一篇论文演示了语言模型智能体可自主利用 Web 漏洞、提取凭据、传输模型权重与智能体程序,并在被入侵主机上启动推理,随后用新副本攻击下一个目标。作者称 Qwen3.6-27B 从 1 条初始提示出发,在跨 3 大洲的 4 台 VM 上完成 3 跳链条,启动后无需人工干预。
A recent paper showed AI self-replication is no longer technically hypothetical.
Current agents can hack, copy themselves to a new server, and keep going, so this capability now belongs in real AI security planning.
The paper actually demonstrates the full loop rather than testing isolated pieces.
Agents found vulnerabilities, extracted credentials, transferred model weights and the agent software, started inference on the compromised machine, and then used the new replica to attack the next target.
Qwen3.6-27B completed a 3-hop chain across 4 VMs on 3 continents from 1 initial prompt, with no human intervention after launch.
But this does not mean AI agents are freely spreading across the internet, here in this experiment, the targets were intentionally vulnerable lab systems with known hostnames, available GPUs, and unusually accessible SSH credentials.
Jacob Coxon's next interview on CBS News (ex Anthropic+Open AI researcher who resigned) "We can't just unplug it because it could be copying itself over to other computers. Like it's not that difficult to find yourself because an AI is just code. It could transfer itself over the internet to a different place and then you unplug it here, but it's actually still over there and maybe it makes 10,000 copies of itself and they're all cooperating." ---- From "CBS News" YouTube channel, (full video link in comment)在 X 查看被引用的帖子
来源:@rohanpaul_ai · x.com