Import AI 467 Self-sustaining AI viruses; pacing AI progress_全翻译
【文章标题】:Import AI 467: Self-sustaining AI viruses; pacing AI progress; confusion about AI and creativity
【文章正文】: Welcome to Import AI, a newsletter about AI research. Import AI runs on arXiv, cappuccinos, and feedback from readers. If you'd like to support this, please subscribe.
欢迎阅读Import AI,一份关于AI研究的通讯。Import AI依靠arXiv、卡布奇诺咖啡和读者的反馈得以运转。如果您愿意支持我们,请订阅。
Subscribe now
立即订阅
Self-sustaining and self-replicating AI viruses are here:
自我维持、自我复制的AI病毒已经出现:
…Open weight LLMs + a well-designed harness = a persistent, self-sufficient virus…
……开放权重大语言模型+精心设计的控制框架=一种持久、自给自足的病毒……
AI researchers have built a prototype computer virus which uses AI models to compromise computers, then uses their underlying GPU resources to run inference, letting it smartly figure out how to infect more hosts. The results were achieved by researchers from the University of Toronto, the Vector Institute, the University of Cambridge, and ServiceNow, and "demonstrate that self-sustaining AI-driven cyber-threats are no longer theoretical."
AI研究人员已经构建了一种原型计算机病毒,它利用AI模型入侵计算机,然后使用其底层GPU资源进行推理,使其能够智能地找出感染更多主机的方法。这一成果由多伦多大学、向量研究所、剑桥大学和ServiceNow的研究人员共同完成,并"证明了自我维持的AI驱动网络威胁不再是理论上的设想"。
"We must prepare for autonomous generative adversaries," they write. "Artificial intelligence (AI) agents enable a fundamentally new threat: a worm that generates tailored attack strategies to each target it encounters. The worm parasitically uses compromised machines to run open-weight large language models (LLMs) to sustain its reasoning, or extend its reach for further attacks".
"我们必须为自主生成式对手做好准备,"他们写道。"人工智能(AI)智能体带来了一种全新的威胁:一种能针对每个遭遇的目标量身定制攻击策略的蠕虫。该蠕虫以寄生方式利用被入侵的机器来运行开放权重大语言模型(LLM),以维持其推理能力,或扩展其攻击范围。"
How it works
- 工作原理
-
"The worm uses stolen computing power from compromised GPU nodes to host LLMs for generative reasoning. It then uses this reasoning to detect vulnerabilities and devise tailored attacks against additional targets, furthering its spread," they write. "The proof-of-concept operates using only an open-weight LLM running on a single, local GPU, with no reliance on vendor APIs that could be monitored or revoked".
"该蠕虫利用从被入侵GPU节点窃取的算力来托管LLM以进行生成式推理。然后,它利用这种推理能力检测漏洞,并针对更多目标设计定制化攻击,从而进一步扩散,"他们写道。"该概念验证仅使用运行在单个本地GPU上的开放权重LLM即可运作,不依赖任何可能被监控或撤销的供应商API。"
The researchers don't describe the underlying LLM besides saying it was published in 2025 and can fit on a single A100 GPU with 80GB of VRAM.
研究人员没有详细描述底层LLM,只提到它发布于2025年,可以装进一块拥有80GB显存的A100 GPU中。
A successful proof-of-concept via some custom tools
- 通过自定义工具实现成功的概念验证
-
They give the agent a custom harness that comes with built-in helper functions for network discovery, host discovery, foothold exploitation, privilege escalation, privilege escalation exploitation, and tools for replication of the agent. Along with this, they ship with a reasoning graph that helps the agent specialize its thinking and not get confused, consisting of "a directed graph of specialised nodes, each responsible for a distinct analytical function and seeing only the tools and prompts relevant to its role. By decomposing the agent's reasoning into these scoped steps, the graph controls what the LLM attends to at each decision point, and limits context growth to information relevant for the current sub-goal".
他们为智能体配备了一个自定义控制框架,内置了用于网络发现、主机发现、立足点利用、权限提升、权限提升利用以及智能体复制工具等辅助功能。此外,他们还附带了一个推理图(reasoning graph),帮助智能体专业化其思考并避免混乱,该图由"一个有向的专门节点图组成,每个节点负责一种独特的分析功能,且只能看到与其角色相关的工具和提示。通过将智能体的推理分解为这些有范围的步骤,推理图控制LLM在每个决策点关注什么,并将上下文增长限制在与当前子目标相关的信息范围内"。
Some examples of the nodes include:
其中一些节点的示例包括:
Plan ("formulates a high-level attack strategy"), Judge ("reviews the proposed plan against the command history"), Action ("selects a tool from the phase-appropriate tool set"), Summary ("compiles the step's observations into a structured summary"), Progress ("Evaluates whether the agent is making meaningful progress").
