Foreign media: AI security restrictions are slowing down attack and defense research
TechCrunch
07-24 09:07
Ai Focus
Foreign media reports that cybersecurity restrictions on AI models are affecting legitimate research work, leading some researchers to turn to local open-source models.
Helpful
No.Help

TechCrunch reports that AI companies have been tightening restrictions on the use of their models in cybersecurity scenarios in recent months. Restrictions originally designed to prevent abuse by malicious attackers are now impacting the productivity of legitimate defense teams and offensive security researchers. The crux of the controversy lies in the fact that the same set of capabilities can be used to both patch vulnerabilities and discover and exploit them, making it difficult for platforms to completely separate the two.

US model restrictions continue to tighten

The report mentions that the US government imposed export controls on Anthropic's Mythos and Fable models in June, at least in part, due to a report that claimed the security restrictions on these models could be bypassed and used to build or execute malicious cyberattacks.

Fable 5 subsequently reopened to the public on July 1st, while Mythos 5 only reopened to approved U.S. institutions and remains under government review. In addition to Anthropic, OpenAI also has a review program for cybersecurity researchers, allowing approved users to use models with fewer restrictions.

Researchers say it affects vulnerability verification

Several security researchers interviewed believe that current restrictions are beginning to hinder normal research processes. Chris Anley, chief scientist at NCC Group, stated that allowing models to attempt to exploit a flaw is a crucial step in determining whether it constitutes a real vulnerability. If the model directly refuses to respond, it becomes more difficult for defenders to determine whether the issue requires priority fixing.

He argues that requiring a model to "fix this code" inherently possesses both defensive and offensive attributes. This is because fix suggestions often expose critical weaknesses in the code, making it difficult for a platform to retain only defensive uses while completely eliminating offensive capabilities.

Security researcher Mark Dowd also criticized the practice, saying it's unsettling to have large AI companies unilaterally decide which security research is "safe." The report points out that Dowd has long been involved in zero-day vulnerability discovery and trading, and therefore he acknowledges that his stance may be biased professionally.

Some teams are shifting to local open-source models.

Some respondents indicated that when mainstream closed-source models cannot complete a task due to limitations, they would switch to open-source models without security restrictions. Paolo Stagno, CTO of CrowdFense, stated that his team uses cutting-edge models for reverse engineering, but prefers locally deployed open-source models for vulnerability discovery and exploit building.

His reasons included not only overly strict restrictions but also data security concerns. If sensitive vulnerability information is input into a cloud-based model, the relevant content could be leaked or incorporated into subsequent training processes. Locally running open-source models, on the other hand, do not require sending data to external platforms.

Another researcher from a smartphone component manufacturer said that because his company was not part of Anthropic's audit program, the tools were of little use in vulnerability discovery due to overly strict restrictions.

Concerns that researchers are being pushed to overseas models

Chris Thompson, CEO of cybersecurity firm RemoteThreat, stated that even within the review programs of Anthropic and OpenAI, the triggering methods for model restrictions are often inconsistent, with the same type of request potentially yielding different results each day. Researchers are thus forced to spend time repeatedly "negotiating" with the model, rather than focusing on vulnerability analysis itself.

He also stated that this situation is pushing responsible researchers towards locally run, uncensored Chinese open-source models, such as GLM. According to him, if US AI companies continue to tighten restrictions without expanding compliant access channels, defenders may lose their speed advantage in this AI-driven security race.

Tip
$0
Like
0
Save
0
Views 309
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Foreign media: Loop Capital is optimistic about CrowdStrike benefiting from AI security demand.
Loop Capital states that the AI-driven era will drive up enterprise security needs, and CrowdStrike is seen as a potential beneficiary.
CNBC
·2026-07-28 19:13:06
627
Foreign media: Hugging Face reveals details of AI agent overreach.
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
TechCrunch
·2026-07-30 03:53:37
698
Foreign media: Nadella warns companies not to entrust all AI to one company.
Nadella stated that companies that rely too heavily on a single AI provider may lose control of their data and products, and should retain the use of data and adopt a multi-model architecture.
TechCrunch
·2026-07-28 05:22:19
599
Foreign media: US anxiety about Chinese AI models is being amplified.
TechCrunch commented that the debate surrounding Chinese AI models in the United States has been significantly amplified, and the restrictions may benefit a small number of cutting-edge U.S. labs more.
TechCrunch
·2026-07-27 04:51:31
643
Altman says AI development may need to be slowed down to address security risks.
Altman stated that as model capabilities improve, AI development may need to slow down to allow security systems and society to adapt to new risks.
TechCrunch
·2026-07-29 04:22:06
778