Register and share your invite link to earn from video plays and referrals.

BlockBeats|We're hiring!
@BlockBeatsAsia
Tomorrow’s news rhymes on BlockBeats. APP下载: 联系我们:Contact@theblockbeats.org
Joined April 2016
2.3K Following    87.9K Followers
Anthropic今天发布了一篇长达154页的威胁情报报告,但意外暴露了一个让人细思极恐的问题:为了追踪这些攻击者,它究竟能看到用户多少对话内容?🤔🤔 这份报告中披露,过去8个月里,Claude被频繁用于网络攻击、舆论操纵、大规模监控、武器研发、生物双用途研究、诈骗和模型蒸馏。 攻击者已经开始把Claude真正接入Agent工作流:自动侦察、寻找漏洞、编写恶意代码、批量窃取数据、生成钓鱼内容、整理外传资料…… 过去可能需要一整支安全团队协作完成的工作,如今几个人,甚至一个人,就可能让多个Agent并行执行。 其中有一个案例尤其夸张: 一个面向马里国家情报系统开发的监控平台,被设计为覆盖全国三家运营商、约2500万张SIM卡。通话、短信、语音、声纹关联、VPN使用情况、身份库匹配等信息,全部被纳入同一套系统。 报告中还提到,有一家中国App工作室运营了20多款交友软件,通过超过4700个AI人设与至少2.5万名用户聊天。真人只负责视频通话、社交媒体互关等最能打消用户怀疑的环节,剩下的大规模、高并发陪聊则交给模型完成。 而这份报告中最敏感的部分之一,是模型蒸馏。 按照Anthropic 的报告指控,被点名的中国模型和实验室包括:阿里巴巴的Qwen、月之暗面的Kimi、DeepSeek、智谱的GLM、小米的MiMo,以及SenseTime和MiniMax。 报告称,Kimi和DeepSeek曾将部分用户请求静默转发给Claude,再利用返回内容训练模型;小米MiMo被指将用户对话和编程会话重放给Claude;Qwen、GLM则被指通过大量虚假账户、代理网络和推理链提取来蒸馏模型能力等等案例。 关键在于,Anthropic称这些被转发的内容可能包含企业内部资料、联系人信息、代码,甚至真实访问凭证❗️⚠️ 也就是说,用户以为自己正在使用Kimi、DeepSeek或MiMo,自己的数据却可能在不知情的情况下进入另一家模型公司的系统。 但比起这些,更值得追问的问题是:Anthropic是怎么知道这些事情的? 为了还原网络攻击、监控项目以及模型蒸馏背后的完整行动链,Anthropic显然需要结合对话内容、模型调用行为、账号关系以及基础设施信号等多种数据。尤其是当报告能够具体还原攻击者的操作步骤、使用的提示词、调用方式,甚至追踪到不同账号之间的关联时。 所以Anthropic究竟能看到用户的多少对话内容?又能看到什么程度的用户行为?这其中的边界在哪里? 这或许是这份154页威胁情报报告,在攻击、诈骗和模型蒸馏之外,值得所有AI用户思考的问题。
Show more
We're publishing our most detailed threat intelligence report to date. It covers how people tried to misuse Claude—for cyberattacks, influence operations, surveillance, biology, and building weapons—and how we found and stopped them. We disrupted every operation in the report, and used the lessons from them to strengthen our safeguards. Where appropriate, we also shared what we found with authorities and other AI companies. These cases are not typical: we’re highlighting some of the most sophisticated misuse we’ve seen. But they’re especially important to discuss, because they show us where AI misuse is headed, where our safeguards work, and where they need to improve. We’re publishing this report so others can spot the same activity on their own platforms, and so we can give the public a clearer view of how emerging threats develop. Read the report:
Show more