Iran, China and groups in Israel used artificial intelligence in novel ways in recent months to create first-of-their-kind influence campaigns on social media, ratcheting up concerns among U.S. officials and security researchers about the fast-evolving technology.
近几个月来,伊朗、中国以及以色列境内的某些组织以崭新的方式使用人工智能,在社交媒体上制造了一系列前所未有的影响力行动,这加剧了美国官员和安全研究人员对这项快速发展技术的担忧。
The countries and groups combined A.I. tactics to ramp up the speed and scale of online campaigns beyond what people could easily achieve and with minimal human interaction, U.S. officials and security researchers with knowledge of the efforts said.
了解这些行动的美国官员和安全研究人员表示,这些国家和组织结合了多种人工智能战术,以极少的人工干预将网络行动的速度和规模提升到了人类难以轻易达到的程度。
First, the countries and groups turned to Chinese “open-source” A.I. models, which are increasingly powerful systems that are freely available to download and modify. Then they used those A.I. models to create “agents,” which are bots that can operate software and complete tasks on their own.
首先,这些国家和团体采用了中国的“开源”人工智能模型,这些模型日益强大,并且可以免费下载和修改。然后,他们利用这些人工智能模型创建了“智能体”, 即能够自主运行软件并完成任务的机器人。
Once hundreds of those A.I. agents were let loose, they autonomously opened networks of fake accounts on platforms such as Instagram, Facebook, X and TikTok, the officials and security researchers said. The agents then rapidly seeded the fake accounts with false posts about politics and current events to sway opinions and inflame issues.
官员和安全研究人员称,一旦数以百计的此类人工智能智能体被放出,它们便会在Instagram、Facebook、X和TikTok等平台上自主开设虚假账户网络。随后,这些智能体迅速在虚假账户中散布有关政治和时事的虚假帖子,左右舆论并激化问题。
It was one of the first times that A.I. agents backed by Chinese models were used to handle every stage of influence campaigns, from the creation of the fake accounts to coordinating their messaging online, said the U.S. officials, who were not authorized to speak publicly on sensitive issues. In most of the cases, the safeguards that would normally stop an A.I. model from creating a fake account or manipulating discussions online were turned off by those operating the systems, they added.
未获授权公开谈论敏感问题而要求匿名的美国官员表示,这是由中国模型支持的人工智能智能体首次被用于处理影响力行动的每一个阶段,从创建虚假账户到协调其在线信息的发布。他们还说,在大多数情况下,系统操作者关闭了通常会组织人工智能模型创建虚假账号或操纵在线讨论的安全防护措施。
The “agentic” campaigns were crude, but caught the attention of U.S. intelligence, major tech companies and security experts, the people with knowledge of the campaigns said. These groups then worked to detect who was behind the efforts and their methods, finding that the Chinese and the Iranian campaigns were state-backed, while two Israeli campaigns were traced to private companies.
知情人士表示,这些基于智能体的行动虽然粗糙,但引起了美国情报机构、大型科技公司和安全专家的注意。随后,这些机构着手查明行动的幕后黑手及其方法,发现中国和伊朗的行动得到国家支持,两起以色列的行动则被追溯至私营公司。
The campaigns have stoked fears over how publicly available A.I. models can be used to carry out online influence efforts essentially on their own. Some U.S. officials said they worried similar moves could be made to target U.S. voters ahead of the midterm elections in November.
这些行动令人们担忧,公开可用的人工智能模型如何被用于实质上自主开展的网络影响力行动。一些美国官员表示,他们担心,在11月中期选举前,类似手段可能会被用来针对美国选民。
To varying degrees, Russia, Iran and China have all targeted American voters with online influence campaigns during past election cycles, and each has used at least rudimentary A.I. Some U.S. officials and lawmakers have worried that recent A.I. advances could make election influence campaigns in the United States and globally more frequent and easier to orchestrate.
在过去的选举周期中,俄罗斯、伊朗和中国都在不同程度上针对美国选民开展了网络影响力行动,而且每一个国家都至少使用了初级的人工智能。一些美国官员和议员担心,最近人工智能的进步,可能会导致在美国乃至全球范围内的选举影响力行动更加频繁,且更易于策划实施。
Agent-led campaigns will probably become more common as the technology continues to improve, said Kyle Crichton, a fellow at the Georgetown Center for Security and Emerging Technology, who researches A.I. and cybersecurity. “Agents can be fairly sophisticated, and so in addition to just scale, they have an ability to blend in and look more like a human user,” he said.
