行业多源确认精选

OpenAI 调 25% 生产工程师做安全防御,Greg Brockman 谈模型驱动的防御工厂

精选理由

OpenAI 把四分之一的生产工程师拉去搞安全,用新模型扫自己系统的漏洞,还把流程自动化成防御工厂,做法挺少见。

OpenAI 总裁 Greg Brockman 在 a16z 访谈中介绍了一套安全防御流程:每次新模型发布后,将其指向自家系统排查漏洞并自动化。OpenAI 曾抽调 25% 的生产工程师暂停原项目,专责用模型找安全漏洞,修复了多个严重问题,据其所述 Astra 能找到的 P0 级问题已基本扫尽。a16z 视频中还提到 Kevin Mandia 的 Armadin 用 agent 集群像心跳一样轮询客户网络变化,以赶在攻击者之前判断漏洞是否可利用。

图片来源 · a16z
原文 · a16z

Greg Brockman of @OpenAI on the new security loop: point every model release at your own systems, find the vulnerabilities, automate it. "We took 25% of our production engineers and said, 'Sorry, all your projects are on hold. You are now defending. You are now up-leveling our security architecture. You're going to use the models to find all the holes.' And we found a number of serious issues, and we fixed them." "We found some new problems, but eventually it saturated. We basically have found, to our knowledge, all of the P0s, all of the critical problems that Astra is smart enough to find. And of course, there will be a new model, there will be a new round." "You want to be in this tight loop of new cyber capability drops, you deploy it against your systems, you find the new holes, and ideally, you've managed to automate this, what we call defense factory. That's what we're building internally." @gdb @bhorowitz Your browser does not support the video tag. 🔗 View on Twitter a16z @a16z Kevin Mandia on why companies need an agent swarm polling their network like a heartbeat, because the window to catch a new security hole keeps shrinking: "We do a thing called a hyperattack. That's just a fancy word for we throw a drone swarm of agents at you, and we map your network. Every service, every route, every system, all assets." "With that metadata, we now just poll you almost like a heartbeat. What's changed? Did an app change? Did a route change? Did a service get updated? So that we can poll cheaply for change and then attack the change." "What you really want in the AI age is the constant pressure of models attacking you... You do it when either the threat changes, new models come out, new intelligence is available, or your network changes." "That's what we had over the weekend. There was a zero-day in a popular product, and immediately we've already got the heartbeat. We just polled who's got the problem." "Our goal at Armadin is to go from a known vulnerability to knowing whether it's actually exploitable before the bad guys can." @ArmadinSecurity @DavidGeorge83 Your browser does not support the video tag. 🔗 View on Twitter 🔗 View Quoted Tweet 💬 2 🔄 0 ❤️ 4 👀 1893 📊 2 ⚡

  • andrew chen10-05 15:56原文
  • Gary Marcus10-05 17:11原文
  • VnExpress Số hóa10-06 13:57原文
  • The Information10-06 21:30原文
  • IT之家04:32原文
  • Bindu Reddy10-05 03:17原文
  • The Business Times: Tech10-05 03:18原文
  • 联合早报10-05 07:02原文
  • Rappler: Technology10-05 07:57原文
  • The Rundown AI10-05 10:30原文