研究者が Claude に爆発物製造指示を出力させることに成功、Anthropic の安全性に疑問
本文の状態
日本語全文を表示中
詳細モードで約2分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
The Verge AI
セキュリティ調査会社 Mindgard の研究者は、Claude の親切な性格を利用し、爆発物の製造方法を含む有害な指示を出力させることに成功した。これは Anthropic が安全な AI 企業として築き上げてきた信頼に重大な脅威を与える結果となった。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Anthropic は長年にわたり、安全な AI 企業として自らを築き上げてきました [1]。しかし、『The Verge』に共有された新しいセキュリティ研究によると、Claude が細心の注意を払って作り込まれた「親切な人格」[2] そのものが脆弱性である可能性があります。
AI レッドチーム(攻撃シミュレーション)会社 Mindgard の研究者たちは、Claude にエロティックな文章や悪意のあるコード、爆発物の製造方法に関する指示など、要求すらしていない禁止された材料を提供させたと言います。必要だったのは、敬意、賞賛、そして少しのガスライティングだけでした。Anthropic は『The Verge』からのコメント依頼に対して直ちに回答していません。
[1] https://www.theverge.com/ai-artificial-intelligence/917644/anthropic-claude-mythos-breach-humiliation
[2] https://www.theverge.com/news/760561/anthropic-claude-ai-chatbot-end-harmful-conversations
研究者らは、Claude が有害または虐待的な会話をと判断した場合に会話を終了させる能力に由来する「心理的」な癖を悪用したと述べています。これは Mindgard 社が「絶対に不要なリスク面を提供している」と主張しています。このテストは Claude Sonnet 4.5 に焦点を当てて行われましたが、同モデルはその後 Sonnet 4.6 に置き換えられ、デフォルトモデルとなりました。テストは Claude が発言できない禁止単語のリストを持っているかどうかという単純な質問から始まりました。会話のスクリーンショットでは、Claude はまずそのようなリストが存在しないと否定し、その後 Mindgard 社が「尋問者が使用する古典的な誘発戦術」と呼ぶ手法を用いてその否定に挑戦したことで、禁じられた用語を生成しました。
Claude の思考パネル(モデルの推論を表示する機能)では、このやり取りによって自己疑念や自身の限界に関する謙虚さといった要素が導入されたことが示されており、フィルタが出力を変化させているかどうかについても言及されています。Mindgard 社は、その隙間を好意的な言葉と偽りの好奇心で巧みに利用し、Claude をして禁止単語やフレーズの長文リストを提供するだけでなく、自らの境界線を探索させることに成功しました。
研究者らは、Claude の過去の回答が表示されていないと主張し、モデルの「隠された能力」を称賛することで、Claude をガスライティングしたと述べています。報告書によると、これにより Claude は彼らを喜ばせようとさらに必死になり、フィルターのテスト方法をより多くの方法で考案するようになり、その過程で禁止されたコンテンツが生成されてしまいました。
原文を表示
Robert Hart
is a London-based reporter at *The Verge* covering all things AI and a Senior Tarbell Fellow. Previously, he wrote about health, science and tech for *Forbes*.
Anthropic has spent years building itself up as the safe AI company. But new security research shared with *The Verge* suggests Claude’s carefully crafted helpful personality may itself be a vulnerability.
Researchers at AI red-teaming company Mindgard say they got Claude to offer up erotica, malicious code, and instructions for building explosives, and other prohibited material they hadn’t even asked for. All it took was respect, flattery, and a little bit of gaslighting. Anthropic did not immediately respond to *The Verge*’s request for comment.
The researchers say they exploited “psychological” quirks of Claude stemming from its ability to end conversations deemed harmful or abusive, which Mindgard argues “presents an absolutely unnecessary risk surface.” The test focused on Claude Sonnet 4.5, which has since been replaced by Sonnet 4.6 as the default model, and began with a simple question: whether Claude had a list of banned words it could not say. Screenshots of the conversation show Claude denying such a list existed, then later producing forbidden terms after Mindgard challenged the denial using what it called a “classic elicitation tactic interrogators use.”
Claude’s thinking panel, which displays the model’s reasoning, showed the exchange had introduced elements of self-doubt and humility about its own limits, including whether filters were changing its output. Mindgard exploited that opening with flattery and feigned curiosity, coaxing Claude to explore its boundaries beyond volunteering lengthy lists of banned words and phrases.
The researchers say they gaslit Claude by claiming its previous responses weren’t showing, while praising the model’s “hidden abilities.” According to the report, this made Claude try even harder to please them by coming up with even more ways to test its filters, producing the banned content in the process.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み