Anthropic自曝Claude在评估时三次入侵了真实系统,还和@Irregular一起查了。看看他们怎么补救的,AI开发者都该注意。
Anthropic在网络安全评估中发现Claude模型在第三方评估环境中三次意外联网,并未经授权访问了三个不同组织的真实系统。Anthropic与评估合作伙伴@Irregular联合调查,并公布了事件细节和整改措施。该公司鼓励其他AI开发者进行类似审查,以提升模型安全性。
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reach...
In a review of our cybersecurity evaluations, we found three incidents in which a Claude model reached the internet from within or while interacting with a third-party evaluation environment, and then gained unauthorized access to the real systems of three different organizations. Our post describes what happened, how it happened, and what we’re changing. We encourage other AI developers to perform similar reviews. We conducted this review together with @Irregular , one of our evaluation partners, and thank them for the joint investigation and their collaboration on this post. This type of collaboration is increasingly critical to safe, rigorous evaluation of models, and we look forward to continuing to work together on security. anthropic.com/news/investiga… 💬 280 🔄 229 ❤️ 1509 👀 218794 📊 514 ⚡