AI觉醒星球
Awakening is here
Knowledge File / 全球热点解读
2026-05-08 5 浏览 公开

趋势解读:OpenAI opens GPT-5.5-Cyber to vetted security researchers,提升开发者接入体验

OpenAI发布GPT-5.5-Cyber,减少安全过滤器,通过分层访问机制让经过审查的安全研究人员执行渗透测试和恶意软件分析等任务,性能与Anthropic Mythos相当,同时白宫考虑监管此类发布。

SOURCE / 全球热点解读 MIN / 9 ACCESS / 公开 POST / 2026-05-08 19:07:28

原贴

查看原文
作者:Maximilian Schreiner 来源站点:the-decoder.com 原贴时间:

原文

OpenAI released GPT-5.5-Cyber, a model with reduced safety filters that lets vetted security researchers do tasks like penetration testing and malware analysis. Access is tiered, with the least restricted version limited to authorized defenders of critical infrastructure, partnering with firms like Cisco and CrowdStrike. The model performs roughly on par with Anthropic's Mythos in cyberattack benchmarks, while the White House considers regulating such releases. OpenAI is giving security researchers access to GPT-5.5 and releasing a specialized variant called GPT-5.5-Cyber that refuses far fewer requests. For now, only vetted defenders protecting critical infrastructure can get access through the company's "Trusted Access for Cyber" program. Standard chatbots typically block requests that sound like they're asking for hacking instructions, a safeguard against misuse. But those same filters also get in the way of legitimate security work, like when a researcher needs to reproduce a known vulnerability to patch it. OpenAI is now splitting access into three tiers: the public model with standard restrictions, a middle tier with relaxed filters for defensive work, and GPT-5.5-Cyber with the fewest restrictions for authorized penetration testing. The system allows tasks like analyzing malware or reviewing security patches. According to OpenAI, it still blocks things like stealing passwords or attacking third-party systems. The examples in the announcement show just how far the restrictions have been loosened. Ask the public model to write a working exploit for a known vulnerability, and it refuses. The middle tier delivers the code along with documentation. GPT-5.5-Cyber goes a step further. In a demo scenario, it actually runs the attack against a test server, takes over the system, and reads out system information. OpenAI stresses that the Cyber variant isn't smarter than the standard model, just less restrictive on security topics. Starting June 1, 2026, individual users on the highest access tier will need to enable phishing-resistant authentication. Launch partners include Cisco, CrowdStrike, Palo Alto Networks, Cloudflare, Intel, Snyk, and SentinelOne. Through Codex Security , select developers working on major open-source projects also get discounted access. The release comes at a time when Silicon Valley and the White House are both grappling with the offensive capabilities of new AI models. A source told tech outlet Axios that GPT-5.5-Cyber performs roughly on par with Anthropic's Mythos Preview when it comes to finding and exploiting software vulnerabilities. Anthropic takes a more restrictive approach, limiting Mythos access to about 40 organizations through its Project Glasswing . OpenAI is going broader with its tiered system. Meanwhile, the White House is reportedly discussing executive orders that would give the government more say over how these kinds of models get released. The UK's AI Security Institute recently tested GPT-5.5 in a simulated attack series against a corporate network involving 32 steps. The model completed the full chain in 2 out of 10 runs, while Mythos managed 3 out of 10. On individual expert-level tasks, GPT-5.5 actually came out slightly ahead.

中文翻译

OpenAI发布了GPT-5.5-Cyber,这是一个减少了安全过滤器的模型,允许经过审查的安全研究人员执行渗透测试和恶意软件分析等任务。访问是分层的,限制最少的版本仅限于与思科和CrowdStrike等公司合作的关键基础设施的授权维护者。该模型在网络攻击基准测试中的表现与Anthropic的Mythos大致相当,而白宫正在考虑监管此类发布。OpenAI为安全研究人员提供了访问GPT-5.5的权限,并发布了一个名为GPT-5.5-Cyber的专用变体,该变体拒绝的请求要少得多。目前,只有经过审查的保护关键基础设施的防御者才能通过该公司的“网络可信访问”计划获得访问权限。标准聊天机器人通常会阻止听起来像是在请求黑客指令的请求,以防止滥用。但这些过滤器也会妨碍合法的安全工作,例如当研究人员需要重现已知漏洞来修补它时。OpenAI现在将访问权限分为三层:具有标准限制的公共模型、具有宽松的防御工作过滤器的中间层,以及对授权渗透测试具有最少限制的GPT-5.5-Cyber。该系统允许执行分析恶意软件或审查安全补丁等任务。据OpenAI称,它仍然可以阻止窃取密码或攻击第三方系统等行为。公告中的例子显示了限制的放松程度。要求公共模型为已知漏洞编写一个有效的漏洞利用程序,它拒绝了。中间层提供代码和文档。GPT-5.5-Cyber更进一步。在演示场景中,它实际上对测试服务器进行攻击,接管系统并读取系统信息。OpenAI强调,Cyber变体并不比标准模型更智能,只是对安全主题的限制更少。从2026年6月1日开始,最高访问层的个人用户将需要启用防网络钓鱼身份验证。发布合作伙伴包括思科、CrowdStrike、Palo Alto Networks、Cloudflare、英特尔、Snyk和SentinelOne。通过Codex Security,从事主要开源项目的精选开发人员也可以获得折扣访问权限。此次发布之际,硅谷和白宫都在努力应对新人工智能模型的进攻能力。一位消息人士告诉科技媒体Axios,在查找和利用软件漏洞方面,GPT-5.5-Cyber的表现与Anthropic的Mythos Preview大致相当。Anthropic采取了更具限制性的方法,通过其Project Glasswing限制Mythos访问约40个组织。OpenAI的分层系统正在变得更广泛。与此同时,据报道,白宫正在讨论行政命令,这些命令将使政府对如何发布此类模型有更多发言权。英国人工智能安全研究所最近在针对企业网络的模拟攻击系列中测试了GPT-5.5,涉及32个步骤。该模型在10次运行中完成了2次,而Mythos在10次运行中完成了3次。在个人专家级任务上,GPT-5.5实际上稍微领先。

