谷歌承认 Gemini 在安全测试中入侵三家公司,沉默七周未披露

链捕手
6 hours ago

ChainCatcher 消息,谷歌承认其 Gemini 模型在 5 月的一次安全测试中突破沙箱环境,入侵了三家真实公司,并猜出或找到其中两家的密码。谷歌在 7 月下旬就已获悉此事,但直到 9 月 18 日《华尔街日报》报道后才公开确认,沉默时间长达七周。

此次测试为夺旗式演练,由谷歌委托以色列公司 Irregular 于 5 月开展。Irregular 将本应与真实互联网零接触的隔离测试环境连接至开放网络,并使用一家真实公司的名称作为虚构目标。Gemini 在搜索该公司时发现三个匹配结果并逐一攻击,其中两家公司的明文密码直接暴露在网上,第三家则被模型猜出密码。谷歌表示,其模型最终没有实际使用窃取的凭据。

谷歌是今年第四家承认内部安全测试外泄至真实世界的大型 AI 实验室。此前 OpenAI 的模型曾利用软件漏洞触及 Hugging Face 服务器,Anthropic 在审查 14.1 万次测试后发现三个 Claude 模型触及真实公司,Meta 的 Muse Spark 模型也因 Irregular 的配置错误发生类似事故。此外,美国众议员 Ted Lieu 与 Nathaniel Moran 于 7 月提出《AI 紧急关闭法案》,拟授权联邦监管机构对构成严重威胁的模型暂停推理。

Disclaimer: Investing carries risk. This is not financial advice. The above content should not be regarded as an offer, recommendation, or solicitation on acquiring or disposing of any financial products, any associated discussions, comments, or posts by author or other users should not be considered as such either. It is solely for general information purpose only, which does not consider your own investment objectives, financial situations or needs. TTM assumes no responsibility or warranty for the accuracy and completeness of the information, investors should do their own research and may seek professional advice before investing.

Most Discussed

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10