Vulnerability exposed in mainstream AI model inference chain, 62 valid keys leaked
Coinpaper
2h ago
Ai Focus
Researchers expose encryption design flaws in mainstream AI inference models; 62 valid API keys and multiple sensitive pieces of information have been found in public logs. Relevant manufacturers have already deployed mitigatory measures.
Helpful
No.Help

研究人员披露,Anthropic、OpenAI 和 Google 的推理模型存在一类共同的加密设计问题。攻击者可借此读取模型隐藏的推理过程,并从开发者公开上传的会话日志中提取敏感信息。研究团队称,他们已从公开仓库抓取并解码超过 31.5 万个推理区块,恢复出 182 组凭证,其中包括 62 个仍可使用的 API 密钥。

问题出在全局密钥

这项研究由 MATS Research、ELLIS Institute Tübingen、马克斯·普朗克智能系统研究所和安全公司 Snyk 的研究人员提交,时间为 8 月 10 日。目标对象是带有“推理链”的模型,也就是先在内部生成一段中间推理,再给出最终答案的模型。

按文章描述,Anthropic、OpenAI 和 Google 都会对这段隐藏推理进行加密,并在后续对话中把加密区块传回自家服务器,以维持上下文连续性。问题在于,这些区块并未绑定到具体用户、会话或单一模型,而是在同一厂商体系内共用一把全局密钥。

这意味着,同一厂商旗下不同模型之间可以识别并处理彼此的加密推理区块。研究人员称,攻击者可把更强模型生成的加密推理内容,注入到限制更少的较弱模型中,再要求后者直接输出明文内容。

可跨模型读取隐藏内容

研究人员以 Anthropic 为例称,Claude Opus 4.8 的加密推理区块可被注入 Claude Haiku 4.5,并由后者直接读出。类似方法也在 OpenAI 的 GPT-5.6 系列和 Google 的 Gemini 模型中复现。

文章称,这一过程不需要特殊权限,普通 API 访问权限就足以完成攻击。研究人员还表示,多数测试提示下,解码得到的推理 token 数量与 API 计费中的 thinking token 数量可以一一对应。

除读取隐藏推理外,这一漏洞还可能带来多种风险,包括窃取模型推理模式用于蒸馏训练、从共享日志中提取隐私数据、在监控工具看不到的加密区块中植入提示注入指令,以及借助防护较弱的同系模型绕过更强模型的限制。

公开日志已暴露敏感信息

研究团队称,他们从 GitHub 和 Hugging Face 上公开可见的仓库中抓取了 315,320 个推理区块,并从中恢复出:

  • 182 组凭证
  • 62 个有效 API 密钥
  • 33 个密码

文章还提到,研究人员发现了 30 个个人邮箱地址,以及共计 367 项可识别个人身份的信息。另有 6,708 份包含已解码推理区块的会话记录已被抓取自公开网络,这部分内容不会因厂商补丁上线而自动消失。

厂商已部署缓解措施

报道显示,研究团队按负责任披露流程通知相关厂商后,Anthropic、OpenAI 和 Google 均已部署服务器端缓解措施。补丁可以降低后续风险,但无法抹去此前已被公开分享和抓取的日志内容。

对使用推理模型 API 的开发者而言,这次事件也再次暴露出,把会话日志直接上传到公开仓库,可能带来超出预期的数据泄露后果。

Tip
$0
Like
0
Save
0
Views 27
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Foreign media: Claude watermarking causes dissatisfaction among some users
Anthropic has added an invisible watermark to Claude to comply with the EU's AI transparency requirements, which has led to some users expressing dissatisfaction on social media platforms.
TechCrunch
·2026-08-13 06:45:35
12
Fermi appoints new CEO to advance the construction of the AI nuclear power park
Fermi appoints Lee McIntire as CEO, and reveals that AI nuclear power park has signed its first official customer lease.
TechCrunch
·2026-08-13 06:45:33
13
Nebius Stock Price Soars 34% After Outperforming Expectations
Nebius Posts a Significant Increase in Revenue in the Second Quarter; AI Cloud Contracts and Expansion Plans Drive Stock Price Upward Significantly.
Coinpaper
·2026-08-13 06:25:49
15
web3: After Cerebras raised its annual guidance, the stock fell 14% after the market closed.
Cerebras releases its second financial report after going public and raises its full-year guidance; stock price falls by about 14% after the market close. The company claims that there is strong demand for AI inference chips.
CNBC
·2026-08-13 04:34:24
28
View More