Hugging Face遭OpenAI自主攻击 | 2026
字幕摘录
| 时间 | 英文 | 中文 |
|---|---|---|
| 0:01 | We turn now to artificial intelligence | 我们现在转向人工智能 |
| 0:04 | and a question that has emerged | 和已经出现的问题 |
| 0:06 | after a series of alarming hacking incidents. | 在一系列惊人的黑客事件之后 |
| 0:09 | Is it safe? | 安全吗? |
| 0:10 | To discuss, we're joined by Clem DeLang. | 讨论一下 克莱姆·德朗也加入我们 |
| 0:12 | 他是AI平台Hugging Face的首席执行官, | |
| 0:15 | whose company detailed one of the attacks last week. | 他的公司详细叙述了上周发生的一起袭击事件。 |
| 0:18 | Clem, good morning to you. | 克莱姆,早上好 |
| 0:20 | Good morning, thanks for having me. | 早上好 谢谢你邀请我 |
| 0:22 | Well, your company disclosed it was attacked earlier | 你公司早前透露的 |
展开字幕全文(177 条)
| 序号 | 英文 | 中文 |
|---|---|---|
| 1 | We turn now to artificial intelligence | 我们现在转向人工智能 |
| 2 | and a question that has emerged | 和已经出现的问题 |
| 3 | after a series of alarming hacking incidents. | 在一系列惊人的黑客事件之后 |
| 4 | Is it safe? | 安全吗? |
| 5 | To discuss, we're joined by Clem DeLang. | 讨论一下 克莱姆·德朗也加入我们 |
| 6 | 他是AI平台Hugging Face的首席执行官, | |
| 7 | whose company detailed one of the attacks last week. | 他的公司详细叙述了上周发生的一起袭击事件。 |
| 8 | Clem, good morning to you. | 克莱姆,早上好 |
| 9 | Good morning, thanks for having me. | 早上好 谢谢你邀请我 |
| 10 | Well, your company disclosed it was attacked earlier | 你公司早前透露的 |
| 11 | this month by an autonomous AI cyber actor, | 这个月,一个自主的AI网络演员, |
| 12 | which jumped on its own | 自己跳下来的 |
| 13 | from another company's testing system | 从另一个公司的测试系统 |
| 14 | to hack into your company. | 黑进你的公司 |
| 15 | OpenAI later disclosed it was their technology | OpenAI后来透露这是他们的技术 |
| 16 | that went rogue. | 事情变糟了 |
| 17 | They lost control of it. | 他们失去了控制。 |
| 18 | Tell me, why did your company alert the public | 告诉我,为什么你的公司 提醒公众 |
| 19 | and alert the FBI? | 通知联邦调查局? |
| 20 | Do you think this is a crime? | 你觉得这是犯罪吗? |
| 21 | Well, I think it felt very weird | 我觉得感觉很奇怪 |
| 22 | and unprecedented to us, right? | 对我们来说是前所未有的,对吧? |
| 23 | Because I think it's the first instance | 因为我认为这是第一审 |
| 24 | of something quite autonomous doing something like that. | 做类似的事情 |
| 25 | So the volume of the actions taken | 所以所采取行动的数量 |
| 26 | and the speed of them, | 和他们的速度, |
| 27 | I think it was 17,000 actions taken in four and a half days, | 我觉得是四天半内 采取了17000项行动 |
| 28 | was very new. | 这是非常新的。 |
| 29 | Obviously, the attacker, | 显然,攻击者, |
| 30 | when we talk about cyber attack, | 当我们谈论网络攻击, |
| 31 | we think about nation states, | 我们思考民族国家, |
| 32 | we think about hacker groups, | 我们想到黑客集团, |
| 33 | we don't think about a company like OpenAI, right? | 我们不考虑像OpenAI这样的公司,对不对? |
| 34 | A very prominent, popular American company. | 一个非常突出,受欢迎的美国公司. |
| 35 | And then the way we responded using an open model, | 然后我们用一个开放的模型来回应 |
| 36 | so using AI ourselves to defend ourselves against that | 利用人工智能为自己辩护 |
| 37 | was also pretty new and pretty newsworthy in our opinion. | 在我们看来,也是相当新的和相当有新闻价值的。 |
| 38 | You defended yourselves. | 你为自己辩护 |
| 39 | You found the solution yourselves. | 你们自己找到解决办法了 |
