郭莉莉, PEI-LIN WU2026年9月14日在中国,政府机构、企业以及近80%的公民都使用微信来处理业务、进行支付和沟通。 David Kirton/ReutersWeChat, a messaging app, is practically part of the national infrastructure in China, woven into daily communications, government services and digital payments.微信这款即时通讯应用在中国几乎已成为国家基础设施的一部分,融入了日常通信、政府服务和数字支付之中。That’s why a recent discovery by a small team of researchers in California — that a tool built with artificial intelligence could breach millions of accounts in just a few hours — has rattled experts and Chinese analysts. It proved that with A.I., even a tiny team with no government backing can mount a devastating attack on an app used by 1.4 billion people a month.正因如此,加利福尼亚州一个小型研究团队最近的发现——一种利用人工智能构建的工具可以在短短几个小时内攻破数以百万计的账户——让专家和中国分析人士感到震惊。这证明,有了人工智能,即使是没有政府背景的小型团队也能对一款每月有14亿人使用的应用程序发起毁灭性的攻击。“From a destruction standpoint, it’s extremely potent,” said Zhao Minghao, deputy director of the Center for American Studies at Fudan University in Shanghai. He said the ability to take down an app like WeChat, given its importance to the Chinese public and its huge user base, amounted to “a new kind of nuclear weapon.”“从破坏力的角度来讲这个是非常强的,”上海复旦大学美国研究中心副主任赵明昊说。他表示,鉴于微信对中国公众的重要性及其庞大的用户群,搞垮这样一款应用程序的能力相当于“一种新的核武器”。This discovery adds fuel to warnings from researchers that A.I. hacking capabilities are advancing faster than defenses can keep up, with tech leaders like Bill Gates warning that addressing risks from A.I. should be “the world’s top priority.”这一发现进一步印证了研究人员的警告:人工智能黑客能力的发展速度超过了防御手段的跟进速度;比尔·盖茨等科技领袖也警告称,应对人工智能带来的风险应成为“全球的首要任务”。That urgency could shape talks between President Trump and China’s leader, Xi Jinping, that are expected on Sept. 24 in Washington, where the two sides are expected to discuss A.I. security as well as trade and other issues.这种紧迫性可能会影响特朗普总统与中国领导人习近平预计于9月24日在华盛顿举行的会谈,届时双方预计将在会谈中讨论人工智能安全以及贸易和其他问题。New risks seem to surface almost daily. Anthropic, the company behind Claude and other A.I. models, said in a report on Thursday that it had disrupted plots by scientists to use its models for research that could have helped develop biological weapons.新的风险似乎每天都在出现。开发了Claude及其他人工智能模型的Anthropic公司在上周四的一份报告中表示,该公司挫败了一些科学家利用其模型进行研究的阴谋,这些研究有可能助长生物武器的研发。Anthropic also described attempts by a Chinese arms manufacturer to use Claude to refine a proposal for an anti-torpedo weapons system for the Chinese military. And it documented instances in which Chinese users tried to use Claude to build surveillance operations targeting foreign governments, Uyghurs in Syria and religious leaders. (Asked about the report, Mao Ning, a spokeswoman for China’s Foreign Ministry, said Friday that Beijing “opposed the distortion of facts and attempts to attack or smear China.”)Anthropic还描述了一家中国武器制造商试图利用Claude为中国军队完善反鱼雷武器系统方案的企图。此外,该公司还记录了中国用户试图利用Claude针对外国政府、在叙利亚的维吾尔人以及宗教领袖建立监控行动的实例。(在被问及该报告时,中国外交部发言人毛宁上周五表示,北京“反对歪曲事实、对中国进行攻击抹黑”。)In the WeChat hack, the researchers who developed the tool were with Calif, a security company based in Palo Alto, Calif., that says it makes such tools not to sell them but to bolster cyberdefense.在微信黑客攻击事件中,开发该工具的研究人员就职于总部位于加利福尼亚州帕洛阿尔托的安全公司Calif,该公司表示,制造此类工具不是为了出售,而是为了加强网络防御。They showed that the tool, which they named WeWorm, could hijack a WeChat user’s account, call their contacts and then spread from phone to phone without anyone ever answering a call. Calif said it took the company a little more than a week to build the bug and that it had disclosed the flaw to the White House and Tencent, the owner of WeChat.他们展示了这款被他们命名为WeWorm的工具,它可以劫持微信用户的账户,拨打其联系人的电话,然后在无需任何人接听电话的情况下,在手机之间传播。Calif表示,该公司花了一个多星期的时间构建了这个漏洞利用程序,并且已经向白宫和微信的母公司腾讯披露了该缺陷。