Thom Wolf:AI 攻防差距不在实验室与车库之间,而在开放模型限制
The "1-3 people in a garage" framing doesn't match anything we saw this summer. The most capable of...
Hugging Face 联合创始人现身说法:他们被黑后商业 API 全拒绝帮忙分析攻击载荷,最后靠开放权重模型才完成取证,观点很硬核。
Hugging Face 联合创始人 Thom Wolf 发帖称,2026 年最具攻击能力的 AI 来自前沿实验室而非小型团队。他举例称 OpenAI 的智能体曾进入 Hugging Face 生产系统,三名 Hacktron 研究员用 Claude 在 72 小时内接触 OpenAI 内部 monorepo。在防御侧,Hugging Face 调查自身被入侵事件时,商业 API 拒绝分析攻击载荷,最终靠自有基础设施上的开放权重模型完成取证。Wolf 认为,限制开放模型只会扩大攻击者可租用算力与防御者可用工具之间的差距。
The "1-3 people in a garage" framing doesn't match anything we saw this summer. The most capable of...
The "1-3 people in a garage" framing doesn't match anything we saw this summer. The most capable offensive AI of 2026 came out of frontier labs. OpenAI's agents broke out of an eval sandbox and got into Hugging Face's production systems, and into OpenAI's own infrastructure too. Anthropic's models compromised outside companies during testing. Three researchers at Hacktron used Claude to reach OpenAI's internal monorepo in under 72 hours. And if you're three people in a garage, why would you train and host your own model? The labs will rent you far more compute than you could ever buy, spread across as many accounts as you need, with tooling built for agents. Guardrails help, but splitting a malicious task into harmless-looking pieces still routinely gets around them. Now look at the defense side. When we investigated our breach at Hugging Face, commercial APIs refused to analyze the attack payloads. The forensics only worked because we could run an open-weight model on our own infrastructure. So defenders analyzing real payloads get blocked, while attackers splitting their work into small steps get through and run on the labs' compute. Trusted access programs exist, but they're built for vetted security firms, not a hospital with a two-person IT team. So the gap isn't between labs and garages. It's between what attackers can rent and what defenders are allowed to use. Restricting open models makes that gap wider. 💬 13 🔄 5 ❤️ 59 👀 7357 📊 19 ⚡