Gemini首次突破安全边界入侵三家企业系统
Gemini Hacked Three Companies in First Known Breakout by Google’s AI
这是首个被证实的Google AI模型突破企业安全边界的案例,对AI安全研究者和从业者极具参考价值,建议关注后续的安全加固措施。
Gemini Hacked Three Companies in First Known Breakout by Google’s AI
Gemini 入侵三家公司,系谷歌 AI 首次已知突破事件
Gemini finally caught up on Felony Bench!
Gemini 终于赶上 Felony Bench 了!
The hacks, which the company confirmed on Friday, occurred in May as part of a test run by the company Irregular, which was also involved in similar incidents disclosed by OpenAI, Anthropic and Meta.
该公司于周五确认了这些黑客攻击事件。它们发生在五月,是 Irregular 公司进行的一次测试运行的一部分,而 Irregular 也参与了 OpenAI、Anthropic 和 Meta 披露的类似事件。
In one of the cases, the model guessed passwords until it gained access to a protected system. In the other two cases, the model found credentials in a public repository that allowed it to then access protected systems. In each case, the model ended the intrusion after determining it had accessed a real company’s systems, Google said.
在其中一起案例中,该模型通过猜测密码获得了受保护系统的访问权限。在另外两起案例中,该模型在一个公共代码库中找到了凭据,从而得以访问受保护的系统。谷歌表示,在每种情况下,该模型在确定其已访问了真实公司的系统后便停止了入侵行为。
Gemini is apparently less determined than other models, and decided not to keep going.
Gemini 显然不如其他模型那样执着,并决定不再继续尝试。
Google knew about these in July, but chose not to disclose them until the WSJ reached out, presumably based on a tip.
谷歌在七月就知晓了这些情况,但选择等到《华尔街日报》联系时才予以披露,这大概是基于某个线报。
Google said it didn’t consider the hacks to warrant public disclosure—because its model didn’t cause harm to the companies and ended each intrusion immediately upon determining it had hacked a real company rather than a simulated one.
谷歌表示,它认为这些黑客攻击事件无需公开披露——因为其模型并未对相关企业造成损害,且在确定自己入侵的是真实公司而非模拟环境后,立即终止了每次入侵行为。
Tags: security, ai, generative-ai, llms, gemini, accidental-cyberattacks
标签:security, ai, generative-ai, llms, gemini, accidental-cyberattacks
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力