In one sense, the news of WeWorm should make Beijing more eager to work with Washington to manage the risks posed by A.I., according to Kyle Chan, a fellow at the Brookings Institution focusing on Chinese technology and industrial policy.布鲁金斯学会专注中国科技和产业政策的研究员陈凯欣(Kyle Chan)认为,从某种意义上说,关于WeWorm的消息应该会让北京更渴望与华盛顿合作,以管控人工智能带来的风险。“It hints at the massive potential for other actors, nation-states or nonstate actors, to use A.I. to attack China’s digital infrastructure,” Mr. Chan said. “The stakes have gotten much higher as A.I. systems make leaps in cyber capabilities.”“这暗示了其他行为体、民族国家或非国家行为体利用人工智能攻击中国数字基础设施的巨大可能性,”陈凯欣说。“随着人工智能系统在网络能力方面取得飞跃进步,风险也大幅升高。”作为一个基本实现无现金化的社会,中国已逐渐依赖微信等移动支付服务来方便日常生活。But deep mutual suspicion between China and the United States could undercut talks. And the revelation of weapons like WeWorm, even as a simulation, could simply accelerate competition over who will wield the world’s most powerful A.I. models.但是,中美之间深深的互疑可能会削弱谈判的效果。而且,像WeWorm这类武器的曝光,即使只是作为一种模拟,也可能只会加速围绕谁将掌握世界上最强大的人工智能模型而展开的竞争。China, now acutely aware of the vulnerabilities in its digital infrastructure, will most likely want to beef up the defense capabilities of domestic A.I. systems to better spot and fix security flaws, said Mr. Zhao, of Fudan University.复旦大学的赵明昊表示,中国现在敏锐地意识到了其数字基础设施中的脆弱性,很可能会希望加强国内人工智能系统的防御能力,更好地发现和修复安全漏洞。The problem is that the U.S. side may then see those systems as potential tools to attack U.S. companies and institutions, pushing the U.S. to strengthen its own cyber defenses. “The boundary between defense and offense gets increasingly blurred,” Mr. Zhao said. “We can call this the A.I. security dilemma.”问题在于,美方随后可能会将这些系统视为攻击美国公司和机构的潜在工具,从而促使美国加强自身的网络防御。“Defense(防御)、offense(进攻) 这个界限越来越模糊了,”赵明昊说。“我们可以把它叫做AI security dilemma(人工智能安全困境)。”WeWorm and Anthropic’s report about abuses of its models are yet more evidence that the world’s two largest A.I. powers need a way to share information about bad actors or to clarify their intentions, experts say.专家表示,WeWorm和Anthropic关于其模型被滥用的报告进一步证明,世界上最大的两个人工智能大国需要找到一种方式来共享有关恶意行为者的信息,或澄清各自的意图。At the same time, few expect the summit to result in limits on the technology itself. Neither government is likely to agree to anything that restricts its own development of A.I. capabilities. But experts say there is value in at least establishing a channel of communication in the event of a crisis.与此同时,很少有人期望这次峰会能对技术本身做出限制。任何一国政府都不太可能同意任何限制其自身人工智能能力发展的条款。但专家表示,至少建立一条危机时的沟通渠道是有价值的。“This is an alarm, a wake-up call,” said Jiang Tianjiao, an associate professor at Fudan University focusing on emerging technologies, referring to WeWorm.“那肯定会是一个alarm(警告),可能是一个警醒吧,”复旦大学专注于新兴技术的副教授江天骄在提到WeWorm时说。“Everyone needs to sit down and discuss how A.I. raises safety and security risks that are very different from traditional issues, and whether we need new frameworks of cooperation,” he said.“大家需要坐下来讨论,人工智能是怎样带来和传统问题截然不同的安全和安保风险,以及我们是否需要新的合作框架,”他说。Even as China embraces A.I. as a strategic technology critical to its economy, officials have also begun to raise concerns about its risks.尽管中国将人工智能视为对其经济至关重要的战略技术,但官员们也已开始对其风险表示担忧。Chinese regulators have warned local governments and companies about using the A.I. assistant OpenClaw and in May released guidelines for how to regulate the use of A.I. agents. Officials are also working on more than a dozen new national standards to strengthen cybersecurity in the age of A.I. Mr. Xi, speaking in July at an A.I. conference, said countries should work together to “ensure that A.I. is always under human control.”中国监管机构已就使用人工智能助手OpenClaw向地方政府和企业发出警告,并于5月发布了关于如何规范人工智能代理使用的指导方针。官员们还在制定十多项新的国家标准,以加强人工智能时代的网络安全。习近平在7月的一次人工智能会议上发言时表示,各国应共同努力“确保人工智能始终处于人类控制之下”。