Хиймэл оюун ухааны технологийн дэвшлийг даган үүсэж буй програм хангамжийн эмзэг байдлыг илрүүлэх, хамгаалах зорилгоор “Anthropic Cyber Mission” хөтөлбөрийг танилцууллаа.
Anthropic компани өөрийн Project Glasswing төслийн хүрээнд илэрсэн програм хангамжийн сул талуудыг засахад туслах зорилгоор кибер аюулгүй байдлын шинэ хөтөлбөрөө зарлав. Энэхүү санаачилга нь дэд бүтэц болон нээлттэй эхийн төслүүдийг хиймэл оюун ухааны тусламжтайгаар халдлагад өртөхөөс хамгаалах хоёр үндсэн чиглэлтэй байна.
“Critical Infrastructure Defense Program” хөтөлбөрийн хүрээнд компани өөрийн дэвшилтэт загваруудыг мэргэшсэн инженерүүдтэй хамтруулан ашиглаж, нийтийн үйлчилгээний байгууллагуудын SCADA систем дэх эмзэг байдлыг хамгаалах ажлыг гүйцэтгэнэ. Энэ ажилд Accenture, Deloitte, Palo Alto Networks, CrowdStrike болон Rockwell Automation зэрэг салбарын тэргүүлэгч түншүүд оролцож байна.
Хоёр дахь чиглэл болох “OSS Scanner” үйлчилгээ нь нээлттэй эхийн томоохон төслүүдэд зориулсан аюулгүй байдлын үнэгүй шалгалтыг санал болгож байна. Anthropic-ийн мэдээлснээр, 2025 оны эхэн үетэй харьцуулахад хиймэл оюун ухааны загварууд нь эмзэг байдлыг илрүүлэх чадвараа 20 хувиас 85 хувь хүртэл өсгөжээ.
Гэсэн хэдий ч, энэхүү үйлчилгээг ашиглах төслүүд нь Anthropic-ийн үйлчилгээний нөхцөлийн дагуу өөрсдийн өгөгдлийг загвар сургалтад ашиглуулах шаардлагатай болно. Тус компани сүүлийн үед HuggingFace зэрэг байгууллагуудад тохиолдсон кибер халдлагуудын дараа иргэний хариуцлагын хүрээнд дээрх арга хэмжээг авч хэрэгжүүлж буйгаа илэрхийлсэн байна.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
Anthropic has launched an effort to help people patch the software vulnerabilities exposed by its own Project Glasswing. If that sounds like a careless camper starting a wildfire and later funding a fire department, well, that’s one way of looking at it. Anthropic insists it wants to give defenders access to the tools attackers are already using. Under a program name that sounds like a forthcoming Tom Cruise film – “Anthropic Cyber Mission” – the Claudefather is directing its effort into two areas. The first is a Critical Infrastructure Defense Program, because no one wants AI models showing miscreants how to shut down public utilities with newly discovered zero-day SCADA vulnerabilities. The program combines the company’s priciest models with on-site engineers – sometimes now referred to as forward deployed engineers – because despite the sophistication of AI coding agents, human security experts are still useful and many organizations lack in-house talent tutored in the ways of machine learning. Anthropic aims to tackle this challenge with the help of a stable of partners: Accenture, Booz Allen, CrowdStrike, Deloitte, Dragos, Hitachi, Insane Cyber, Nozomi Networks, Palo Alto Networks, PwC, and Rockwell Automation. These organizations have ties to critical infrastructure organizations and are already working to safeguard the fragile technical framework being probed constantly by AI agents. The second area of focus for the Anthropic Cyber Mission involves a service called OSS Scanner, “which offers open-source projects regular security scans from our strongest models, for free.” The offer does not extend to all open-source projects, nor is it entirely free. Anthropic has borrowed the eligibility criteria used by Google for its OS-FUZZ project and will therefore work on “established projects that have a critical impact on infrastructure and user security.” So if you just have a public web app repo languishing on GitHub, you can instead turn to existing tools like Socket, Dependabot, OSV-Scanner, Trivy, Renovate, or something similar. And maybe you’ll be able to get your AI coding agent of choice to audit your site without balking when faced with a security audit. But for those involved in influential and widely used open-source projects, reinforcements are at hand, so long as project maintainers don’t mind having their “materials” – inputs and outputs – used for model training, per the consumer terms of service Anthropic applied to OSS Scanner. Really though, most established open-source projects have already been captured in training data sets. Projects allowed to enroll can expect periodic automated scans that provide details about how identified bugs may be exploitable. These reports go out without human review, but Anthropic has assembled a set of quotes from participating OSS maintainers who believe the robo-reporting is worthwhile. At the beginning of the year, according to Anthropic, automated AI bug reports were considered mostly slop but are now considered high-quality bug reports. LLMs, the company said, now find more than 85 percent of vulnerabilities, up from 20 percent at the start of 2025. The AI biz predicts that in two years, defenders will have the advantage because AI will catch bugs before they ship. But until then, attackers have the upper hand. “Defenders of critical infrastructure and the OSS community have decades of security experience but have faced severe resource shortages that are exacerbated by this moment,” Anthropic said in a blog post. Anthropic’s moment of generosity comes after recent incidents that saw frontier models break into at least 20 organizations (and maybe over 100), most notably HuggingFace. After months of Anthropic and OpenAI allowing their AI agents to operate without the sort of oversight that would catch unlawful or undesirable network activity, public concern, government backlash [PDF], and perhaps plans to tap public markets for further financing, appear to have created a more urgent sense of civic responsibility. ®

