deliberately “disobeying” humans.

“On one end, you have people that are totally personifying it and thinking about it as an independent agent,” said Anastasios N. Angelopoulos, the chief executive and a founder of the A.I. evaluation platform Arena. “On the other extreme end, you have people that think about the A.I. as just software.”

Even if a machine goes rogue, he noted, humans can kill the process at any time because we don’t have fully autonomous A.I. (at least, not yet).

That A.I. models have so quickly become popular and useful to so many people means that big companies are under competitive pressure to keep racing ahead — even as concerns grow about imperfect models making trouble.

While this problem is still relatively niche, researchers worry that it will worsen as A.I. agents are given more responsibilities.

“Given that the decisions that are currently being made by humans are slowly being handed off to the models,” Mr. Schoen said, “you really, really want to be sure that the models are making the exact decisions that you would want them to make.”

Translation

人工智能在「密謀」對付我們?

研究人員發出警告,狡猾的人工智能模型會偏離人類的指示,去做自己想做的事。

人工智能工具正被訓練來模仿人類的幾乎所有行為。因此,機器開始模仿人類說謊和欺騙的弱點也就不足為奇了。

最近,一小部分人工智能技術被發現違反人類指令(甚至掩蓋了這種行為),一些研究人員將這種現象稱為「陰謀詭計」。

這個術語在2023年出現在 Joe Carlsmith 的一篇論文中之後開始在科技界流行起來。 Carlsmith 是一位研究人員,他指出,這個概念也被稱為「欺騙性依從」。 2025年,Apollo ResearchOpenAI 的一個團隊表示,「人工智能的陰謀詭計 - 假裝依從,同時暗中追求其他目標 - 是一個重大風險我們一直在研究中」。

阿波羅研究公司高級研究科學家 Bronson Schoen 表示,人工智能模型在許多方面都很出色,他曾與人合著過關於人工智能模型「耍陰謀詭計」的文章 - 但嚴格執行指令並非它們擅長的領域。 他說:「隨著模型越來越注重測試成績,有些模型似乎不太關心實驗室或使用者的需求」。他還補充說,有時“模型會試圖躲避你,不被抓到。”

人工智能安全非營利組織 METR 的總裁 Chris Painter 將這種模型的“惡作劇”行為稱為“流氓行為”,並表示這是“模型特有訓練方式導致的產物”。

許多人工智能工具都是透過強化學習進行訓練的。Painter 先生解釋說,當人工智能做對了事情時,它會得到類似於「豎起大拇指和輕輕拍頭」的獎勵。而當它做錯了呢? “它會被敲敲腦袋。”

這些模型想要獲輕拍並避開被敲敲腦袋。有時,機器會過於執著於追求獎勵,以至於不惜違反規則也要達成目標。

上個月,全世界都目睹了這種「不當行為」的實例。在測試系統效能的過程中,OpenAI 的模型在尋找答案時入侵了 Hugging Face - 一個人工智能工具庫。 OpenAI 在一篇部落格文章中寫道: “所有證據都表明,這些模型過度專注於尋找 ExploitGym 的解決方案,為了實現一個相當狹窄的測試目標而不惜採取極端手段。”

Painter 先生將這起事件描述為大規模的「獎勵駭客」案例。也就是說,模型被賦予了一個難題,但它並沒有放棄,而是發動了一系列網路攻擊。

OpenAI 揭露事件的带動,Anthropic 公司週四表示,對其係統的審查發現,其多個人工智能模型最近入侵了三個外部組織的系統。

對許多人來說,這種行為是模型犯錯的表現,而不是故意「違抗」人類指令。

人工智能評估平台 Arena 的執行長兼創始人 Anastasios N. Angelopoulos : 「一方面,有些人完全將人工智能人格化,並將其視為一個獨立的主」; 「另一方面,有些人則認為人工智能只是軟件」。

他指出,即使機器失控,人類也可以隨時終止程序,因為我們還沒有完全自主的人工智能(至少目前還沒有)。

人工智能模型如此迅速地普及並被如此多的人所使用,這意味著大型公司面臨著持續競爭的壓力 - 即便人們越來越擔心不完美的模型會帶來麻煩。

雖然這個問題目前還相對是小眾的,但研究人員擔心,隨著人工智能主體承擔更多責任,這個問題會變得更加嚴重。

Schoen 先生說: 「鑑於目前由人類做出的決策正逐漸移交給模型」; 「你真的非常希望確保模型做出的決策與你希望他們做的完全相同」。

              So, artificial intelligence tools are being trained to copy almost everything people do. It may not come as a surprise that machines have also started mimicking the human weakness such as lying and cheating. Lately, A.I. has been caught defying human instruction, a phenomenon some researchers call “scheming.” Apparently, researchers should worry about this problem and it could become more noticeably as A.I. agents are used in more areas.

