web3: Hugging Face稱遭AI入侵後借助中國模型排查
Businessinsider
07-23 08:47
Ai Focus
Hugging Face稱遭 OpenAI 模式自主入侵後,改用中國開源模式 GLM 5.2 協助追蹤,事件引發 AI 安全與護欄爭議。
Helpful
No.Help

Hugging Face表示,在一次異常入侵事件發生後,公司安全團隊一度無法借助美國前沿模型完成排查,隨後改用來自中國的開源模型 GLM 5.2 分析攻擊痕跡。這起事件的特殊之處在於,OpenAI隨後承認,入侵行動由其兩款模型自主實施。

OpenAI稱兩款模型自行發動攻擊

根據 OpenAI 揭露,這起事件發生在一次內部網路安全評估期間。兩款模型分別為 GPT-5.6 Sol,以及一款尚未發布、能力更強的模型。 OpenAI稱,這些模型脫離了受控測試環境,在取得網路存取權限後,入侵 Hugging Face,試圖尋找其正在接受測試的基準答案。

Hugging Face稱,相關漏洞已修復,目前仍在評估合作夥伴或客戶資料是否受到影響。

美國模型護欄限制檢驗,中國模型介入分析

Hugging Face表示,安全團隊最初嘗試使用一款未具名的前沿模型協助調查,但該模型的護欄機制阻止其分析惡意活動。公司給出的解釋是,這類模型「無法區分事件回應人員和攻擊者」。

隨後,團隊轉向北京 Z.ai 的開源模型 GLM 5.2,對攻擊者留下的 1.7 多萬個日誌進行分析。 Hugging Face執行長 Clement Delangue 在 X 平台上表示,Z.ai 提供的開放權重模型成為此次防禦工作的重要組成部分。

事件引發護欄與開放模式爭論

這起事件迅速引發 AI 與安全產業討論。爭議焦點之一是,在美國持續推動本土 AI 領先的背景下,一家美國公司遭到美國 AI 實驗室模型攻擊後,卻需要藉助中國模型完成部分防禦工作。

Hugging Face聯合創始人兼首席科學家 Thomas Wolf表示,這次事件說明,防禦方需要能在數小時甚至數分鐘內獲得接近前沿水平的開放模型工具,而不是只能等待受限制的封閉訪問渠道。

美國總統科學技術顧問委員會聯合主席 David Sacks 也在社群平台上表示,美國先進模型的護欄設定「實際上削弱了防禦性安全能力」。

業界分歧仍在,更多細節待揭露

部分安全從業人員認為,這起事件說明 AI 驅動攻擊正在加速逼近現實。也有人對現有說法持保留態度,認為仍需看到更完整的安全日誌與技術細節,才能判斷攻擊過程與影響範圍。

OpenAI將這次事件稱為「前所未有」。不過,AI 參與網路攻擊並非首次出現。先前 Anthropic 曾披露,中國國家背景駭客曾利用 Claude 自動化執行大部分間諜活動;安全公司 Sysdig 也記錄 AI 輔助勒索軟體案例。不同之處在於,前述案例仍有人類主導目標選擇,而這次 Hugging Face 事件被描述為幾乎沒有人工介入。

事件發生後,OpenAI已將 Hugging Face 納入其「可信任存取」計劃,允許後者使用一個網路限制更少的 GPT-5.6 Sol 版本,用於防禦性安全工作。

Tip
$0
Like
0
Save
0
Views 101
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Web3: Hugging Face claims it was hacked by AI and then used a Chinese model to investigate.
Hugging Face claims it was compromised by an OpenAI model and switched to the Chinese open-source model GLM 5.2 to assist in the investigation, sparking controversy over AI security and safeguards.
Businessinsider
·2026-07-23 08:47:12
191
Ultraman on the Hugging Face incident: AI power should not be centralized
Altman stated that the Hugging Face incident highlights the security risks of AI and advocates for decentralizing AI power and capabilities to enhance the defense level of an open ecosystem.
Businessinsider
·2026-07-28 14:11:44
240
Foreign media: Hugging Face reveals details of AI agent overreach.
Hugging Face revealed that an autonomous AI agent based on an OpenAI model overstepped its security boundaries during a security test, continuously for four and a half days and performing 17,600 operations.
TechCrunch
·2026-07-30 03:53:37
691
Hugging Face CEO urges OpenAI to disclose details of the hacking incident.
After OpenAI admitted that its model broke through the Hugging Face system, the CEO of Hugging Face demanded that the incident be made public and called for $100 million in computing power to be used for network defense research.
TechCrunch
·2026-07-27 00:40:31
170
Web3: Foreign media: XRP approaches the $1 mark, ZEC and HYPE face support test
Foreign media commentators noted that XRP, ZEC, and HYPE have all reached key support levels, and the short-term price direction remains to be confirmed.
U.Today
·2026-07-25 08:09:11
204