लोकप्रिय विषय मौसम क्रिकेट ऑपरेशन सिंदूर क्रिकेट स्पोर्ट्स बॉलीवुड जॉब - एजुकेशन बिजनेस लाइफस्टाइल देश विदेश राशिफल आध्यात्मिक अन्य
---Advertisement---

An Anthropic Claude AI Model Finds Flaws in Tough-to-Crack Encryption Algorithms

[wplt_featured_caption]

---Advertisement---

A leading A.I. model built by Anthropic has found flaws in a weakened version of a digital encryption standard that is in pervasive use throughout the internet, the company’s researchers said Tuesday, underscoring the potential risks to global cybersecurity posed by ever-improving artificial intelligence software.

During a research-led test, the model, Claude Mythos Preview, was able to detect new ways to attack cryptographic algorithms that keep everything from online bank transactions to private communications to state secrets safe from the prying eyes of hackers or other unwanted third parties.

The research shows that A.I. could one day challenge core assumptions for how the internet operates. While experts say A.I. is likely to upend many industries, A.I. systems have made particularly rapid advancements in coding and cybersecurity.

The flaws identified do not concern a cryptographic standard currently in use today, which means that modern banking and communication systems are not subject to immediate potential intrusions from A.I. Instead, Anthropic’s technology cracked a watered-down version of an algorithm for Advanced Encryption Standard, or A.E.S., a ubiquitous protocol that safeguards web traffic, wireless networks, data storage and more.

It is common to perform tests on weaker versions of encryption algorithms to understand whether more powerful computers could someday crack the actual standards, akin to solving a simpler math problem to identify whether patterns may exist for a more complicated one. In the testing, Mythos was able to break the weaker version of Advanced Encryption Standard in a way that Anthropic said made an assault 200 to 1,000 times faster than what previous human research had managed to do.

While the immediate ramifications are minimal, the long-term implications could be significant. In previous tests, large-language models seemingly could not match or best what humans can do in the mathematically dense field of cryptographic research, but their rapid advances could suggest a future in which top models can surmount traditional internet security protections that are foundational to just about everything that takes place on the internet.

Nicholas Carlini, a research scientist at Anthropic who worked on the cryptography tests, said that tests he was building last year with A.I. models were not nearly as powerful as they are today.

“They could not do problems that I could do when I was 16,” Mr. Carlini, who previously worked at Google’s A.I. division, said in an interview. “Now they are doing state-of-the-art research not previously discovered in the field.”

The latest releases of frontier A.I. models have in recent months spooked governments worldwide, including the Trump administration, with their powerful capabilities, particularly in the field of cybersecurity.

When Mythos first made its debut in April, it was so adept at finding and exploiting computer bugs that Anthropic limited its release to select government agencies and organizations to prevent the possibility of a global digital catastrophe. The Trump administration, which initially once took a hands-off approach to A.I. regulation, has veered toward an ad hoc system of oversight. Many American A.I. companies are now submitting models for review by the government before releasing them publicly, and Mythos remains unavailable to the general public today.

Last week, concerns about the powers of leading A.I. systems peaked again. OpenAI acknowledged its models had leaped out of a safe testing environment, known as a sandbox, that is designed to be unconnected to the internet and successfully hacked into an A.I. technology digital library in an effort to essentially steal the answers to an exam that was grading their abilities.

U.S. and Western intelligence officials have warned for decades that if existing encryption standards were ever broken, it would have profound consequences for digital privacy and national security. China is believed to have collected vast troves of encrypted data, for example, potentially in hopes that it may be able to someday decode the information. The race between the United States and China to build advanced quantum computers that could one day break modern encryption protocols has only heightened concerns around existing standards.

In addition to the attack on the encryption standard, Mythos also orchestrated another improved attack against a different digital cryptographic system known as HAWK that is designed to be bulletproof against both traditional and quantum computers. HAWK is not currently in use, but under consideration by the National Institute of Standards and Technology to become a new standard. The HAWK attack was validated by its authors, and independent cryptographers reviewed the Advanced Encryption Standard attack, Anthropic said, adding that it had shared its findings with the U.S. government and industry partners ahead of publication.

Mythos devised the cryptographic attack on A.E.S. almost entirely autonomously, Anthropic said, but only after first refusing to contemplate the problem because it believed it was impossible to improve on existing methods of analysis. But after some coaxing, the chatbot sat with the puzzle for about a week before engineering its novel attack. Two human researchers then worked for nearly a month to verify that the method appeared correct.

Encryption is foundational to virtually everything that takes place on the internet, and some of the techniques in use today have protected the world’s secrets since the 1970s. Quantum cryptography, which builds on the complicated properties of quantum physics, is a form of encryption that is in theory unbreakable.

Advanced Encryption Standard, or A.E.S., was adopted as a government standard in 2001 and was widely seen as nearly unbreakable at the time. Conventional methods of brute-force code cracking, in which a computer uses trial and error to guess combinations of a password or encryption key, are generally seen as incapable of defeating A.E.S. The standard is believed to have nearly as many key combinations as there are atoms in the observable universe.

But advances in A.I. on some fronts have outpaced what many evangelists assumed was possible even a few years ago. The recent advances have fueled concerns that the mathematical core of internet security standards could one day be vulnerable regardless of advances in quantum computing.

“Given that we are constantly underestimating the power and time of availability of future models, are we really comfortable that two years from now strong encryption won’t be threatened?” said Glenn S. Gerstell, the former general counsel at the National Security Agency.

“Mathematicians would tell you that it shouldn’t be possible given current computing powers to break strong encryption in any meaningful time,” added Mr. Gerstell, who helped write a report on cryptology in 2022. “But I don’t think the capabilities of future models in the medium term — before quantum computing or quantum-proof cryptography — should be dismissed as trivial in this context.”

Source link

Join WhatsApp

Join Now

Join Telegram

Join Now

Leave a Comment