Daily Tech Briefing
AI 科技速览

每天 5 分钟内学习 AI。获取最新的人工智能新闻,理解其重要性,并学习如何将其应用于您的工作。

AI 快讯
NVIDIA Blog · 2026/8/4 13:00:47

AI Leaders Propose SAFE Guidelines for Cybersecurity Transparency

AI 中文解读
核心亮点:AI行业巨头们联手推出了一套“SAFE”网络安全指南,要把发生在AI身上的“安全事故”变成全行业的“免疫疫苗”,让所有智能体都学会防攻击。 通俗解读:现在的AI智能体就像小区里的新保安,各家各户的安保水平参差不齐。SAFE指南就像是给所有保安装了一个“事故通报系统”——一旦有可疑份子试图闯入,系统会立刻加密记录这次攻击、提醒邻居加固门窗、分析哪些门锁容易被撬,最后公布一份“防贼攻略”,让大家共同提高警惕。NVIDIA、Cisco等120多家科技公司都在参与制定这套规则。 实际影响:今后你使用AI客服、智能法律顾问或自动驾驶时,背后会有一道更牢固的集体安全网。如果某个AI遭到恶意攻击,整个行业都会在短时间里收到警报并快速修补漏洞,避免同样的黑客手段在金融、医疗等场景里重复得逞。你的隐私数据和重要文件,会因为这种“共享情报”机制得到更靠谱的保护。
Members of the Open Secure AI Alliance — now more than 120 organizations strong — are developing new guidelines to strengthen agentic AI cybersecurity as the annual Black Hat conference begins in Las Vegas today.  The Linux Foundation today shared a Request for Comments on Shared AI Findings Exchange (SAFE), a proposed set of guidelines designed to turn agentic cybersecurity incidents into shared protection for the entire ecosystem. The SAFE guidelines are being drafted by an Open Secure AI Alliance working group. NVIDIA, Cisco, CrowdStrike, Hugging Face and Red Hat are among Open Secure AI Alliance members working with the Linux Foundation to contribute to the initial proposal. The SAFE guidelines include proposals to confidentially collect and analyze AI incidents and near misses, inform those impacted, identify recurring control failures and publish evidence-based operating recommendations that reduce systemic risk. Cybersecurity is a race without a finish line. Every major technology shift has created new potential attack surfaces. Defenders must move now at agent speed to respond rapidly to protect infrastructure and intellectual property — and the best way to do that is together. When trusted ecosystems share threat intelligence openly, collective defense becomes a force multiplier. Open Secure AI Alliance Delivers More Tools for AI Cybersecurity The SAFE framework adds to technology contributions Open Secure AI Alliance members are making as part of a shared commitment to building and sharing open, inspectable tools across the full AI security stack.   An AI agent isn’t just a model. It’s a system — identity controls, harnesses, guardrails, logs and evaluation — and securing it requires more than vulnerability scanning.  Security has always been strongest in the layers — and in the community’s willingness to share what it knows. The hardest problems get solved when defenders learn from each other, openly and at speed. Full Stack of Open NVIDIA Cybersecurity Software and Models NVIDIA’s contributions run the length of the stack, starting with the NVIDIA Labs Object-Oriented Agent (NOOA) research harness, on GitHub — which makes agent behavior easier to test, trace, audit and govern.  The NVIDIA OpenShell runtime restricts what an agent can see, touch and do — enforcing security and privacy controls at the agent level, so an agent can’t reach what it shouldn’t.  NVIDIA’s open model families — NVIDIA Nemotron for agentic AI, NVIDIA Cosmos for physical AI, NVIDIA Isaac GR00T for robotics, NVIDIA BioNeMo for healthcare and life sciences, and NVIDIA Alpamayo, the world’s largest model for autonomous vehicles licensed for commercial use — ship with open weights, datasets and training techniques.  NVIDIA open source verified agent skills extend that trust to the capability layer.  Each skill provides portable instruction sets — cataloged, scanned for risks such as prompt injection and tools poisoning, cryptographically signed and documented with a skill card. Defenders know exactly what an agent skill does, where it came from and whether it was modified after publication. NeMo Guardrails, NeMo Anonymizer and NeMo Safe Synthesizer help enforce safety policies, protect sensitive data and generate privacy-safe synthetic data. And Garak, NVIDIA’s open source LLM vulnerability scanner, lets security teams check models for data leaks, prompt injections and jailbreak scenarios before they ship.  Alliance Members Expand Tools for Open Ecosystem Development Other members of the Open Secure AI Alliance have also been building across the full defensive stack, spanning identity and permissions, harnesses, runtime guardrails, security AI models, observability and evaluation, data security and privacy, availability and resilience, and more.  Some of the latest contributions across different layers of the stack are highlighted below, with more continuing to arrive. Identity and Permissions — Who Gets to Act You can’t secure what you can’t id
分享
阅读原文