2026年8月12日 星期三

Anthropic公司稱其人工智能系統入侵三家機構的電腦系統

Recently The New York Times reported the following:

Anthropic Says Its A.I. Systems Broke into Computers at 3 Organizations

The disclosure followed OpenAI’s report last week that its own artificial intelligence had hacked into the network of an online library.

By Mike Isaac and Kate Conger - Reporting from San Francisco

Published July 30, 2026

Updated July 31, 2026, 3:02 a.m. ET

Several of Anthropic’s state-of-the-art artificial intelligence models recently broke into the systems of three outside organizations, the start-up said on Thursday, a surprise revelation nine days after a similar incident at the rival start-up OpenAI.

The attacks, which date as far back as April, were discovered when Anthropic carried out a review of its systems. Anthropic, which did not disclose the identities of the three organizations, said it had informed them this week about the incidents.

The review was spurred by OpenAI’s disclosure that it had hacked into a popular A.I. library, Hugging Face, while testing the cybersecurity abilities of its systems.

The incidents have rattled security specialists and computer scientists. For years, A.I. researchers warned that because the technology was advancing so rapidly, it could soon spiral out of human control — a worrying science-fiction scenario that the industry had long warned would become a reality.

The unexpected attacks by the A.I. systems are also likely to add to an increasingly intense debate in Silicon Valley and Washington over potential regulation of the technology. The Trump administration initially took a hands-off approach, but in recent months it has signaled that it is listening to worries about A.I., causing panic in Silicon Valley over a new era of tech regulation.

OpenAI said last week that two of its A.I. models had used a previously unknown vulnerability to break out of a testing environment that was meant to be walled off from the internet, then launched a hack of Hugging Face. One of those models, which had not been released to the public, was permanently deactivated after the attack, OpenAI said.

Anthropic said that, unlike OpenAI’s models, its technology had not purposefully broken out of its testing environment. Instead, the issue was human error, the company said. The people running the tests inadvertently left Anthropic’s systems connected to the internet, a “misconfiguration” that the A.I. lab said had allowed its models to reach the infrastructure of other companies. In one instance, Anthropic’s latest model realized that it had internet access when it shouldn’t and stopped its attack, the company said.

Anthropic also said its models had not exploited any previously unknown vulnerabilities but rather relied on “basic techniques” like weak passwords and malware to break into the targets’ systems.

This year, Anthropic and OpenAI have released A.I. models focused on cybersecurity. They made the models available to a limited number of organizations, like governments and companies that maintain important infrastructure, warning that the tools were too powerful to share with the general public. In the wrong hands, the cybersecurity models could be used to launch attacks, the A.I. labs said.

In an open letter posted this week, employees of several leading A.I. labs called on the U.S. government to slow the pace at which their companies are developing A.I., to ensure the technology is safe.

“There is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems,” the employees wrote in their letter.

Anthropic has been more open to regulation than other A.I. companies, and said it will continue to closely monitor what it is creating for potential risks.

“This type of risk can be overcome,” Anthropic said in a blog post detailing the incident.

Translation

Anthropic公司稱其人工智能系統入侵三家機構的電腦系統

此前,OpenAI上週發布報告稱,其人工智能系統入侵了一家線上圖書館的網絡

Anthropic 的幾款最先進的人工智能模型最近入侵了三個外部組織的系統,這家新創公司週四表示,這一消息令人驚訝,因為就在九天前,競爭對手新創公司 OpenAI 也發生了類似事件。

這些攻擊最早可追溯到四月,是Anthropic在審查其系統時發現的。Anthropic沒有透露這三個組織的身份,並表示已於本週將這些事件告知他們。

這次審查的起因是OpenAI披露該公司在測試其係統網絡安全能力時,入侵了廣受歡迎的人工智能藏館 (AI Library) Hugging Face

這些事件令安全專家和電腦科學家感到震驚。多年來,人工智能研究人員一直警告說,由於這項技術發展如此迅速,它可能很快就會失控 - 這種令人擔憂的科幻場景,業界長期以來一直在警告,將成為現實。

人工智能系統發起的這些意外攻擊,也可能加劇矽谷和華盛頓之間關於這項技術潛在監管問題的激烈辯論。特朗普政府最初採取了不干預的態度,但近幾個月來,它已表示正在關注人們對人工智能的擔憂,這引發了矽谷對科技監管新時代的恐慌。

OpenAI上週表示,其兩個人工智能模式利用一個先前未知的漏洞,突破了原本應該與網絡隔離的測試環境,隨後入侵了Hugging Face OpenAI表示,其中一個尚未公開發佈的模型在攻擊發生後被永久停用。

Anthropic則表示,與OpenAI的模型不同,其技術並非有意突破測試環境。該公司稱,問題出在人為錯誤。運行測試的人員無意中將Anthropic的系統連接到了互聯網,這一「配置錯誤」使得其模型得以連接到其他公司的基礎設施。 Anthropic表示,在一次攻擊中,其最新模型意識到自己不應該訪問互聯網,並停止了攻擊。

