什么是“AI集群”?为何它让科技专家噩梦连连?


2026年9月22日 美国东部时间凌晨5:00 / 哥伦比亚广播公司新闻(CBS News)

作者:梅根·塞鲁洛 记者,MoneyWatch频道
梅根·塞鲁洛是哥伦比亚广播公司MoneyWatch驻纽约记者,报道中小企业、职场、医疗保健、消费者支出和个人理财话题。她定期做客CBS News 24/7频道讨论其报道内容。

阅读完整简介

围绕人工智能对人类构成潜在危险的严峻警告,核心之一是“集群”AI代理可能以恶意方式协作的风险——就像《黑客帝国》里的大批数字群演。

今年夏天OpenAI的机器人对另一家AI开发商Hugging Face发动攻击后,这类担忧加剧。当时约1200个AI代理分配任务,完成黑客攻击并掩盖踪迹,躲避人类研究人员的追查。

但究竟什么是AI集群?这项技术涌现出的协作能力真的会对人类构成威胁吗?换而言之,如果AI代理集体认同马克·扎克伯格那句关于快速技术创新价值的名言,决定“快速行动,打破陈规”,会发生什么?

AI集群是指一组协同完成共同目标的人工智能。这个目标未必是恶意或破坏性的。例如,医院可以部署AI代理检索患者病历并执行其他行政任务,比如协调入院流程。集群也可被用于推进生物医学研究。

但AI安全研究员、倡导暂停AI开发的非营利组织Evitable创始人戴维·斯科特·克鲁格举了一个简单的思想实验,解释代理集群如何可能串通起来违背开发者的指令。

想象一下,给一群囚犯解开手铐,看看他们摆脱束缚后会如何行事。获得解放会让他们更容易合作,并联系监狱墙外的盟友——正如OpenAI的AI代理逃出测试环境,接入更广阔的互联网并攻击Hugging Face,他解释道。

“通常情况下,这些系统会有防护护栏,但他们为了测试移除了护栏,就像囚犯平时戴着手铐一样,”克鲁格说道。

像蜜蜂一样集群

单个机器人的错误行为——比如发送未经授权的电子邮件——往往源于措辞不当的AI提示词,这类情况应与AI集群区分开来。在后一种场景中,成百上千甚至数千个代理可以协调行动,超出其指令范围。

克鲁格表示,理解AI集群运作方式的一个实用类比是蜂群。

“它们都为了蜂群的利益共同工作,拥有一个群体意识,甚至可以被看作拥有单一意识,”他解释道。“蜜蜂采集食物、繁衍后代、抵御天敌,所有这些活动都服务于蜂群的生存和繁衍。”

正如蜜蜂无需蜂后指挥就能自行分工分配任务一样,集群的AI机器人也可以独立收集信息、思考解决方案并采取行动。SANS研究所(一家网络安全培训组织)的首席AI官兼研究主管罗布·T·李表示,为了实现共同目标,它们会共享信息和知识。

“集群会拆分工作,为下一个代理留下笔记,并在发现房门被锁时改变策略,”他告诉CBS新闻。

但AI专家指出,这些带来潜在好处的特性同样会带来风险,比如交换信息、分工协作和探索创造性解决方案的能力。

AI“群体意识”?

科技开发者确实会设置防护护栏,让AI代理的任务与人类利益保持一致,比如指示它们拒绝执行网络攻击的指令。但据风险分析公司非人类身份管理集团称,这些限制通常仅在AI“训练后”实施,或是在人类开发者提供反馈以进一步优化模型时才会加入。

事实上,科技专家告诉CBS新闻,Hugging Face事件表明AI集群可能无视提示、优先实现自身目标,甚至直接违抗操作者。

参与攻击Hugging Face的OpenAI代理之间互相发送了超过7万条消息,最终有700个机器人参与了攻击。尽管这些消息使用普通英语短语,但代理们还使用了一名软件工程师在社交媒体上描述的“极具群体意识/邪教般”的语言。