Zhao Lei, director of the research office at the Central Party School, which trains Chinese Communist Party officials, warned in an essay published on WeChat on Thursday that extremist forces could leverage A.I. to design “highly transmissible and virulent pathogens” or to optimize weapons. This threat, he said, would “trigger a new kind of existential crisis for humanity.”培训中共官员的中央党校研究室负责人赵磊在周四发表于微信的一篇文章中警告说,极端势力可能会利用人工智能来设计“高传染性、高毒力的人工病原体”,或优化武器。他说,这种威胁将“引发新型的人类生存危机”。Last year, China’s cybersecurity authorities warned about the risk that extremist groups or others could use A.I. to learn how to design and build “nuclear, biological, chemical and missile weapons.”去年,中国网络安全部门曾警告称,极端组织或其他人可能会利用人工智能来学习如何设计和制造“核⽣化导武器”。Another issue hanging over A.I. safety talks with Washington is how transparent both sides would be. It is unclear whether Chinese A.I. firms would approach an American company if they found a flaw in their system, in the way that Calif described. Chinese firms are required to report such discoveries first to China’s Ministry of Industry and Information Technology.悬在中国与华盛顿人工智能安全谈判之上的另一个问题是双方的透明度如何。目前尚不清楚中国的人工智能公司如果在美国公司的系统中发现漏洞,是否会像Calif公司描述的那样与美国公司接触。中国公司被要求将此类发现首先报告给中国工业和信息化部。Pei Wang, a cybersecurity expert, said that Chinese companies would approach such disclosures “with caution,” given the risk that they could be politicized amid the intense tech competition between the two countries.网络安全专家王培表示,鉴于中美之间激烈的科技竞争,此类披露可能被政治化,因此中国企业会“谨慎”对待此类披露。中国领导人习近平7月在一场人工智能会议上表示,各国应通力合作,“确保人工智能始终处于人类控制之下”。China has long accused Washington of trying to hold back China’s technological progress with sanctions on Chinese companies, export controls cutting off the country’s access to advanced technology and tariffs on Chinese goods.长期以来,中国一直指责华盛顿试图对中国企业实施制裁、通过出口管制切断中国获取先进技术的渠道以及对中国商品加征关税,以这些手段来遏制中国的技术进步。The WeWorm vulnerability sends a signal to Beijing about American A.I. capabilities at the same time that U.S. officials have signaled new willingness to attack Chinese companies. On Tuesday, the deputy C.I.A. director, Michael Ellis, said that Chinese companies were a legitimate target for espionage in areas like artificial intelligence, semiconductors and biotechnology.WeWorm漏洞向北京发出了有关美国人工智能能力的信号,而与此同时,美国官员也释放出了攻击中国企业的新意愿。周二,美国中央情报局副局长迈克尔·埃利斯表示,在人工智能、半导体和生物技术等领域,中国企业是间谍活动的正当目标。Some Chinese scholars have suggested that American and Chinese officials could potentially discuss voluntary “negative lists” of unacceptable A.I.-enabled cyber activities or identify categories of critical infrastructure that are protected.一些中国学者建议,中美官员可就不可接受的人工智能网络活动讨论自愿性的“负面清单”,或确定受保护的关键基础设施类别。Chinese officials have not publicly acknowledged the disclosure of the WeChat hacking tool, perhaps in an effort not to add more tensions between the two countries before the summit. Ms. Mao, the foreign ministry spokeswoman, was asked about WeWorm at a news conference on Wednesday. She said she “was not familiar” with the issue.中国官员尚未公开承认这款微信黑客工具的披露,这或许是为了避免在峰会前加剧两国之间的紧张局势。在上周三的新闻发布会上,外交部发言人毛宁被问及WeWorm时,表示自己对此“不了解”。For Tencent, the hack is likely to draw intense scrutiny by Chinese regulators, said Xiaomeng Lu, who researches U.S.-China tech competition at Eurasia Group.欧亚集团研究美中科技竞争的鲁晓萌表示,对于腾讯而言,这次黑客事件可能会引来中国监管机构的严厉审视。“I wouldn’t be surprised if after this event agencies like the Cyber Administration of China invite some Tencent people over for tea and ask them exactly what happened and what’s the chance of something happening again,” Ms. Lu said.“如果在此次事件之后,像中国国家网信办这样的机构请腾讯的一些人去‘喝茶’,询问他们到底发生了什么,以及再次发生类似事件的几率有多大,我不会感到惊讶,”鲁晓萌说。Dustin Volz自华盛顿、Steve Lohr自首尔对本文有报道贡献。郭莉莉(Lily Kuo)是《纽约时报》报道中国记者,常驻台北。Pei-Lin Wu是《纽约时报》记者/研究员,报道台湾和中国新闻。翻译:纽约时报中文网点击查看本文英文版。