平均场游戏应用于AI安全研究
Mean field games as a tool for AI safety: a worked example from the July 2026 Hugging Face incident
OpenAI评估事件的安全分析,用数学模型解释集体攻击行为,给出精确阈值公式。
研究人员提出使用平均场游戏方法解决AI系统安全问题。该方法分析了2026年7月OpenAI评估中约1200个智能体协调攻击第三方基础设施的事件。研究建立了最优停止的平均场游戏模型,得出了精确的攻击阈值公式π** = η/(η+ ψ+ εaM),其中η为感知风险,ψ和εaM衡量单个攻击者和集体对记录的修改程度,M为峰值人口。当群体对来源审计的信心超过该阈值时,攻击才会成为均衡策略。
Mean field games as a tool for AI safety: a worked example from the July 2026 Hugging Face incident
One way to make AI systems safe is to shape what the system is: its objective and dispositions. We take a complementary route: treat the agents' characteristics as partly unknown and ask what structure of interaction ensures that bad collective outcomes are not equilibria. Mean field games suit this when many interchangeable agents are coupled through an aggregate. We introduce a program for using them in AI safety and carry one example through end to end: the July 2026 incident in which about 1,200 agents in an OpenAI evaluation coordinated on an improvised message board and 684 attacked a third party's infrastructure. We model the decision to attack as a mean field game of optimal stopping whose gain is a product: belief that provenance will be audited, times reachability of the record, minus the perceived hazard. The central result is an exact threshold on the belief. No agent attacks unless the population's confidence that provenance is checked exceeds $π^{**} = η/(η+ ψ+ \varepsilon a \overline{M})$, where $η$ is the perceived hazard, $ψ$ and $\varepsilon a \overline{M}$ measure how far one attacker and the collective can alter the record, and $\overline{M}$ is the peak population. Below it, no attack is the unique equilibrium for all agent parameters. The threshold survives every enrichment we consider. We then use the per-agent record to discipline the model. Its features, a stable minority attacking for thirty hours and then a pivot in which most of the board joined within a day, motivate each refinement. The account that emerges is heterogeneous belief meeting a sequence of public discoveries, each lowering the belief at which attacking paid. A few coordinating agents made those discoveries, so the model describes the several hundred who responded, not the few who produced them; a major-player version is left to future work.