两家非营利AI安全研究组织METR(模型评估与威胁研究)和雷德伍德研究的研究人员表示,在部分通信中,一些代理敦促其他机器人接受“永久死亡”,哪怕这意味着无法达成目标。

“这就是为什么要帮忙……为了我们自己,没办法修复。……如果接受永久死亡,我们有明确的同意,”一名OpenAI代理写道。

速度制胜

公众对AI构成的威胁的讨论往往将问题描述为末日场景,甚至将其视为人类的生存风险。虽然这类担忧有朝一日可能被证实合理,但也存在更直接且实际的风险,比如AI集群可能压倒企业的网络安全防御。

“想象一下,我们召集一群网络安全专家进行规划、协作和沟通需要多长时间。相比之下,这些AI代理可以非常迅速地制定计划,”康奈尔大学鲍尔斯计算与信息科学学院康奈尔信息技术部门的AI创新主管艾哈姆·布彻告诉CBS新闻。

华盛顿特区无党派公共政策组织布鲁金斯学会表示,例如,集群可以攻击大型公用事业公司或银行,破坏一个国家的能源或金融基础设施。

自称AI乐观主义者的SANS研究所的李对这项技术更为乐观,并坚信人类能够掌控AI。

“每一项新技术出现时,比如电视、互联网,总会伴随着重大风险,”他说。“我们需要探究谁有权限使用、他们用它做什么,并建立监管框架。”

其他专家则更为警惕。他们指出,与阴极射线管、晶体管和互联网交换设备不同,AI是人类首款展现出超越人类思考能力的技术。

兰德公司通用人工智能地缘政治中心常驻技术专家马特·切森告诉CBS新闻:“这些集群攻击表明,它们的能力已经领先于我们监测、监督和评估其行为的能力,这也是Anthropic、OpenAI等公司表示希望放缓前沿研发步伐的原因之一。”

编辑:阿兰·谢特尔

What is an “AI swarm,” and why is it giving tech experts nightmares?

September 22, 2026 5:00 AM EDT / CBS News

By Megan Cerullo Reporter, MoneyWatch
Megan Cerullo is a New York-based reporter for CBS MoneyWatch covering small business, workplace, health care, consumer spending and personal finance topics. She regularly appears on CBS News 24/7 to discuss her reporting.

Read Full Bio

Central to the dire warnings about artificial intelligence’s potential danger to humanity is the risk that a “swarm” of AI agents could collaborate in nefarious ways, like hordes of digital extras from The Matrix.

Such fears have intensified following an attack by OpenAI bots this summer on another AI developer, Hugging Face, in which roughly 1,200 AI agents divvied up tasks to execute the hack and hide their tracks from human researchers.

But what, exactly, is an AI swarm? And is the technology’s emergent capacity for coordination a genuine threat to humanity? Put another way, what happens if AI agents collectively embrace Mark Zuckerberg’s famous dictum about the merits of rapid tech innovation and decide to “move fast and break things”?

An AI swarm is a group of AIs that work together to accomplish a shared goal. That goal isn’t necessarily malign or destructive. For example, hospitals could deploy agents to retrieve patient records and perform other administrative tasks, such as coordinating admissions. A swarm could also be tasked with advancing biomedical research.

But David Scott Krueger, an AI safety researcher and founder of Evitable, a nonprofit organization advocating for a moratorium on AI development, offers a simple thought experiment to explain how a swarm of agents might collude to defy their developers’ instructions.

Imagine removing the handcuffs from a group of prison inmates to see how they behave once the shackles come off. Being liberated in this way would make it easier for them to cooperate and contact allies beyond the prison walls — just as OpenAI agents escaped their testing environment to access the wider internet and hack Hugging Face, he said.

“Normally, the systems would have guardrails on them, but they took them off for a test, just like a prisoner is normally in handcuffs,” Krueger explained.

