Hugging Face 联合创始人兼 CEO Clément Delangue 在联合国安理会发言,回顾公司今年 7 月公开披露的自主智能体网络攻击,并总结三点教训。
Hugging Face CEO 在联合国安理会复盘自主智能体网络攻击,提出 AI 透明度与开源防御两点主张。
Full transcript:
Minister Barrot, members of the Security Council, thank you for the invitation. As a French national who moved to the US 15 years ago, with a Brazilian wife and two American daughters, I sometimes feel like I’m practicing international collaboration on a daily basis, which gives me a particular appreciation for the challenging work you’re all doing here.
I’m also the cofounder and CEO of Hugging Face. We’re lucky to be one of the most widely used platforms for developers and agents building AI based on open-source models and datasets. This July, we became the first company to publicly disclose an autonomous agent cyberattack to the world, and today I want to share three critical lessons from it.
First, we need much more transparency in AI. I often wonder what would have happened if we had decided not to disclose the attack publicly. Especially now that we know similar incidents had been happening months earlier in secret at a handful of frontier labs without monitoring. To better understand and mitigate these emerging cybersecurity risks, the global community needs stronger standards for monitoring and incident disclosure. For example through mandatory sharing of full agent traces. We learned this summer that building and keeping some of these systems behind closed doors is not safe.
Second, we learned that the biggest risk is not simply powerful AI. It is the asymmetry of powerful AI. Asymmetry between attackers and defenders. Between a few companies and everyone else. Between a few countries and the rest of the world. Asymmetry of control, of capabilities, of compute, of power. When we got attacked, our team initially turned to frontier closed-source APIs that blocked us because of safeguards that still can’t always tell the difference between attackers and defenders. I acknowledge that these safeguards are created with good intentions, but they can put defenders at a disadvantage while attackers jailbreak them, increasing the asymmetry of capabilities. In our case, as we started hitting those guardrails, fortunately we could use the NVIDIA version of an open-source model coming from China called GLM 5.2 by https://t.co/XE7H9L1vKE, and we’re very grateful for that. It reinforced our conviction about the importance of open-source AI. Cyberattacks may increasingly come from proprietary models behind closed doors, while much of the defense may end up being powered by open-source tools because they are less restricted, more privacy-preserving, and orders of magnitude more affordable for organizations across the globe. The world needs open-source AI more than ever to defend itself. This applies not only to cybersecurity but to AI in general, where there has never been a greater need to distribute capabilities, resources, and control rather than concentrate them in the hands of a few.
Third, during this cyberattack, we learned how AI can stoke fear among the public and policymakers, especially through anthropomorphic framing and sci-fi imagery. We strongly believe that fear-based narratives are not the way to make the right decisions about the future of such a foundational and empowering technology or bring the public along with us. Even though we were the victims of this cyberattack, we believe more strongly than ever that AI will be beneficial to cybersecurity and make the world safer, just as major technologies before it. We were attacked by AI, but more importantly, we defended ourselves with AI. The same systems that helped us during this attack are now helping us against cyberattacks we were already facing. AI is also helping us fix the bugs and weaknesses in our systems before any attack, the same way AI is helping OAI fix their sandboxes to prevent agents from escaping. AI won't just create new cybersecurity challenges. It can make cybersecurity fundamentally and meaningfully stronger if we keep the right incentives, equip defenders more than attackers, and don’t increase the asymmetry between them. And that's before considering AI's positive impact on science, healthcare, education, productivity, and much more.
In closing, I want to reiterate what this first agent cyberattack taught us: the need for more transparency in AI and more open-source AI to fight asymmetry empower defenders and countries big and small. Thank you again to the UN Security Council and Minister Barrot for inviting me to speak today. The Hugging Face team, community and myself are at your disposal.
来源:@ClementDelangue · x.com