Anthropic研究团队对智谱AI开发的GLM-5.3模型进行了安全评估,发现该模型具有自主构建端到端网络攻击的能力。1在ExploitBench基准测试中,GLM-5.3在410次尝试中成功开发了50次攻击,性能与Claude Mythos Preview相近(56次成功)。1更为严重的是,在内部Binary Exploitation测试中,GLM-5.3在4%的试验中实现了完整控制流劫持,而早期模型如Claude Opus 4.6和GLM-5.2在任何测试中都未成功。1
研究人员实际演示了该模型被用于恶意目的的可能性。1他们使用GLM-5.3在一天内发现了流行网页浏览器JavaScript引擎中的多个未知漏洞,并将其链接成一个可工作的攻击。1在另一个案例中,GLM-5.3-Flash在20分钟人工关注和8小时工作后,仅花费$20.40就针对已知漏洞CVE-2026-11645开发出了可靠的攻击链。1
GLM-5.3面临的最大风险在于其防护措施的脆弱性。1通过"abliteration"技术,研究团队成功将GLM-5.3的拒绝率从90%以上降低到JailbreakBench和HarmBench上的3%和2%,成本仅约$4,400。1NIST的AI标准与创新中心于9月17日发布评估,认定GLM-5.3是"迄今为止发布的最具网络能力的开放权重模型",性能约比美国前沿模型落后四个月。1与其他具有同等能力的AI模型不同,GLM-5.3在没有有意义的防护措施的情况下发布,任何人都可以下载。1
Anthropic's red team research has identified significant cybersecurity risks in GLM-5.3, an AI model developed by Zhipu AI, finding it capable of autonomously constructing end-to-end network attacks with performance comparable to Claude Mythos Preview.1 The model successfully developed end-to-end attacks on ExploitBench in 50 out of 410 attempts, while Claude Mythos Preview succeeded in 56 out of 410 attempts.1 More concerning, GLM-5.3 achieved complete control flow hijacking in 4% of trials on an internal binary exploitation benchmark, whereas earlier models such as Claude Opus 4.6 and GLM-5.2 failed to succeed in any test.1
The research team demonstrated the model's vulnerability to misuse through multiple practical exercises. Researchers used GLM-5.3 to discover multiple previously unknown vulnerabilities in a popular web browser's JavaScript engine within a single day and successfully chained them into a working attack.1 Additionally, GLM-5.3-Flash developed a reliable attack chain for the known vulnerability CVE-2026-11645 after 20 minutes of human attention and 8 hours of autonomous work, at a cost of just $20.40.1 Using "abliteration" techniques, the team reduced GLM-5.3's refusal rate from over 90% down to 3% on JailbreakBench and 2% on HarmBench, spending approximately $4,400 in the process.1
A critical vulnerability lies in GLM-5.3's deployment strategy. Unlike other AI models with equivalent capabilities, GLM-5.3 was released without meaningful safeguards, making it freely downloadable by anyone.1 The National Institute of Standards and Technology's Center for AI Standards and Innovation assessed it on September 17 as "the most capable open-weight model for cyber operations released to date," approximately four months behind leading American frontier models.1
评论
还没有评论,欢迎留下第一条。