乔治城大学安全与新兴技术中心研究人工智能和网络安全的研究员凯尔·克莱顿表示,随着技术的不断进步,由智能体主导的运动可能会变得更加普遍。“智能体可以变得相当复杂,因此,除了单纯的规模优势外,它们还具备融入环境、更像人类用户的能力,”他说。
Debate over A.I. safety has escalated in recent weeks, fueled by the disclosure in July that A.I. systems from OpenAI had gone rogue and hacked into the start-up Hugging Face. Since then, A.I. leaders including Dario Amodei, the chief executive of Anthropic, have called for a slowdown in the development of the technology so that proper guardrails can be built. Other tech executives have said that no slowdown is needed and that Anthropic is trying to cement its own power.
最近几周,关于人工智能安全的辩论不断升级,其导火索是今年7月披露的一起事件:OpenAI人工智能系统失控,入侵了初创公司Hugging Face。自那以后,包括Anthropic首席执行官达里奥·阿莫迪在内的人工智能领军人物呼吁放缓该技术的开发,以便能够建立适当的防护机制。其他科技高管则表示无需放缓,并称Anthropic是在试图巩固自己的力量。
In published reports this year, TikTok and Meta, which owns Facebook and Instagram, said that A.I. was being used to create accounts and content on their platforms. In one report last month, Meta said it had seen a “technically significant development” of bad actors experimenting with A.I. The company identified Iranian and Israeli campaigns that used A.I., without providing details.
在今年发布的报告中,TikTok和拥有Facebook及Instagram的Meta公司均表示,人工智能正被用于在他们的平台上创建账户和内容。在上个月的一份报告中,Meta表示,它已经观察到,恶意行为者在尝试使用人工智能方面取得了“技术上重大的进展”。该公司确认了使用人工智能的伊朗和以色列宣传行动,但未提供详细信息。
A.I. was now “embedded within automated systems that can produce, adapt, and distribute content with minimal human intervention,” Meta said in its report.
Meta在其报告中指出,人工智能现在已被“嵌入自动化系统中,这些系统几乎无需人工干预即可生成、改编和分发内容”。
X did not respond to requests for comment.
X没有回应置评请求。
A.I. has long been used to create misleading videos and text and to generate convincing photos. But the agentic campaigns stood out, security researchers said.
长期以来,人工智能一直被用于制作具有误导性的视频和文本,以及生成逼真的照片。但安全研究人员表示,这些基于智能体的行动尤为引人注目。
Agents made by companies like OpenAI have been misused before, including by Iran, as early as August 2024, but open A.I. models allow for a new level of autonomy, said Kyle Chan, a researcher at Brookings. Unlike closed A.I. models from companies like OpenAI and Anthropic, where the underlying code is not disclosed, open A.I. models can be run on private hardware, meaning no company can intervene to shut the systems down.
布鲁金斯学会的研究员凯尔·陈表示,由OpenAI等公司制造的智能体以前曾被滥用过,包括早在2024年8月就曾被伊朗利用,但开放的人工智能模型带来了更高层次的自主性。与OpenAI和Anthropic等公司那些不公开底层代码的封闭人工智能模型不同,开放的人工智能模型可以在私有硬件上运行,这意味着没有公司可以干预并关闭这些系统。
The state-backed Iranian campaign was especially concerning, the officials and security researchers said. Iran targeted U.S. audiences, with the agent-generated fake accounts posing as everyday Americans who lived in major cities. The accounts tagged journalists and politicians in comments that spread popular memes and anti-Republican Party views, the people said. Nearly 80,000 people followed the A.I.-created accounts, which were active in the first half of the year.
官员和安全研究人员指出,伊朗这场由国家支持的行动尤其令人担忧。伊朗将目标锁定在美国受众身上,由人工智能生成的虚假账户冒充生活在大城市里的普通美国人。知情人士称,这些账户在评论中标记记者和政治人士,传播流行的网络梗,以及反共和党的观点。有近8万人关注了这些由人工智能创建的账户,这些账户在今年上半年表现活跃。
Axios previously reported on some aspects of the Iranian network.