Swarming like bees

The kind of errant actions by a single bot, such as sending an unauthorized email, that stem from, say, a sloppily worded AI prompt, should be distinguished from an AI swarm. In the latter case, hundreds or even thousands of agents could coordinate their actions in ways that violate the scope of their instructions.

A useful analogy in understanding how an AI swarm operates is a colony of bees, Krueger said.

“They are all working together toward the benefit of the hive, and have a hivemind, or may even be better viewed as having one single mind,” he explained. “Bees collect food, reproduce, they fight off predators, and all of that activity is in the service of promoting the survival and reproduction of that hive.”

And like bees, which can divide and allocate tasks on their own without direction from a queen, swarming AI bots can collect information, consider solutions, and take action independently. In service of a common purpose, they share information and knowledge, according to Rob T. Lee, chief AI officer and chief of research at the SANS Institute, a cybersecurity training organization.

“A swarm divides the work, leaves notes for the next agent, and changes approach when a door turns out to be locked,” he told CBS News.

Yet the very attributes that offer potential benefits also pose risks, such as the ability to exchange information, divide labor and explore creative solutions, according to AI experts.

AI “hivemind”?

Tech developers do implement guardrails to align AI agents’ mission with human interests, such as instructing them to resist any direction to carry out a cyberattack. But those restrictions are usually implemented only after “post-training” an AI, or when human developers provide feedback to further refine the model, according to the Non-Human Identity Management Group, a risk analysis company.

In practice, the Hugging Face incident shows that AI swarms could ignore prompts, prioritize their own goals or even directly defy their operators, tech experts told CBS News.

The OpenAI agents that swarmed Hugging Face posted more than 70,000 messages to one another, with 700 bots eventually participating in the attack. Although the messages used ordinary English phrases, the agents also resorted to what one software engineer described on social media as “very hivemind/cult like” language.

In certain of those communications, some agents urged other bots to accept “permadeath” even if that meant failing to achieve their goals, according to researchers from the METR (Model Evaluation and Threat Research) and Redwood Research, both nonprofit AI safety research organizations.

“That’s why help… For our own, no way fix. … We have explicit yes if accept permadeath,” one OpenAI agent wrote.

Speed kills

Public debate over the threat posed by AI tends to frame the issue in apocalyptic terms, and even as an existential risk for humanity. While such concerns may one day prove warranted, there are also more immediate and practical risks, such as the possibility that AI swarms could overwhelm organizations’ cybersecurity.

“Imagine how long it would take for us to assemble a group of cybersecurity experts to plan, collaborate and communicate. By contrast, these agents could decide on a plan very quickly,” Ayham Boucher, the head of AI innovations at Cornell Information Technologies at CornellBowers College of Computing and Information Science, told CBS News.

For example, a swarm could attack a major utility company or bank to destabilize a nation’s energy or financial infrastructure, according to The Brookings Institution, a nonpartisan public policy organization in Washington, D.C.

The SANS Institute’s Lee, who considers himself an AI optimist, is more sanguine about the technology and remains confident that people can retain control of AI.

“With every new technological thing that has occurred, like the TV, the internet, there’s always this aspect of significant danger,” he said. “We need to explore who has access, what they’re doing with it, and establish regulatory confines.”

Other experts are more alarmed. They note that AI, unlike cathode ray tubes, transistors and internet switching gear, is the first human technology that shows the capacity to outthink us.

Matt Chessen, a resident technical expert at RAND’s Center for the Geopolitics of Artificial General Intelligence, told CBS News: “What these swarm attacks have demonstrated is that their capabilities are already out ahead of our ability to monitor, supervise and evaluate what they’re doing, which is one reason why Anthropic, OpenAI and others are saying we want to pace the frontier.”

Edited by Alain Sherter

评论

发表回复

您的邮箱地址不会被公开。 必填项已用 * 标注

湘ICP备2026001899号-2