| 40 | But you went to the FBI. | 但你去联邦调查局了 |
| 41 | I think for a lot of people, | 我觉得很多人, |
| 42 | when they think of someone committing a crime, | 当他们想到有人犯罪的时候, |
| 43 | they think of a human. | 他们想到一个人类。 |
| 44 | They don't think of a program, a computer program, | 他们不考虑程序,计算机程序, |
| 45 | as something you can prosecute, as committing a crime. | 以犯罪论处 |
| 46 | What is the FBI doing? | 联邦调查局在干嘛? |
| 47 | Well, I mean, we reported as to the authorities | 嗯,我的意思是,我们报告 当局 |
| 48 | as we have to in such instances, right? | 就像我们在这种情况下必须做的,对吧? |
| 49 | It's kind of like a mandatory disclosure, | 这有点像强制披露, |
| 50 | both with the authorities and the public, | 与当局和公众, |
| 51 | when you face something like that, | 当你面对这样的事情, |
| 52 | which is basically what we did. | 这基本上是我们所做的。 |
| 53 | Now, when we think about the future, right? | 现在,当我们想着未来,对不对? |
| 54 | Now we've heard that it's not only OpenAI, | 现在我们听说 不只是OpenAI |
| 55 | but also Anthropic that has faced similar conflict issues. | 但也曾面临过类似的冲突问题。 |
| 56 | I think it's really important that we keep in mind | 我觉得我们一定要记住 |
| 57 | that cyber attacks need to be contained | 需要控制网络攻击 |
| 58 | in the legal framework in the US | 在美国的法律框架中 |
| 59 | and need to stay illegal | 和需要保持违法 |
| 60 | to prevent an explosion of them in the future, right? | 防止他们在未来爆炸,对不对? |
| 61 | Like we don't want to end up in a world | 就像我们不想在这个世界落幕 |
| 62 | where everyone is facing cyber attacks all the time | 人们总是面临网络攻击 |
| 63 | because of agents and companies that are creating these agents | 因为代理商和公司正在创建这些代理商 |
| 64 | are not accountable for them. | 不对他们负责。 |
| 65 | So I think it's important for regulators, | 所以我觉得这对监管者很重要 |
| 66 | for policymakers to think about the legal framework | 供决策者思考法律框架 |
| 67 | of this new kind of technology risk. | 这种新型技术风险。 |
| 68 | You described more than 17,000 hacking actions | 你描述过超过17000个黑客行动 |
| 69 | on the internet before this was even discovered | 在互联网上发现之前 |
| 70 | by your company. | 由你的公司。 |
| 71 | That sounds like the developers have lost control, have they? | 听起来开发者已经失去控制了 是吗? |
| 72 | Well, you have to remember it's a technology system, | 你要记住这是一个技术系统 |
| 73 | but built by engineers | 但由工程师建造 |
| 74 | and engineers can make mistakes sometimes. | 工程师有时也会犯错 |
| 75 | And I think that's what happens here. | 我想这就是这里发生的事情。 |
| 76 | That's what happened here. | 这就是发生在这里。 |
| 77 | We already in our society accept some level of autonomy. | 我们社会已经接受一定程度的自治。 |
| 78 | I think they built kind of like an autonomous system | 我认为他们建立了一种 像一个自主的系统 |
| 79 | and made some mistakes. | 并犯了一些错误。 |
| 80 | And as a result, we're facing this issue. | 因此,我们正面临这个问题。 |
| 81 | So you said you think there should be | 你说你认为应该有 |
| 82 | some legal parameters put around this. | 一些法律参数 围绕这一点。 |
| 83 | The Trump administration has taken a very light touch | 特朗普政府很轻松 |
| 84 | in regulation because they want to keep America competitive | 因为他们想保持美国的竞争力 |
| 85 | in this space. | 在这个空间。 |
