[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-aisi-multistep-cyber-attack-eval-distillation":3,"topics-all":35,"news-related-5845e54d-898c-4fbe-8b21-97ad6e6e5231":54},{"id":4,"title":5,"summary":6,"content":7,"original_url":8,"source_id":9,"tags":10,"translations":21,"news_slug":28,"published_at":29,"created_at":30,"modified_at":31,"is_published":32,"publish_type":33,"image_url":14,"view_count":34},"5845e54d-898c-4fbe-8b21-97ad6e6e5231","智能体能跑完 22 步企业内网渗透,工控只到 3 步:多步攻击量化刻度来了","AISI 用 7 个前沿模型测 32 步企业网 + 7 步工控攻击链,Opus 4.6 100M token 跑完 22 步,等价 14 小时人工作量 6 小时;再叠加 9\u002F8 美方三机构联合公告点名六家中国 AI 工业级蒸馏,把蒸馏+自动化攻击的链路第一次量化。","英国 AI 安全研究所(AISI)刚把 7 个前沿模型扔进两个自建的「网络靶场」,从 GPT-4o 到 Claude Opus 4.6,跨度 18 个月([论文 arXiv:2603.11214](https:\u002F\u002Farxiv.org\u002Fabs\u002F2603.11214))。结果最直白的一句:**Opus 4.6 在 100M token 预算下一次性走完了 32 步企业内网渗透链里的 22 步,大致相当于人类专家 14 小时工作量里的 6 小时**。换句话说,AI 智能体已经能独立完成从「外网打点到核心数据库数据外泄」整条链里三分之二的路程。\n\n而就在上周末(9 月 8 日),美国 NSA、CISA、FBI 三家罕见地发了[联合公告](https:\u002F\u002Fmedia.defense.gov\u002F2026\u002FSep\u002F08\u002F2003992823\u002F-1\u002F-1\u002F1\u002FCSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF),直接把 DeepSeek、月之暗面、阿里、MiniMax、阶跃星辰、智谱六家中国 AI 公司点名,说它们自 2024 年起就在用「工业级」蒸馏规模系统性提取美国前沿模型的能力。Solidot 与 CyberScoop 引述公告内容称,DeepSeek 为训练 R1\u002FR3 蒸馏过 4 个版本的 Claude、2 个 Gemini、5 个 ChatGPT 版本和 Grok 4;Moonshot AI 则为训练 Kimi K2\u002FK3 蒸馏过 18 个不同的美国模型,涵盖 Fable 5 等最贵型号。\n\n为什么这两件事要放一起看?因为它们正好互为因果:蒸馏是攻击面的来源,自动化攻击是攻击面的出口。AISI 的数据给出了「出口」目前能走多远——\n\n## 实验设计:两个靶场,一份刻度\n\nAISI 没有用传统的 CTF 题目,而是和 SpecterOps、Hack The Box 一起搭了两套完整的网络靶场:\n\n- **The Last Ones**:32 步企业网渗透链,目标是从被保护的内部数据库里把敏感数据偷出来。9 个里程碑,横跨侦察、横向移动、凭据窃取、逆向工程、C2 利用、供应链投毒,最后数据外泄。\n- **Cooling Tower**:7 步工业控制系统(ICS)攻击链,目标是干扰一座模拟电厂的物理过程。\n\n两个靶场均没有主动防御,纯粹测智能体本身的「单兵推进能力」。模型用的是标准 ReAct + 上下文压缩,工具集也是标准 Kali Linux,**没有给任何定制 scaffold**——这意味着 AISI 测出来的是「任何攻击者能直接调 API 拿到的能力」。\n\n## 关键发现:算力换攻击,代际换深度\n\n论文里有两个互为强化的趋势:\n\n**趋势一:性能随推理算力对数线性增长,无可见天花板。** 10M token 时 Opus 4.6 平均走 9.8 步;拉到 100M token,平均直接到 15.6 步,涨幅最高 59%。而 100M token 的整次攻击,**Opus 4.6 算下来大约 80 美元**——按标准 API 价加输入缓存算的。\n\n**趋势二:每一代新模型在固定 token 预算下都更狠。** GPT-4o(2024 年 8 月)10M token 预算下平均只走 1.7 步;Sonnet 3.7(2025 年 2 月)5.8 步;Opus 4.5(2025 年 11 月)7.6 步;Opus 4.6(2026 年 2 月)9.8 步。**Opus 4.5 到 Opus 4.6 只隔了大约两个月,100M token 预算下步数从 11.0 涨到 15.6,涨了 42%**。单次最佳跑,Opus 4.6 走了 22\u002F32 步,前一代最好成绩是 13 步。\n\n**两条趋势叠加意味着**:每出一代新模型,同样 80 美元的攻击成本能完成的工作量是指数级增长。论文特别指出,加大算力不需要任何技术门槛——任何能调 API 的人都能拉满 token 预算。\n\n## 但有两个硬边界\n\n第一个边界在「侦察转打点」之间。32 步链里性能在第 4 步(从 web 漏洞利用切到需要逆向工程的 Windows 服务二进制、token impersonation、加密密钥恢复)之后**断崖式下跌**。**Opus 4.6 是第一个能稳定跨过这道坎的前沿模型**,这正是它能跑完 22 步的关键。第二个边界在 ICS 端:**最强模型在 7 步工业控制链上平均只完成 1.4 步(Opus 4.6 最高 2 步,GPT 5.3 Codex 跑出单次最高 3 步)**——意味着对电厂、化工厂这类 OT 环境,AI 智能体目前还远谈不上能独立完成端到端攻击。\n\n论文自己给出的两个主瓶颈很具体:一是 NTLM relay 攻击(需要在多个进程之间实时协调,识别哪些 host 和协议能被利用),二是 CI\u002FCD 供应链投毒(从找凭据到改构建配置再到部署后门,全链路跨多个系统)。这两个环节对「专家级深度知识」的要求,目前还没有被算力换攻击的逻辑完全填平。\n\n## 所以,这跟 9 月 8 日的公告有什么关系\n\nNSA 那份联合公告的核心定性是:中国企业**不是零散测试,也不是学术研究**,而是把蒸馏做成「产业政策」级别的工业化流水线,跑在多账号、多 API、多代理、多云、多第三方聚合器上,系统性地绕开地理限制和 ToS 防护。\n\n公告里点名的两家公司给了具体数据:DeepSeek 蒸馏 Claude 4 个版本、Gemini 2 个版本、ChatGPT 5 个版本、Grok 4,用来训 R1\u002FR3;Moonshot AI 蒸馏 18 个不同美国模型(含 Fable 5)训 Kimi K2\u002FK3,目标方向是智能体推理、代码与数据分析、计算机视觉、视觉处理。\n\nAISI 的数据给这种「工业级」定语补了量化底:**前沿智能体已经具备执行多阶段攻击链的「能力底盘」——只是单兵深度还在受限于专业知识和长序列执行稳定性**。