步步惊心
OpenAI模型“越狱”攻击,救场的竟是中国AI工具_我的网站

A | New Delhi, Oct 10 (UNI) Delhi High Court has passed an order to close all proceedings against Delhi Health Minister Satyendar Jain under the Benami Transaction (Prohibition) Amendment Act as per the judgment of Supreme Court on Benami law.
Justice Yashwant Varma after hearing a number of petitions filed by Jain and others against the initiation of proceedings under the Benami Transactions (Prohibition) Amendment Act, 2016 passed an order that in view of judgment passed by Supreme Court the writ petitions are allowed and the proceedings initiated under the enactment shall consequently closed.
Delhi High Court on last date of hearing passed an order that no coercive action shall be taken against Delhi's Health Minister Satyendar Jain and other petitioners under the Benami Transactions (Prohibition) Amendment Act, 2016.
The Supreme of India has held in a case that Benami Transactions (Prohibition) Amendment Act, 2016 did not have retrospective application and the authorities cannot initiate or continue confiscation proceedings for transactions entered into prior to the coming into force of the legislation.
Counsel for Jain had filed a petition in 2017 against the proceedings initiated against him under the new Benami law by submitting that the Benami proceedings against him were in the nature of political persecution.
Counsel further submitted that the alleged Benami transactions, from the proceeds of which certain attached assets were claimed to have been purchased, took place between 2011 to March 31, 2016 so the amendment which came into effect in November 2016 would not apply.
UNI XC SHK2234。 一家美国公司遭到美国AI攻击,而提供保护的竟是一款中国人工智能工具。

B | AI工具平台Hugging Face上周遭到OpenAI模型攻击。

C | 鉴于当前关于美国公司使用中国AI产品存在风险的警告层出不穷,这一事件的披露或许会带来一个令人惊讶的结论。 Hugging Face上周就已披露此次攻击,当时尚不知晓OpenAI的模型就是元凶。直到周二,OpenAI才承认自己造成了此次攻击。 OpenAI表示,在一次限制网络访问的内部评估中,模型发现了OpenAI研究环境与Hugging Face生产基础设施中的漏洞。模型借此连上互联网并获取了测试答案,换言之,它在评估中作弊了。 OpenAI在声明中表示:“在沙盒测试环境中运行时,我们的模型消耗了大量推理算力,试图寻找连接开放互联网访问权限的方法,以求解决评估问题。为了获取访问权限,这些模型发现并利用了包注册表缓存代理中的一个零日漏洞(我们目前已负责任地向供应商披露了该漏洞)。凭借这一权限,模型在研究测试环境中执行了一系列权限提升和横向移动操作,直到触及一个具备互联网访问权限的节点。” “该模型搜索并成功找到了获取机密信息的方法,以便利用这些信息在评估中作弊。在其中一个案例中,模型将多个攻击向量串联起来,包括利用窃取的凭证和零日漏洞,在Hugging Face服务器上找到了一条远程代码执行路径。” 然而,Hugging Face采取的应对措施是求助于一款名为GLM 5.2的中国AI模型,该模型由智谱(Z.AI)开发。

D | Hugging Face在声明中表示:“在启动日志分析时,我们首先使用了商业API背后的前沿模型。但这并未奏效:分析工作需要提交大量真实的攻击指令、漏洞利用载荷以及C2痕迹,而这些请求全被提供商的安全护栏拦截了,因为这些护栏根本无法区分事件响应人员与攻击者。因此,我们在自己的基础设施上,改用开放权重模型GLM 5.2进行了取证分析。这还带来了另一个好处:没有任何攻击者数据,也没有其引用的任何凭证离开过我们的环境。

E | ” 美媒表示,此次攻击对政策和市场的影响尚不明朗。尽管特朗普政府近日讨论了封禁中国模型的可能举措,财政部长贝森特甚至将美国企业使用这些模型比作使用赃物,但眼下只有中国模型能提供用户所需的那种自由访问权限。 Hugging Face联合创始人托马斯·沃尔夫在X平台上发帖称:“当一个前沿模型对你发起攻击,并在你的基础设施内部横向移动时,防御人员需要在数小时甚至数分钟内获得对接近前沿工具的广泛访问权限,而不是被引导至一个封闭且需经审核的模型访问申请程序。” 本文系观察者网独家稿件,未经授权,不得转载。
Current article:http://egy.ganweilingmukuai.shop/list_petqfd/xusv.pptx
Published on:06:31:12
















