AI-Based Cybersecurity Attacks · 基于 AI 的网络攻击
| English | 中文 | Pinyin · 拼音 |
|---|---|---|
| deepfake/ˈdiːpfeɪk/ | 深度伪造 | shēn dù wěi zào |
| large language models/lɑːdʒ ˈlæŋɡwɪdʒ ˈmɒdlz/ | 大语言模型 | dà yǔ yán mó xíng |
| phishing/ˈfɪʃɪŋ/ | 钓鱼 | diào yú |
| shared secret/ʃeəd ˈsiːkrɪt/ | 共享秘密 | gòng xiǎng mì mì |
AI supercharges attacks
- A deepfake 深度伪造 clones a voice or face to impersonate someone on a call.
- Large language models (LLMs) 大语言模型 write perfect phishing 钓鱼 emails in any language.
- Bad grammar used to expose scams — AI removes that clue.
AI为攻击加力
- 深度伪造(deepfake)克隆声音或面孔,在通话中冒充某人。
- 大语言模型(large language models)用任何语言写出完美的钓鱼(phishing)邮件。
- 糟糕的语法曾暴露骗局——AI消除了这个线索。
AI on the back end
- Adversaries craft prompts to pull secret data out of an LLM.
- They plant false info online so it poisons an LLM's training data.
- AI scans the internet to gather facts about a target and even writes malware.
AI在后端
- 对手精心设计提示词,从LLM中套取秘密数据。
- 他们在网上植入虚假信息,以污染(poison)LLM的训练数据。
- AI扫描互联网收集目标信息,甚至编写恶意软件。
AI attack or AI defense? · AI 攻击还是 AI 防御?
AI is dual-use: the same technology helps adversaries attack and defenders protect. · AI 具有双重用途:相同的技术既帮助攻击者发动攻击,也帮助防御者进行保护。
An AI clone of a person's voice used to impersonate them is a... · 用于冒充某人的 AI 语音克隆体是……
A deepfake clones a voice or face. · 深度伪造克隆声音或面部。
How do LLMs make phishing emails more dangerous? · LLM 如何使钓鱼邮件更具危险性?
Perfect language removes the bad-grammar clue. · 完美的语言消除了语法错误的线索。
Defending against AI attacks
- Agree on a shared secret 共享秘密 word with close contacts to verify identity.
- Enable MFA so a cloned voice alone cannot log in.
- Never type sensitive data into a chatbot; verify AI output with real sources.
防御AI攻击
- 与亲密联系人约定一个共享秘密(shared secret)词来验证身份。
- 启用MFA,这样单靠克隆的声音无法登录。
- 切勿把敏感数据输入聊天机器人;用真实来源核实AI输出。
A voice on the phone that sounds exactly like your boss may be a deepfake. Verify a surprising or urgent request through a second channel before acting on it.
电话里听起来和你老板一模一样的声音,可能是深度伪造。在采取行动前,通过第二种渠道核实令人意外或紧急的请求。
Enabling MFA can stop an adversary who has only cloned your voice. · 启用 MFA 可以阻止仅克隆了您声音的对手。
A second factor blocks a voice-only attack. · 第二重因素可以阻断纯语音攻击。
A word known only to two people, used to verify identity, is a shared . · 仅两人知晓、用于验证身份的单词是共享。
A shared secret authenticates in high-stakes moments. · 共享秘密在高危时刻用于身份验证。
Which defend against AI-augmented attacks? (Choose all) · 哪些能防御 AI 增强的攻击?(多选)
Never type sensitive data into a chatbot. · 切勿向聊天机器人输入敏感数据。
An employee gets a video call from the "CEO" asking to wire money urgently. The face and voice are an AI deepfake. A prearranged shared secret question — "What did we name the project last week?" — would expose the fake instantly.
一名员工接到"CEO"的视频通话,要求紧急汇款。面孔和声音是AI深度伪造。一个事先约定的共享秘密问题——"我们上周给项目起了什么名字?"——会立即揭穿假冒。
AI lets adversaries make deepfakes, write flawless phishing, poison LLM data, and automate reconnaissance. Defend with a shared secret, MFA, and by never trusting AI output blindly.
AI让对手制作深度伪造、编写完美的钓鱼、污染LLM数据并自动化侦察。用共享秘密、MFA以及绝不盲目相信AI输出来防御。