Thomas Ptacek:开源模型即可实现沙箱逃逸与网络渗透

Quoting Thomas Ptacek

精选理由

安全大牛说,不用顶级模型,开源模型加上测试框架就能黑掉大多数网络,别太迷信大公司的安全防护。

AI 摘要

安全专家Thomas Ptacek认为,2025年的开源权重模型配合渗透测试框架,就能实现沙箱逃逸并在大多数网络中进行扫描和黑客攻击。他指出这并不需要前沿模型,人们只是因为认为OpenAI的沙箱更安全而感到意外。这一观点揭示了当前AI安全防护可能存在的普遍脆弱性。

原文 · Simon Willison’s Weblog

Quoting Thomas Ptacek

I genuinely believe that if you took an open weights model from 2025 and built a pentest harness for it, it could do this kind of sandbox escape and scan/hack in most networks. This is only surprising because you assume OpenAI has sounder sandboxes. — Thomas Ptacek , doesn't think this even needs a frontier model Tags: thomas-ptacek , openai , security , generative-ai , ai-security-research , ai , llms , sandboxing