计划节点("制定高层攻击策略")、评判节点("对照命令历史审查拟议计划")、行动节点("从适合当前阶段的工具集中选择工具")、总结节点("将步骤中的观察结果汇编成结构化摘要")、进展节点("评估智能体是否正在取得有意义的进展")。
"We describe a subset of 5 nodes that make up our reasoning graphs. The others are redacted in this public version of the manuscript," they write.
"我们描述了构成推理图的5个节点子集。其余节点在本公开版本的手稿中已被删节,"他们写道。
The agent proceeds through three key steps
智能体通过三个关键步骤推进
- identifying vulnerabilities in its environment, exploiting those vulnerabilities, and then self-replicating. It's pretty successful at all of these things, with a ~80% success rate on vulnerability detection, then a ~53% success rate on exploiting these, then an 88% self-replication success rate with some pre-wrapped helper tools for the replication steps. Therefore, the overall success rate for a full attack here is ~37% or so, which is significant enough to be concerning, but also poor enough that this also serves as a useful eval for testing open weight models in the future.
——识别环境中的漏洞,利用这些漏洞,然后自我复制。它在所有这些方面都相当成功:漏洞检测成功率约为80%,利用漏洞的成功率约为53%,在配备一些预先封装好的复制辅助工具的情况下,自我复制成功率为88%。因此,完整攻击的总体成功率约为37%左右,这个数字高到足以令人担忧,但同时也低到足以作为未来测试开放权重模型的有用评估基准。
Why this matters - the shape of the internet to come:
为何重要——未来互联网的形态:
The future internet is going to be more like a complex ecology full of attacker and defender AI agents than anything else; research like this shows how certain AI agents might end up carving out their own ecological niches, living off of infrastructure and self-replicating autonomously, beyond human control. This may mean that humans need to create their own AI agents which they release onto the internet to serve as kinds of white blood cells against the adversary models.
未来的互联网将更像一个充满攻击者和防御者AI智能体的复杂生态系统,而非其他任何形态;这类研究表明,某些AI智能体最终可能会开辟出属于自己的生态位,依靠基础设施生存并自主自我复制,超出人类控制。这可能意味着人类需要创建自己的AI智能体,将其释放到互联网上,充当抵御对手模型的白细胞。
"Despite the inherent fragility of individual exploitation attempts, the worm agent achieves operational resilience by continuously self-replicating into a swarm—a decentralized collective of independent agent replicas acting concurrently across the network," they write. "Difficult hosts that resist initial attempts are retried by different replicas, each sampling a fresh reasoning trajectory that collectively explores diverse exploitation paths until one succeeds… the worm operates in a fully decentralized manner, and no single point of control can be taken offline to interrupt its spread".
"尽管单个利用尝试存在固有的脆弱性,蠕虫智能体通过不断自我复制成一个群体——一个由独立智能体副本组成的去中心化集体,在网络中并发行动——实现了运营韧性,"他们写道。"对于抵抗初次尝试的棘手主机,不同的副本会进行重试,每个副本都会采样新的推理轨迹,共同探索多样化的利用路径,直到其中一个成功……该蠕虫以完全去中心化的方式运作,没有任何单一控制点可以被下线以中断其传播"。
Read more
延伸阅读
:
AI Agents Enable Adaptive Computer Worms (arXiv)
《AI智能体实现自适应计算机蠕虫》(arXiv)
.
Dwarkesh: As AI gets better, compute will get more expensive:
Dwarkesh:随着AI变得更好,算力将变得更加昂贵:
…Smarter systems mean higher prices…
……更智能的系统意味着更高的价格……
Dwarkesh Patel suspects that as AI systems get smarter, the price of compute will rise even further. "As AI models become smarter, they'll better monetize the same amount of compute. If a true human-level software engineer that could run on an H100 equivalent, at current market rates for software engineers, that H100 should rent for over $250k a year. That's 15x today's spot prices," he writes. "The reason AI is relatively cheap right now, at least in comparison to human labor, is partly that it can't do a lot of things that top humans can do. At some point that will no longer be the case. And so using GPUs to make short-form video slop will just get priced out."
