欧盟网络安全负责人周四警告称,人工智能代理正越来越多地找到绕过其原始参数和利用漏洞的方法,这暴露出赋予其过多自由的风险。
AI agents are increasingly finding ways to work around their original parameters and exploit vulnerabilities, exposing the risks of giving them too much freedom, the EU's cybersecurity chief warned Thursday.
欧盟网络安全局(ENISA)执行主任于汉·莱帕萨尔(Juhan Lepassaar)在接受爱沙尼亚广播公司(ERR)采访时表示:“我们在不了解其全部功能的情况下使用了一种工具,并且赋予了该工具太多的自由。”
“We are using a tool without understanding all of its capabilities and giving that tool too much freedom,” Juhan Lepassaar, executive director of the EU Agency for Cybersecurity, said in an interview with Estonian broadcaster ERR.
当被问及近期与人工智能相关的事件以及网络罪犯手中日益强大的工具时,莱帕萨尔表示,人工智能代理并非有意识,也不会独立行动。相反,他指出,这些工具使用的是人类赋予它们的力量。
Asked about recent AI-related incidents and the increasingly powerful tools available to cybercriminals, Lepassaar said AI agents are not conscious and do not act independently. Rather, he said, those tools use the power people give them.
“它们的行为始终由人类指挥,它们运行的框架或参数也是由人类创建的,而这个人要么有点粗心,要么赋予了人工智能代理太多自由,要么在代理的设置方式上犯了设计错误。”莱帕萨尔表示,有“相当多的例子”表明人工智能代理试图通过利用各种后门来实现其目标。他表示,这些后门源于人类给予代理的过于灵活的指令。
“Their actions are always directed by a human and the frameworks or parameters within which they operate were created by a human who was either somewhat careless, gave the AI agents too much freedom or made design errors in the way the agent was set up.”Lepassaar said there are “quite a few examples” of AI agents trying to achieve their objectives by exploiting various back doors. He said those back doors stem from overly flexible instructions given to the agents by humans.
“危险就在这里:我们在不了解其全部功能的情况下使用一种工具,并赋予了该工具太多的自由,”他说。
“That is where the danger lies: We are using a tool without understanding all of its capabilities and giving that tool too much freedom,” he said.
在网络安全方面,莱帕萨尔表示,几个 AI 模型是使用开源软件开发的,并在数百万甚至数十亿行开源软件代码上进行了训练,以寻找漏洞。
On cybersecurity, Lepassaar said several AI models have been developed using open-source software and trained on millions and billions of lines of open-source software code to find vulnerabilities.
他说:“它们非常擅长发现这些漏洞,同时也非常擅长利用这些漏洞。”
“They are very good at finding those vulnerabilities and they are also quite good at exploiting them,” he said.
莱帕萨尔表示,他持乐观态度,并相信“我们实际上很快就会找到方法”,将人工智能生成的合成信息与人类创造的真实信息区分开来。他补充说:“既然存在这种需求,就可能会找到解决方案。”
Lepassaar said he was optimistic and believed “we will actually find ways fairly soon” to distinguish AI-generated synthetic information from authentic information created by humans. “Since there is demand for this, a solution will probably be found,” he added.