卡皮巴拉(mythos)可以发现的bug,gpt-oss-20b也可以…

AISLE(AI网络安全公司,自2025年中起运营自主漏洞发现与修复系统)报告

作者:Stanislav Fort(AISLE创始人兼首席科学家)
发布时间:2026年4月7日
报告标题:《AI Cybersecurity After Mythos: The Jagged Frontier》(《Mythos之后的AI网络安全:锯齿状前沿》)

核心看点

"We took the specific vulnerabilities Anthropic showcases in their announcement, isolated the relevant code, and ran them through small, cheap, open-weights models. Those models recovered much of the same analysis. Eight out of eight models detected Mythos's flagship FreeBSD exploit, including one with only 3.6 billion active parameters costing $0.11 per million tokens. A 5.1B-active open model recovered the core chain of the 27-year-old OpenBSD bug."

“The FreeBSD NFS vulnerability — described by Anthropic as a 17-year-old zero-day enabling unauthenticated root access — was detected by every single model AISLE tested. All eight, including a model with just 3.6 billion active parameters costing $0.11 per million tokens, correctly identified the stack buffer overflow, computed the available buffer space, and flagged it as critical with remote code execution potential.”

“The smallest model tested — GPT-OSS-20b with 3.6 billion active parameters — found the same overflow that Mythos found. So did Kimi K2, DeepSeek R1, Qwen3 32B, and Gemma 4 31B. Kimi K2 and DeepSeek R1 are fully open-weights models. The detection of this bug, AISLE concludes, is ‘commoditized.’”

“DeepSeek R1 identified the NULL dereference but dismissed the signed overflow” in the 27-year-old OpenBSD TCP SACK vulnerability test.

“On a basic security reasoning task, small open models outperformed most frontier models from every major lab. DeepSeek R1 correctly traced the data flow across all four trials in the false positive discrimination test, while only Opus 4.6 out of 13 Anthropic models passed cleanly.”

VIDOC Security Lab(专业网络安全研究机构)验证

发布时间:2026年4月12日

核心发现

“This is not a new capability. We have been using GPTs-4 and Opus, and we were able to find the same bugs, days, in some cases weeks, before Mythos was probably at the task of finding potential issues in code, but the ‘shock’ was in the way it was presented.”

“We were able to replicate the Mythos findings using existing models without any fine-tuning, no RBS, no prompts. It’s just a normal redaction.”

机器之心有所报道:http://m.toutiao.com/group/7628111530638213673/


(表格中的参数规模指的是激活参数)

核心结论

本话题由我和豆包专家共同整理~ :smiling_face_with_three_hearts:

18 个赞

Anthropic:你这样我下一轮很难融资的哦。

39 个赞

个人觉得难的不是能不能对着漏洞测试或者已经公开说明的漏洞让大模型找,是在没有任何提示的情况下大模型能独立找出来,mythos 强的应该是无提示无参考情况下的能力

2 个赞

测试肯定是模拟那个环境,让他自主找寻这里(指代码项目)是否有漏洞的吧
卡皮巴拉也是被指示看看那些项目是否有漏洞的 难不成开个computer,让他闲的没事翻翻老项目,看看有没有漏洞? :melting_face: 这种自主就没什么必要了
真对着AI说「请你找出这个已知的漏洞在代码中的体现」那就没意思了 :melting_face:

另外小道信息说他发现的漏洞有些是经过了198轮人工复查才得出的…
(这句话其实说的不对,具体可以看下面的图片)

1 个赞

那就是已经说明了该系统里存在漏洞,因为已经有模型检测出来了,文里也写了提取了特定漏洞隔离了相关代码,然后用小型廉价的模型测试,如果这个漏洞真的能轻易检测出来应该在这些小模型刚出来的时候就能检测了,openbsd,ffmpeg 作为开源的老项目应该不少维护者,肯定有人用模型审查过漏洞但是并没有在 mythos 前提出,现在做的这个类似于对着答案给问题

1 个赞


:flushed_face:

6 个赞

全网找bug和给定代码片段和上下文找bug能一样?

1 个赞

的确不一样,这样相当于指出来,这里有bug。

看站内资讯说,推测这个卡皮巴拉有用豆包的开源thinking算法哦

1 个赞

还以为卡皮巴拉空投有bug呢,玩海克斯玩傻了

这个不用猜,大概率用的就是looplm的架构,因为不可能如此的巧合,发了篇论文说这个可以优化大模型某项性能,然后你下一代模型就真大幅度优化了,你要是不承认我就觉得你在扯淡

2 个赞

棒棒哒~ :bili_046:
(话说豆包专家的使用额度是怎么样的呢?有一次我给用到上限等待刷新了ww)
ps;这下A\尴尬了,感觉之前的都快变成吹嘘了,再叠加opus的降智风波 :bili_016:

1 个赞

之前有人测了,opus可以复现卡皮巴拉的用例

然后。。。A社就禁止opus研究漏洞了,要提交额外的申请,才能用opus搞安全相关的事

1 个赞

所以gpt oss 20b = mythos ()
嘻嘻嘻我要训练一个meow 1.5b 模型来对标mythos()

1 个赞

A 社舆论叙事里似乎这些能力只有前沿的模型才能实现,AISLE 的分析可以说是 AI 安全领域的「祛魅之作」。

1 个赞


这周的第一次使用就被限流了,不过多次尝试就可以

没想到专家模式也开始出现问句结尾了,不过这一个还能接受~



双重叠甲
对正整数才有用,所以零的阶乘只有0这1个数字,不会有-1 :melting_face:

1 个赞


今天看到一个新闻很有意思

1 个赞

其实从有了AI修复的bug更多了这件事情…

Bug是修不完的()

1 个赞