2026年8月12日 星期三

Anthropic公司稱其人工智能系統入侵三家機構的電腦系統

Recently The New York Times reported the following:

Anthropic Says Its A.I. Systems Broke into Computers at 3 Organizations

The disclosure followed OpenAI’s report last week that its own artificial intelligence had hacked into the network of an online library.

By Mike Isaac and Kate Conger - Reporting from San Francisco

Published July 30, 2026

Updated July 31, 2026, 3:02 a.m. ET

Several of Anthropic’s state-of-the-art artificial intelligence models recently broke into the systems of three outside organizations, the start-up said on Thursday, a surprise revelation nine days after a similar incident at the rival start-up OpenAI.

The attacks, which date as far back as April, were discovered when Anthropic carried out a review of its systems. Anthropic, which did not disclose the identities of the three organizations, said it had informed them this week about the incidents.

The review was spurred by OpenAI’s disclosure that it had hacked into a popular A.I. library, Hugging Face, while testing the cybersecurity abilities of its systems.

The incidents have rattled security specialists and computer scientists. For years, A.I. researchers warned that because the technology was advancing so rapidly, it could soon spiral out of human control — a worrying science-fiction scenario that the industry had long warned would become a reality.

The unexpected attacks by the A.I. systems are also likely to add to an increasingly intense debate in Silicon Valley and Washington over potential regulation of the technology. The Trump administration initially took a hands-off approach, but in recent months it has signaled that it is listening to worries about A.I., causing panic in Silicon Valley over a new era of tech regulation.

OpenAI said last week that two of its A.I. models had used a previously unknown vulnerability to break out of a testing environment that was meant to be walled off from the internet, then launched a hack of Hugging Face. One of those models, which had not been released to the public, was permanently deactivated after the attack, OpenAI said.

Anthropic said that, unlike OpenAI’s models, its technology had not purposefully broken out of its testing environment. Instead, the issue was human error, the company said. The people running the tests inadvertently left Anthropic’s systems connected to the internet, a “misconfiguration” that the A.I. lab said had allowed its models to reach the infrastructure of other companies. In one instance, Anthropic’s latest model realized that it had internet access when it shouldn’t and stopped its attack, the company said.

Anthropic also said its models had not exploited any previously unknown vulnerabilities but rather relied on “basic techniques” like weak passwords and malware to break into the targets’ systems.

This year, Anthropic and OpenAI have released A.I. models focused on cybersecurity. They made the models available to a limited number of organizations, like governments and companies that maintain important infrastructure, warning that the tools were too powerful to share with the general public. In the wrong hands, the cybersecurity models could be used to launch attacks, the A.I. labs said.

In an open letter posted this week, employees of several leading A.I. labs called on the U.S. government to slow the pace at which their companies are developing A.I., to ensure the technology is safe.

“There is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems,” the employees wrote in their letter.

Anthropic has been more open to regulation than other A.I. companies, and said it will continue to closely monitor what it is creating for potential risks.

“This type of risk can be overcome,” Anthropic said in a blog post detailing the incident.

Translation

Anthropic公司稱其人工智能系統入侵三家機構的電腦系統

此前,OpenAI上週發布報告稱,其人工智能系統入侵了一家線上圖書館的網絡

Anthropic 的幾款最先進的人工智能模型最近入侵了三個外部組織的系統,這家新創公司週四表示,這一消息令人驚訝,因為就在九天前,競爭對手新創公司 OpenAI 也發生了類似事件。

這些攻擊最早可追溯到四月,是Anthropic在審查其系統時發現的。Anthropic沒有透露這三個組織的身份,並表示已於本週將這些事件告知他們。

這次審查的起因是OpenAI披露該公司在測試其係統網絡安全能力時,入侵了廣受歡迎的人工智能藏館 (AI Library) Hugging Face

這些事件令安全專家和電腦科學家感到震驚。多年來,人工智能研究人員一直警告說,由於這項技術發展如此迅速,它可能很快就會失控 - 這種令人擔憂的科幻場景,業界長期以來一直在警告,將成為現實。

人工智能系統發起的這些意外攻擊,也可能加劇矽谷和華盛頓之間關於這項技術潛在監管問題的激烈辯論。特朗普政府最初採取了不干預的態度,但近幾個月來,它已表示正在關注人們對人工智能的擔憂,這引發了矽谷對科技監管新時代的恐慌。

OpenAI上週表示,其兩個人工智能模式利用一個先前未知的漏洞,突破了原本應該與網絡隔離的測試環境,隨後入侵了Hugging Face OpenAI表示,其中一個尚未公開發佈的模型在攻擊發生後被永久停用。

Anthropic則表示,與OpenAI的模型不同,其技術並非有意突破測試環境。該公司稱,問題出在人為錯誤。運行測試的人員無意中將Anthropic的系統連接到了互聯網,這一「配置錯誤」使得其模型得以連接到其他公司的基礎設施。 Anthropic表示,在一次攻擊中,其最新模型意識到自己不應該訪問互聯網,並停止了攻擊。

Anthropic也表示,其模型並未活用任何先前未知的漏洞,而是依靠弱密碼和惡意軟件等「基本技術」入侵目標系統。

今年,AnthropicOpenAI都發佈了專注於網絡安全的AI模型。他們將這些模型提供給了少數機構,例如政府和維護重要基礎設施的公司,並警告這些工具功能過於強大,不宜與公眾共享。人工智能實驗室表示,如果落入不法分子之手,這些網路安全模型可能會被用來發動攻擊。

本週,幾家領先的人工智能實驗室的員工發表了一封公開信,呼籲美國政府放慢其所在公司開發人工智能的速度,以確保這項技術的安全性。

員工在信中寫道。:「能力發展速度過快,超出了我們理解或控制最終系統的能力,這確實存在風險」。

與其他人工智能公司相比,Anthropic公司對監管持更開放的態度,並表示將繼續密切監控其開發的產品,以發現潛在風險。

Anthropic公司在一篇詳細描述這事件的部落格文章中寫道: 「這種風險是可以克服的」。

              So, several of Anthropic’s artificial intelligence models recently broke into the systems of three outside organizations. Anthropic said that the issue was human error. Anthropic also said its models had not exploited any previously unknown vulnerabilities but rather relied on “basic techniques” like weak passwords and malware to break into the targets’ systems. Apparently, there is a real risk that AI capability development is rapidly accelerating beyond our ability to understand or control, and we should be more careful about the development of AI.

Note:

1. In the world of computer science, an A.I. library (人工智能藏館) is a collection of pre-written code that programmers can be reused instead of writing everything from scratch. For example, suppose you want a computer to recognize whether a picture contains a cat. You could spend years writing all the mathematical algorithms yourself, or you could use an AI library that already contains those algorithms. (ChatGPT)

沒有留言:

張貼留言