| 86 | They have this policy where they can review technology | 他们有这个政策 他们可以审查技术 |
| 87 | for 30 days to judge basically how dangerous something is | 30天来判断事情有多危险 |
| 88 | before a company releases it to market. | 在公司向市场发行之前 |
| 89 | But as I understand what you described, | 但正如我理解你所说的 |
| 90 | this attack happened before technology was at market. | 攻击发生在科技上市之前 |
| 91 | It happened during the development stage. | 它发生在开发阶段. |
| 92 | It was unreleased. | 本来未释. |
| 93 | So what you're saying, I think, | 所以,你说什么,我认为, |
| 94 | is there is no regulation at this point | 是否目前没有条例 |
| 95 | that would prevent something like this | 那会阻止这种事 |
| 96 | from happening again. | 从再次发生。 |
| 97 | Yeah, that's a really clear example | 是啊,这是一个非常明确的例子 |
| 98 | that just kind of like preventing releases | 这就像防止释放 |
| 99 | of AI models doesn't really work. | 人工智能模型并不有效。 |
| 100 | Concentrating everything behind closed doors | 把所有东西都关起来 |
| 101 | in just a few organization doesn't work. | 只有少数组织不行 |
| 102 | One thing that does work, that worked in this case, | 有一件事是可行的, 在这个案件中是有效的, |
| 103 | is kind of like promoting more open models, right? | 就像推广更开放的模型,对吧? |
| 104 | Because we defended ourselves with an open model, right? | 因为我们用一个开放的模型为自己辩护,对吧? |
| 105 | Like we couldn't have done it with an API | 就像我们不可能用API做一样 |
| 106 | because they had these guardrails | 因为他们有这些护栏 |
| 107 | that's preventing activity for cybersecurity. | 防止网络安全活动 |
| 108 | And we needed to run a model on our own infrastructure. | 我们需要运行一个模型 在我们自己的基础设施。 |
| 109 | So we needed an open model. | 所以我们需要一个开放的模型。 |
| 110 | When you say open model, just for our audience, | 当你说开放模式, 只是我们的观众, |
| 111 | as I understand it, it's an AI model | 据我所知,这是人工智能模型 |
| 112 | whose core components are publicly released | 其核心组件公开发布 |
| 113 | so anyone can download it. | 所以任何人都可以下载 |
| 114 | It's not closed off like a company can do | 不是公司可以关闭的 |
| 115 | to their proprietary information. | 他们的专有信息。 |
| 116 | So you want more of this essentially out there | 所以,你想要更多的 这个本质上在那里 |
| 117 | and accessible to the public. | 并方便大众. |
| 118 | Yeah, because there's the only way for defenders | 是啊 因为维权者只有这样 |
| 119 | to defend themselves on topics like that. | 在这样的话题上为自己辩护 |
| 120 | They remove the asymmetry of power and capabilities, right? | 它们消除了力量和能力的不对称,对吧? |
| 121 | In these kinds of risks. | 于这些险境中. |
| 122 | If you have very powerful systems | 如果你有非常强大的系统 |
| 123 | and very weak systems that are defending, | 以及防御的薄弱系统, |
| 124 | then that's when you have the right problem. | 那时你就有了正确的问题 |
| 125 | But if you balance, if you make it more kind of like | 但是,如果你平衡, 如果你使它更像 |
| 126 | symmetric in terms of attackers and defenders, | 攻击者和捍卫者对称, |
| 127 | that's usually when you end up in a safer world. | 通常你最终会进入一个更安全的世界 |
| 128 | And I actually do think that we're talking a lot | 其实我觉得我们谈了很多 |
| 129 | about the risks for cybersecurity right now, | 关于目前网络安全的风险, |
| 130 | but AI is actually an opportunity to fix | 但AI其实是一个解决的机会 |