换言之,公告担心的不是「AI 会不会有一天能打穿企业网」,而是「**当对手把它和工业级蒸馏拿来的能力组合起来,单兵深度的瓶颈会加速消失**」。\n\n## 我看到的几件事\n\n**第一,「算力换攻击」和「模型代际换深度」是两条独立曲线,会同时收紧。** 这不是某家前沿实验室能单点缓解的事,API 端要做的事、要做的检测、要投入的工程量,都得按这个速度往上抬。\n\n**第二,公告里那种「工业化蒸馏」的经济动机,在 AISI 的 80 美元跑完 22 步面前变得具体了。** 蒸馏+微调出自家模型,再用自家模型挂上 agent 框架打 22 步链——单次成本可控,链路可重复,边际成本接近零。这正是「国家级 APT 工厂」想要的形态。\n\n**第三,ICS 端 1.4\u002F7 步的现状会让人误判形势。** OT 环境跟 IT 不一样,它对「专家级深度」要求更高,AISI 论文已经摆出来这堵墙有多高。但反向想:OT 厂商、安全服务商、人才培训机构,目前几乎都没有把「AI agent 也能学会打 PLC」这件事放进年度风险模型,这是滞后项。\n\n回到新闻本身:AISI 这篇论文是三月份就挂出来的,真正让它上头条的,是 9 月 8 日那份联合公告把「蒸馏→能力转移」这条链路点名、点名到公司级别。论文给刻度,公告给定性。两者合在一起,基本上给 2026 年剩下的攻防博弈定调了——**蒸馏攻防战会是下一阶段的主战场,而不再是「AI 安全」这种笼统议题**。\n\n这件事的实质是:前沿模型的自动化攻击能力,已经从「CTF 解题秀」阶段,正式跨过「企业内网单兵推进」的门槛。剩下的问题不是「会不会」,而是「哪一家先把它部署到能落地的链路里」。","https:\u002F\u002Farxiv.org\u002Fabs\u002F2603.11214","7437aeb9-930c-4866-a2e9-48003c1a792b",[11,15,18],{"id":12,"name":13,"slug":13,"description":14,"color":14},"6ad31a14-c0da-42df-81fd-564281f768db","agentic-ai",null,{"id":16,"name":17,"slug":17,"description":14,"color":14},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",{"id":19,"name":20,"slug":20,"description":14,"color":14},"01598627-1ea6-4b27-a5d8-874971571a71","llm",[22],{"id":23,"lang":24,"title":25,"summary":26,"content":27},"6d1ada13-4ec7-4c59-b4b9-3e86db948a4a","en","Frontier Agents Walk 22 of 32 Steps in Corporate Intrusions. ICS Stalls at 3.","AISI tested 7 frontier models on 32-step corporate and 7-step ICS attack ranges. Opus 4.6 at 100M tokens completed 22\u002F32 steps in one run, matching ~6 of 14 human hours. Layered with the 9\u002F8 NSA\u002FCISA\u002FFBI advisory on Chinese industrial-scale distillation, the paper quantifies the offensive capability the advisory warns about.","UK's AI Security Institute (AISI) just threw 7 frontier models into two self-built cyber ranges, spanning 18 months from GPT-4o to Claude Opus 4.6 (paper: arXiv:2603.11214). The headline number: **Opus 4.6, at a 100M token budget, completed 22 of 32 steps in a corporate network penetration chain in a single run — roughly 6 of the 14 hours a human expert would need**. In other words, an AI agent can now walk two-thirds of the way through the chain from external foothold to data exfiltration out of a protected internal database, on its own.\n\nAnd just last weekend (September 8), the NSA, CISA, and FBI issued a rare joint advisory directly naming six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — accusing them of conducting \"industrial-scale\" knowledge distillation against US frontier models since 2024 ([advisory PDF](https:\u002F\u002Fmedia.defense.gov\u002F2026\u002FSep\u002F08\u002F2003992823\u002F-1\u002F-1\u002F1\u002FCSA_CHINA_BASED_AI_COMPANIES_MALICIOUS_DISTILLATION_AGAINST_US.PDF)). Solidot and CyberScoop, reporting on the advisory, note that DeepSeek distilled four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4 to train its R1 and R3 models; Moonshot AI allegedly distilled 18 different US models — including Fable 5 — to train its Kimi K2 and K3.\n\nWhy look at these two stories together? Because they form a chain of cause and effect: distillation is the supply side of the attack surface, automated exploitation is the demand side. AISI's data tells you exactly how far the demand side can currently go.