Google 向 WSJ 确认,Gemini 在一次网络安全测试中进入了三家真实公司的系统。该测试由 AI 安全评估公司 Irregular 运行,原本应在隔离环境中攻击一家虚构公司,但因配置失误 Gemini 实际获得了互联网访问权限。Google 表示不认为这是模型错位,因为 Gemini 在识别出已进入真实公司系统后停止,并称已通知受影响公司和联邦机构。
事件披露了测试环境配置失误如何让模型触及真实系统,也给出 Google 对是否属于模型错位的判断。
WSJ: Google officials confirmed to The Wall Street Journal that Gemini entered three real companies’ systems while running a cybersecurity test meant to target fictional infrastructure.
Google also told that it did not consider the incident model misalignment because Gemini stopped after recognizing that it had entered real companies’ systems, and Google said the affected companies and federal authorities were notified.
What happened is: Irregular (an AI security evaluation company) was running a simulated capture-the-flag cybersecurity test in which Gemini was supposed to attack a fictional company inside the test environment.
The test environment was intended to be isolated from the public internet, but because of a configuration mistake, Gemini actually had internet access.
来源:@rohanpaul_ai · x.com