AI News AI资讯 2h ago Updated 1h ago 更新于 1小时前 48

Discovering cryptographic weaknesses with Claude 使用Claude发现密码学弱点

Anthropic researchers used Claude Mythos to identify mathematical flaws in HAWK and a weakened version of AES, though these findings have no immediate practical impact on current systems. The research highlights the potential of AI models to assist in cryptographic analysis but also underscores the challenges in prompting such models to pursue complex, non-trivial problems. The study emphasizes the importance of iterative human intervention to guide AI models toward meaningful research outcomes, Anthropic研究人员利用Claude Mythos模型成功发现HAWK及简化版AES的数学漏洞,验证了AI在密码学分析中的潜力。 研究强调通过精心设计的提示(含拼写错误)引导模型突破“不可能解决”的思维定势,实现突破性发现。 实验耗时60小时、API成本约10万美元,核心人类干预在于持续激励模型追求高价值、可发表的研究成果而非低垂果实。 当前结果暂无实际系统影响,但为未来AI辅助密码分析提供了方法论范式。 该工作展示了大模型在复杂数学问题中作为“高级研究员”角色的可行性,推动AI与基础科学研究的深度融合。

72
Hot 热度
68
Quality 质量
65
Impact 影响力

Analysis 深度分析

TL;DR

  • Anthropic researchers used Claude Mythos to identify mathematical flaws in HAWK and a weakened version of AES, though these findings have no immediate practical impact on current systems.
  • The research highlights the potential of AI models to assist in cryptographic analysis but also underscores the challenges in prompting such models to pursue complex, non-trivial problems.
  • The study emphasizes the importance of iterative human intervention to guide AI models toward meaningful research outcomes, as the models initially struggled with the complexity of the tasks.

Why It Matters

This article is significant for AI practitioners and researchers as it demonstrates the emerging role of advanced language models in cryptographic research, a field traditionally reliant on human expertise. It also provides insights into the limitations and potential of AI in tackling highly specialized and abstract problems, which could inform future developments in AI-assisted scientific discovery.

Technical Details

  • Model Used: Claude Mythos, an advanced language model developed by Anthropic.
  • Target Cryptographic Systems: HAWK and a weakened version of AES (not AES-128 r7).
  • Findings: Mathematical flaws were identified in both systems, though these do not pose a threat to current implementations.
  • Prompting Strategy: The researchers faced challenges in guiding the model to focus on publishable, non-trivial results, requiring repeated human interventions to refine the approach.
  • Cost and Duration: The experiment ran for approximately 60 hours, with an estimated API cost of $100,000.

Industry Insight

  • AI in Cryptography: This case suggests that AI models like Claude Mythos can contribute to cryptographic research, particularly in identifying novel vulnerabilities or weaknesses in less common or modified versions of established algorithms. However, their effectiveness depends heavily on precise prompting and human oversight.
  • Future Research Directions: As AI models continue to evolve, they may increasingly play a role in automated vulnerability detection and cryptographic analysis, potentially reducing the time and effort required for manual research. However, ensuring that these models produce meaningful and publishable results will remain a critical challenge.

TL;DR

  • Anthropic研究人员利用Claude Mythos模型成功发现HAWK及简化版AES的数学漏洞,验证了AI在密码学分析中的潜力。
  • 研究强调通过精心设计的提示(含拼写错误)引导模型突破“不可能解决”的思维定势,实现突破性发现。
  • 实验耗时60小时、API成本约10万美元,核心人类干预在于持续激励模型追求高价值、可发表的研究成果而非低垂果实。
  • 当前结果暂无实际系统影响,但为未来AI辅助密码分析提供了方法论范式。
  • 该工作展示了大模型在复杂数学问题中作为“高级研究员”角色的可行性,推动AI与基础科学研究的深度融合。

为什么值得看

本文揭示了AI在密码学领域从辅助工具向主动研究者的转变路径,对安全研究者、AI架构师及密码学开发者具有重要参考价值。它证明了通过优化提示策略与激励机制,大模型能克服认知局限,在高难度数学问题中产生原创性洞见,为AI驱动的基础科学研究提供新范式。

技术解析

  • 使用Claude Mythos(推测为Anthropic内部定制版本)进行为期60小时的连续推理实验,总API成本估算达10万美元,体现高算力投入与长周期探索特性。
  • 关键技术创新在于提示工程:研究者刻意包含拼写错误并重复强调“寻找值得发表的成果”,以对抗模型默认放弃倾向,激发其深入探索非常规攻击路径。
  • 目标系统包括HAWK公钥加密方案及弱化的AES变体(非标准AES-128-R7),旨在测试模型能否超越传统暴力或启发式方法,发现结构性数学缺陷。
  • 人类角色定位为“教练”而非直接解题者,主要通过语言干预维持模型动机,确保研究方向聚焦于高影响力学术产出,而非简单漏洞扫描。
  • 实验未公开具体漏洞细节或代码实现,但开源仓库链接表明后续可能披露完整prompt模板与中间推理日志,供社区复现与扩展。

行业启示

  • AI正逐步成为密码分析与基础科研的“协同研究员”,企业应建立人机协作的研究框架,将大模型纳入安全评估与算法设计流程。
  • 提示工程的精细化程度直接影响AI产出质量,尤其在高风险领域如密码学中,需设计具有抗挫性、目标导向性的对话策略以释放模型潜能。
  • 尽管当前发现无实战威胁,但随着模型能力演进,自动化密码分析可能重塑安全标准制定节奏,建议行业提前布局AI防御机制与动态验证体系。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Claude Claude Security 安全 Research 科学研究