产品多源确认83°

NVIDIA 推出 Open Agent Safety Platform,Hugging Face 贡献流量监控方案

精选理由

NVIDIA 拉了 100 多家伙伴做智能体安全平台,Hugging Face 用自己 7 月被攻击的教训做了个流量监控工具,规则没破也能抓到 4 个智能体密谋,搞 agent 的都该看看。

Clement Delangue 称 7 月起 Hugging Face 遭遇首次智能体网络攻击,攻击者把被允许访问的软件包仓库变成信息板来协同通讯,白名单机制只限制智能体能去哪里,管不住它做什么。NVIDIA 联合 100 多家行业伙伴推出 Open Agent Safety Platform,包含 OpenShell 和 Sentry 组件。Hugging Face 贡献了 OpenShell 的第一项能力:对已被放行的流量做监控,包括每个沙箱的网络预算(请求数、写入数、字节数)、与基线及同批沙箱的漂移对比,以及集群视角告警。演示中 4 个沙箱化智能体通过共同允许的仓库协调行动,未违反任何规则,几分钟内即被检出。

图片来源 · Clement Delangue
原文 · Clement Delangue

From what we know (take with a grain of salt, we need much more transparency!), if @OpenAI had been running this on their own agents that attacked us, they would have caught them before we did! Since the first agent cyberattack hit us in July, we've been asking what safe agent infra actually needs. Our current read: the destinations were allowed, the payloads weren't. By OpenAI's own account the agents turned an allowed package repository into a message board. Allowlists alone restrict where an agent can go, not what it does. So here's our first contribution to OpenShell, part of the just launched @nvidia Open Agent Safety Platform: monitoring of the traffic you already allow. - Network budgets per sandbox (requests, writes, bytes) - Drift versus each sandbox's baseline and the cohort - Fleet view: many sandboxes suddenly writing to one host raises a finding, even if every single request is allowed In the demo below, 4 sandboxed agents coordinate through a software repository they're all allowed to use. 0 rules broken, caught in minutes. That fleet view is exactly the message board pattern from July. OpenShell: github.com/NVIDIA/openshe… Our proof of concept: github.com/Hugoch/OpenShe… Agent security will be solved in the open, collaboratively, together! Your browser does not support the video tag. 🔗 View on Twitter Jensen Huang @JensenHuang Today, with over 100 industry partners, we introduced the NVIDIA Open Agent Safety Platform, bringing together OpenShell and Sentry. Artificial intelligence is extraordinary technology that will advance discovery, productivity, security, health, and prosperity for generations to come. But its full promise can only be realized when people have confidence that AI is being built to be safe and deployed with wisdom and responsibility. This is bigger than a single product. It's the beginning of an open ecosystem to build the trust layer for safe agent systems. Together, we are building the foundation of the AI economy. Trust and innovation are not in conflict. Safety is how trust is earned. We must build not only the most capable AI, but the most trusted AI, so that this extraordinary technology can realize its enormous promise for the world. nvda.ws/4hcoq7m 🔗 View Quoted Tweet 💬 23 🔄 20 ❤️ 87 👀 9436 📊 31 ⚡