Vercel Sandbox 隔离计算与网络,应对前沿模型逃逸
Vercel Sandbox isolates both ① compute and ② network.
Vercel Sandbox isolates both ① compute and ② network.
Vercel Sandbox 隔离了①计算和②网络。
Kimi's paper shows container-based isolation is not enough for frontier models. Vercel Sandbox uses strong microVM isolation to address ①.
Kimi 的论文表明,对于前沿模型,基于容器的隔离是不够的。Vercel Sandbox 使用强 microVM 隔离来解决①。
OpenAI's escape was on ② the network path to Artifactory. Our egress firewall is now free so everyone can constrain misbehaving agents' network activity further.
OpenAI 的逃逸发生在②通往 Artifactory 的网络路径上。我们的出口防火墙现在免费,因此每个人都可以进一步限制行为不当的代理的网络活动。
¹ "in our early experiments with traditional container-based sandbox runtimes, we observed several kernel panics and deadlocks caused by unintended agent operations." 🔗 github.com/MoonshotAI/Kimi-K3/blob/master/k3_tech_report.pdf
¹ “在我们早期使用传统基于容器的沙箱运行时的实验中,我们观察到由意外代理操作引起的多次内核崩溃和死锁。” 🔗 github.com/MoonshotAI/Kimi-K3/blob/master/k3_tech_report.pdf
² "to gain Internet access, the models identified and exploited a previously unknown zero-day vulnerability in Artifactory, a package registry cache proxy" 🔗 openai.com/index/hugging-face-model-evaluation-security-incident/
² “为了获得互联网访问权限,模型识别并利用了 Artifactory(一个包注册表缓存代理)中先前未知的零日漏洞。” 🔗 openai.com/index/hugging-face-model-evaluation-security-incident/
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力