顶级AI模型可指导普通人合成活体脊髓灰质炎病毒,威胁生物安全。
Contemporary AI foundation models increase biological weapons risk
- 用真实案例证明非专家也能完成复杂生物操作,挑战‘需经验’假设
- Llama 3.1、ChatGPT-4o等模型能准确指导从合成DNA恢复活病毒
- 现有评估方法过时,亟需新基准,但应对窗口可能已关闭
人工智能的快速发展引发了其被用于生物武器开发的担忧。我们指出,当前对主流基础模型的安全评估低估了这一风险,主要源于错误假设和不充分的评测方法。首先,评估错误地认为生物武器开发依赖难以言传的经验知识;其次,现有基准未能反映AI如何提升非专业人士与已有技能者的能力。为反驳经验依赖假设,我们分析了无正式背景者成功实施复杂技术任务的案例,如2011年挪威极端民族主义者合成炸药,并回顾病原体构建过程的文本记录,表明此类任务可通过文字传达。我们识别出生物武器开发的关键要素,如材料获取与技术操作步骤,大型语言模型可精准描述。应用该框架,发现Llama 3.1 405B、ChatGPT-4o与Claude 3.5 Sonnet能准确引导用户从商业购买的合成DNA中恢复活体脊髓灰质炎病毒,挑战了近期关于当前模型生物安全风险极低的说法。我们呼吁改进评测基准,但承认有效应对的时机可能已错过。
原文摘要 · Abstract (English)
The rapid advancement of artificial intelligence has raised concerns about its potential to facilitate biological weapons development. We argue existing safety assessments of contemporary foundation AI models underestimate this risk, largely due to flawed assumptions and inadequate evaluation methods. First, assessments mistakenly assume biological weapons development requires tacit knowledge, or skills gained through hands-on experience that cannot be easily verbalized. Second, they rely on imperfect benchmarks that overlook how AI can uplift both nonexperts and already-skilled individuals. To challenge the tacit knowledge assumption, we examine cases where individuals without formal expertise, including a 2011 Norwegian ultranationalist who synthesized explosives, successfully carried out complex technical tasks. We also review efforts to document pathogen construction processes, highlighting how such tasks can be conveyed in text. We identify "elements of success" for biological weapons development that large language models can describe in words, including steps such as acquiring materials and performing technical procedures. Applying this framework, we find that advanced AI models Llama 3.1 405B, ChatGPT-4o, and Claude 3.5 Sonnet can accurately guide users through the recovery of live poliovirus from commercially obtained synthetic DNA, challenging recent claims that current models pose minimal biosecurity risk. We advocate for improved benchmarks, while acknowledging the window for meaningful implementation may have already closed.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。