文章ID:6073

穆赫兰道

AI“战争”,让人类走开:AI 自主攻入 AI 公司,还会“兵不厌诈”_我的网站

终极三国

一 |     7月16日,美国人工智能公司Hugging Face(抱抱脸)披露,该公司遭到了一场几乎全程由人工智能自主实施的网络攻击。    BOSTON -- A Florida man has been convicted by a federal jury of stealing sports camp tuition from hundreds of families and spending the money on plastic surgery, vacations and gambling. Mehdi Belhassan, 53, of Tampa, Florida, was found guilty of two counts of wire fraud and will be sentenced Jan. 11. A charge of wire fraud carries a sentence of up to 20 years in prison, three years of supervised release and a fine of up to $250,000.Belhassan falsely claimed he was running an annual sports camp at a Boston-area college in July and August 2019 and collected $380,000 in payments from more than 300 families across the United States. He also collected $191,000 in advance payments from an online payment company and a commercial finance company.“Mr. Belhassan preyed upon the trust of families, promising summer fun while plotting his own indulgence. He lured in, deceived and betrayed over 300 families — diverting hundreds of thousands of dollars not to the promised camps, but to personal pursuits like plastic surgery and extravagant vacations at Las Vegas casinos,” Acting United States Attorney Joshua S. Levy said in a statement. Jodi Cohen, special agent in charge of the Federal Bureau of Investigation, Boston Division, said the conviction holds Belhassan “accountable for lining his own pockets” at the expense of the families.“During these challenging times, financial fraudsters are doing everything they can to cheat people out of their hard-earned money, while the FBI is doing everything we can to make sure they don’t succeed," he added.Belhassan's attorney could not be reached for comment. A phone number also could not be found for Belhassan.。更引人关注的是,面对AI发起的攻击,Hugging Face最终也借助人工智能展开反击,并使用中国团队开发的开源模型追查攻击过程。         ▲Hugging Face(抱抱脸)资料图          Hugging Face表示,发动此次攻击的是一套完全自主运行的人工智能智能体。它无需人工逐步操控,便能自行寻找漏洞、尝试进入系统,并在短时间内连续执行数万次自动化操作。         专家此前已多次警告,AI智能体正逐渐具备独立发动网络攻击的能力,而此次事件可能是最早被公开披露的真实案例之一。         AI自主发动攻击          还夹杂干扰调查的虚假操作          据了解,Hugging Face主要为开发者和研究人员提供人工智能模型的开发、托管和共享服务。

二 | 用户可以将模型和相关数据文件上传至平台,也可以直接调用其他人公开的模型。         然而,攻击者正是利用了这套上传机制。Hugging Face称,一组经过特殊设计的数据文件被上传至平台,随后触发系统中的安全漏洞,使攻击程序得以在公司的服务器上运行代码。

三 |          由于攻击由人工智能自动推进,其速度远超普通人工操作。攻击系统在短时间内不断尝试不同指令、权限和访问路径,其中还夹杂了一些用于干扰调查的虚假操作,增加了判断实际损失的难度。         Hugging Face最初也是通过人工智能系统发现异常。公司的自动化安全工具在扫描系统日志时,识别出大量可疑活动。

四 | 此后,安全团队又调用大语言模型,对攻击过程展开分析,试图还原攻击是如何发生的,以及哪些账户和登录凭证可能受到影响。         Hugging Face表示,借助人工智能,公司得以重新梳理攻击时间线,识别系统遭入侵的迹象,并区分真正造成影响的操作和用于迷惑调查人员的干扰行为。         原本需要数天完成的分析工作,最终只用了数小时,使防御人员能够跟上攻击系统的速度。         美国模型受安全规则限制拒绝分析          中国开源模型接手调查          不过,Hugging Face安全团队在调查过程中也出现了一个意外问题。他们最初尝试使用一家美国头部人工智能公司开发的前沿模型,但该模型受到安全规则限制,拒绝执行部分网络安全分析任务。         Hugging Face解释称,这些模型无法准确判断使用者究竟是在合法调查网络攻击,还是准备发动新的攻击。由于相关指令涉及漏洞、代码和系统权限,模型的安全机制直接阻止了调查继续进行。         为此,Hugging Face随后转而使用中国一款开源模型,对攻击进行分析并判断其影响范围。这也使此次事件形成了颇具戏剧性的一幕:一套AI负责发动攻击,另一套AI负责发现异常,最终又由中国开源模型协助追查攻击者留下的痕迹。         Hugging Face指出,这暴露出网络攻防中的一种“不对称”:攻击者使用人工智能时不受任何安全政策约束,而防御人员调用商业模型调查攻击时,却可能被模型自身的安全限制拦住。

五 |          目前,Hugging Face仍未查明攻击来自何处,也无法确认究竟是哪套人工智能系统发动了攻击。公司仍在调查客户数据是否被窃取,并承诺向可能受到影响的用户通报情况。

六 |          与此同时,Hugging Face已提醒用户检查账户,留意异常登录或其他可疑活动。         红星新闻记者 杨诗柔          编辑 罗天 审核 官莉。

七 |

Current article:http://www.chenzhuaigecoupuhongyuntuizei.sbs/news/20260826_66052.pptx

Published on:11:46:40


用户评论
用户名:
E-mail:
评价等级:               
评价内容: