开放权重大模型加剧网络攻击风险,需聚焦高危能力管控。
Mitigating Cyber Risk in the Age of Open-Weight LLMs: Policy Gaps and Technical Realities
- 以能力而非模型整体为单位进行安全评估与管控
- 实测显示开放模型可加速恶意软件开发与社会工程攻击
- 适合政策制定者与网络安全研究者参考
开放权重通用人工智能(GPAI)模型虽带来显著效益,但也引发重大网络安全风险。如在MITRE的OCCULT评估中,DeepSeek-R1等模型展现出强大的进攻能力,使更多攻击者能自动化、规模化实施网络攻击,挑战传统防御与监管范式。本文分析了开放权重模型带来的具体威胁,包括加速恶意软件开发和增强社会工程攻击能力。我们批判性评估了欧盟《人工智能法案》及GPAI行为准则,指出开放分发导致控制权丧失,使常规安全措施失效,存在显著监管漏洞。为此提出新路径:聚焦评估与管控特定高风险能力,倡导对开放权重系统采取务实政策解读,推动防御型AI创新,并加强国际间标准制定与网络威胁情报共享,以保障安全而不抑制技术进步。
原文摘要 · Abstract (English)
Open-weight general-purpose AI (GPAI) models offer significant benefits but also introduce substantial cybersecurity risks, as demonstrated by the offensive capabilities of models like DeepSeek-R1 in evaluations such as MITRE's OCCULT. These publicly available models empower a wider range of actors to automate and scale cyberattacks, challenging traditional defence paradigms and regulatory approaches. This paper analyzes the specific threats -- including accelerated malware development and enhanced social engineering -- magnified by open-weight AI release. We critically assess current regulations, notably the EU AI Act and the GPAI Code of Practice, identifying significant gaps stemming from the loss of control inherent in open distribution, which renders many standard security mitigations ineffective. We propose a path forward focusing on evaluating and controlling specific high-risk capabilities rather than entire models, advocating for pragmatic policy interpretations for open-weight systems, promoting defensive AI innovation, and fostering international collaboration on standards and cyber threat intelligence (CTI) sharing to ensure security without unduly stifling open technological progress.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。