一篇在Usenix安全会议后发表的文章指出,人工智能模型在软件漏洞发现领域的进步将带来意想不到的后果[1]。随着AI技术能力的提升,远程可利用漏洞预计在未来两年内将逐步消失[1],这一发展可能迫使美国执法和情报机构采取措施来维持其网络监控能力[1]。
文章作者担忧,当传统漏洞利用路径消失后,政府将转向要求企业在系统中建立意图性后门[1],这种做法将直接削弱国家自身的系统安全性[1]。这一困境在历史上已有先例。FBI局长Comey在2014年启动了所谓的"Going Dark"计划[1],Apple从2010年开始使用用户密码派生的密钥加密iPhone数据[1],WhatsApp在2016年拥有近10亿用户并采用端到端加密技术[1],这些都曾引发政府对监控能力的担忧。
当前,Anthropic公司已于4月推出了名为Mythos的漏洞发现模型[1],美国政府随即对其出口进行了临时禁止,仅允许其供美国机构使用[1]。
Following the Usenix security conference, a researcher warned that rapid advances in artificial intelligence for identifying software flaws will gradually eliminate remotely exploitable vulnerabilities from mainstream applications [1]. This development raises concerns that U.S. law enforcement and intelligence agencies may respond by pressuring companies to install intentional backdoors, ultimately weakening the nation's own cybersecurity defenses [1].
The tension between security and surveillance access has deep roots. FBI Director James Comey introduced the "Going Dark" initiative in 2014 to address law enforcement's difficulty accessing encrypted communications [1]. By 2010, Apple had begun encrypting iPhone data using keys derived from user passwords [1], and by 2016, WhatsApp had grown to nearly one billion users while employing end-to-end encryption [1]. These developments sparked ongoing debates about balancing privacy with investigative capabilities.
The acceleration of AI-driven vulnerability discovery has now raised the stakes. Anthropic unveiled the Mythos model in April for identifying software flaws [1], while the U.S. government has temporarily prohibited its export, restricting access to American institutions only [1]. Researchers project that within the next two years, major software platforms will exhaust their supply of remotely exploitable vulnerabilities [1]. As this window closes, authorities may face pressure to demand backdoor access rather than rely on traditional intelligence-gathering methods, creating a paradox where national security could be compromised in pursuit of law enforcement objectives [1].