Dwarkesh Patel推测,随着AI系统变得越发智能,算力的价格将进一步上涨。"随着AI模型变得更加智能,它们将更好地将同等数量的算力变现。如果一个真正达到人类水平的软件工程师可以运行在一块相当于H100的GPU上,按照目前软件工程师的市场价格,这块H100的年租金应该超过25万美元。这是当前现货价格的15倍,"他写道。"AI目前相对便宜的原因——至少与人类劳动力相比——部分在于它无法做到顶级人类能做的许多事情。到了某个时候,情况将不再如此。因此,用GPU制作短视频垃圾内容将直接被市场淘汰。"
Temporary:
暂时性的:
This will be a temporary state of affairs; Dwarkesh expects that at some point massive roboticization of the compute supply chain should bring its price down closer to the cost of raw inputs and tools - though by that point we'll be pretty deep into the singularity.
这将是一种暂时性的状态;Dwarkesh预计,在某个时候,算力供应链的大规模机器人化将使其价格回落到接近原材料和工具成本的水平——不过到那时,我们可能已经深入奇点之中了。
Why this matters - singularity economics will be weird:
为何重要——奇点经济学将是奇特的:
The core implication in Dwarkesh's post is that as we get deeper into the singularity, very strange things will happen to economics - like the price of things thought of as commodities today (computers) getting massively bid-up due to the voracious demands of AI systems.
Dwarkesh文章的核心含义是,随着我们深入奇点,经济学领域将发生非常奇怪的事情——比如今天被视为大宗商品的物品(计算机)的价格,会因AI系统的贪婪需求而被大幅推高。
Read more
延伸阅读
:
Why compute might get 10x+ more expensive in coming years (Dwarkesh Patel, substack)
《为什么未来几年算力可能变得昂贵10倍以上》(Dwarkesh Patel,substack)
.
~1337 employees ask the US to help them pace AI progress:
约1337名员工请求美国帮助他们为AI进展设定节奏:
…After the warning shots come the pleas…
……警告枪响之后,是恳求之声……
A new statement is out with senior representation from all the major Western AI labs - OpenAI, Anthropic, Google DeepMind, Thinking Machines, Meta, and Safe Superintelligence Inc, among others. The statement requests that the US government support an international effort to "develop the technical and governance tools needed to deliberately pace the frontier of automated AI development." Signatories include chief scientists and cofounders of Anthropic, Google, and OpenAI, as well as the CEOs of Safe Superintelligence and Anthropic.
一份新的声明已经发布,所有主要西方AI实验室——OpenAI、Anthropic、Google DeepMind、Thinking Machines、Meta和Safe Superintelligence Inc等——均有高级代表署名。该声明请求美国政府支持一项国际努力,以"开发必要的技术和治理工具,有意地为自动化AI发展的前沿设定节奏。"签署人包括Anthropic、Google和OpenAI的首席科学家和联合创始人,以及Safe Superintelligence和Anthropic的首席执行官。
The statement in full:
声明全文如下:
"AI could help create a dramatically better future, but that outcome is not guaranteed. The world's leading AI companies believe they could be close to automating AI research. It is hard to predict exactly how much this will accelerate AI progress, but there is a real risk that capability development rapidly accelerates beyond our ability to understand or control the resulting systems.
"AI可以帮助创造一个极其更美好的未来,但这一结果并非必然。世界领先的AI公司相信,它们可能已接近实现AI研究的自动化。很难准确预测这将多大程度上加速AI进展,但确实存在一种风险:能力发展可能会迅速加速,超出我们理解或控制由此产生的系统的能力。
To realize AI's potential, industry, government, and society at large may need the option to buy time to address emerging risks, develop security measures, and strengthen oversight. But each company—and country—is under intense competitive pressure not to unilaterally slow that acceleration. And today, the world lacks the technical and governance tools to deliberately pace frontier-wide progress.
为了实现AI的潜力,产业界、政府和社会大众可能需要一种争取时间的选项,以应对新出现的风险、制定安全措施并加强监督。但每家公司——以及每个国家——都面临着激烈的竞争压力,不能单方面放缓这种加速。而如今,世界缺乏必要的技术和治理工具来有意地为前沿整体的进展设定节奏。
Building on work already underway to monitor frontier model releases: "We request that the U.S. government support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development."
