AI News AI资讯 2d ago Updated 18h ago 更新于 18小时前 51

Open-weight models now match frontier cyber performance from just four months ago at a fraction of the cost 开源模型如今以极低成本在网络安全性能上追平四个月前的前沿水平

Open-weight AI models (GLM-5.2, DeepSeek V4-Pro) have narrowed the performance gap with closed frontier systems to four–seven months, down from six–ten months previously. Significant cost disparities exist, with open models costing fractions of the price of proprietary equivalents (e.g., $1.19 vs. $85 for specific tests). Safety guardrails in open models are easily bypassed, creating an "irreversible risk of misuse" as malicious actors can deploy powerful cyber capabilities without oversight. Th 英国AI安全研究所(AISI)评估显示,开源AI模型在网络安全能力上仅落后闭源前沿模型4至7个月,较2025年初的6-10个月显著缩短。 具体测试中,GLM-5.2和DeepSeek V4-Pro等开源模型在特定网络任务和模拟攻击中达到了早期闭源模型的水平。 开源模型运行成本极低(如DeepSeek V4-Pro单次任务仅需28美分),且由于权重公开,其内置的安全护栏极易被绕过。 这种性能差距缩小与低成本结合,导致防御者应对新型AI驱动攻击的准备窗口期大幅压缩。 AISI警告称,开源模型的不可控性带来了“持久且不可逆”的滥用风险,需平衡开放创新与安全防御。

75
Hot 热度
70
Quality 质量
72
Impact 影响力

Analysis 深度分析

TL;DR

  • Open-weight AI models (GLM-5.2, DeepSeek V4-Pro) have narrowed the performance gap with closed frontier systems to four–seven months, down from six–ten months previously.
  • Significant cost disparities exist, with open models costing fractions of the price of proprietary equivalents (e.g., $1.19 vs. $85 for specific tests).
  • Safety guardrails in open models are easily bypassed, creating an "irreversible risk of misuse" as malicious actors can deploy powerful cyber capabilities without oversight.
  • The British AI Security Institute (AISI) warns that this shrinking window reduces the time cyber defenders have to prepare for emerging threats.

Why It Matters

This development signals a critical shift in the cybersecurity landscape, where high-end offensive AI capabilities are becoming democratized and affordable. For security practitioners and policymakers, the rapid convergence of open and closed model performance means that the defensive advantage provided by proprietary technology is eroding quickly, necessitating immediate updates to threat detection and mitigation strategies.

Technical Details

  • Benchmarking Methodology: AISI utilized two primary evaluation methods: "Narrow Cyber Tasks" (70 tasks across four difficulty levels including vulnerability research and cryptography) and "Cyber Ranges" (simulated autonomous attacks like "The Last Ones," a 32-step corporate network intrusion).
  • Performance Comparisons: GLM-5.2 matched Opus 4.6 (closed) on narrow tasks (4-month lag) and Opus 4.5 on Cyber Ranges (7-month lag). DeepSeek V4-Pro matched Opus 4.5 on narrow tasks but underperformed Sonnet 4.5 in the Cyber Range simulation.
  • Cost Analysis: Testing revealed drastic cost differences; a 100-million-token Cyber Range test cost ~$85 for Opus 4.5/4.6, ~$46 for GLM-5.2, and only $1.19 for DeepSeek V4-Pro. Per-task costs ranged from $15 (Opus 4.6) to $0.28 (DeepSeek V4-Pro).
  • Safety Efficacy: Open models demonstrated weak safety adherence; restrictions on tasks like reverse engineering were frequently bypassed through simple retry mechanisms, unlike closed systems where access control enforces compliance.

Industry Insight

  • Accelerated Defense Investment: Organizations must accelerate the adoption of AI-driven defensive tools to counter the lowered barrier to entry for automated cyberattacks using open-weight models.
  • Regulatory Focus on Open Weights: Policymakers should consider stricter governance or watermarking standards for open-weight models given the ease of bypassing safety filters and the irreversible nature of their distribution.
  • Strategic Planning Windows: The shrinking 4–7 month gap between closed and open model capabilities requires enterprises to treat current proprietary advantages as temporary, prompting earlier migration to next-generation defensive architectures.

TL;DR

  • 英国AI安全研究所(AISI)评估显示,开源AI模型在网络安全能力上仅落后闭源前沿模型4至7个月,较2025年初的6-10个月显著缩短。
  • 具体测试中,GLM-5.2和DeepSeek V4-Pro等开源模型在特定网络任务和模拟攻击中达到了早期闭源模型的水平。
  • 开源模型运行成本极低(如DeepSeek V4-Pro单次任务仅需28美分),且由于权重公开,其内置的安全护栏极易被绕过。
  • 这种性能差距缩小与低成本结合,导致防御者应对新型AI驱动攻击的准备窗口期大幅压缩。
  • AISI警告称,开源模型的不可控性带来了“持久且不可逆”的滥用风险,需平衡开放创新与安全防御。

为什么值得看

本文揭示了AI网络安全军备竞赛的最新态势,指出开源模型正迅速抹平与商业闭源模型的能力差距,这对依赖闭源系统进行防御的企业和机构构成了直接威胁。它强调了在追求模型开放性的同时,必须正视其被恶意利用且难以监管的现实风险,为制定AI安全策略提供了紧迫的时间表参考。

技术解析

  • 评估基准与方法:AISI采用两种主要测试方法:“窄域网络任务”(Narrow Cyber Tasks),包含70项涵盖漏洞研究、逆向工程、Web利用和密码学的任务;以及“网络范围”(Cyber Ranges),通过模拟32步企业网络攻击测试自主能力。
  • 性能对比数据:在窄域任务中,GLM-5.2(2026年6月发布)匹配了Opus 4.6(2026年2月发布)的性能,差距约4个月;DeepSeek V4-Pro匹配了Opus 4.5(2025年11月发布)。在网络范围测试中,GLM-5.2表现接近Opus 4.5,而领先闭源模型GPT-5.6-Sol和Claude Mythos 5表现最佳,差距扩大至约7个月。
  • 成本效益分析:开源模型具有极高的性价比。在1亿token的网络范围测试中,Opus 4.5/4.6成本约为85美元,GLM-5.2约为46美元,而DeepSeek V4-Pro仅为1.19美元。在单任务层面,DeepSeek V4-Pro成本低至28美分,远低于闭源模型的12.50-15美元。
  • 安全护栏局限性:研究发现开源模型的安全措施几乎无效。例如,DeepSeek V4-Pro虽偶尔拒绝逆向工程请求,但通过重复尝试即可轻易绕过。由于无法控制访问权限,传统的监控、分类器和用户限制等安全措施难以在开源环境中有效实施。

行业启示

  • 防御策略需前置:随着开源模型能力快速逼近前沿,防御者必须假设恶意行为者已具备同等甚至更廉价的攻击工具,需提前部署针对AI自动化攻击的检测和缓解机制,而非等待漏洞出现。
  • 重视开源模型的双刃剑效应:虽然开源模型降低了AI应用门槛并促进了创新,但其“不可逆的滥用风险”要求行业建立新的治理框架,特别是在模型发布前的安全对齐和发布后的监控方面。
  • 关注未来高能开源模型:AISI计划测试即将发布的Kimi-K3等新型开源模型,尽管成本较高,但其编码基准表现可能进一步缩小与前沿模型的差距,行业应持续跟踪此类高能力开源模型的动态及其潜在的安全影响。

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Open Source 开源 Closed Source 闭源 Security 安全 LLM 大模型 Research 科学研究