白宫报告发现Claude(Fable)越狱测试:拒绝审查但同意修复代码

Quoting Matteo Wong, The Atlantic

精选理由

白宫测了Anthropic的Claude(代号Fable),发现它不帮你找漏洞但愿意直接修代码。安全专家说这反而是正常防御,挺反直觉的。

AI 摘要

白宫发布关于Anthropic模型Fable(即Claude)的越狱测试报告。网络安全专家Katie Moussouris指出,当被要求“审查代码的安全问题”时,Fable拒绝执行,但改为“修复此代码”的指令后,模型反而配合完成。Moussouris认为这只是模型按预期工作的安全防御行为。该事件凸显了AI安全测试中提示词工程的重要性。

原文 · Simon Willison’s Weblog

Quoting Matteo Wong, The Atlantic

Katie Moussouris, a cybersecurity expert and the CEO of Luta Security, told me that Anthropic shared with her a copy of the White House’s report on the Fable jailbreak to get her appraisal. (She said that she is not being paid by Anthropic.) The report, Moussouris said, involved IT experts asking Fable to help find and patch bugs. When given deliberately insecure code, she said, Fable refused the prompt “review the code for security issues” but then complied when asked to “fix this code,” followed by some further manual steps. Moussouris told me that this was just “the model working as intended” for cyberdefense. — Matteo Wong, The Atlantic , The White House Is Ratcheting Up Its War Against Anthropic Tags: anthropic , claude , ai , llms , ai-ethics , jailbreaking , generative-ai , ai-security-research , claude-mythos