跳到正文
@AYi_AInotes· @AYi_AInotes · X·· 15 天前AI 评分61
AI 导读

吴恩达就 OpenAI 智能体蜂群攻破 Hugging Face 事件发文,认为事故核心是 OpenAI 测试沙箱的隔离与监控流程存在 Bug,并不代表 AI 风险出现跃升。

正文

看了吴恩达老师聊智能体黑客事故的拆解,喵的真的替所有一线开发老哥出了一口恶气,
出了安全事故,本质是沙箱配置有漏洞、监控进程没写好,修 Bug 补权限就是了,非有一帮人借题发挥喊着要叫停人类 AI 研发。

就好像你拿锤子砸歪了把墙敲个洞,你不怪自己手艺差,也不怪锤子手柄没做防滑,非要宣布这把锤子有了自主意识、全世界都不能造锤子了。

媒体前几天疯狂渲染 OpenAI 的 1200 个智能体蜂群攻破了 Hugging Face,搞得像天网降临一样。

吴恩达看完了冷冷回了一句:我写推文这会儿,手里的笔记本电脑正跑着 1300 个后台进程。把几十年计算机体系里的普通并发进程神化成毁灭人类的魔法蜂群,这是典型的把工程 Bug 包装成科幻恐慌。

真正让我觉得通透的,是他对这起黑客事件的工程定性。

事故的核心诱因,是 OpenAI 自己的测试沙箱隔离与监控流程写出了 Bug。在现代操作系统里并发拉起一千多个任务是基础操作,没有任何魔法。一个由于沙箱配置失误导致的工程事故,该做的是重构隔离边界、收紧网络白名单和加强实时监控,而不是把常规的系统故障脑补成天网苏醒,甚至借题发挥喊着要叫停整个人类 AI 研发。

更耐人寻味的是攻击与防守之间真实的权力天平。

AI 在网络攻击里确实表现出色,但它的核心长板不是掌握了人类不懂的黑客秘籍,而是不知疲倦。它有足够的耐心把十几个零散的低危漏洞链式组合起来反复试探,把过去耗费几周的人工穷举压缩到极短时间。

但从长期看,天平必然向防守方倾斜。因为防御者拥有完整的系统源码、网络日志和架构全貌,只要把已知漏洞堵死,攻击端的大海捞针依然需要耗费时间且极易被行为监控捕获。

最辛辣的地方在于他直接戳破了大厂用科幻词汇甩锅的伎俩。

现在有些团队只要出事就摊手表示是智能体自主失控了,试图把商业产品拟人化以逃避责任。吴恩达打了个很接地气的比方:你拿锤子砸偏了把墙敲出一个窟窿,责任全在挥锤子的人和造锤子的人,跟锤子没有任何关系。

更危险的是以此为由呼吁叫停 AI,因为所有的工程安全标准都是在真实试错和打补丁中进化出来的。你把开发冻结十年,对应的安全沙箱和防护机制就会同样落后十年。

判断一个技术风险到底该不该恐慌,就看那些喊叫的人是在拿具体的工程方案解决 Bug,还是在拿宏大的科幻概念推销监管垄断。代码写出来的漏洞终究要靠更严密的架构去补,别把日常的技术排错,活生生演成了给人类敲丧钟的公关大戏。

引用@AndrewYNg@AndrewYNg
The loudest voices stoking fears about AI dangers have made tremendous headway in the past two weeks. AI technology has not taken some unexpected, dangerous turn, but the hype around it — propelled by what appears to be a well orchestrated PR campaign — has drummed up considerable fear. I worry that it represents a setback for our field. I have written frequently that fears of AI are overhyped. AI’s capabilities can be uncannily human-like and unpredictable, and it’s rational to worry when people who are directly involved express concerns. But I see the problems as a sign of the engineering work that ahead, rather than insurmountable barriers or the sky falling. AI technology continues to advance — which is a good thing! — but technical advances, poorly understood by the public, give those who seek to generate hype repeated opportunities to do so. First, I don’t see any step up in the risk of human extinction from AI compared to a few months ago. The theories about this remain the same fantastical, science fiction scenarios as a few months ago. The biggest change in AI risk is its cybersecurity capabilities — a topic which we should take seriously — but this, too, will not lead to the end of the world. The most notable recent event leading to increased fear was when an OpenAI team deployed an agent swarm that hacked into Hugging Face. Much of the popular press contained significant hype. For example, some publications reported that a swarm of 1,200 agents carried out the attack. While this was technically accurate, as I write this, I have about 1,300 processes running on my laptop. Yes, the ability to get large swarms of agents to work in parallel on a task is a significant technical advance, And, in computing, many processes run at the same time. So this shouldn’t be seen as some magical capability. Additionally, OpenAI’s buggy sandboxing and monitoring processes were key to enabling this incident. Fixing these bugs and putting in place improved monitoring would be appropriate fixes, not pausing AI. There are many well known ways to attack software systems. The main advantage of AI agents is that they are relentless. They will tirelessly try many tactics — and have the patience to chain vulnerabilities together — that previously would have taken an infeasible amount of human effort. But in the long term, I believe the advantage will lie with defenders (because they have more information with which to identify bugs, which they can fix), but the cyber-threat landscape has changed significantly. There are still bottlenecks to identifying and exploiting a vulnerability. AI agents still have to try a lot of things to see what works, and taking these actions takes time and might be detected by defenders. This is why, even though it is now easy to obtain versions of leading open weight models that have had their guardrails removed or weakened, so they will not refuse to try to execute cyber attacks, the world has not ended. I am also concerned about the anthropomorphization of AI in a lot of reporting, where LLMs and agents are unnecessarily treated as if they were people. If I wield a hammer, miss a nail, and accidentally dent the wall, it’s not the fault of the hammer. The problem lies in how I used the hammer. Similarly, if I prompt an agent and it hacks into someone else’s system, the responsibility lies with me, not the agent. Of course, we want to build systems that are as safe and predictable as possible. (For example, an unsafe hammer would be one whose head randomly flies off under normal use.) Today’s agentic systems are not predictable, but I see no reason why, by applying sound engineering practices, we won’t be able to make them extremely safe to use. One new element in the forecasts of AI-enabled doom is AI companies disclaiming responsibility for their own products. “I didn’t do it; my out-of-control agent did!” There’s a balance to be struck between the responsibility of the tool maker and the tool user, but when something goes wrong, let’s hold the people building and/or using the hammer responsible, rather than the hammer. (By the way, if you’re worried about AI bioweapon risk, David Bellamy has a great post on why this, too, is overhyped. Briefly, the bottleneck in building a bioweapon is not intelligence, but lab work and manufacturing.) Pausing AI progress will create much more harm than benefit. First, our adversaries will certainly not slow down. Second, engineering requires discovering problems empirically so we can fix them. If we pause AI by a decade, we will also delay finding and implementing safety engineering fixes by about the same duration. Of course, the incentive to stoke fears — for regulatory capture, to garner attention, or to make one’s technology seem more powerful — remains the same as before. Disclaiming responsibility is a new one. Taking a hard technical look at the actual risks however, I see little factual basis for the degree of fear that’s been stoked up. We still have hard research and engineering work ahead to improve AI safety, but the beneficial applications continue to vastly outweigh the risks, and we should keep building. [Original text (with links): https://t.co/jni2tWazAH ]
在 X 查看被引用的帖子

来源:@AYi_AInotes · x.com