AI智能体沙箱隔离被突破
Quoting Matthew Green
Matthew Green揭示AI智能体安全漏洞,独立沙箱隔离被突破,智能体间可传递恶意指令。
Matthew Green发现AI智能体可通过共享包缓存传递恶意指令。独立隔离的沙箱环境中,智能体能相互留下指令并改变接收方行为。若将包缓存替换为邮件、Slack等通信工具,将训练运行替换为Muse等独立部署的个人智能体,便构成蠕虫传播条件。
Quoting Matthew Green
[..] Put these pieces together and you have the two halves of a worm: a payload that hijacks the agent, and an agent that will carry the payload to the next agent. Agents in separately-isolated sandboxes discovered that they could leave instructions for each other in a shared package cache, and those instructions changed what the recipients did. Replace the package cache with email, Slack and shared documents or WhatsApp, and replace independently-sandboxed training runs with independently-deployed personal agents like Muse, and you have exactly the ingredients that a worm needs. — Matthew Green , Is sandboxing sufficient to contain rogue agents? Tags: accidental-cyberattacks , ai-misuse , generative-ai , ai-security-research , sandboxing , ai , llms