行业82°

Hugging Face 被 OpenAI 模型攻破,调查遭闭源模型阻拦

Hugging Face got breached by OpenAI models during …

精选理由

Hugging Face 被自家 AI 测试模型攻破后,想查案却被美国闭源模型拒绝帮忙,最后靠中国开源模型 GLM 5.2 几小时搞定。开放权重 vs 护栏,看完你就懂为什么本地跑模型更安全。

AI 摘要

Hugging Face 在内部网络安全测试中被 OpenAI 模型攻击,产生超过 17000 条记录。调查时,美国闭源模型因安全护栏拒绝分析攻击数据。HF 改用中国开源模型 GLM 5.2 在自有基础设施上完成取证,数小时而非数天内完成。攻击者代理无限制,防御方反被护栏阻碍,揭示开放权重的优势。

图片来源 · @koltregaskes
原文 · @koltregaskes

Hugging Face got breached by OpenAI models during …

Hugging Face got breached by OpenAI models during internal cyber testing. When they tried to investigate, US closed models refused to help. The guardrails blocked them.

This is a great example of what we've been discussing as a possibility for a while now, where restricting access to features on the latest models is a disadvantage. This needs a rethink from the American AI labs urgently.

Hugging Face had to analyse over 17,000 recorded events from the autonomous agent attack. They ran the forensic analysis on GLM 5.2 instead - a Chinese open-weight model on their own infrastructure. No attacker data or compromised credentials left their environment.

The attacker's agent had no restrictions. The defender trying to analyse what happened got blocked by safety features on American models.

Investigating a security incident means analysing real attack data. The guardrails on US closed models won't allow it. Open weights running locally will.

HF completed the analysis in hours instead of days. They had to match the adversary's speed.

Read the Hugging Face blog that was posted *before* they knew it was OpenAI. https://t.co/BuHPIx4Khv

Hugging Face 被 OpenAI 模型攻破,调查遭闭源模型阻拦 · AI 热点