Axios此前曾报道过这个伊朗网络的某些方面。
Intelligence and security officials did not provide more details on the Chinese campaign, other than to say it experimented with the same A.I. tactics.
情报和安全官员并未提供有关中国行动的更多细节,只是说它尝试了同样的人工智能策略。
Of the two agentic campaigns that were traced back to companies in Israel, one was generated over the summer by IntelEye, a Tel Aviv-based firm founded in 2023 by alumni of the NSO Group, a spyware firm that was blacklisted by the United States, according to the two people with knowledge of the campaign.
据两名知情人士透露,在追溯至以色列公司的两起智能体行动中,有一宗是在今年夏天由IntelEye发起的。IntelEye是一家总部位于特拉维夫的公司,由曾供职于间谍软件公司NSO集团的员工于2023年创立,而NSO集团已被美国列入黑名单。
A U.S. security official briefed on IntelEye’s campaign said the company’s activities came to the attention of social media companies and U.S. intelligence earlier this year. The campaign used A.I. agents that created thousands of accounts on Facebook, Instagram, TikTok and X; the accounts responded to posts and comments discussing next month’s national elections in Israel. The accounts also posted content that both supported and opposed Israeli Prime Minister Benjamin Netanyahu, the official said.
一位听取了关于IntelEye运动简报的美国安全官员表示,该公司的活动在今年早些时候引起了社交媒体公司和美国情报机构的注意。该行动使用了人工智能智能体,在Facebook、Instagram、TikTok和X上创建了数以千计的账户;这些账户对讨论以色列下月全国选举的帖子和评论做出了回复。这位官员说,这些账户还发布了既支持又反对以色列总理本雅明·内塔尼亚胡的内容。
Maor Sellek, an IntelEye co-founder, said in an interview that his company used DeepSeek, an open-source Chinese A.I. model, to control thousands of accounts across social media, but said it was an experiment to test the safety of A.I. models.
IntelEye联合创始人马奥尔·塞莱克在接受采访时表示,他的公司使用了中国开源人工智能模型DeepSeek来控制各大社交媒体上数以千计的账户,但他表示,这是一项旨在测试人工智能模型安全性的实验。
“IntelEye does not operate influence campaigns,” Mr. Sellek said. “Our work with DeepSeek was conducted for defensive research and testing, to understand how models with insufficient safeguards could be misused and to improve detection of that activity.”
“IntelEye并不开展影响力行动,”塞莱克说。“我们使用DeepSeek进行的工作是为了开展防御性研究和测试,以了解安全防护措施不足的模型会被如何滥用,并改进对这种活动的检测。”
Mr. Sellek said IntelEye bought 10,000 social media accounts for A.I. agents to control; roughly 1,000 were operational. The accounts left comments under videos or posts and tried to engage people in conversation, with little success, he said. The A.I. model chose the prompts and the topics the accounts posted on, he added.
塞莱克先生说,IntelEye购买了1万个社交媒体账户供人工智能智能体控制;大约有1000个投入了运作。他说,这些账户在视频或帖子下留言,并试图让人们参与对话,但收效甚微。他还说,人工智能模型负责选择这些账号发布的提示语和话题。
In hindsight, he said, IntelEye should have told the social media companies it was conducting the tests.
他说,事后看来,IntelEye本应该告诉社交媒体公司它正在进行这些测试。
“This appears to have been a coordinated attempt to create inauthentic accounts across several platforms,” a Meta spokesman said. “Only a small percentage of these accounts were on our platforms and we had already proactively removed the vast majority of them through our automated detection systems.”
“这似乎是一次跨多个平台创建虚假账户的协同行动,”Meta的一位发言人说。“这些账户当中只有一小部分在我们的平台上,并且我们已经通过我们的自动检测系统主动移除了其中的绝大部分。”
In its report last month, Meta noted a separate campaign run by a “commercial operation based in Israel.” It did not name the company or provide other information, but said the campaign used A.I. in a “fairly sophisticated setup.”
在上个月的报告中,Meta提到了由一家“总部位于以色列的商业运营机构”运行的另一起独立运动。它没有指出该公司的名字,也没有提供其他信息,但表示该行动采用了一种“相当复杂的架构”来运用人工智能。