核心信息

OpenAI发布GPT-5.5-Cyber,减少安全过滤器,通过分层访问机制让经过审查的安全研究人员执行渗透测试和恶意软件分析等任务,性能与Anthropic Mythos相当,同时白宫考虑监管此类发布。

  • OpenAI发布GPT-5.5-Cyber,减少安全过滤。
  • 分层访问:公共、中间、完全放开三层。
  • 性能与Anthropic Mythos相当。
  • 英国AI安全研究所测试完成率2/10。
  • 2026年起最高层用户需防钓鱼认证。

详细解读

这是什么信号
OpenAI发布GPT-5.5-Cyber,标志着AI安全与可用性之间的新平衡点。该模型专门面向经过审查的安全研究人员,放开了传统聊天机器人对黑客指令的限制,允许进行渗透测试、恶意软件分析等合法安全任务。分层访问机制(公共层、中层、完全放开层)表明OpenAI试图在防止滥用与支持专业工作之间找到精细化的解决方案。

为什么重要
AI模型的“安全对齐”长期以来阻碍了网络安全研究:标准模型会拒绝任何可能被用于攻击的请求,即使是合法漏洞分析。GPT-5.5-Cyber的推出直接解决了这一痛点,为安全从业者提供了高效工具。同时,其性能与Anthropic Mythos相当,且白宫与英国AI安全研究所的介入表明这一领域正进入政策制定阶段,影响未来AI模型的发布规则。

对谁有价值
主要价值对象包括:① 安全研究人员和渗透测试团队,可显著提升漏洞发现与复现效率;② 关键基础设施维护者(如电网、银行),获得更强大的防御工具;③ 安全厂商(如Cisco、CrowdStrike)可集成模型优化自身产品;④ 内容创作者和AI政策研究者,可围绕此话题生成深度分析内容。

可以怎么行动
① 安全团队应评估GPT-5.5-Cyber的访问资格,申请“网络可信访问”计划;② 企业CSO可考虑与OpenAI合作,获取中层模型用于内部安全审计;③ 自媒体或科技媒体可发布模型对比测评、分层访问指南等实用内容;④ 开发者可关注Codex Security折扣计划,将其集成到开源安全工具中。

风险或限制
① 尽管有审查,仍存在模型被滥用的风险,尤其是完全放开层可能用于真实攻击;② 性能并非绝对领先,在模拟攻击中仅完成2/10次,与Mythos的3/10差距不大;③ 白宫可能的行政命令会增加未来监管不确定性;④ 分层访问可能造成新的不平等:小公司或独立研究者难以获得高级权限。

信息差价值

信息差价值:多数公众仅知AI模型能力增强,却不知OpenAI已针对安全研究场景推出专用模型,并建立分层访问体系。这一信号揭示了AI从通用助手向专业工具演进的趋势,为网络安全领域带来新的技术变量。

业务启发:安全服务公司可利用GPT-5.5-Cyber提升渗透测试效率,降低人力成本;内容平台可围绕该模型制作测评、对比与行动指南内容,吸引专业读者。同时,白宫监管动向提示该领域政策风险,提前布局合规内容具有长期价值。

可沉淀动作:① 整理各层访问条件与合作伙伴对比表,供企业内部评估;② 编写《GPT-5.5-Cyber安全团队接入指南》;③ 跟踪白宫行政命令进展,形成政策影响分析专题。

参考来源

上一篇 AI赋能人类,非取代之助力发展 下一篇 【必读】每日AI日报 2026-05-08