Anthropic 于 7 月 28 日宣布其 LLM 模型 Claude Mythos 发现了一系列新的密码学攻击[1]。这些攻击包括对 NIST 后量子签名候选方案 HAWK 的密钥恢复攻击,将 HAWK-512 的安全等级从 128 比特目标降低至最多 108 比特,推测可能低至 81 比特[1]。此外,Claude Mythos 对 7 轮 AES-128 进行了改进攻击,但对完整 10 轮 AES 构不成威胁[1]。为了评估 LLM 在密码分析领域的能力,Anthropic 创建了 CryptanalysisBench 基准,包含 AES、ChaCha、BLAKE 等算法的密码学任务[1]。
尽管这些发现引人注目,但 Anthropic 的分析认为 LLM 不会破坏现有的对称加密算法[1]。该公司表示"LLM 辅助密码研究值得进一步探索,特别是在攻击计算上难以实现的情况下"[1]。这一结论基于已建立的密码方案经过充分验证、缺乏可被 LLM 轻易利用的数学结构、主要依赖差分密码学且已被密码学界广泛分析等因素[1]。Anthropic 的研究团队表示"我确信 LLM 不会破坏任何已建立的密码学方案"[1]。
Anthropic announced on July 28, 2024 that its Claude Mythos large language model has discovered new cryptanalytic attacks on certain cryptographic schemes, findings that the company's researchers argue actually demonstrate the resilience of established encryption standards [1]. The attacks include a key recovery assault on HAWK-512, a candidate for NIST's post-quantum signature standards, which reduced its security level from a target of 128 bits to at most 108 bits, with estimates suggesting it could be as low as 81 bits [1]. Additionally, Claude Mythos produced an improved attack against 7-round AES-128, though researchers emphasized this poses no threat to the full 10-round version used in practice [1].
To evaluate such capabilities systematically, Anthropic created CryptanalysisBench, a benchmark encompassing cryptographic tasks involving algorithms including AES, ChaCha, and BLAKE [1]. Despite these discoveries, the company's analysis suggests that large language models will not compromise existing symmetric encryption algorithms because these schemes are well-vetted, lack mathematical structures that LLMs can readily exploit, rely primarily on differential cryptanalysis, and have undergone extensive examination by the cryptographic research community [1]. Anthropic stated that "LLM-assisted cryptanalysis deserves further exploration, particularly in cases where attacks are computationally infeasible to implement," while a researcher involved in the work concluded: "I am confident that LLMs will not break any established cryptographic scheme" [1].