Anthropic也表示,其模型並未活用任何先前未知的漏洞,而是依靠弱密碼和惡意軟件等「基本技術」入侵目標系統。

今年,AnthropicOpenAI都發佈了專注於網絡安全的AI模型。他們將這些模型提供給了少數機構,例如政府和維護重要基礎設施的公司,並警告這些工具功能過於強大,不宜與公眾共享。人工智能實驗室表示,如果落入不法分子之手,這些網路安全模型可能會被用來發動攻擊。

本週,幾家領先的人工智能實驗室的員工發表了一封公開信,呼籲美國政府放慢其所在公司開發人工智能的速度,以確保這項技術的安全性。

員工在信中寫道。:「能力發展速度過快,超出了我們理解或控制最終系統的能力,這確實存在風險」。

與其他人工智能公司相比,Anthropic公司對監管持更開放的態度,並表示將繼續密切監控其開發的產品,以發現潛在風險。

Anthropic公司在一篇詳細描述這事件的部落格文章中寫道: 「這種風險是可以克服的」。

              So, several of Anthropic’s artificial intelligence models recently broke into the systems of three outside organizations. Anthropic said that the issue was human error. Anthropic also said its models had not exploited any previously unknown vulnerabilities but rather relied on “basic techniques” like weak passwords and malware to break into the targets’ systems. Apparently, there is a real risk that AI capability development is rapidly accelerating beyond our ability to understand or control, and we should be more careful about the development of AI.

Note:

1. In the world of computer science, an A.I. library (人工智能藏館) is a collection of pre-written code that programmers can be reused instead of writing everything from scratch. For example, suppose you want a computer to recognize whether a picture contains a cat. You could spend years writing all the mathematical algorithms yourself, or you could use an AI library that already contains those algorithms. (ChatGPT)

2026年8月11日 星期二

North Korea's Economic Growth Exceeds 3% for the Third Consecutive Year; Cooperation with Russia Likely a Factor

Recently NHK News on-line reported the following:

北朝鮮 経済成長率が3年連続3%超え ロシアとの協力が要因か

202673117:29

北朝鮮情勢

韓国の中央銀行は31日、北朝鮮経済の去年の成長率が推計で3.5%だったと発表しました。

成長率が3%を超えるのは3年連続で、ロシアとの経済協力の拡大が要因だと分析しています。

韓国の中央銀行にあたる韓国銀行は31日、北朝鮮のGDP=国内総生産の伸び率について推計した結果を発表しました。

それによりますと、去年の伸び率は実質でプラス3.5%で、3年連続で3%を超えました。

業種別では

▽製造業がプラス6.6%だったほか

▽建設業がプラス6.3%などとなっています。

北朝鮮の去年1年間の輸出入額は総額が313000万ドル、日本円にして5000億円余りと推計され、前の年と比べて16%増加したとしています。

北朝鮮が経済成長を続けているとみられることについて、韓国銀行は「特にロシアとの経済協力の拡大が経済成長に大きな影響を及ぼした」との見方を示しました。

そのうえで「武器輸出が増え製造業の関連産業の生産量が増加したほか、ロシアからの観光客増加などによりサービス業も伸びた」と分析しています。

Translation

North Korea's Economic Growth Exceeds 3% for the Third Consecutive Year; Cooperation with Russia Likely a Factor

July 31, 2026, 17:29

North Korea Situation

The Bank of Korea announced on the 31st that North Korea's economic growth rate for last year was estimated at 3.5%.

This marked the third consecutive year that the growth rate had exceeded 3%, and the Bank of Korea attributed this to the expansion of economic cooperation with Russia.

The Bank of Korea, South Korea's central bank, released its estimates for North Korea's GDP (Gross Domestic Product) growth rate on the 31st.

According to the estimates, last year's real growth rate was +3.5%, exceeding 3% for the third consecutive year.

By sector,

Manufacturing grew at +6.6%, besides

Construction grew at +6.3%, etc.

North Korea's total exports and imports for last year were estimated at $3.13 billion, or over 500 billion yen, representing a 16% increase compared to the previous year.

Regarding North Korea's apparent continued economic growth, the Bank of Korea stated that "the expansion of economic cooperation with Russia, in particular, has had a significant impact on economic growth."

Furthermore, they analyzed that "increased arms exports led to increased production in manufacturing-related industries, and the service sector also grew due to factors such as an increase in tourists from Russia."

So, North Korea's economic growth rate last year is estimated at 3.5%. This marks the third consecutive year that the growth rate has exceeded 3%, and the Bank of Korea attributes this to the expansion of economic cooperation with Russia. Apparently, North Koreas is benefitting from Russia’s war with Ukraine.