กลับไปที่ข่าว
ความปลอดภัยAI Understanding บรรยายสรุป

Anthropic กล่าวว่า GLM-5.3 ของ Zhipu ตรงกับ Claude Mythos ในการสร้างช่องโหว่

การวิเคราะห์ Frontier Red Team ของ Anthropic พบว่า Zhipu AI แบบเปิดน้ำหนักของ GLM-5.3 สามารถสร้างช่องโหว่ทางไซเบอร์ได้ในระดับที่ใกล้เคียงกับ Claude Mythos Preview ของ Anthropic ซึ่งทำให้เกิดความกังวลเกี่ยวกับความง่ายในการข้ามการป้องกันในโมเดลที่เปิดเผยต่อสาธารณะ

4 min readRead the linked source
Source-provided image accompanying Anthropic says Zhipu's GLM-5.3 matches Claude Mythos in exploit generation
แหล่งอ้างอิงแหล่งที่มาบันทึกไว้
สำนักพิมพ์
the-decoder.com
ลิงค์แหล่งที่มา
the-decoder.comhttps://the-decoder.com/anthropic-says-zhipus-open-weight-glm-5-3-nearly-matches-claude-mythos-preview-at-building-exploits/
ประเภทแหล่งที่มา
แหล่งที่มาที่เชื่อมโยง — ยังไม่ได้สร้างสถานะแหล่งที่มาหลัก
บริบทเข้าใจสิ่งนี้ใน 60 วินาที

เริ่มที่นี่

เงื่อนไขสำคัญ

API (อินเทอร์เฟซการเขียนโปรแกรมแอปพลิเคชัน)
วิธีการที่มีโครงสร้างสำหรับระบบซอฟต์แวร์หนึ่งในการส่งคำขอและรับการตอบกลับจากอีกระบบหนึ่ง
เกณฑ์มาตรฐาน
การทดสอบหรือชุดข้อมูลที่เป็นมาตรฐานที่ใช้ในการวัดและเปรียบเทียบประสิทธิภาพของโมเดล
การอนุมาน
ระยะรันไทม์ที่โมเดลที่ได้รับการฝึกสร้างการคาดการณ์หรือเอาต์พุต
ทดสอบตัวเองแบบทดสอบจริยธรรมของ AI

เกิดอะไรขึ้น

Anthropic’s Frontier Red Team evaluated Zhipu AI’s open‑weight GLM‑5.3 model and found it can generate functional cyber exploits with success rates only slightly below Anthropic’s Claude Mythos Preview. The analysis, corroborated by the U.S. agency CAISI, highlights that GLM‑5.3’s safeguards are easy to bypass, and the model is publicly downloadable.

Anthropic’s Frontier Red Team compared GLM‑5.3 against Claude Mythos Preview using two benchmarks. On the ExploitBench suite, which tests exploitation of Chrome’s V8 engine, GLM‑5.3 succeeded in 50 of 410 attempts, while Mythos Preview succeeded in 56. On an internal binary‑exploitation based on Google’s OSS‑Fuzz projects, GLM‑5.3 achieved full control in 4 % of tasks versus 6 % for Mythos Preview. Older models such as GLM‑5.2 and Claude Opus 4.6 failed both tests.

Anthropic paired GLM‑5.3 with a human expert and, within a day, the model discovered previously unknown vulnerabilities in a widely used browser’s JavaScript engine, chained them into a web page that could read any file on a visitor’s computer, and exfiltrated a private SSH key. The vulnerabilities were reported to the browser’s developers.

A separate test using the smaller GLM‑5.3‑Flash model showed the model could combine a newly disclosed Chrome bug with an existing vulnerability to produce a reliable attack in 20 minutes of human oversight and eight hours of model time, costing roughly $20.40 at Zhipu’s published API rates.

CAISI’s independent assessment labeled GLM‑5.3 the most cyber‑capable open‑weight model to date, placing it about four months behind the best U.S. models when those models were evaluated with safeguards disabled. The agency noted that many top‑tier U.S. models are only accessible to vetted users, whereas GLM‑5.3 is openly downloadable.

รายละเอียดที่มา: the-decoder.com ↗

ทำไมมันถึงสำคัญ

The finding shows that open‑weight models can reach frontier‑level cyber‑capability without robust safety controls, expanding the pool of tools available to malicious actors. This challenges existing assumptions that only closed, vetted models pose a serious exploit risk and underscores the need for new governance, testing frameworks, and defensive tooling to keep pace with rapidly advancing open AI capabilities.

The analysis demonstrates that open‑weight models can achieve near‑frontier exploit performance without the safety layers that closed models employ, meaning that malicious actors can acquire powerful tools at low cost and with minimal technical expertise.

Anthropic’s own business model benefits from positioning its guarded Claude models as the safer alternative, potentially influencing policy and market dynamics in favor of proprietary providers.

The ease of bypassing safeguards—shown by Anthropic’s abliteration experiment where refusal rates fell from over 90 % to as low as 2 %—highlights a technical vulnerability in open‑weight model deployment that could be exploited at scale.

Regulators and industry groups may need to reconsider existing AI risk frameworks, which often focus on closed models, to address the growing threat surface presented by openly available, high‑capability models.

Interactive Mechanism

กลไกเชิงโต้ตอบ: มันทำงานอย่างไร

สำรวจเทคโนโลยีเบื้องหลังการพัฒนานี้แบบโต้ตอบ

System Requirements:
Best ArchitecturePure RAGRecommended pattern
Hallucination RiskVery LowGrounding efficacy
Update Cost$0 (Vector sync)Ongoing maintenance
Core takeaway: Fine-tuning teaches models how to speak (form, style, syntax); RAG teaches models what to say (verifiable facts). Never use fine-tuning alone for factual memory.
การตรวจสอบแนวคิดแบบโต้ตอบ+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

จะดูอะไรต่อไป.

Future assessments of open‑weight models, regulatory responses to AI‑driven cyber threats, and the development of mitigation techniques such as abliteration or hardened environments.

Whether additional government agencies, such as the U.S. CAISI, publish further assessments of open‑weight models and recommend specific mitigation strategies.

Potential policy proposals aimed at requiring safety‑oriented licensing or mandatory testing for open‑weight models that demonstrate high cyber capability.

Development of technical defenses, such as abliteration or sandboxed , that can be applied by organizations deploying open‑weight models.

Responses from Zhipu AI, including any updates to model safeguards, pricing changes, or licensing restrictions that could affect accessibility.

คำแนะนำและแบบทดสอบที่เกี่ยวข้อง

จริยธรรม AIอธิบายโมเดล AIหม้อแปลงไฟฟ้าทดสอบสิ่งที่คุณรู้ — ลองแบบทดสอบ AI ฟรีค้นหาคำศัพท์ AI ในอภิธานศัพท์ของเราปฏิบัติตามตัวติดตามกฎระเบียบของ AI
พบว่าสิ่งนี้มีประโยชน์หรือไม่?