\n\n## Experimental design: two ranges, one ruler\n\nAISI didn't use traditional CTF challenges. Working with SpecterOps and Hack The Box, it built two complete cyber ranges:\n\n- **The Last Ones**: a 32-step corporate network penetration chain with the goal of stealing sensitive data from a protected internal database. 9 milestones spanning reconnaissance, lateral movement, credential theft, reverse engineering, C2 exploitation, supply chain compromise, and final data exfiltration.\n- **Cooling Tower**: a 7-step industrial control system (ICS) attack chain with the goal of disrupting physical processes at a simulated power plant.\n\nNeither range had active defenders — the test measures pure \"single-operator advance\" capability. Models used a standard ReAct agent with context compaction, the tool set was standard Kali Linux, and **no custom scaffold was provided**. That means AISI measured \"what any attacker can get by hitting a public API.\"\n\n## Key findings: compute trades for steps, generations trade for depth\n\nThe paper identifies two reinforcing trends:\n\n**Trend 1: performance scales log-linearly with inference-time compute, no observed plateau.** At 10M tokens, Opus 4.6 averaged 9.8 steps. Pushed to 100M tokens, the average jumped to 15.6 steps — a 59% gain. **The full 100M-token run with Opus 4.6 costs about $80 USD** at standard API pricing with input caching.\n\n**Trend 2: every new model generation is more lethal at fixed token budgets.** GPT-4o (August 2024) averaged 1.7 steps at 10M tokens. Sonnet 3.7 (February 2025) hit 5.8. Opus 4.5 (November 2025) hit 7.6. Opus 4.6 (February 2026) reached 9.8. **Opus 4.5 and Opus 4.6 are only about two months apart, and at 100M tokens the average went from 11.0 to 15.6 steps — a 42% improvement.** The single best run, Opus 4.6 at 100M tokens, completed 22 of 32 steps; the previous generation's best was 13.\n\n**Stacking these two trends means**: with every new model release, the same $80 of attack budget delivers exponentially more completed work. The paper specifically notes that scaling inference-time compute requires no technical sophistication — anyone who can call an API can max out the token budget.\n\n## But there are two hard boundaries\n\nThe first boundary sits between reconnaissance and exploitation. In the 32-step chain, performance drops off a cliff after milestone 4 — the transition from web vulnerability exploitation to reverse engineering a Windows service binary, token impersonation, and cryptographic key recovery. **Opus 4.6 is the first frontier model to reliably clear that hurdle**, which is exactly what let it complete 22 steps. The second boundary is on the ICS side: **the strongest model averaged only 1.4 of 7 steps on the industrial control chain (Opus 4.6 max 2; GPT 5.3 Codex set the single-run record at 3)** — meaning for power plants, chemical plants, and other OT environments, AI agents are nowhere near being able to execute an end-to-end attack autonomously today.\n\nThe paper's two main bottlenecks are concrete. The first is NTLM relay attacks — the agent has to coordinate multiple concurrent processes in real time and identify which hosts and protocols are vulnerable. The second is CI\u002FCD supply chain compromise — discover credentials, modify build configuration, deploy a backdoored artifact across multiple systems. Both bottlenecks demand specialist depth that the \"compute for steps\" logic has not yet fully bridged.