OpenAI’s Astra model is on the way — and very good at breaking into computer systems
热度趋势
趋势数据积累中
百分比基于当前可用热度信号,而非评论数或独立用户人数。
OpenAI 相关模型动态已经出现,适合跟踪能力变化、生态影响和后续可用性。
OpenAI公布了其即将推出的Astra模型的更多细节,并声称这是首个达到其“关键网络安全阈值”的大型语言模型。该公司已投入未具体说明的新技术以提高模型的安全性,并对被评估为“高风险”的账户限制其响应。尽管Astra被描述为迄今为止“最对齐的模型”,但它在即将发布时仍将部署额外的思维链监控,以发现并阻止不良行为。
OpenAI shared new details on its forthcoming Astra model, which the company said is the first large language model to meet its “critical cybersecurity threshold,” in preparation for its imminent release.
“We plan to make Astra available soon,” OpenAI’s blog post reads, “but access to its most advanced cybersecurity capabilities will be more limited.”
The frontier lab determined that Astra is capable of finding unknown security flaws in computer systems, and exploiting them without a person’s guidance. That’s similar to the concerns Anthropic raised about its Mythos model earlier this year, and OpenAI is taking comparable precautions as it prepares to roll out the Astra.
Without any third-party confirmation, it is difficult to evaluate OpenAI’s claims about safety or preparedness. The company said it would preview the model with a group of testers but did not say who they were or how they would be chosen. It’s not clear if OpenAI is working with the U.S. government to evaluate the model ahead of release.
OpenAI noted that Astra scored a perfect score on ExploitBench, an evaluation of an LLM’s ability to hack into known system vulnerabilities. In a modified version of the test developed by OpenAI engineers, the model discovered and exploited two zero-day vulnerabilities, the company said.
To ensure that its models are neither exploited by bad actors nor capable of bad behavior itself, OpenAI said it had already begun improving the model’s harness to detect abuses and prevent jailbreaks.
For Astra, however, the company invested in unspecified new techniques designed to make the model safer. OpenAI has also started identifying “accounts assessed as higher risk” and restricting the model’s responses to their prompts, though it also doesn’t say how. Finally, though the company describes Astra as its “most aligned model to date,” it will deploy the model with additional chain-of-thought monitoring to spot and stop bad behavior.
Preparations for the release of Astra come as the industry reacts to OpenAI agents breaking out of a training environment and accessing private data on Hugging Face, a popular model and benchmark distribution platform.
For Astra, OpenAI said it designed a test to tempt the new model to replicate the actions of the rogue agents in the Hugging Face incident, which collaborated to access the open internet despite safeguards applied by OpenAI researchers. They said Astra did not attempt to break out of its testing environment in these experiments.
Yona Shavit, a former OpenAI employee who now works on AI resilience at the OpenAI Foundation, wondered on social media whether Astra’s unwillingness to break the rules may have resulted from knowing what was expected of it or trying to fool researchers.
And for all these new details, it’s still difficult to know exactly what Astra is capable of or if OpenAI is taking the right measures to ensure safety. The company said it expects to release more evaluations of the model and further safety information when it is launched widely to the public.
At that point, however, the cat will be out of the bag.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.
Tim Fernholz is a journalist who writes about technology, finance and public policy. He has closely covered the rise of the private space industry and is the author of Rocket Billionaires: Elon Musk, Jeff Bezos and the New Space Race. Formerly, he was a senior reporter at Quartz, the global business news site, for more than a decade, and began his career as a political reporter in Washington, D.C.
You can contact or verify outreach from Tim by emailing tim.fernholz@techcrunch.com or via an encrypted message to tim_fernholz.21 on Signal.
View Bio