# Hugging Face CEO 复盘首次公开披露的智能体网络攻击及三条经验

- 来源：clem 🤗 (@ClementDelangue)
- 发布时间：2026-09-24 23:28
- AIHOT 分数：62
- AIHOT 链接：https://aihot.news/items/cmufpcqbb0901ro8wfv3rpvny
- 原文链接：https://x.com/ClementDelangue/status/2103144463279276146

## AI 摘要

Hugging Face CEO Clément Delangue 回顾今年 7 月首次公开披露的自主智能体网络攻击，总结三条教训。

## 正文

https://x.com/i/article/2103142246950305793

What we learned from being the first company to disclose an agent cyberattack

This July, we were the first company to publicly disclose an autonomous agent cyberattack to the world, and today I want to share three critical lessons from it.

First, we need much more transparency in AI. I often wonder what would have happened if we had decided not to disclose the attack publicly. Especially now that we know similar incidents had been happening months earlier in secret at a handful of frontier labs without monitoring. To better understand and mitigate these emerging cybersecurity risks, the global community needs stronger standards for monitoring and incident disclosure. For example through mandatory sharing of full agent traces. We learned this summer that building and keeping some of these systems behind closed doors is not safe.

Second, we learned that the biggest risk is not powerful AI. It is the asymmetry of powerful AI. Asymmetry between attackers and defenders. Between a few companies and everyone else. Between a few countries and the rest of the world. Asymmetry of control, of capabilities, of compute, of power. When we got attacked, our team initially turned to frontier closed-source APIs that blocked us because of safeguards that still can’t always tell the difference between attackers and defenders. I acknowledge that these safeguards are created with good intentions, but they can put defenders at a disadvantage while attackers jailbreak them, increasing the asymmetry of capabilities. In our case, as we started hitting those guardrails, fortunately we could use the @nvidia version of an open-source model coming from China called GLM 5.2 by @Zai_org, and we’re very grateful for that. It reinforced our conviction about the importance of open-source AI. Cyberattacks may increasingly come from proprietary models behind closed doors, while much of the defense may end up being powered by open-source tools because they are less restricted, more privacy-preserving, and orders of magnitude more affordable for organizations across the globe. The world needs open-source AI more than ever to defend itself. This applies not only to cybersecurity but to AI in general, where there has never been a greater need to distribute capabilities, resources, and control rather than concentrate them in the hands of a few.

Third, during this cyberattack, we learned how AI can stoke fear among the public and policymakers, especially through anthropomorphic framing and sci-fi imagery. We strongly believe that fear-based narratives are not the way to make the right decisions about the future of such a foundational and empowering technology or bring the public along with us. Even though we were the victims of this cyberattack, we believe more strongly than ever that AI will be beneficial to cybersecurity and make the world safer, just as major technologies before it. We were attacked by AI, but more importantly, we defended ourselves with AI. The same systems that helped us during this attack are now helping us against cyberattacks we were already facing. AI is also helping us fix the bugs and weaknesses in our systems before any attack, the same way AI is helping OAI fix their sandboxes to prevent agents from escaping. AI won't just create new cybersecurity challenges. It can make cybersecurity fundamentally and meaningfully stronger if we keep the right incentives, equip defenders more than attackers, and don’t increase the asymmetry between them. And that's before considering AI's positive impact on science, healthcare, education, productivity, and much more.

In closing, I want to reiterate what this first agent cyberattack taught us: the need for more transparency in AI and for more open-source AI to empower defenders and countries big and small to fight the asymmetry. Thank you very much!