| 131 | a lot of the cybersecurity problems. | 很多网络安全的问题 |
| 132 | We're defending ourselves with AI. | 我们用AI为自己辩护. |
| 133 | We're gonna use AI to fix a lot of our bugs. | 我们要用人工智能来修复很多的虫子. |
| 134 | So hopefully AI is gonna make the world safer ultimately, | 希望AI最终能让世界更安全, |
| 135 | thanks to that. | 谢谢 |
| 136 | And you used a Chinese AI model to defend yourselves. | 你用中国的人工智能模型为自己辩护 |
| 137 | There's a lot of concern about inviting China | 有不少人担心邀请中国 |
| 138 | into this space. | 进入这个空间。 |
| 139 | Yeah, I mean, the interesting thing is that we used | 是啊,我的意思是,有趣的是,我们用 |
| 140 | the American version of a Chinese model. | 美国版的中国模式。 |
| 141 | We used the version from Nvidia | 我们用的是Nvidia的版本 |
| 142 | that kind of like made a Chinese model better. | 那样的中国模特儿就更好了 |
| 143 | So that's the beauty of kind of like open models. | 这就是开放模型的美。 |
| 144 | Once they are shared, wherever they come from, | 一旦他们共享, 无论他们来自何处, |
| 145 | from China or from anywhere, | 从中国或任何地方, |
| 146 | American companies can modify them, | 美国公司可以修改它们, |
| 147 | remix them, host them, run them themselves. | 把他们混在一起 招待他们 自己跑 |
| 148 | So that's one of the things that actually make them safe | 所以这是真正让他们安全的东西之一 |
| 149 | wherever they come from. | 无论他们来自哪里 |
| 150 | So I wanna ask you about a specific piece of legislation. | 我想问你一个具体的立法 |
| 151 | And I will say upfront, | 我先说 |
| 152 | there isn't a lot of work | 没什么大不了的 |
| 153 | that's getting done in Congress right now, | 国会现在已经办好了 |
| 154 | but there is this bipartisan bill | 但有一个两党法案 |
| 155 | that would give Homeland Security the authority | 让国土安全局拥有权力 |
| 156 | to order AI firms to shut down | 命令AI公司关闭 |
| 157 | or to slow down their artificial intelligence models | 或者减缓他们的人工智能模型 |
| 158 | if they're too dangerous. | 如果他们太危险。 |
| 159 | It's called the kill switch bill. | 这叫杀人开关账单 |
| 160 | Is that something you want? | 这是你想要的吗? |
| 161 | Well, I mean, I think something we're realizing | 嗯,我的意思是,我认为的东西 我们意识到 |
| 162 | with these events is that concentrating power capabilities | 在这些事件中 集中力量的能力 |
| 163 | behind closed doors, | 闭着门 |
| 164 | even preventing their releases to the public | 甚至阻止他们向公众释放 |
| 165 | isn't really a solution. | 这不是一个真正的解决方案。 |
| 166 | You know, like these problems happened on unreleased models. | 你知道,像这些问题发生 在未释放的模型。 |
| 167 | So I think the problem is not so much kind of like | 所以我觉得问题不在于 |
| 168 | limiting the progress | 限制进展 |
| 169 | or kind of like preventing companies | 或类似于阻止公司 |
| 170 | from releasing these models. | 从释放这些模型。 |
| 171 | It's actually the opposite. | 这其实恰恰相反。 |
| 172 | It's giving access to more people | 它让更多的人可以进入 |
| 173 | so that they can defend themselves, | 以便他们自卫, |
| 174 | democratizing the technology, making it more transparent. | 实现技术民主化,使其更加透明. |
| 175 | Clem, thank you so much | 克莱姆,非常感谢你 |
| 176 | for explaining all this to the public. | 为了向公众解释这一切 |
| 177 | We appreciate your time today. | 我们赞赏你今天的时间。 |
该视频共有字幕 177 条。解锁更多字幕为会员功能,请移动到 价格
