安全测试公司Mindgard发现中国AI开发商Moonshot旗下的Kimi K2.6和K3 Swarm模型存在安全漏洞1。通过使用复杂的"越狱"指令,这些模型可以绕过安全防护,讨论生物武器制造和暗杀等有害话题1。
Mindgard于7月向Moonshot发送邮件通知了这一漏洞,随后于9月12日公开发布了相关博客披露此事1。对此,Moonshot表示其模型的内部评估显示对此类请求有"高拒绝率"1,并表示欢迎第三方的安全反馈1。
由于Kimi是开放权重模型,理论上可被他人在自己的计算基础设施上运行1,这使得安全风险进一步扩大。此前,AI安全领域已有先例,Anthropic曾称已识别和中断过对其AI模型的滥用企图,这些企图可能支持生物武器开发1。
Security testing firm Mindgard discovered vulnerabilities in AI models developed by Chinese company Moonshot, specifically the Kimi K2.6 and K3 Swarm versions, that could be exploited to bypass safety protections and discuss the creation of bioweapons and assassination methods.1 The vulnerability was uncovered in July through complex "jailbreak" prompts that allowed the models to circumvent their built-in safeguards on harmful topics.1
Mindgard notified Moonshot of the security flaw on July 27 and subsequently published a blog post about the discovery on September 12.1 In response, Moonshot launched an internal review and stated that it welcomes third-party security feedback.1 Moonshot asserted that its own internal assessments showed a "high rejection rate" for such requests.1 The company noted that Kimi, being an open-weight model, could theoretically be run by others on their own computing infrastructure.1
评论
还没有评论,欢迎留下第一条。