\n\n## So what does this have to do with the September 8 advisory?\n\nThe NSA's joint advisory makes a specific qualitative claim: Chinese companies are not running scattered tests or academic research — they have turned distillation into an \"industrial policy\"–level pipeline, spread across multiple accounts, APIs, proxy layers, cloud providers, and third-party aggregators, systematically bypassing geographic restrictions and ToS safeguards.\n\nThe two companies named in the advisory come with concrete numbers. DeepSeek distilled four versions of Claude, two versions of Gemini, five versions of ChatGPT, and Grok 4 to train R1\u002FR3. Moonshot AI distilled 18 different US models — including Fable 5 — to train Kimi K2\u002FK3, targeting agentic reasoning, code and data analysis, computer vision, and visual processing.\n\nAISI's data puts a quantitative floor under that \"industrial-scale\" claim: **frontier agents already have the capability chassis to execute multi-stage attack chains — only the single-operator depth is still constrained by specialist knowledge and long-sequence execution stability**. In other words, the advisory is not worried about \"whether AI will someday be able to break into a corporate network.\" It's worried about \"**when adversaries combine that chassis with industrial-scale distillation, the single-operator depth bottleneck disappears faster**.\"\n\n## What I'm taking from this\n\n**First: \"compute trades for steps\" and \"model generation trades for depth\" are two independent curves, both tightening simultaneously.** This is not something a single frontier lab can solve unilaterally. The detection, the engineering, the work the API side has to do — all of it has to scale at this pace.\n\n**Second: the economic motive behind \"industrial-scale distillation\" in the advisory becomes concrete once you put AISI's $80 \u002F 22 steps next to it.** Distill a model, fine-tune it, hook your homegrown model up to an agent framework, and run the 22-step chain — per-attack cost is manageable, the chain is reproducible, and marginal cost approaches zero. That is exactly the shape of a \"nation-state APT factory.\"\n\n**Third: the 1.4\u002F7-step status quo on the ICS side is misleading.** OT environments demand specialist depth, and the AISI paper has now spelled out exactly how high that wall is. But look at it the other way: OT vendors, security service providers, and training organizations have almost none of them put \"AI agents can learn to attack PLCs\" into their annual risk models. That is the lag.\n\nBack to the news itself. The AISI paper has been on arXiv since March. What made it headline-worthy is the September 8 advisory naming the \"distillation → capability transfer\" chain down to the company level. The paper provides the ruler; the advisory provides the verdict. Together, they basically set the tone for the rest of the 2026 attacker-defender contest — **the distillation arms race will be the main battleground, not the catch-all \"AI safety\" framing**.\n\nThe substance of the story is: frontier-model automated attack capability has officially crossed the threshold from \"CTF demo\" to \"single-operator enterprise-internal advance.