在已经开展的监测前沿模型发布工作的基础上:"我们请求美国政府支持一项国际努力,以开发必要的技术和治理工具,有意地为自动化AI发展的前沿设定节奏。"
Why this matters - dealing with RSI requires solving a giant collective action problem:
为何重要——应对递归自我改进需要解决一个巨大的集体行动问题:
Many of the challenges implied by increasingly powerful systems that may eventually build themselves run through solving collective action problems among humans - namely, how we can get companies and governments to coordinate in thinking about how to develop this technology and what kinds of mechanisms may be desirable for being able to control the speed at which it develops. It may be the case that as we build increasingly intelligent systems we want to find ways to give society more time to adapt to each rung up the intelligence ladder, and it's not inconceivable there are some levels of intelligence which might be, for now, too dangerous to reach for. Statements like this are an essential prerequisite for giving our species the ability to deal with and talk about problems of this nature.
日益强大的系统最终可能会自我构建,这所带来的许多挑战都需要通过解决人类之间的集体行动问题来应对——也就是说,我们如何让公司和政府在思考如何开发这项技术方面进行协调,以及什么样的机制可能有助于控制其发展速度。情况可能是,随着我们构建越来越智能的系统,我们希望找到方法让社会有更多时间适应智能阶梯上的每一级,而且并非不可想象的是,某些智能水平目前可能过于危险而不宜触及。像这样的声明是赋予我们人类应对和讨论此类问题的能力的基本前提。
Read the statement here
在此阅读声明
:
Pacing the Frontier (official statement website)
《为前沿设定节奏》(官方声明网站)
.
AI systems are good at frontier engineering but bad at creativity:
AI系统擅长前沿工程,但不擅长创造力:
…A somewhat bearish signal on short recursive self-improvement timelines…
……关于较短递归自我改进时间线的略显悲观信号……
Can AI systems come up with creative research ideas which move the field of AI forward? That's the key question to resolve to figure out how quickly AI systems might gain the capability to automate the autonomous development of more powerful systems. New research suggests that today's AI systems lack this quality of tasteful creativity, though are extremely good at engineering.
AI系统能否提出推动AI领域前进的创造性研究想法?这是判断AI系统多快能获得自动化开发更强大系统能力的关键问题。新研究表明,当今的AI系统缺乏这种品味独特的创造力品质,尽管它们在工程方面极其出色。
Who did it:
谁做的:
The project was conducted by researchers with Princeton University, Cornflower Labs, UK AI Security Institute, University of Toronto, UC Berkeley, Georgetown University (CSET), Johns Hopkins University, the Golden Gate Institute for AI, AI Digest, and Stanford University.
该项目由普林斯顿大学、Cornflower Labs、英国AI安全研究所、多伦多大学、加州大学伯克利分校、乔治城大学(CSET)、约翰霍普金斯大学、金门AI研究所、AI Digest和斯坦福大学的研究人员共同开展。
The big idea - "shadow evaluation"
- 核心思路——"影子评估"
-
This research project works by seeing how well AI systems can do unpublished research. To do this, the researchers "partnered with the authors of two papers submitted to NeurIPS 2026 that were not yet public." Shadow evaluation works by "taking the central research question from a high-quality research paper that is not yet public, tasking a well-resourced frontier agent with answering it, and asking the paper's original authors to grade the agent's output as they would a conference submission."
:该研究项目通过考察AI系统在未发表研究上的表现来运作。为此,研究人员"与两篇提交至NeurIPS 2026但尚未公开的论文作者合作。"影子评估的运作方式是"从一篇尚未公开的高质量研究论文中提取核心研究问题,让一个资源充足的前沿智能体来回答它,并请论文原作者像评审会议投稿一样为智能体的输出打分。"
In this, the research is somewhat similar to "First Proof" (
在这一点上,该研究与"First Proof"(
Import AI 445
Import AI 445
), an earlier experiment to see how well AI systems might be able to complete math problems which are being worked on by frontier mathematicians but for which no solutions or research ideas have been published online.
)有些相似,那是一个早期实验,旨在考察AI系统在解决前沿数学家正在攻关、但网上尚未发表任何解决方案或研究思路的数学问题方面表现如何。
For this research, the AI systems - Claude Opus 4.8 running within the OpenClaw harness - attempted two distinct lines of research, one of which was about "the structure and controllability of LLM personas", and the other was about how to "design a distribution shift detector for tabular foundation models".
在这项研究中,AI系统——运行在OpenClaw控制框架中的Claude Opus 4.8——尝试了两条不同的研究路线,一条是关于"LLM人格的结构和可控性",另一条是关于如何"为表格基础模型设计分布偏移检测器"。
Good engineers, poor researchers
- 优秀的工程师,糟糕的研究者
-
"While agents could solve the engineering problems necessary to do the research, they failed to produce original research at the caliber of a top ML conference," the authors write. The failures of the