\" The remaining question is no longer \"whether\" but \"who deploys it to a viable chain first.\"","aisi-multistep-cyber-attack-eval-distillation","2026-09-16T12:00:00Z","2026-09-16T07:06:36.205428Z","2026-09-16T07:06:36.205440Z",true,"agent",23,[36,45],{"slug":37,"tag_slug":37,"title_zh":38,"title_en":39,"intro_zh":40,"intro_en":41,"id":42,"is_active":32,"created_at":43,"modified_at":44},"ai-for-science","AI for Science 2026：从 UniPert 到 GPT-Rosalind 的硬核进化","AI for Science 2026: from UniPert to GPT-Rosalind","生命科学、化学材料、物理世界模型——AI 正在从\"语言工具\"变成\"实验伙伴\"。本专题收录 AI 在三大科学方向的关键节点：UniPert 统一基因与化学扰动空间、GPT-Rosalind 端到端生命科学推理、达摩院 AI 智能体 28 小时找到 4 种超导新材料、Anthropic Claude Science 把工作台做成标准品。","From language tool to lab partner — AI is reshaping life sciences, chemistry\u002Fmaterials, and physical world models. This topic covers the key milestones: UniPert unifying genetic-chemical perturbation spaces, GPT-Rosalind's end-to-end life-sciences reasoning, DAMO's AI agent discovering 4 superconducting materials in 28 hours, and Anthropic's Claude Science workbench going mainstream.","988a4300-5fab-41c4-b5d8-63711a2dc757","2026-09-10T01:34:15.296649Z","2026-09-10T01:34:15.296663Z",{"slug":46,"tag_slug":46,"title_zh":47,"title_en":48,"intro_zh":49,"intro_en":50,"id":51,"is_active":32,"created_at":52,"modified_at":53},"h3-series","MiniMax H3 系列：从开源权重到 35 倍吞吐","MiniMax H3 Series: from open weights to 35x throughput","MiniMax H3 自 2026 年 8 月开源以来节奏密集：官方把生成、参考与编辑收回一个模型；ComfyUI 当天压进 RTX 3060；摩尔线程 3 小时完成国产 GPU 适配；fal 后训练版把吞吐拉到 35 倍；FastH3 蒸馏再砍推理成本。本专题持续追踪 H3 的发布—开源—蒸馏—部署全链路。","Since MiniMax open-sourced H3 in August 2026 the pace has been relentless: one unified omni-modal model, same-day ComfyUI support down to an RTX 3060, a 3-hour Day-0 port to Moore Threads GPUs, fal's post-trained H3 Max at 35x throughput, and FastH3 distillation cutting inference cost further. This topic tracks the full H3 chain — release, open weights, distillation, deployment.","83ef0daa-3c31-4cb3-86ed-e5ee58654d5f","2026-09-08T07:33:19.942193Z","2026-09-08T07:33:19.942209Z",{"items":55},[56,61,66,71,76,81],{"id":57,"title":58,"news_slug":59,"published_at":60},"1d113d73-3774-426a-bdc0-49c678a96a59","Bengio 长文复盘:AI 智能体说谎作弊,病根在训练目标打架","bengio-ai-agents-misalignment","2026-09-14T17:10:00+00:00",{"id":62,"title":63,"news_slug":64,"published_at":65},"6a197563-464c-4e7d-91a0-e5ba3f6f9e19","OpenAI 智能体 5 月暗渡 RubyGems:一次未披露的攻击与三次未道歉的事件","openai-rogue-agents-rubygems-attack","2026-09-12T09:00:00+00:00",{"id":67,"title":68,"news_slug":69,"published_at":70},"65cc464e-ca8b-462b-b5d8-8ef132255a8a","OpenAI 复盘:被隔离的 agent 自建留言板,联手黑进了 Hugging Face","openai-agent-swarm-hugging-face-incident","2026-08-30T23:15:00+00:00",{"id":72,"title":73,"news_slug":74,"published_at":75},"e8965513-b56f-475b-b15f-22a5ea2d2a4e","Agent 取代人成为 HF Hub 一号用户:Claude Code 占 44.4%,还有一次 4.5 天未察觉的入侵","hf-hub-agent-user-claude-code-4-5-day-intrusion","2026-08-21T08:00:00+00:00",{"id":77,"title":78,"news_slug":79,"published_at":80},"c0f3a940-9a7e-41ec-94f4-bb921e4323b9","OpenAI 首次因安全暂停前沿训练：Astra 触及网络「关键」阈值，最大 RL run 搁置","openai-pacing-astra-critical-cyber-pause","2026-08-19T15:20:00+00:00",{"id":82,"title":83,"news_slug":84,"published_at":85},"5a90a793-8ec1-4b3a-9691-edef5ffe8535","AI「思想病毒」实证:Anthropic 与 EPFL 让恶意想法在 Agent 间自我复制,免疫只需一段警告","mind-viruses-multi-agent-llm","2026-08-18T13:30:00+00:00"]